Last updated: July 2026
When you follow a short link, your IP address is not stored. It is resolved to country, region and city in memory, then truncated and folded into a checksum whose key changes every day. Once the key has been replaced, the checksum can no longer be traced back to you — not even by us.
The redirect domain sets no cookies and does not access your device. That is why there is no consent banner: §25 of the German TDDDG, which requires consent for cookies, only applies where information stored on your device is accessed. No such access takes place.
We do not pass data on for advertising, we do not build profiles of individuals, and we do not recognise anyone across multiple links or multiple days.
The controller for the processing of personal data within the meaning of Art. 4(7) GDPR is:
Philipp Ecker Unterhüttensölden 11 94481 Grafenau Deutschland
No data protection officer has been appointed; the conditions of §38 BDSG are not met. Please direct data protection enquiries to the address above.
This service processes data in two distinct roles, and which one applies determines who to address your rights to.
For processing on behalf of others we conclude an agreement pursuant to Art. 28 GDPR with the operators of workspaces.
When you follow a short link, your request reaches us with the information every browser sends: IP address, user agent, possibly the page you came from (referer) and your preferred language. This information is evaluated and then discarded. Only the result of that evaluation is stored.
Specifically, we store:
| What is stored | What it is derived from | What is not stored |
|---|---|---|
| Country, region, city | resolving the IP address against a local database | the IP address itself |
| Device type, operating system, browser | a coarse classification of the user agent (e.g. “mobile, iOS, Safari”) | the verbatim user agent, in particular version numbers |
| Referring domain | the hostname from the referer | the path and parameters of the referring page |
| Language | the language part of Accept-Language (e.g. “de”) | the region subtag |
| Time, short link, type of access | the request itself (link, QR code or API) | — |
| Campaign parameters (utm_source, utm_medium, utm_campaign) | the short link’s address, where present | any other parameters |
| A visitor checksum | see the following section | every value it was computed from |
To be able to show “142 clicks from 96 visitors”, a repeat request has to be recognisable as such. We use a checksum for this rather than an identifier. It is produced as follows:
Once the previous day’s key has been replaced, nothing can be derived from the stored checksum. Matching “which checksum belongs to this IP address” is impossible without the key, even by exhaustive search. From that point on we therefore regard the stored click data as anonymous within the meaning of Recital 26 GDPR.
Within the current day the checksum is a pseudonym and thus personal data. For that period we base the processing on Art. 6(1)(f) GDPR. The legitimate interest is reach measurement for the creator of the short link; we have weighed it against your interests and limited the processing to what is necessary — in particular by truncating the IP address, rotating the key daily and including the link identifier.
To use the service with an account we process your email address and, where provided by you or supplied by a sign-in provider, your name and profile picture. The legal basis is Art. 6(1)(b) GDPR — the data is necessary to provide the service.
Three ways to sign in are available: a one-time sign-in link by email, a passkey on your device, or signing in via GitHub or Google. We do not store a password. When signing in via GitHub or Google, that provider learns that you are signing in here; what data it processes itself is governed by its own privacy policy.
For each session we store a coarse device description such as “Chrome on macOS” so that you can spot and end sessions you do not recognise. The session token itself is held only as a checksum; reading the database does not allow anyone to sign in.
For every short link we store the destination address and the details you supply, such as the short name, title, note and tags. Please note that destination addresses may themselves contain personal data, for example in parameters.
If you have the link preview imported automatically from the destination, our server calls up the destination page once in order to read its title, description and preview image. The operator of the destination page sees our server’s IP address, not yours. Calls into internal or private networks are technically prevented.
Every destination address is checked against Google Safe Browsing and the URLhaus list from abuse.ch when the link is created and after every update of those lists. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is protecting users and preventing misuse of our service.
During this check your destination address never leaves our server. We merely download a list of shortened checksums from Google and match against it locally. Services that transmit the full address for checking — such as VirusTotal or the Safe Browsing lookup API — are deliberately not used, because private destination addresses would end up with third parties and in some cases become publicly searchable.
If you report a short link, we store the reason, your description and — only if you supply it voluntarily — your email address for follow-up questions. Reports can also be made without an address. Interventions by our administrators are logged so that decisions remain traceable.
Every report, appeal and enquiry submitted through the contact form becomes a case with a state and a history, so that nothing is left lying around and you receive an answer. If you left no address we still handle the case — we just cannot reply.
If you reply to an email from [email protected], your reply is automatically attached to the matching case and stored there. The same applies to mail you send to that address unprompted. Automatically generated messages — out-of-office replies, mailing lists, delivery failure notices — are discarded, as are messages our mail server classifies as spam.
We do not sell data and do not pass it on for advertising purposes. Transfers take place only in the following cases:
Beyond this we disclose data where we are legally obliged to do so, for example on the order of an authority or a court.
Processing takes place on servers within the European Union. Downloading the blocklists and the location database involves a connection to providers in the USA; no data about you is transmitted in the process, only files are retrieved. If you sign in via GitHub or Google, a transfer to the USA takes place on the basis of the EU-US Data Privacy Framework or the standard contractual clauses.
You have the following rights vis-à-vis the controller:
For access, portability and deletion of your account you do not need to write to us — both are available while signed in under “Settings”.
One limitation we must disclose: for stored click data we cannot provide access or carry out erasure. We store nothing that would allow an individual click to be attributed to a person — after the daily key rotation the attribution is technically impossible, including for us. Under Art. 11(2) GDPR we are in that case not obliged to collect additional data solely in order to comply with these rights. That is precisely what the design is built for.
Independently of this, you may lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is: Bayerisches Landesamt für Datenschutzaufsicht, https://www.lda.bayern.de. You may also contact the authority where you live.
We adapt this policy when the service changes or the legal situation requires it. The version published here is the one that applies; the date is given above.