Privacy
Last updated
urli.sh shortens links and counts the clicks on them. That means two different people’s data passes through it: the creator who makes a link, and the visitor who taps one. This page covers both, and keeps them separate, because what we hold about each is very different.
The short version for visitors: we never store your IP address, short links set no cookies, and nothing here can tell that two clicks came from the same person.
If you tap a short link
You are a visitor. We record one row per click so the creator can see how their link performed. That row holds:
- the country, region, city and continent our host derives from your connection at the edge;
- your browser, operating system and device type, and the user-agent string they were read from;
- the referring site, if your browser sent one, and any campaign tags in the link;
- the address you were sent to, and the time.
What we deliberately do not collect
Your IP address is never stored. Our host uses it at the edge to work out roughly where you are, and we keep only that result. The address itself never reaches our database and never appears in a log we keep.
Short links set no cookie and read no storage. There is no identifier of any kind attached to you, which means we cannot tell that two clicks came from the same person, cannot build a profile, and cannot follow you between links. That is a property of how the redirect is built, not a promise we are asking you to take on trust.
No analytics scripts run on a short link. The redirect is served without a page, so no third-party script loads and nothing runs in your browser.
If you have an account
You are a creator. We hold:
- your email address, and a password that is stored only as a hash by our authentication provider;
- the links you create — destinations, titles, notes, tags, campaign tags, any custom preview text or image you upload, and any domain you connect;
- click records for your own links, as described above;
- if you subscribe, your Stripe customer and subscription identifiersand when the paid period ends. Card numbers are entered on Stripe’s own checkout page and we never see or store them;
- anything you send us through the feedback form.
The dashboard and this marketing site use Vercel Analytics and Speed Insights for aggregate page views and loading performance. Neither runs on a short link.
Who else processes it
We use these services to run urli.sh. We do not sell personal data, and we do not share it for advertising.
- Supabase
- The database and sign-in. Everything above is stored here.
- Vercel
- Hosting and the edge that serves redirects, plus aggregate analytics on the app pages.
- Stripe
- Payments. They handle card details; we never receive them.
- Resend
- Sending email — the welcome message and trial notices.
- Anthropic
- Screening destinations for phishing and malware when a link is created. Only the destination URL is sent, never anything about you or your visitors, and links to well-known platforms skip it entirely.
How long we keep it
Account and link data is kept until you delete it or ask us to close your account.
Click records currently have no automatic expiry — they are kept indefinitely. We would rather say that plainly than claim a retention period we do not yet enforce. We intend to introduce a limit; until we do, you can ask us to delete the click history on your links at any time and we will.
Your choices
You can edit or delete any link, and its click history goes with it. You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete your account and everything attached to it. Write to us through the feedback form in your dashboard and we will act on it.
Because click records contain no identifier for a visitor, we cannot find “your” clicks from an email address or an IP — there is nothing in the row to match against. That is a consequence of collecting less, and it is the trade we chose.
Security
Traffic is served over HTTPS. Each account can reach only its own rows, enforced by the database rather than by the application, so a bug in a page cannot expose another creator’s links.
No system is perfectly secure, and we cannot promise one. We do not accept responsibility for loss or harm caused by unauthorised access we did not cause, by a breach at one of the providers listed above, or by someone getting hold of your password. The full position is in the terms of service, under Liability.
Children
urli.sh is not intended for anyone under 16, and we do not knowingly create accounts for them.
Changes
If this page changes materially we will update the date at the top and, for anything that affects what we collect, tell account holders by email.
Contact
Questions, requests, or anything that looks wrong: the feedback form in your dashboard. See also the terms of service.