Privacy Policy
Last Updated: August 7, 2026 (Previously revised: July 22, 2026)Information We Collect
We collect information you provide directly (such as email addresses via Google Auth) and technical information gathered automatically (such as device fingerprints, IP addresses, and click analytics on shortened URLs). IP addresses and device fingerprints are SHA-256 hashed before storage to anonymize users while preventing abuse. We operate a zero-trust architecture, meaning even internal access to this data requires temporary, heavily audited cryptographic grants.
Mouse Idle & User Engagement Policy
To optimize platform resources and prevent automated abuse, our application actively monitors user interaction state, including mouse movement, keyboard strokes, and scroll events. If your session is idle for an extended period (typically exceeding 30 minutes without active interaction), your active secure token may be automatically invalidated to protect against session hijacking. This 'Mouse Idle Policy' ensures enterprise-level security, particularly in shared workspace environments.
Cookies and Client-Side Storage
We use strictly necessary cookies for authentication via Firebase Auth and to persist consent state (e.g., your agreement to these policies). We utilize a deterministic device fingerprint hash acting as a secure session token to seamlessly track analytics without compromising anonymity. No third-party advertising cookies or tracking pixels are ever injected into our application.
Emergency Appeals Data Protocol
During active Emergency Maintenance Holds (Kill Switch mode), direct appeal submissions (user email and inquiry details) are stored with zero-trust encryption in administrative logs. This data is accessed exclusively by authorized security engineers solely for incident resolution and emergency query response.
Data Retention & Account Bans
We enforce zero-tolerance abuse policies. If your account violates our Acceptable Use standards, we reserve the right to retain minimal identifying information (hashed email, IP addresses, device fingerprints) indefinitely to prevent ban evasion. Standard active data is retained as long as your account exists.
Data Portability & User Archive Export Rights (GDPR / CCPA)
All registered XURL accounts (Free, Starter, Pro, Business, and Enterprise) possess the unconditional right to export a machine-readable data archive of their account profile, shortened URL records, click telemetry, and billing history under GDPR Article 20 and CCPA §1798.100. Data exports may be requested at any time via our dedicated Data Portability Portal (/data-export). To prevent distributed denial-of-service (DDoS) attacks, CPU resource exhaustion, and bot scraping, data exports are strictly rate-limited to a maximum of 3 export archives per hour per user account, with a mandatory 60-second cooldown between downloads. Guest accounts are unauthenticated and ephemeral, and are therefore excluded from data archive exports under our Guest Usage Policy.