LEGAL SPECIFICATION · PRIVACY POLICY

Privacy Policy.

Our zero-collision URL shortening infrastructure is built on strict data minimalism. We do not track users across the web, embed advertising beacons, or monetize link data.

Doc IDSNIPX-LEGAL-PRIV-01
EffectiveSeptember 2026
Version1.0.0
Status
ENFORCED
01 //SECTION SPECIFICATION

Architectural Philosophy & Zero-Tracking Guarantee

Snipx is engineered as a developer-native, collision-free URL shortening and analytics platform. Our core tenet is strict data minimalism: we collect and retain only the absolute minimum telemetry required to resolve short URLs and provide accurate click metrics.

Zero Collision, Zero Unnecessary Telemetry

Shortcodes are derived strictly from atomic PostgreSQL sequence increments encoded via bijective Sqids mapping. Every shortcode corresponds directly to a database record without invasive user profiling, behavioral graph generation, or advertising cookies.

You do not need to create an account or provide any identifying details to shorten links. Unauthenticated users can freely generate shortcodes with zero tracking attachments.

02 //SECTION SPECIFICATION

Information We Collect

When you interact with the Snipx platform, the data we collect is grouped into two distinct categories:

A. Account Data (Registered Users Only)

If you register for an account to manage personal links and view portfolio analytics:

  • [+]Identity & Authentication: Your email address and cryptographic password hash (salted using industry-standard bcrypt algorithms), or an avatar image URL if provided.
  • [+]Link Associations: Records linking newly shortened URLs to your account identifier for dashboard portfolio management.

B. Technical Routing & Server Diagnostics

Standard operational telemetry collected when resolving links:

  • [+]Target Destination URLs: The original destination URI supplied during shortcode generation.
  • [+]Diagnostic Logs: Transient server logs (request timestamp, HTTP response status code, and coarse IP routing details) strictly utilized for DDoS mitigation, rate limiting, and system availability.
03 //SECTION SPECIFICATION

Information We Explicitly Do Not Collect

Snipx takes a definitive stand against surveillance marketing and data brokerage. We explicitly reject common SaaS tracking mechanisms:

  • [!]No Third-Party Advertising Trackers: We do not embed Google Analytics, Meta Pixels, ad-network beacons, or user session recording tools.
  • [!]No Sale or Brokerage of User Data: We do not sell, rent, monetize, or disclose your personal data or destination links to data aggregators, advertisers, or third-party marketers.
  • [!]No Cross-Site Fingerprinting: We do not construct hardware, browser, or audio/canvas fingerprint profiles of visitors resolving short links.
04 //SECTION SPECIFICATION

Link Telemetry & Click Analytics

Link analytics in Snipx are privacy-preserving by construction:

When a visitor navigates through a shortcode, Snipx performs an atomic counter increment on the destination record in our database. This records aggregate engagement metrics (such as total redirects served) without tying click events to individual user identities or invasive device profiles.

Any future telemetry expansion (e.g., aggregate geographic or referrer grouping) will operate exclusively on anonymized buckets without persisting raw IP addresses or personally identifiable footprints.

05 //SECTION SPECIFICATION

Cookies & Local Storage Policy

Snipx minimizes client-side persistence and does not employ advertising cookies:

Storage KeyMechanismPurposeLifespan
access_token / refresh_tokenHttpOnly Cookie (SameSite=Lax)Secure authentication session managementSession / 7 Days
themeLocal StoragePersistent light/dark mode preferencePersistent

Authentication cookies are strictly restricted to the Snipx domain and cannot be accessed by client-side JavaScript, shielding them from cross-site scripting (XSS) vectors.

06 //SECTION SPECIFICATION

Security & Data Integrity Protocols

Snipx enforces multi-tiered security safeguards to protect both operational data and user credentials:

  • [+]End-to-End Encryption in Transit: All connections between your client, reverse proxies, and core services are encrypted via modern Transport Layer Security (TLS 1.2 / TLS 1.3).
  • [+]Cryptographic Credential Hashing: User passwords are salted and hashed with high-work-factor bcrypt. Plaintext passwords are never logged, stored, or transacted.
  • [+]Automated Defense Against Malicious URLs: Snipx rejects invalid URI schemes, loops, internal network addresses (RFC 1918), and known malicious targets.
07 //SECTION SPECIFICATION

User Rights & Data Deletion

We uphold your sovereignty over your data. Regardless of your physical jurisdiction, you retain full rights regarding information associated with your account:

  • [+]Link Deletion: You may delete any shortened link associated with your account at any time via your dashboard, permanently revoking redirection.
  • [+]Account Erasure: You can request full deletion of your user profile and all corresponding metadata.
  • [+]Data Portability: Export your links, click counts, and timestamps directly from your analytics console.
08 //SECTION SPECIFICATION

Questions, Issues & Open Source Governance

Snipx is developed as an open source project. We do not use unmonitored generic email inboxes. If you have questions about privacy, want to file a data inquiry, or wish to audit how our redirection pipeline functions, please reach out via our official GitHub repository:

Official Repository & Issue Tracker

Open an issue, propose an enhancement, or review our backend sequence code at: