Legal
Privacy Policy
Last updated:
peyaji does not show ads, and you don’t need an account to make a short link. This page explains the little we do store.
When you create a link
- The long URL, the short code and the time it was created. These are needed for the link to work, and are public through the link itself.
- A one-way, salted hash of your IP address. It is used to limit how many links one person can create, and to trace abuse. We never store the IP address itself.
If you sign in
An account is only needed to use your own domain, or to keep your links in one place. When you sign in with Google, Microsoft or Apple we receive and store your
name and email address (no password, no contacts, nothing else), plus the time you last signed in.
If you choose to hide your email with Apple, we only get the private relay address Apple gives us.
We also keep the list of links you make while signed in (and the ones you add to your account from this browser) and the domains you add, so you can see them on any device.
A sign-in cookie (__Host-session) keeps you signed in for up to 30 days. Sign out everywhere
on your account page ends it on every device at once.
When someone opens a link
We count the click and record when the link was last used. If the link is in someone’s account, we also add the click to that day’s count for the country it came from (the country Cloudflare sees the connection in), so the account can see a chart of its link’s clicks. These daily counts are kept for 90 days. We do not record who clicked or their address.
A link’s clicks are shown only to the person who made it: in the browser they made it with, in their account, and on the link’s private clicks page. That page’s address carries a secret key that only they were given, after the #, the part of an address browsers never send anywhere; anyone they share the address with can see the numbers too, and can’t change anything.
In your browser
- Your links on the homepage are kept in your browser’s local storage; you can download or clear them any time. A link made without signing in comes with a token that only your browser has. To show the clicks of your links, the page sends us those tokens: a link’s clicks are shown only to the browser that made it, or to the account it is in, never on its preview page. The token also lets you add the link to an account later. We don’t keep who asked.
- Light or dark, and the colour and frame of your QR codes: what you pick is kept in local storage too.
- Previews: if you turn on previews, we set one cookie (
previews) so links show their destination first. Turning previews off removes it.
Services we use
- Cloudflare hosts the site, stores the links (Cloudflare D1), provides DNS and protects the site from attacks. If the “I am human” check is shown, it is Cloudflare Turnstile. Visits to these pages are counted with Cloudflare Web Analytics, which uses no cookies and doesn’t follow you to other sites (never on a link’s private clicks page).
- Google Safe Browsing may be used to check links against lists of unsafe sites, when they are made and again when someone previews them. Only the link being checked is sent.
- Sign in with Google is used if you choose it. Google’s own privacy policy applies to your Google account.
- Sign in with Microsoft is used if you choose it. Microsoft’s own privacy policy applies to your Microsoft account.
- Sign in with Apple is used if you choose it. Apple’s own privacy policy applies to your Apple account.
Contact
Questions, want a link removed, or want your account deleted? Email abuse@peyaji.com.
See also our Terms of Use.