Privacy Policy
Last updated
Linky is a URL shortener operated by Ajinkya Dhotre. This page explains what data the service stores, why, and how to get it removed. It is written to describe what the software actually does — if the behaviour described here and the behaviour of the service ever disagree, the service is the bug.
Data you give us
- Account details — your name, email address and, optionally, a profile photo. Your password is stored only as a bcrypt hash; it is never stored or logged in plain text.
- Links you create — the destination URL, the short code, and any options you set (password, expiry, one-time use, tags). Link passwords are also stored hashed.
Data collected when a link is clicked
Linky exists to report on clicks, so each visit to a short link is recorded. For every click we store the time, the referring page, the browser, operating system and device type derived from the user agent, and a country-level location derived from the IP address.
- We do not sell click data or share it with advertisers.
- We do not set advertising or cross-site tracking cookies.
- Click data is visible only to the owner of the link (and to a site administrator for abuse handling).
Cookies
Linky sets one cookie, linky_at. It is an httpOnly, SameSite session cookie holding your access token, and it exists so that opening a private short link directly in a browser can check that you are allowed to see it. It is strictly necessary for the service to function and is not used for analytics or advertising, so no consent banner is shown for it.
Third parties
- Supabase — hosts the PostgreSQL database holding accounts, links and click records.
- Render — hosts the API, and processes request metadata such as IP addresses as part of serving traffic.
- Resend — delivers transactional email (password resets only). No marketing email is sent.
Retention and deletion
Link and click records are kept for as long as the link exists. Deleting a link deletes its click history. Deleting your account deletes your links and their click history. Password reset tokens and refresh tokens expire automatically and are removed once expired.
Your choices
You can edit or delete any individual link at any time, and delete your account and everything attached to it, from your settings page. For anything that page does not cover — including a request to see or erase data held about you — email ajinkyadhotre202@gmail.com and we will action it.
Changes
If this policy changes materially, the “last updated” date above changes with it. Continued use of the service after that date means the updated policy applies.