Privacy & data
Operator: Gabriel Molter. For privacy questions, access, correction or deletion requests, contact [email protected].
Public pages and redirects do not set analytics cookies or create persistent visitor identifiers. Account sessions use an essential, HTTP-only cookie.
Audience measurement
When enabled, we increment daily aggregate counters for views and clicks, grouped by resource, referring hostname, broad device class, and likely bot traffic. We do not store IP addresses, full referrer URLs, or full user-agent strings in these counters. Do Not Track and Global Privacy Control signals disable this measurement.
Security and infrastructure logs are separate. Their configuration, retention, providers, and legal basis must be documented by the instance operator.
Security and abuse reports
Client-based security limits at this instance’s proxy use temporary in-memory counters. Abuse reports store the reported public URL, reason, details, review status and time for up to 90 days; administrators can review them and disable links or unpublish profiles. Reports do not require a reporter email or store reporter IP addresses in the application database. Please avoid including sensitive personal information in a report.
Retention
Aggregate analytics are retained for 365 days. Expired account tokens, invitations and rate-limit records are removed by the cleanup worker, which runs every six hours. Security audit records are retained for 90 days. Account sessions expire after seven days. Account data and uploaded images remain until deleted.
Your account
You can export your account, profile, and links from Settings. Account deletion removes the account and its associated content and analytics from the active database; backup expiry is governed by the operator’s retention policy.
Service providers and operational data
Hostinger hosts Frink and PostgreSQL in Brazil; the operator reports Sao Paulo, pending provider-location confirmation. Cloudflare proxies HTTPS traffic through its global network. Twilio SendGrid sends account and operational email, with click and open tracking disabled for these messages. These providers may process operational data outside Brazil. Encrypted backups are copied to Homer in Brazil, retaining seven daily, four weekly and three monthly restore points. Backups contain account data and recovery secrets.
Application logs are separate from analytics and use size-based rotation; this does not establish a fixed retention period. Provider-side logging, processing locations, international-transfer arrangements and the applicable legal bases remain under operator review before broader launch.
Privacy requests
Use Settings to export or delete your account. You may also contact the operator for access, correction, deletion, or questions about processing. Deleted data may remain in encrypted backups until those restore points expire; recovery must reconcile deletions made after a snapshot. This notice documents the technical safeguards and does not replace the operator’s legal review.
This notice does not claim regulatory certification or establish a legal basis for processing.