LinkStacked

Part 14 — Trust & Safety

Trust & Safety

How we protect LinkStacked, our creators, and every visitor who clicks a link.

Last updated: June 6, 2026Effective: June 6, 2026Operator: Devpitch UG (haftungsbeschränkt)
01

Overview

LinkStacked's Trust & Safety framework operates on three levels:

  • Proactive technical safeguards — automated systems that prevent harmful content from reaching the platform in the first place.
  • Community reporting — a trusted system for users to flag content that violates our policies.
  • Human review — our trust and safety team reviews reports, escalations, and high-risk accounts manually.

Our policies are grounded in German law (Netzwerkdurchsetzungsgesetz / NetzDG), the EU Digital Services Act (DSA), and applicable international standards including the INHOPE network's guidance on illegal online content.

02

Child safety — absolute priority

We maintain the following measures:

Detection

  • Photo hash scanning using Microsoft PhotoDNA or equivalent technology to detect known CSAM
  • Automated detection of keywords and patterns associated with grooming or child exploitation
  • Proactive monitoring of accounts that link to external platforms flagged for CSAM by law enforcement

Response

  • Immediate permanent account termination upon detection — no warning, no appeal
  • Mandatory reporting to the German Federal Criminal Police Office (BKA) and to the National Center for Missing & Exploited Children (NCMEC) CyberTipline within 24 hours of detection, as required by US law (18 U.S.C. § 2258A) and best practice for GDPR-compliant platforms
  • Content preserved for law enforcement use under legally required retention obligations
  • Referral to INHOPE member hotlines in the relevant country

Age requirements

  • Users must be at least 13 years old to create a LinkStacked account
  • We do not allow minors to participate in commerce features (digital product sales, tip collection) without verifiable parental consent
  • Accounts we have reason to believe belong to a child under 13 are terminated and data deleted
03

Self-harm & crisis content

We take content related to self-harm and suicide seriously. Our approach is guided by safe messaging guidelines from mental health organisations.

  • Content that provides detailed methods, encouragement, or "how-to" instructions for self-harm or suicide is prohibited
  • Content that graphically depicts or promotes self-harm in a way that may normalise or encourage it is prohibited
  • Content that targets or encourages at-risk individuals to harm themselves is subject to immediate removal and account suspension

What we allow

Personal narratives about mental health struggles, recovery, grief, and lived experience are permitted and valued. We also allow:

  • Links to mental health resources, crisis lines, and support organisations
  • Discussion of mental health topics in an educational, supportive, or advocacy context
  • Content from mental health professionals, therapists, or researchers
04

Dangerous organisations & violent extremism

LinkStacked may not be used to promote, represent, or recruit for:

  • Organisations designated as terrorist organisations by Germany, the EU, the UK, or the UN Security Council
  • Organisations with a documented history of mass violence, genocide, or ethnic cleansing
  • Groups that promote or plan acts of terrorism, political violence, or insurgency
  • Neo-Nazi, white supremacist, or other groups that promote violent racial ideology
  • Organised crime groups or cartels

This includes: creating profiles for these organisations, sharing their propaganda, using their symbols or slogans, or fundraising on their behalf. Accounts engaged in this activity are permanently terminated and reported to relevant authorities.

05

Anti-spam measures

We maintain several technical layers to prevent spam and inauthentic activity:

  • Email verification required for all new accounts — disposable email domains are blocked
  • Rate limiting on account creation per IP and per email domain
  • CAPTCHA on account creation and login flows for unusual patterns
  • Automated detection of profile content that matches known spam patterns (repeated link farms, affiliate redirect chains)
  • Redis-backed rate limiting on all public API endpoints and profile visits
  • Monitoring for abnormal traffic spikes that may indicate coordinated view inflation
07

Inauthentic activity detection

We monitor for signals of inauthentic activity including:

  • Abnormal profile view counts relative to account age and social footprint
  • Sudden spikes in link click rates inconsistent with organic traffic patterns
  • Multiple accounts sharing the same payment method, device fingerprint, or IP range
  • Account creation patterns matching mass-registration toolkits
  • Coordinated behaviour across accounts (identical bios, same-time activity, shared links)

Accounts found to be artificially inflating metrics or engaging in coordinated inauthentic behaviour have their analytics data corrected, their engagement zeroed, and face suspension or termination depending on severity.

08

Account security

We protect your account with multiple layers of security. Our technical security measures are documented in the Privacy Policy — Security section. Key user-facing security features include:

  • Two-factor authentication (TOTP) — enable at Settings → Security → Two-factor authentication
  • Active session management — view and revoke any active session at Settings → Security → Sessions
  • Login notifications — receive an email alert when a new device logs in to your account
  • Password breach detection — we check passwords against known breach databases at login
  • Security headers and HTTPS enforcement on all pages and API endpoints
09

Data protection in safety

Our safety enforcement activities involve processing personal data (reports, account data, moderation logs). We process this data under our legitimate interest in maintaining a safe platform (GDPR Article 6(1)(f)).

  • Moderation records are retained for up to 3 years to document enforcement decisions and support appeals
  • We share data with law enforcement only where legally required or where we have a good-faith belief it is necessary to prevent serious harm
  • We do not sell safety-related data to any third party
  • We may share anonymised, aggregated safety statistics in transparency reports
10

Contact our safety team

General safety

For reports, concerns, and non-urgent safety issues.

safety@linkstacked.com

CSAM / emergency

Child safety or immediate harm. We respond within 1 hour.

safety@linkstacked.com — subject: URGENT

Law enforcement

For legal process, court orders, or official requests.

legal@linkstacked.com

Security vulnerabilities

Responsible disclosure. Response within 72 hours.

security@linkstacked.com

Questions about this policy?

Contact our legal team at legal@linkstacked.com or privacy@linkstacked.com for data matters. We respond within 5 business days.

All policies