Legal

Privacy Policy

The short version: we collect the minimum needed to run a link shortener and stop it being abused. No tracking cookies, no advertising, no data sales.

Last updated: July 2026Applies to: short.msyb.dev

1. What we collect

When you shorten a link

  • The destination URL you submitted, and the short code we generated for it.
  • Your IP address and browser user-agent string.
  • A timestamp.

The IP address and user-agent are kept so we can trace and act on abuse, and enforce rate limits. They are never shown publicly.

When someone clicks a short link

  • A timestamp.
  • The visitor’s IP address, used to count unique visitors and detect abuse.
  • The referring page, if the browser sends one.
  • An approximate country, derived at the network edge. Never a precise location.
  • Browser, operating system and device type, derived from the user-agent.
  • Whether the request looked like a bot or a link-preview crawler.

When you contact us or report a link

  • Your name (contact form only), email address and message.
  • Your IP address and user-agent, for spam prevention.

2. What we do not collect

  • No tracking or advertising cookies. The only things stored in your browser are your theme preference and your own recent links, both of which stay on your device.
  • No third-party analytics or advertising scripts.
  • No accounts, passwords, or payment details for public use of the service.
  • No precise geolocation, and no cross-site tracking of any kind.

3. What is public

Aggregate click statistics for a short link, meaning totals, daily trends, referrer domains, countries and device types, are visible to anyone with the link. Individual visitor records, IP addresses and user-agents are never public and are only accessible to site administrators.

4. Why we are allowed to hold it

Where the UK or EU GDPR applies, our lawful basis is legitimate interest: operating the service, producing the analytics we advertise, and preventing fraud and abuse. For messages you send us, the basis is your consent in sending them.

5. How long we keep it

  • Links: for as long as the link exists. Removed links are retained in a disabled state so the same code is not reissued.
  • Click records: indefinitely in aggregate. The per-visit rows carrying IP addresses are what a deletion request removes.
  • Messages and reports: until resolved and archived.
  • Administrator audit logs: retained for security review.

6. Who we share it with

Nobody, other than the infrastructure providers needed to run the service, meaning our hosting platform and our database provider, which process it on our behalf. We will disclose data if legally compelled to.

7. Your rights

You can ask us to confirm what we hold about you, correct it, or delete it. Message us through the contact form with enough detail to identify the record, such as the short link in question or the email address you used. We respond within 30 days.

8. Security

All traffic is served over HTTPS and database connections are TLS-encrypted. Administrator accounts use hashed passwords, short-lived signed sessions, and rate-limited sign-in with automatic lockout.

9. Children

The service is not directed at children under 13, and we do not knowingly collect their personal data. If you believe we have, contact us and we will delete it.

10. Changes

We may update this policy. Material changes will be reflected in the “last updated” date above.