Data policy
The short version: a short link needs a few facts to work: where it goes, its code, when it was made and when it expires. We keep those, plus click counts as daily totals for 30 days. No ads, no third-party analytics, no tracking sold. Everything we hold is listed below, with why and for how long.
Squeezin is not live yet. Today this site stores nothing about you: the link previews on the home page are made in your browser and kept there, in local storage, until you remove them. Items marked planned describe how the service will work when it launches.
1. Who is responsible
Squeezin is a division of Factory Zero Pte. Ltd., Singapore (“we”), which is the controller of the personal data described here. Contact: privacy@squeez.in. Because we offer the service to people in the European Union and the United Kingdom, we will appoint an EU and a UK representative under Article 27 of the GDPR before launch and name them on this page.
2. What a short link stores planned
- The destination URL and the short code (random, easy-to-say or your custom ending). A destination can contain personal data if you put it there, for example a name in a query string; it is public to anyone who opens the link or its + check page.
- When it was created and when it expires (never, 24 hours, 7 days or after the first click).
- Who made it, by type: a person without an account, a signed-in person, or an AI agent with the agent’s name and the account it acts for. The check page shows this so people know where a link came from.
- Click counts as aggregate daily totals, kept for 30 days on the free plan (2 years on Pro). We count clicks; we don’t build a profile of who clicked.
Basis: the contract with you when you create a link (Art. 6(1)(b)), and our legitimate interest in running and protecting a public redirect service (Art. 6(1)(f)). An expired link stops working at once; its record is deleted within 30 days unless it is part of an open abuse report.
3. Clicks and visitors planned
- When someone opens a squeez.in link we add one to that link’s count for the day. We don’t store the visitor’s IP address with the click, don’t set cookies on redirects, and don’t sell or share click data.
- IP addresses appear only in short-lived rate-limit and abuse logs, kept up to 14 days. Basis: legitimate interest in keeping the service safe (Art. 6(1)(f)). We don’t use IP addresses for advertising or location tracking, and never sell them.
- No ads, no advertising trackers, and no third-party analytics, on the redirects or on this site.
4. Link checks planned
To show whether a link is safe, we check its destination against Google Safe Browsing when the link is created and from time to time after. We use the Update API where we can, which compares short hashes of the address against a local list; only when a hash prefix matches do we send Google that prefix (not the full address) to confirm. No information about you or about who clicked is sent. Google processes these lookups under its own terms. The check page also shows the page title we read from the destination, its redirects and its certificate, which we fetch from our servers, not from your browser.
5. Abuse reports planned
Anyone can report a link as phishing, malware or spam from its check page. We keep the report (the link, the reason, the time, and an email address if you choose to give one so we can reply) for as long as we need to handle it and up to 12 months after, so repeat abuse can be spotted. Basis: legitimate interest in keeping people safe (Art. 6(1)(f)). Reported links can be disabled, and we may pass a report to the hosting provider or to authorities when the law requires it.
6. Accounts, handles and payments planned
- Account: an email address, or a passkey, and your plan. Basis: contract. Kept while your account is open, deleted within 30 days of closing it.
- Agents: API keys (stored hashed), the agent’s name, and a prepaid balance with its usage records. Basis: contract.
- Payments: handled by our payment provider; we never see or store card numbers. Invoices are kept as long as tax law requires (Art. 6(1)(c)).
7. This website, today
No cookies, no analytics and no advertising trackers. Link previews and your light or dark choice are kept in your browser’s local storage and never leave your device; clear them from My links or your browser settings. The site is served by Cloudflare, which processes visitor IP addresses to deliver and protect it. Typefaces load from Google Fonts, so your browser’s request, including your IP address, reaches Google.
8. Your rights
Under the GDPR and UK GDPR you can ask us to access, correct, delete or export your personal data, to restrict or object to its processing, and you can withdraw any consent at any time. Write to privacy@squeez.in; we answer within one month. If a link points at something about you without your consent, write to us or report it from its check page. You can also complain to the data protection authority where you live or work.
9. Transfers and processors
We will use processors that sign a data processing agreement with us and, for transfers outside the EU or UK, offer Standard Contractual Clauses or an adequacy decision. We will list them here before launch.
10. Changes
We will post changes here with a new effective date and email account holders about material ones.