EvidenceBound Privacy Policy
This policy describes how EvidenceBound, maintained by Ruslan Vrublevskyi, handles information on evidencebound.org and in the owner-authorized LinkedIn publishing integration.
Minimal data by design.
Website content
The public EvidenceBound site is primarily static. EvidenceBound does not intentionally request LinkedIn credentials, passwords, private messages, payment information, or sensitive profile data through this website.
Infrastructure logs
The site is hosted through Vercel and source/deployment workflows use GitHub. Those infrastructure providers may process ordinary request, security, deployment, and service logs under their own terms and privacy practices.
Data used for authorized publishing.
When the EvidenceBound LinkedIn integration is explicitly authorized, it may process only information needed to verify authority, publish approved content, and record bounded operational receipts.
Identifiers and authority
Authenticated LinkedIn member identifier, EvidenceBound organization identifier, and organization role/authorization results needed to prove that the caller may act for the requested LinkedIn surface.
Approved content
Post commentary, article-link metadata, image/document metadata and approved media that the maintainer has chosen to publish.
Operational receipts
LinkedIn publication resource identifiers, content hashes, timestamps, API version, readback status, and workflow metadata used for auditing and duplicate prevention.
Tokens are credentials, not content.
LinkedIn OAuth access tokens and any refresh tokens or client credentials are treated as secrets. They are intended to remain only in approved secret stores such as GitHub Actions Secrets or an explicitly configured server-side secret store. They are not intentionally committed to source code, drafts, receipts, issues, pull requests, public logs, or published content.
Authorization
LinkedIn permissions are granted by the authenticated member through LinkedIn's own authorization flow or Developer Portal tooling. EvidenceBound requests only permissions required for the enabled use cases.
Revocation
The LinkedIn member may revoke application access through LinkedIn account settings. EvidenceBound will stop using a revoked or expired credential and fails closed when required authority cannot be verified.
Keep only what supports the control record.
Retention
Approved source-controlled drafts may remain as project records. Publication receipts may be retained for the period needed for audit and duplicate prevention; current GitHub Actions receipt artifacts are configured with a 90-day retention window. OAuth credentials are retained only while valid and operationally required, subject to revocation and provider expiry.
Service providers
Information may be processed by LinkedIn, GitHub/GitHub Actions, and Vercel when those services are used to authorize, build, host, publish, or verify the integration. EvidenceBound does not sell personal data to advertisers.
Access, deletion and questions.
For questions about this policy, a request to remove EvidenceBound-controlled operational data, or a request to stop an authorized integration, contact ruslan@evidencebound.org. Requests can only apply to data controlled by EvidenceBound; LinkedIn, GitHub and Vercel retain and process information under their own policies and controls.