Privacy notice
This notice describes the service as it runs today, in the wording of the operator's compliance note: where a sentence below states a fact, the compliance note records the same fact.
Who we are
TrueRedirect is the controller for the personal data the service processes.
For any data-subject request — access, erasure, objection — write to privacy@trueredirect.com
What we store
Your account data
Workspaces, links, custom domains, API-key verifiers, entitlements and audit events live in the relational store, placed in the EU jurisdiction. Audit rows carry ids and action metadata only — never an e-mail address or a URL.
Click telemetry
A click writes one append-only event: the workspace, link and domain ids, the event type, a coarse classification, an optional country and coarse device strings. No raw IP addresses, ever — the only network identity is a daily-rotating keyed hash, bound to the link, so cross-link correlation is impossible by construction. The hash changes every 24 h with no overlap, and the master salt rotates at least every 90 days. Region and city are not collected; they may return only with a documented DPIA update.
The resolution cache
Link-resolution entries only. No visitor data at all — the keys are slugs and hostnames, never user identifiers.
The Node runtime's telemetry store
Where the product runs on the Node runtime, the same telemetry is written to a deletion-capable store, and the retention sweep purges everything older than 90 days.
Operational logs
The structured log surface deliberately excludes raw IPs, credentials, and full destination URLs; it carries request ids and security-event metadata, never click telemetry.
Backups
The intended policy is for the monthly staging export to be stored as a workflow artifact for 30 days and encrypted live database dumps to be kept for 30 days. Off-host retention and recovery remain unverified. Under the required workflow, the plaintext export never leaves the machine that encrypts it, and the private key never touches any server or the repository.
Restores
A restore resurrects erased rows — direct identifiers included — so every restore inside the window is followed by the mandatory post-restore re-erasure.
On what basis
- Running your account, your links, your sessions and the transactional e-mail they involve: processing necessary to provide the service the user signed up for (contract, Article 6(1)(b)).
- Click analytics: legitimate interest (Article 6(1)(f)) — the product's core feature is honest aggregate analytics. It is pseudonymized by construction: no raw IPs, daily-rotating keyed hash.
- Security logging and rate limiting: legitimate interest (Article 6(1)(f)) — keeping the service and its users' accounts secure (fraud/abuse detection, incident response).
- Sign in with Google: contract, exercised at the user's direction. Google acts as an independent controller for its own authentication flow.
Who else processes data
Personal data is processed by these third parties, each named in the operator's compliance note:
- Cloudflare — the hosting platform: the entire serving path, the relational store, the cache, the click-event store and the logs.
- Resend — transactional e-mail delivery (verification codes, password resets): the recipient address and the message content.
- Google — for accounts that sign in with Google: the OAuth profile fields the code reads (e-mail, verified flag, name/avatar).
- Self-hosted Forgejo — CI execution and encrypted backup artifacts are the intended workflow; off-host backup retention and recovery remain unverified. Encryption uses the public recipient key on the runner; the private recovery key must stay outside the runner and repository.
- URLhaus is the configured threat-feed source, not a processor of product account or visitor data. No product account or visitor payload is sent to it; authenticated downloads send the operator's provider credential and request metadata.
No analytics vendors, no advertising, no crash-reporting SDKs.
How long we keep it
- Click telemetry: 90 days, platform-enforced; only the aggregate rollups outlive the raw window.
- Aggregate rollups are retained indefinitely — they are aggregate counts, not personal data; no visitor-level rows exist to retain.
- Restore windows: 7 days on the free plan, 30 days on paid — and the mandatory post-restore re-erasure follows every restore, so a restore never silently resurrects an erased account.
- Encrypted backups: a 30-day horizon, aligned with the erasure clock.
- Sessions are deleted at expiry; a verification code or password-reset request leaves state that is cleared 24 h after its own expiry.
- Audit events: 395 days — accountability outlives the account, but not forever. On account deletion the trail is kept and anonymised.
Your right to object
Article 21(4) of the GDPR gives you the right to object, on grounds relating to your particular situation, to processing based on legitimate interests. The processing in question here is the click analytics and the security logging described above. Write to privacy@trueredirect.com and your objection is answered like any other data-subject request; where it stands, the processing of your data stops.
Erasure and export
The dashboard erases the account on request, and the export answers the access right with the whole account as one JSON download. Both self-service actions are reachable unaided: the Data tab of the dashboard's settings renders the export as a one-click download and deletion as one proof dialog.
Self-service export and deletion: the dashboard's Data tab
What erasure cannot reach immediately
Some copies age out rather than delete; the horizons are:
- Raw click telemetry ages out within 90 days — the store is append-only and holds no raw IP addresses and no per-user identifiers, so stored events are not reasonably re-attributable to the erased person once the salt has rotated.
- Operational log lines that mention the account age out with the platform's short free-tier window.
- Mail already sent to your address lives with the mail provider under its own retention.
- Backup copies — the artifact and the dumps — age out on a 30-day horizon, and the mandatory post-restore re-erasure follows any restore.
Cookies
The signed-in surfaces set five functional first-party items, and none of them are advertising, analytics or third-party, so no consent banner is required. A short-link visit carries none of this: redirect responses set no cookies, and this page sets no cookie and reads none.
- trueredirect_session — the dashboard sign-in session; revoked server-side at sign-out.
- trueredirect_totp_challenge — the signed five-minute two-factor challenge between sign-in and verification.
- trueredirect_oauth_state — the signed single-use state for the Google round-trip.
- trueredirect_locale — the dashboard language you picked, kept for 1 year.
- trueredirect_theme — the dashboard theme you picked, kept for 1 year; JS-readable by design, and it carries a closed-set display preference, never a credential.
No tracking
No third-party trackers, no advertising, no analytics vendors, no crash-reporting SDKs. The public pages make first-party requests only, with no separate tracking of any kind — and this page loads no script at all.