Draft — not yet reviewed
This document has not been checked by a lawyer, and no postal address is published for the operator yet — one is required before the service can properly be offered to the public. Contact by email works in the meantime.
Privacy Policy
How Trimly collects, uses and stores personal data — both for account holders and for people who click a shortened link.
Last updated: 26 July 2026
Who is responsible
Trimly is run by Tim Manje, an individual rather than a company, who is the controller for the data described here.
[A postal address is still to be published here. Data protection law requires the controller's address to be given, so that a request or a complaint can reach them by post as well as by email].
Privacy enquiries go to datenschutz@zerogov.lol. There is no Data Protection Officer: appointing one is only required for larger-scale or higher-risk processing, and this service does not meet that threshold.
Account data
When you create a workspace I store your name, email address, a hash of your password, and — if you sign in with Google or GitHub — the account identifier that provider returns. Your password is never received from those providers.
Passwords are stored only as a scrypt hash and cannot be read back. If two-factor authentication is enabled, the shared secret and your recovery codes are encrypted at rest.
Sign-ins are recorded with the time and originating address so that you can review your active sessions and so that suspicious access can be investigated. You can revoke any session from your settings at any time.
What is recorded when someone clicks a link
This section concerns people who never signed up: anyone who follows a shortened link.
For each click the following is stored:
- the approximate location derived from the IP address — country, and where available city and region;
- the device type, browser and operating system, with major versions;
- the preferred language your browser sends;
- the referring page and its domain, when your browser sends one;
- any campaign parameters carried in the link;
- whether the request looked automated;
- the time of the click.
The IP address itself is never stored. It is combined with the browser identifier, the link, and a salt that changes every day, and only the resulting one-way hash is kept. That hash allows returning visitors to be counted within a single day; once the salt rotates, clicks from the same person can no longer be connected, and the hash cannot be turned back into an address.
Location is looked up in a database held on the server. Your IP address is not sent to any third party for this.
Cookies
Three cookies are set, and none of them are for advertising:
- a session cookie and a refresh cookie, both inaccessible to scripts, which keep you signed in;
- a token used to confirm that requests changing your data really came from this site.
Following a shortened link sets no cookie. There are no third-party analytics or tracking scripts anywhere on this site.
Account holders may attach their own retargeting pixels to their links. Where they do, the provider they chose receives data directly from the visitor and acts under that account holder's instructions, not mine — their own privacy notice governs it, and this one does not.
How long data is kept
Analytics reporting reaches back as far as your plan allows — 30 days on the free plan, 90 on Starter, a year on Pro, two years on Business, and without limit on Enterprise.
Be aware that this limits what can be queried, not what is stored. Click records are currently retained indefinitely, including beyond your plan's reporting window. They hold no IP address and no directly identifying data — only the daily hash described above, which stops being linkable once the day ends.
Expired sign-in sessions and unused verification tokens are deleted automatically. Webhook delivery logs are removed after 30 days.
When you delete your account, your record is anonymised: your email address and name are replaced, and your password hash, two-factor secret, recovery codes and avatar are erased. Workspaces you alone owned are withdrawn, and their shortened links stop resolving immediately. Click records for those links remain, in the anonymous form described above.
Who else processes this data
Running the service needs a few providers. Each receives only what its function requires:
- Fly.io — hosts the application servers and serves the redirects, so it handles every request in transit.
- Neon — the managed PostgreSQL database where everything described above is stored.
- Vercel — serves the web interface.
- Resend — sends account email, and therefore receives the recipient address and the message.
Servers are located in the European Union. [If you later add a provider outside the EEA, name it here together with the transfer mechanism you rely on].
No data is sold, and none is shared for advertising.
Legal basis
Where the GDPR applies, the bases are:
- Performance of a contract — running your account, storing your links and serving the redirects. Without this data the service cannot be provided.
- Legitimate interests — keeping the service secure, preventing abuse of shortened links, and producing the click statistics that are the point of the product. The design reflects the balancing test: no IP address is retained, and the visitor identifier expires daily.
- Legal obligation — retaining records where a law requires it, such as responding to a lawful takedown request.
[Confirm this against the law of the country you operate from, particularly the basis for click analytics — it is the point most likely to be challenged].
Your rights
Depending on where you live, you may have the right to access your personal data, correct it, receive a copy in a portable format, have it deleted, restrict or object to its processing, and complain to a supervisory authority.
Write to datenschutz@zerogov.lol and you will receive a reply within 30 days. There is no charge, and no account is needed to make a request.
One limit worth stating honestly: click records cannot be traced back to an individual — that is the point of the daily hash — so a request to delete or export them cannot be fulfilled for a specific person. The data no longer identifies anyone by the time it is stored.
Children
Trimly is not intended for children under 16, and their data is not knowingly collected. If you believe a child has created an account, write to datenschutz@zerogov.lol and it will be removed.
Changes
Any change is posted here with the date above updated. Where a change materially affects how your data is handled, account holders are notified by email at least 30 days beforehand.
See also the Terms of Service.