Privacy policy

Last updated: July 2026

The short version

When you follow a short link, your IP address is not stored. It is resolved to country, region and city in memory, then truncated and folded into a checksum whose key changes every day. Once the key has been replaced, the checksum can no longer be traced back to you — not even by us.

The redirect domain sets no cookies and does not access your device. That is why there is no consent banner: §25 of the German TDDDG, which requires consent for cookies, only applies where information stored on your device is accessed. No such access takes place.

We do not pass data on for advertising, we do not build profiles of individuals, and we do not recognise anyone across multiple links or multiple days.

1. Controller

The controller for the processing of personal data within the meaning of Art. 4(7) GDPR is:

Philipp Ecker Unterhüttensölden 11 94481 Grafenau Deutschland

Phone
+49 160 3212781

No data protection officer has been appointed; the conditions of §38 BDSG are not met. Please direct data protection enquiries to the address above.

2. Two roles: our own service and processing on behalf of others

This service processes data in two distinct roles, and which one applies determines who to address your rights to.

As controller
for everything to do with accounts: sign-in, workspace, the management interface, outgoing email and abuse checks. Here we are your point of contact.
As processor
for the click figures of our users’ short links. Whoever creates a short link decides on the purpose and means of that analysis; we merely carry it out technically. If you followed someone else’s short link, its creator is your first point of contact. Write to us anyway — we will forward your request as far as we are able.

For processing on behalf of others we conclude an agreement pursuant to Art. 28 GDPR with the operators of workspaces.

4. How visitor counting works without recognition

To be able to show “142 clicks from 96 visitors”, a repeat request has to be recognisable as such. We use a checksum for this rather than an identifier. It is produced as follows:

  • Your IP address is truncated first: for IPv4 the last block is dropped (to /24), for IPv6 everything from the fourth block onwards (to /48). The exact connection is therefore already absent before the calculation begins.
  • A SHA-256 value is computed from a randomly generated daily key, the truncated IP address, the user agent and the identifier of the short link. 132 bits of it are stored.
  • The random key exists only in the volatile memory of our cache and is replaced every day. It is never backed up.
  • The short link’s identifier is included deliberately. As a result the same browser produces two entirely different checksums for two different short links — recognition across multiple links is therefore ruled out.

Once the previous day’s key has been replaced, nothing can be derived from the stored checksum. Matching “which checksum belongs to this IP address” is impossible without the key, even by exhaustive search. From that point on we therefore regard the stored click data as anonymous within the meaning of Recital 26 GDPR.

Within the current day the checksum is a pseudonym and thus personal data. For that period we base the processing on Art. 6(1)(f) GDPR. The legitimate interest is reach measurement for the creator of the short link; we have weighed it against your interests and limited the processing to what is necessary — in particular by truncating the IP address, rotating the key daily and including the link identifier.

5. Retention periods

Individual clicks
90 days by default, then deleted automatically. Owners and administrators of a workspace can change the period under “Settings”; 90 days is the upper limit. Shortening deletes older events on the next cleanup run and cannot be undone.
Aggregated figures
Daily and hourly totals per attribute (such as “on 14 July, from Germany, 37 clicks”) are kept beyond that. They contain no visitor checksum and cannot be attributed to a person.
Account and short links
until the account is deleted.
Sign-in sessions
at most 30 days; immediately upon sign-out.
Abuse reports and the record of interventions
until the review is complete, and beyond that for as long as the decision needs to remain traceable.
Cases (reports, appeals, enquiries)
The description text and, if provided, your email address are deleted 90 days after the case is closed. The period starts when the case is closed, not when it arrives — a case under review for longer does not vanish mid-process.
Data exports
The generated file is deleted seven days after it was produced.
Profile pictures
until you replace or remove the picture, at the latest when the account is deleted.

6. Account, sign-in and dashboard

To use the service with an account we process your email address and, where provided by you or supplied by a sign-in provider, your name and profile picture. The legal basis is Art. 6(1)(b) GDPR — the data is necessary to provide the service.

Three ways to sign in are available: a one-time sign-in link by email, a passkey on your device, or signing in via GitHub or Google. We do not store a password. When signing in via GitHub or Google, that provider learns that you are signing in here; what data it processes itself is governed by its own privacy policy.

