Legal
Privacy
Two kinds of people show up here. You, who have an account, and whoever clicked one of your links. This says what is kept about both.
Last updated 18 August 2026.
What we keep about you
Your email address and your name, because an account needs them. A profile image if you set one.
How you sign in. A password is never stored in a form anyone can read back. If you use Google or GitHub instead, we hold the account identifier they give us and what is needed to keep the connection working. Turning on two-factor stores your codes encrypted.
A record of each session while you are signed in, with the address you signed in from and your browser, so you can see and end sessions you do not recognise. An API key is not kept in usable form. We hold enough to show you which key is which, and not enough to use one.
The answers you gave at sign-up. Account type and country, and then company name, website, industry, team size, what you plan to use it for and where you heard about us. Everything after the first two is optional, and the whole step can be skipped.
Your links, and everything attached to them. Destinations, slugs, tags, categories, lists, custom domains, routing rules, monitors and any image you upload. We also fetch the page a link points at to read its title, description and preview image, which is what makes a shared link unfurl properly. Our crawler says who it is and explains itself here.
A record of the mail we sent you. Who it went to, what it said and whether it arrived, so support can look it up with you.
Billing. Your plan and your subscription status. Card details go straight to Stripe and never reach our servers.
What we record when somebody clicks
A click on a short link is recorded once. We keep the time, the visitor's country, the page they came from, and the device, browser and operating system they used.
The visitor's IP address is not stored. It is turned into an anonymous identifier that cannot be turned back, and that is what we keep. The same visitor produces the same identifier, which is how unique visitors are counted. If that cannot be done safely, the visit is left uncounted.
Clicks recorded before that change still carry the address they were written with. Nothing records it any more, and those age out under the window below.
The redirect sets no cookie and runs no script. There is no tracking pixel, no fingerprinting, and nothing that follows a visitor to the site they land on. Click figures are only ever shown inside the account that owns the link.
What we count for ourselves
Sign-ups, upgrades, cancellations and a few other moments are counted, along with your email and the plan, account type and country as they were at the time. It is how we know whether the business is working. These counts are held separately from your account, so they are not removed when the account is, and they are never sold or handed to an advertising network.
Who else touches it
- Cloudflare runs the service and sends the mail we send you.
- PlanetScale hosts the database, in North America.
- AI models suggest tags, categories, preview copy and slugs. What goes to them is the destination page we read and the tags your account already uses. They run inside our own Cloudflare account, so no other AI company sees any of it.
- Stripe takes the payments and holds the card.
- Google and GitHub, only if you choose to sign in with one of them.
That is the whole list. There is no analytics vendor, no advertising network, no data broker, and nothing about you or your visitors is sold or traded.
Cookies
A cookie for your session, set when you sign in and gone when it expires or you sign out. Nothing else on the marketing site, nothing at all on a short link.
How long it is kept
Individual clicks are deleted once they pass 400 days. Your plan sets a shorter window on what the dashboard will show you, so a plan with 30 days of analytics shows 30 days.
Everything else stays while the account does. Delete a link and its clicks go with it, immediately and for good.
Getting it back, or getting rid of it
Deleting your account from settings needs a confirmation by email, and then it takes your links, domains, analytics, sessions, keys, connected clients and the record of mail we sent you with it. A paid subscription is cancelled at Stripe as part of the same step, and any custom domain is handed back. Short links stop resolving at that point, which matters if any of them are in print.
One thing survives it. An identical image uploaded by two accounts is only stored once, so deleting your account removes it from your library and leaves the file itself in place. Another account may still be pointing at it. Nothing about it is tied to you any more.
For a copy of what we hold, or for the counts described above to be scrubbed, write to support@fixed.link and we will do it by hand. There is no self-serve export yet.
Assistants and other clients
Connecting an assistant or the browser extension mints a token for your account. It can do what you can do through the API, and nothing else. Revoke it from settings and it stops working everywhere at once. What that client does with the links it reads is covered by whoever makes it, not by us.
Changes
This page changes when the product does, and the date at the top moves with it. Carrying on using the service after a change means the new version applies.
Asking
Anything at all, to support@fixed.link. The terms sit alongside this, and the extension has its own page.