TinylinkBack to home

Privacy Policy

Last updated October 9, 2026

The short version

We collect the minimum needed to run a URL shortener: your links, anonymous click analytics, and — if you create an account — your name, email, and a bcrypt hash of your password. We never store raw IP addresses, we don't run third-party trackers, and we don't sell anything because there's nothing to sell.

Data we store

When you shorten a link, we store:

  • The short slug and the destination URL
  • An optional title you give the link
  • The account that created it, if you were logged in — otherwise the link is anonymous

When someone opens a short link, we store one analytics row with:

  • The referring page, if the browser sends one
  • Device type, browser, and operating system, derived from the user agent
  • A daily-salted SHA-256 hash of the visitor's IP address — never the address itself
  • The timestamp of the click

If you register an account, we also store your name, email address, and a one-way hash of your password.

What we deliberately don’t do

  • No raw IP addresses — the daily-salted hash can't be reversed to identify a visitor
  • No third-party analytics, ad pixels, or trackers
  • No selling or sharing of data with data brokers
  • No email marketing lists

Cookies

TinyLink uses a single session cookie to keep you logged in to your dashboard. It is set when you log in and expires when you log out. There are no advertising or tracking cookies.

Data retention

Links persist until you delete them — they never expire on their own by default. Analytics rows live as long as their link does. Account data is kept until you ask us to remove it.

Your choices

You can delete any link (and its analytics) from your dashboard at any time. To request deletion of your account and all its data, contact us via the contact page.

Changes to this policy

If we change how TinyLink handles data, this page will be updated with a new “last updated” date. Material changes will be announced on the homepage.