For each session we store a coarse device description such as “Chrome on macOS” so that you can spot and end sessions you do not recognise. The session token itself is held only as a checksum; reading the database does not allow anyone to sign in.

7. Cookies

No cookies are set on the redirect domain. On the main domain two cookies are used, both strictly necessary within the meaning of §25(2)(2) TDDDG and therefore exempt from consent:

CookiePurposeLifetime
ctx_sessionkeeps you signed in; not readable from JavaScriptup to 30 days
NEXT_LOCALEremembers your language choiceuntil you close the browser

Without an account and without changing language, no cookie is set. There are no analytics or advertising cookies.

9. Protection against malware and phishing

Every destination address is checked against Google Safe Browsing and the URLhaus list from abuse.ch when the link is created and after every update of those lists. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is protecting users and preventing misuse of our service.

During this check your destination address never leaves our server. We merely download a list of shortened checksums from Google and match against it locally. Services that transmit the full address for checking — such as VirusTotal or the Safe Browsing lookup API — are deliberately not used, because private destination addresses would end up with third parties and in some cases become publicly searchable.

If you report a short link, we store the reason, your description and — only if you supply it voluntarily — your email address for follow-up questions. Reports can also be made without an address. Interventions by our administrators are logged so that decisions remain traceable.

Every report, appeal and enquiry submitted through the contact form becomes a case with a state and a history, so that nothing is left lying around and you receive an answer. If you left no address we still handle the case — we just cannot reply.

If you reply to an email from [email protected], your reply is automatically attached to the matching case and stored there. The same applies to mail you send to that address unprompted. Automatically generated messages — out-of-office replies, mailing lists, delivery failure notices — are discarded, as are messages our mail server classifies as spam.

10. Recipients and processors

We do not sell data and do not pass it on for advertising purposes. Transfers take place only in the following cases:

Hosting
Nürnberg - Deutschland. The provider processes the data on our instructions under an agreement pursuant to Art. 28 GDPR.
Location lookup
IP addresses are mapped to locations using MaxMind’s GeoLite2 database, which we download regularly and run locally. Nothing is transmitted to MaxMind during the lookup itself.
Blocklists
We regularly download lists from Google (Safe Browsing) and abuse.ch (URLhaus). No user data and no destination addresses are transmitted in the process.
Sign-in providers
GitHub or Google — only if you choose that way of signing in.
Outgoing email
Sign-in links and notifications are sent via a mail server we operate ourselves. No external delivery provider is involved.

Beyond this we disclose data where we are legally obliged to do so, for example on the order of an authority or a court.

11. Transfers to third countries

Processing takes place on servers within the European Union. Downloading the blocklists and the location database involves a connection to providers in the USA; no data about you is transmitted in the process, only files are retrieved. If you sign in via GitHub or Google, a transfer to the USA takes place on the basis of the EU-US Data Privacy Framework or the standard contractual clauses.

12. Your rights

You have the following rights vis-à-vis the controller:

  • Access to the data processed about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)

For access, portability and deletion of your account you do not need to write to us — both are available while signed in under “Settings”.

Access and portability (Art. 15, 20 GDPR)
Under “Settings → Data export” you can generate a complete copy of your data as JSON. The file is available for seven days and is deleted afterwards. Individual click events are not included: they concern the visitors of your links rather than you, and Art. 15(4) GDPR protects those third parties. Aggregated figures are included; per-link event data is available as CSV in the dashboard.
Erasure (Art. 17 GDPR)
Under “Settings → Delete account”. After the request your access is locked and the account is deleted for good after 30 days. During that time you can still sign in and cancel the request; afterwards the deletion is irreversible.
Remaining rights
For rectification, restriction and objection an informal message via the contact form or to [email protected] is sufficient. We respond within one month.

One limitation we must disclose: for stored click data we cannot provide access or carry out erasure. We store nothing that would allow an individual click to be attributed to a person — after the daily key rotation the attribution is technically impossible, including for us. Under Art. 11(2) GDPR we are in that case not obliged to collect additional data solely in order to comply with these rights. That is precisely what the design is built for.

Independently of this, you may lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is: Bayerisches Landesamt für Datenschutzaufsicht, https://www.lda.bayern.de. You may also contact the authority where you live.

13. Changes to this policy

We adapt this policy when the service changes or the legal situation requires it. The version published here is the one that applies; the date is given above.