YOUR DATA

Only what makes your links work.

We store your Google account identifier, display name, handle, destinations, connected custom domains, application sessions, purchase and subscription references, profile branding, link history, campaign settings, collaborator memberships, hashed invitations and API keys, and reports. Your profile and enabled links are public. Your Google identifier and purchase records are private.

Google handles sign-in, Stripe handles card payments, and Cloudflare hosts this service and verifies human submissions. We do not store card details or raw visitor IP addresses. For subscribed workspaces, we count clicks in daily aggregates by link, campaign, referring hostname, country, and device category. Country may be derived by Cloudflare from the request; we do not retain the IP. Referrer paths and arbitrary query parameters are not stored. We filter known bots and previews. Analytics is retained for 12 months on Pro and 24 months on Studio; after cancellation, existing history is retained for up to 12 months. We keep at most 50 earlier versions per link or shared destination. Customers can use external HTTPS images for branding; those image hosts receive the visitor’s image request. Campaign links attach the customer’s configured UTM campaign fields to the destination URL. These providers process information under their own policies.

Essential cookies keep you signed in. Profile owners with an active subscription may connect their own Google Analytics, Plausible, or PostHog account. Studio also includes an optional reverse proxy, which forwards supported analytics scripts and events through the profile domain to the configured provider. For accurate location and visitor counts, the proxy forwards the visitor IP address to that provider but does not retain it or forward account cookies or authorization headers. Proxy usage is counted monthly, with a separate allowance of one million requests per workspace; proxy delivery pauses at that allowance and direct links keep working. Their chosen provider receives visitor requests and usage data on that public profile, including on connected custom domains, under its own policies. Google Analytics and PostHog load or receive events only after you choose Allow analytics; you can change that choice using Analytics preferences on the profile. This choice is saved separately for each profile and site in your browser. Plausible runs without analytics cookies. PostHog receives a random session identifier; session replay, autocapture, and person profiles are disabled. Supported integrations honor browser Global Privacy Control and Do Not Track preferences. Profile URLs omit query strings and fragments when sent by our integration. These integrations measure profile visits and link selections; they do not run on our dashboard or on direct short-link redirects. External analytics configuration is public, uses no private API keys, and pauses when the subscription expires. You can export your links or delete your account in settings. Deletion removes your public content, analytics, API credentials, workspace memberships, and login access; a reserved handle and necessary purchase records remain. Backups expire on the hosting provider's recovery schedule. Contact jhgaylor@gmail.com for privacy questions.