Guide · Trust and privacy

Counting link opens without cookies

A shortener can count opens because the redirect is its one job. This guide explains what the open log records, why it holds no cookies and no tracking identifiers, and when every line of it is deleted.

What an open records

One row per open: the link, the moment, the destination, the browser's User-Agent string, the domain that referred the visitor, and the visitor's IP address — which is stored as a keyed hash, not as the address. HTTP carries no identity of its own (RFC 9110 documents this: the protocol has no notion of a session), so the count is a count of requests, and the hash is enough to recognise abuse patterns — a burst from one network, a single link opened from a thousand addresses in a minute — without ever holding the address itself.

Why no cookies

  • A tracking cookie follows a person across sites; an open count follows one link's rows, and ends with them.
  • Nothing in the log links two opens by the same person: the hash rotates with the IP and the browser name, and the row holds nothing else.
  • The log is not sold, not exported, and read only by the operator's abuse tooling.

When it is deleted

The open log is purged on a fixed retention period the operator sets — days, not months — and a link's expiry takes its row's usefulness with it. What survives after the purge is the count itself: totals per link, kept as aggregates. The privacy page names the retention in force and the legal basis, which is the service's legitimate interest in keeping itself safe (NIST SP 800-63B applies to the credentials on this site — pack keys and link passwords — and they are stored as keyed hashes for the same reason: the record must not carry the secret).

Questions

Do short links set cookies?

Not for counting opens. Google ads set cookies only where a visitor allows them, and the consent gate explains that before anything loads.

What do you store about a visitor who opens a link?

The link, the time, the browser's name, the referring domain, and the IP address as a keyed hash. Nothing else, and nothing that links one open to the next.

Can you identify a person from the open log?

No. The hash cannot be turned back into the address, and no identifier in the log persists across opens.

Where can I read the privacy policy?

On the privacy page, in the footer of every page. It names the retention period the operator runs and what is never stored.

Sources

The documents this guide's statements rest on. Each link opens in a new page.

  1. RFC 9110: HTTP Semantics
  2. NIST SP 800-63B: Digital Identity Guidelines — Authentication
  3. Google Safe Browsing