Privacy

Privacy Policy

Last updated: August 27, 2026

This policy explains what personal data NanoLink collects, why we collect it, and what your choices are. We’ve tried to keep it short and easy to understand.

1. What we collect

When you use NanoLink we collect:

  • Account info — name, email, avatar, and (if you sign in with Google) your Google account ID.
  • Links you create — the destination URL, alias, and any tags or folders you add.
  • Click data — timestamp, country/region (from IP), device type, browser, and referring site. We store an anonymized visitor fingerprint to detect fraud, not to profile individuals.
  • Payment info — the payout method you choose (PayPal address, wallet address, etc.). We do not store card numbers.
  • Support messages — anything you send us.

2. How we use it

  • To run the Service — sign you in, resolve short links, show your analytics.
  • To process payouts and comply with tax and finance regulations.
  • To detect fraud, abuse, and inflated traffic.
  • To send transactional emails (verification, payouts, security alerts).
  • To improve NanoLink — we use aggregated, non-identifying usage stats to fix bugs and design better features.

We do not sell your personal data.

3. Who we share it with

We only share personal data with providers we need to operate NanoLink, and only what they need:

  • Google — for Sign in with Google.
  • Cloudflare R2 — for file uploads (logos, page assets).
  • Tinybird — for aggregate click analytics.
  • Gmail SMTP — for transactional email.
  • Payout providers — when you request a withdrawal.

We may disclose data if required by law, or to protect NanoLink and its users from fraud or abuse.

4. How long we keep it

We keep account data as long as your account is active. If you delete your account, we remove your personal data within 30 days, except records we must keep for tax, fraud, or legal reasons.

Click logs are aggregated and stripped of IP addresses after 90 days.

5. Your rights

You can access, correct, download, or delete your personal data from your account settings, or by emailing us. Depending on where you live, you may also have the right to object to certain processing or to complain to a data-protection authority.

6. Security

We use TLS for all traffic, encrypt refresh tokens at rest, and hash passwords with bcrypt. We’re a small team, so perfect security doesn’t exist — but we take it seriously and will notify affected users of any breach that affects them.

7. International transfers

NanoLink is operated from servers that may be located outside your country. By using the Service you agree to your data being transferred and processed in those countries, with the protections described in this policy.

8. Children

NanoLink is not for children under 16. We don’t knowingly collect data from anyone under that age.

9. Changes to this policy

We’ll update this page if our practices change, and highlight material changes in-app or by email.

Questions?

Email us at support@nanolink.site. We reply within 2 business days.