Privacy Policy
Last updated October 9, 2026
The short version
We collect the minimum needed to run a URL shortener: your links, anonymous click analytics, and — if you create an account — your name, email, and a bcrypt hash of your password. We never store raw IP addresses, we don't run third-party trackers, and we don't sell anything because there's nothing to sell.
Data we store
When you shorten a link, we store:
- The short slug and the destination URL
- An optional title you give the link
- The account that created it, if you were logged in — otherwise the link is anonymous
When someone opens a short link, we store one analytics row with:
- The referring page, if the browser sends one
- Device type, browser, and operating system, derived from the user agent
- A daily-salted SHA-256 hash of the visitor's IP address — never the address itself
- The timestamp of the click
If you register an account, we also store your name, email address, and a one-way hash of your password.
What we deliberately don’t do
- No raw IP addresses — the daily-salted hash can't be reversed to identify a visitor
- No third-party analytics, ad pixels, or trackers
- No selling or sharing of data with data brokers
- No email marketing lists
Cookies
TinyLink uses a single session cookie to keep you logged in to your dashboard. It is set when you log in and expires when you log out. There are no advertising or tracking cookies.
Data retention
Links persist until you delete them — they never expire on their own by default. Analytics rows live as long as their link does. Account data is kept until you ask us to remove it.
Your choices
You can delete any link (and its analytics) from your dashboard at any time. To request deletion of your account and all its data, contact us via the contact page.
Changes to this policy
If we change how TinyLink handles data, this page will be updated with a new “last updated” date. Material changes will be announced on the homepage.