Last updated: 2026-10-10. This statement covers the stalelink command-line
tool (source).
stalelink reads documents you point it at on your local disk (PDF, DOCX, XLSX, PPTX, Markdown, HTML, and plain text), extracts links from them, and checks whether those links are alive. It is a local tool: document contents never leave your machine.
For every link found in a document, stalelink issues an HTTP(S) request to that link's URL (HEAD first, GET where needed) to determine its status. The only data sent to those hosts is the URL request itself plus the configured User-Agent header. No document content, file names, or directory structure is transmitted.
Link checks run in one of three authentication tiers, controlled by
--auth off|cookies|browser:
--browser) so that links behind login walls can be checked.
Matching cookies are attached as request headers only to the link's own host;
cookie values are never sent elsewhere, logged, or persisted by stalelink.--cdp-url debugging endpoint you provide) to re-check hosts that
block non-browser requests. Browser cookies and credentials stay inside the
browser profile; stalelink does not export them.These credential-reading capabilities exist solely to authenticate requests to document-derived link targets. No credentials are transmitted to any third party.
stalelink keeps a local SQLite database (verdicts.sqlite3) in your
operating system's per-user cache directory (or STALELINK_CACHE_DIR
when set). Each row stores a checked URL, its verdict, the check timestamp, and
the auth tier used. The cache stays on your machine and is never uploaded.
Cached verdicts expire after a TTL (default or your --cache-ttl
value) and are refreshed on later scans. You can bypass the cache with
--no-cache and delete it entirely with stalelink cache
clear. Backup files written by fix --backup
(<name>.<ext>.bak) remain next to the originals until you
delete them. Uninstalling stalelink does not remove the cache directory or
backups; delete them if you want them gone.
stalelink has no telemetry, analytics, crash reporting, accounts, advertising,
or update check-ins. It makes no network requests other than the link checks
described above (and, when --auth browser is used, the browser's own
traffic under its profile). Everything it reads and writes stays local unless a
link target you asked it to check is on the network.
Questions: GitHub Issues.