Privacy

This page says what Kort stores about you and why. We keep as little as we can to run the service and stop abuse.

Last updated 11 October 2026

The short version

  • A random link needs no account, no name and no email address.
  • We never store your IP address as it is. We keep a hash of it.
  • If you log in, Google shares your name and email address with us.
  • We set a login cookie, plus three short-lived cookies while you sign in with Google. We set no tracking or advertising cookies.
  • We don't sell your data and we don't show ads.

What we store

  • Links. The long link, the short code, when it starts and ends, and how many times it has been opened. We only count opens. We don't record who opened a link, their IP address or their browser.
  • Who made a link. Your account, if you were logged in. If you weren't, a hash of your IP address.
  • Old links. When a rented code goes to someone else, we keep a record of its last link, with where it went, how often it was opened and who made it. We use it to look into abuse.
  • Your account. If you log in with Google, your name, your email address and the ID number Google gives your account. We never see your Google password.
  • Your login. A random token in a cookie. We store only a hash of the token, not the token itself.
  • Reports. The link you report, the reason, any details you write, and a hash of your IP address or your account.
  • The waitlist. Your email address, the character you chose and the date you joined.

IP addresses

We never store your IP address as it is. We turn it into a hash with HMAC-SHA-256 and a secret key that only we hold. Without that key, nobody can work out your address from the hash. We use the hash to limit how fast one address can make links and to spot abuse.

Cookies

Kort sets no tracking or advertising cookies. These are all the cookies it sets:

  • sid keeps you logged in. It is set only when you log in, lasts 30 days or until you log out, and is sent only over HTTPS. Page scripts can't read it.
  • oauth_state, oauth_verifier and oauth_next carry the login step to Google and back. They last a few minutes and are deleted when you come back.

Services we use

  • Google sign-in. When you press Continue with Google, your browser goes to Google, and Google tells us your name, your email address and your account ID. Read the Google privacy policy.
  • Google Web Risk. We send each new long link to Google Web Risk to check that it isn't a known unsafe site. We send it from our server, so Google gets the link, not your IP address or your account.
  • Cloudflare Turnstile. Pages with a form run a bot check from Cloudflare. It runs in your browser and loads from challenges.cloudflare.com, so Cloudflare sees your IP address and details of your browser. Read the Cloudflare privacy policy.
  • Cloudflare hosting. Kort runs on Cloudflare's network and database. Cloudflare handles every request, so it sees IP addresses, as any web host does.

We share information only with these services, which we need to run Kort, or when the law says we must.

How long we keep it

We keep a link, an account or a waitlist entry as long as it exists. We keep old links and reports as long as we need them to run Kort and look into abuse. We haven't set fixed times for deleting them yet.

Your choices

  • Log out any time. That ends your session on our side too.
  • Release a rented code from Your links when you no longer need it. It stops working at once.
  • Ask us to delete your data, or to tell you what we hold about you. We don't have an email address for this yet. For now, use the report page: choose “Something else” as the reason, write “Privacy request” and what you want in the details, and add the email address you use with Kort. The form asks for a short link. If you have none, enter any Kort link and say so in the details. We may need to keep some records to look into abuse.

Changes

If we change this page, the date at the top changes too. Our terms and the FAQ give the wider picture.