Privacy
What Click stores, and what it does not
No click tracking beyond a per-link counter. No visitor data is stored. This page lists every file Click’s code writes, what is in it, and how long it is kept.
If you open a short link
Click’s code stores nothing about you. Opening a preview page adds one to that link’s counter, a file that holds a number and nothing else: no IP address, no time, no browser, no referrer. The preview page carries no analytics tag and the server sets no cookie.
When you press Continue, the link is marked noreferrer and the page carries a no-referrer policy, which ask your browser not to tell the destination that you came from Click. What the destination does once you arrive is up to the destination.
If you make a short link
The address you typed is sent to Click’s server when you press Shorten, and not before. Three things are stored:
| What | Where | Kept |
|---|---|---|
| The code, the destination and the time the link was made | The store, one line per link | Until the store is cleared by the people who run Click |
| A count of the links made this hour and this day, filed under a salted hash of your IP address | One small file per hash | Until the first link is made or opened after 00:00 UTC |
| That day’s salt: 32 random bytes made on the server | One file | Until the first link is made or opened after 00:00 UTC |
After 00:00 UTC the old salt is never used again; it and the counts under it are deleted by the next request that makes or opens a link. Your IP address itself is never written to a file by Click’s code. The hash is an HMAC-SHA-256 of the address under the day’s salt; an IPv6 address is reduced to its /64 network first. When the salt is deleted, the hashes made under it cannot be tied to an address or to the next day’s hashes. The store does not record who made a link.
The limit is 10 new links in a clock hour and 40 in a day, both counted in UTC.
Cookies and browser storage
One, and only if you use it. Pressing the paper or dark switch at the top of a page saves your choice in your browser under the name labs_edition, as a cookie and in local storage, for a year. It holds the word “paper” or “dark”. Click’s server does not read it.
The form does not save the links you make in your browser. If you lose a short link, shorten the same address again and you will be given the same link.
Analytics
The five written pages of this site — the home page, About, Report, Terms and this one — carry a small loader for Google Analytics 4. The loader does nothing, and asks Google for nothing, until this site has been given a property of its own. Once it has, those pages load Google’s tag and report visits to that property; when a link is made, the tag is told that the tool was used, and it is not told the address or the code.
The preview pages do not load the tag. Opening a short link is not reported to Google or to anyone else.
What is outside Click’s code
This page describes what Click’s own code does. The company that hosts the site runs the web server, and a web server can keep an access log of its own — typically the address, the time and the path of each request. Click’s code does not read or write that log.
The server never contacts a destination, so no site learns that a link to it was made.
Having a link withdrawn
There are no accounts, so a link cannot be deleted from a settings page. Write to labs@labs.llc with the short link and it can be blocked, after which its destination is no longer shown. Reporting a short link works the same way, and the method page describes the store.