Privacy Policy
Your privacy is fundamental. This policy explains what we collect, why we collect it, and how we protect it. We are GDPR-ready and privacy-by-design.
What we collect
Account data: Email, name, and hashed password (bcrypt). OAuth profile data if you sign in via Google/GitHub.
Link data: Original URLs, short codes, titles, and settings (expiry, password hash). We never store the plaintext of password-protected links.
Analytics data: Click events contain truncated/hashed IP, country (GeoIP), device, browser, OS, and referrer. Raw IPs are never stored. Bot traffic is flagged and excluded from aggregates.
Operational data: API logs (request ID, status, latency) with automatic redaction of tokens, emails, and cookies.
How we use it
- Provide the service (shorten, redirect, analytics, QR)
- Secure your account and prevent abuse
- Improve performance and reliability (aggregated metrics only)
- Communicate service updates (you can opt out of marketing)
Data deletion & export
Go to Dashboard → Settings or use the API: GET /api/v1/export and DELETE /api/v1/user. Deletion is immediate and irreversible — backups are purged within 30 days. This satisfies GDPR Article 17.
Contact
Data Protection Officer: privacy@yas.sh — response within 30 days. EU representative: yas.sh EU Ltd., Bratislava, Slovakia.