Last updated: 23 August 2026
srt.to is a URL shortener. This policy explains what we collect when you use srtto.com, app.srt.to, api.srt.to, and short links on srt.to.
It is not legal advice. If you need a formal review for your own compliance, talk to a lawyer.
Who we are
We operate the srt.to service. For privacy questions, email privacy@srt.to.
What we collect
Account data
If you create an account we store your email address and a user ID from our sign-in provider, Firebase Authentication (Google). You can sign in with email and password or with Google. We also store your plan, usage counts, and whether the account is suspended.
Links and other content you create
When you create or edit a short link we store the destination URL, slug, title, tags, QR settings, password hash if you set one, expiry, and similar settings. If you use custom domains, workspaces, a link-in-bio page, API keys, or webhooks, we store the details you submit (for example a domain name, workspace name, member email, bio handle, or webhook URL).
Click analytics
When someone opens a short link we record a click so you can see analytics. For each click we store:
- time of the click
- country and city, derived from the visitor IP using a local GeoIP lookup (or from a country header when the request includes one)
- referrer (the page that sent the visitor, if the browser sends one)
- browser language, from the
Accept-Languageheader (primary tag only, for examplefroren) - device, browser, and operating system, derived from the User-Agent and then stored as categories — we do not keep the raw User-Agent in the click row
We increment a click counter on the link. How long you can view that history depends on your plan (for example 30 days on Free).
We use visitor IP addresses for rate limiting, abuse prevention, and a local GeoIP lookup for country and city. Rate-limit counters are short-lived. We do not sell click data.
Abuse reports
If you report a link we store the slug or URL, the reason, optional details, optional email, and the reporter’s IP address so we can review the report and stop repeat abuse.
Technical logs
Our servers and infrastructure may log IPs, request paths, and error data for a short time to keep the service up and to investigate incidents.
How we use it
- Run redirects, QR codes, analytics, bio pages, workspaces, and the API
- Show you your own links, members, and reports
- Enforce plan limits and stop abuse (including blocking destinations and suspending accounts)
- Check some destinations against our own heuristics and blocklist, and — when configured — Google Safe Browsing
- Send clicks to webhook URLs you configure
- Reply to privacy, support, and abuse requests
If you invite someone to a workspace, they can see shared links and related analytics for that workspace.
Cookies and similar storage
We use:
- Essential storage for sign-in (Firebase session) and to remember cookie-banner choice (
srtto_cookie_consentin localStorage). - Google Analytics on marketing pages, only if you click Accept on the cookie banner. This uses the Google tag (
G-1YCHQG928S) to count visits, pages, and approximate country. IP addresses sent to Google are anonymized in our config. Decline leaves this off. - Google advertising on marketing pages such as the homepage. Google AdSense may set cookies or use identifiers on those pages. That is not fully gated by our banner today.
Click analytics on short links (time, country, city, language, referrer, device category) are part of the product. They are not the same as Google Analytics on the marketing site.
You can block cookies in your browser. If you do, sign-in or ads may not work as expected. Google’s ad settings are described in the Google Privacy Policy and Advertising pages.
Advertising
The public marketing site may show ads served by Google AdSense. Google may collect device and usage data to show and measure ads, including via cookies. We do not put ads on this Privacy Policy or the Terms page.
Who we share data with
We do not sell your personal data. We share data only as needed to run the service:
- Google Firebase — authentication
- Google Analytics — page views on the marketing site, if you accept cookies
- Google AdSense — ads on marketing pages
- Google Safe Browsing — optional destination checks when that integration is turned on
- Hosting and operations — the servers, database, and cache that run srt.to
- You and people you add — workspace members see shared links; webhook endpoints you set receive click events you subscribe to
- Law or safety — if we must, or to investigate abuse
Those providers have their own privacy policies for data they process.
Retention
- Account, links, bio pages, domains, workspaces, and keys stay until you delete them or we close the account.
- Click rows are kept so we can show analytics. Older clicks may drop out of what your plan can query even if a row still exists.
- Rate-limit records expire after a short window (minutes).
- Abuse reports stay as long as we need them for safety review.
Your choices
You can update or delete links in the dashboard. You can ask us for a copy of the account data we hold, or to delete your account and links, by emailing privacy@srt.to. We will handle that in a reasonable time. We may keep a minimal record if we must (for example a blocked slug or an abuse case).
Depending on where you live, you may also have rights to correct data, object to some processing, or complain to a data-protection authority.
Children
The service is not directed at children under 16. Do not create an account if you are under 16.
International use
We may process data on servers outside your country. If you use srt.to, you understand that your data may be stored and processed where we and our providers operate.
Changes
We will update this page when our practices change and change the date at the top. Continued use after an update means you accept the new policy.
Contact
Privacy: privacy@srt.to
Report a bad link: srt.to/report.html
See also our Terms of Service.