Skip to content
Y
YAS.SH
PRIVACY • LAST UPDATED AUGUST 2026

Privacy Policy

Your privacy is fundamental. This policy explains what we collect, why we collect it, and how we protect it. We are GDPR-ready and privacy-by-design.

Minimal Collection
We store hashed IPs (HMAC, daily salt), never raw IPs. No fingerprinting.
Encrypted At Rest
AES-256 for backups, TLS 1.3 in transit, HSTS preloaded.
Your Rights
Export or delete all your data via the API or dashboard — instantly.

What we collect

Account data: Email, name, and hashed password (bcrypt). OAuth profile data if you sign in via Google/GitHub.

Link data: Original URLs, short codes, titles, and settings (expiry, password hash). We never store the plaintext of password-protected links.

Analytics data: Click events contain truncated/hashed IP, country (GeoIP), device, browser, OS, and referrer. Raw IPs are never stored. Bot traffic is flagged and excluded from aggregates.

Operational data: API logs (request ID, status, latency) with automatic redaction of tokens, emails, and cookies.

How we use it

  • Provide the service (shorten, redirect, analytics, QR)
  • Secure your account and prevent abuse
  • Improve performance and reliability (aggregated metrics only)
  • Communicate service updates (you can opt out of marketing)

Data deletion & export

Go to Dashboard → Settings or use the API: GET /api/v1/export and DELETE /api/v1/user. Deletion is immediate and irreversible — backups are purged within 30 days. This satisfies GDPR Article 17.

Contact

Data Protection Officer: privacy@yas.sh — response within 30 days. EU representative: yas.sh EU Ltd., Bratislava, Slovakia.

This is a template — replace with counsel before production. See also Cookies and Terms.
🍪 Cookies & privacy. yas.sh uses only essential cookies to keep you signed in and remember your preferences. We do not run third-party trackers. See our cookie policy and privacy policy.
Settings