Privacy Policy
Last updated: July 2026
This policy explains what we collect when you use pinr and how we handle it. We aim to collect as little as possible and to be clear about it.
Information we collect
- Account data - your name, email, and (for password accounts) a securely hashed password. If you sign in with Google, we receive your basic profile from Google.
- Content you create - your links, their destinations, settings, tags, folders, and workspace details.
- Click analytics - when someone opens one of your short links, we record the event: timestamp, approximate country, device type, browser, OS, and referrer.
Privacy-safe click tracking
We do not store the raw IP addresses of people who click your links. To count unique visitors we use a daily-rotating one-way hash that cannot be reversed to an individual and changes every day. Bot traffic is filtered out. Country is derived at the network edge and is approximate.
How we use data
- To operate the Service - resolve your links, apply redirect rules, and show your analytics.
- To secure accounts, prevent abuse, and enforce our Terms.
- To send essential account email (verification codes, invitations, and important notices).
Cookies
We use a small number of first-party cookies and local storage strictly to keep you signed in and to remember your active workspace. We do not sell your data or use it for third-party advertising.
Sharing
We do not sell personal data. We share it only with service providers that help us run pinr (such as hosting, database, storage, and email delivery), and only as needed to provide the Service, or where required by law.
Retention
We keep account and link data for as long as your account is active. Raw click events are retained for a limited window (currently 90 days) and then aggregated into anonymous daily totals; the aggregates contain no per-person data.
Security
Passwords are hashed, secrets and API keys are stored hashed, and access to workspace data is scoped by membership and role. No system is perfectly secure, but we take reasonable measures to protect your data.
Your choices
You can update your profile, delete links, remove workspace members, revoke API keys, and delete a workspace from your dashboard. To request deletion of your account and associated data, contact us.
Contact
Privacy questions? Email [email protected].