Information recorded about link activity
When a short link redirects a request, the service records the request IP address and a separate keyed hash of that address, created with HMAC, for unique-visit counts. The hash does not replace the stored IP address or make the activity record anonymous.
Activity records also include the visit time, the short link used, the referring page when supplied, the user-agent string, the detected browser, operating system and device category, the HTTP request method, an estimated bot flag, and whether the visitor continued after an intermediate page. Country and region are recorded when supplied in request headers.
These records support activity reporting and service operation. Authenticated dashboard users can access link activity reports. Counts, inferred device details, and geographic information may be incomplete or approximate.
Accounts, links, domains, and messages
An account stores a username and a password hash. Link records include destinations, titles, descriptions, settings, creation and update dates, creator information, and any content or uploaded media supplied for intermediate pages. Custom-domain records include hostnames and related DNS and provisioning information.
If you use the contact form, the service stores your submitted name, email address, message category, message, and any short-link details you provide. Site administrators can read those submissions to handle support inquiries, abuse reports, and privacy requests. Include only what is needed to explain your request; do not send passwords or other secrets.
If you open a support ticket while signed in, the service stores its subject, topic, status, messages, and the account that opened it. Your ticket is visible to your account and site administrators. Replies and status changes remain in the ticket history. Do not include passwords, CAPTCHA secret keys, or payment details in a message.
Application records are stored in the site's database under the operator's control. The host and application can also produce operational logs used to investigate errors and maintain the service.
Cookies and browser storage
Protected authentication cookies maintain signed-in sessions. Anti-forgery cookies help protect form submissions. These cookies use the application's data-protection system. An administrator preview cookie supports switching dashboard views.
Browser local storage remembers your theme and, when applicable, dashboard panel preferences. You can clear cookies and local storage through your browser. Clearing authentication cookies signs you out, and blocking form-protection cookies can prevent a form from submitting.
Optional external services and embedded content
When configured, a page may use Cloudflare Turnstile or Google reCAPTCHA for verification, or Google advertising. Those providers receive information through their embedded services and apply their own privacy practices. Review Cloudflare's privacy policy and Google's privacy policy for details about their processing.
Where Google advertising is enabled, Google and its partners may use cookies or similar technologies to serve and measure ads. Ads may be personalized using information such as earlier visits to this or other websites, depending on provider settings and applicable choices. You can manage Google's personalized advertising through My Ad Center and manage cookies in your browser.
Link creators may include HTML, advertising, or media on intermediate pages. That content can make requests to additional external services. Browser privacy settings can affect how embedded content, advertising, or verification widgets work.
Destination websites are independent
After you follow a short link to its destination, that website's operator controls its content, cookies, and collection of information. This policy describes the short-link service; it does not describe the destination website's practices.
Retention and requests about your information
The operator can configure an automatic retention period for detailed link activity; without that configuration, activity records do not expire automatically. Lifetime link counters remain when older activity is removed. Account and contact records do not have a fixed automatic expiry. Deleting a link removes its associated activity and uploaded media from the application database. Other account, operational, and contact records may remain; the treatment of any host backups is separate.
Use the contact page to ask about information concerning you or request a correction or deletion. Provide enough detail to identify the relevant account, link, or earlier message. The operator may need to verify your request and consider operational or legal requirements.
This policy may be updated as the service changes. The current version is published on this page.