cutthis.link
Features Themes Pricing FAQ About
Log in Create account
cutthis.link
Features Themes Pricing FAQ About
Log in Create account

cutthis.link

Privacy Policy — last updated September 11, 2026

We keep this short and honest. Here's exactly what cutthis.link collects and why.

What we collect

  • Account basics: username, email address, and a bcrypt hash of your password (we never see or store your actual password). If you sign in with Google, you get a random internal password instead since Google handles authentication.
  • Email verification: we store when your email was verified and send a one-time verification link at signup. Until it's confirmed you get a 7-day grace period, then access is locked until you verify.
  • Google sign-in data: only what you authorize on Google's consent screen — your Google-registered email address and, if you allow it, your name and profile photo. We don't see your Google password, contacts, or any other Google data, and the connection is entirely optional.
  • Optional profile stuff: bio text, custom link buttons, theme choice, avatar image, and social link usernames (Instagram, X, YouTube, TikTok, GitHub, LinkedIn, Email) if you add them.
  • Your short links: the short code, destination URL, optional expiration date, any custom thumbnail URL, and optional tags you add.
  • Referral info: if you sign up through someone's invite link, we record which account invited you and when, so your inviter can get credit. The invite can come from a shared ?ref=username link or the "get your own" link on a friend's bio page. Credit for the inviter only counts once your email is verified, and referral records are tied to usernames, not to anything you ever type.
  • Bio pages: if you create a bio page, we store its slug (your username), display name, bio text, link layout, theme, avatar, social link usernames, and view count.
  • Guest links: you can shorten without an account. Guest links store only the code and destination — they're not attached to any identity, and creation is rate-limited per browser session (10 per hour).
  • Click counts: how many times each of your links was opened and when. For paid users, we also record the referrer domain, device type (desktop/mobile/tablet) and a one-time country lookup — the country code is stored but the IP address is discarded immediately.
  • QR scan counts: when a link is opened via a QR code (detected by a ?qr=1 URL parameter), we increment a scan counter on the link. No cookies, IP addresses, or browser data are involved in scan detection.
  • QR design: if you're on a paid plan and customize your QR codes, we store the ink and backdrop colors you pick and whether to center a logo, so the same look reapplies on your dashboard and in stats. The QR itself is drawn in your browser — your chosen colors are never sent to third parties.
  • QR logo image: if you upload a logo for the center of your QR codes, the image file (and its format) is stored on our servers and served back to you, your dashboard and the stats page. It's used only to draw onto your own QR codes and is deleted when you remove it from settings or delete your account.
  • Subscription data: if you upgrade to a paid plan, we store your plan name, subscription status, and a PayPal subscription ID. We do not see or store your credit card number, PayPal password, or any payment credentials — all payment processing is handled entirely by PayPal.
  • Login codes: when you log in with a one-time email code, only a secure hash of the code is stored, and it expires after a few minutes.
  • Abuse reports: if someone reports a link, we ask for their email address and a quick human check. The report is only forwarded to our team after the reporter confirms it via an email link. Reports store the reporter's email and IP address for moderation.

What we don't do

  • No ads. No analytics trackers. No selling data. Ever.
  • QR codes are generated in your browser — nothing is sent to third parties.
  • QR scan detection uses only a URL parameter (?qr=1) — no cookies, no fingerprinting, no external services.
  • CSV export is generated on our servers from your own links — the exact same data you already see on your dashboard, just arranged into a spreadsheet. It adds no new collection.
  • Social link usernames you enter are stored as plain text and displayed as clickable links on your bio page. We don't connect to or verify these social platforms.
  • Signing in with Google happens on Google's own consent screen under Google's policies. We receive only the information you authorize there and nothing else.
  • Custom thumbnail URLs are stored and displayed on your bio page. We don't proxy, cache, or analyze these images.
  • By default the site runs a self-contained math human check on registration, forgot-password requests, guest link creation and abuse reports; no external service is involved, and the answer is used once then discarded. If Cloudflare Turnstile is enabled, its challenge instead runs under Cloudflare's own policies.
  • To keep signups honest, temporary/disposable email services are blocked at registration. We look at the email domain only — nothing else about your inbox.

Emails you may receive

  • A welcome email when you sign up.
  • A verification email with a sign-in link shortly after signup (required within 7 days to keep access).
  • Password reset emails, only when you request one.
  • One-time login codes, only when you request one.
  • A notice when your account's email address is changed (sent to both the old and new address).
  • If you submit an abuse report: a one-time confirmation email containing a verification link (valid 24 hours).

Cookies

One essential session cookie keeps you logged in, protects forms against CSRF attacks, powers the human check, and enforces the guest rate limit. There are no advertising or tracking cookies. Arriving via a referral link also sets a small referral cookie for 7 days so that if you sign up later we can credit the correct referrer — it carries only the referrer's username, is only set when you land on the site through an invite link, and is never used to follow you around the web. Your cookie consent preference is stored in your browser's localStorage, not in a cookie. If you sign in with Google, Google may set its own cookies on Google's pages during that sign-in, under Google's cookie policies.

Retention & deletion

  • Delete any link from your dashboard and its click history, scan count and daily aggregates are permanently removed with it.
  • Bio pages can be deleted from your bio settings. Your default bio page is recreated automatically if deleted.
  • Want your whole account gone? Email support@cutthis.link from your account's email address and we'll delete your profile, links, bio pages, click data, referral records, QR logo and avatar.
  • Referral records (who invited whom and when) are deleted when either account involved is deleted, and stop counting toward referral credits for the inviter.
  • Abuse report records (including reporter IP) are kept for moderation purposes.

Contact

Questions or requests about your data: support@cutthis.link

© 2026 cutthis.link
About Privacy Terms Report abuse

We use essential cookies to keep your account secure. No tracking, no ads, no third-party scripts.

Privacy policy