Privacy Policy
Last updated: July 23, 2026
Routly is a link management platform operated by Lunacria LLC, a company registered in Wyoming, United States (“Routly”, “we”, “us”). This policy explains what data we collect, why, and what your choices are. It covers two groups of people: account holders (people who sign up at routly.link) and link visitors (people who click a Routly short link, for example on routly.click).
Questions about anything here: [email protected].
1. Data we collect from account holders
When you create and use a Routly account, we store:
- Profile: your name, email address, and optional avatar image.
- Sign-in: we support Google, GitHub, and email magic links. We store the identifier your sign-in provider shares with us. We never see or store a password — Routly has no password login. Magic-link tokens are stored only as hashes and expire quickly.
- Your content: the links you create and their settings (destinations, targeting rules, UTM tags, custom domains, API keys — keys are stored hashed).
- Plan and billing status: which plan you are on. Payments are handled by a third-party payment processor acting as our merchant of record — your card details go directly to that provider and never touch our servers. Its handling of your payment data is described in its own privacy policy, shown at checkout.
2. Data we collect from link visitors
When someone clicks a Routlylink, we record a click event so the link’s owner can see aggregate analytics. Each event contains:
- a timestamp and the link that was clicked;
- approximate location (continent, country, region, city) and network operator, derived from the visitor’s IP address using a geolocation database that runs on our own servers;
- device information: device type, operating system, browser and versions, and the browser’s user-agent string;
- device characteristicsread on a brief page shown during the redirect — screen size, timezone, language, hardware hints, and the browser’s graphics/canvas, audio and font characteristics (together a “device fingerprint”), plus high-entropy browser client-hints. These are combined into a visitor identifier used only to count unique and returning visitors in a link’s analytics;
- the referring page, UTM campaign tags, and, where the link runs an A/B test, which variant was served.
We never store visitors’ IP addresses. The IP is used only in the moment of the click — to look up the approximate location above and to compute a pseudonymous visitor identifier — and is then discarded. We derive two such identifiers, neither of which reveals who you are: a one-way hash built with a secret salt that rotates every day (so it cannot link visits across days), and a more stable device-fingerprint identifier derived from the device characteristics above, so a link owner can tell new visitors from returning ones. Both are used purely for a link’s aggregate analytics — never to identify a person or to track anyone across unrelated websites — and we do not sell or share them.
Our redirects set no cookies on your device and store nothing on it. Computing the device fingerprint reads characteristics your browser already exposes to sites you visit, but places no cookie or persistent identifier on your device.
3. Features controlled by link owners
Two optional features let our customers do their own measurement. In both cases the customer — not Routly — decides to enable them and is responsible for any notice or consent their use requires:
- Custom link scripts: a link owner can attach their own script (for example a conversion pixel) to a link. It runs on a brief Routly-hosted page before the redirect. Any data such a script collects goes to the link owner or their vendor, under the link owner’s responsibility.
- Conversion tracking: a customer can embed our small script on their own website to attribute sign-ups or purchases to link clicks. That script sets one first-party cookie (
routly_id, 90 days) on the customer’s site — not on routly.link or routly.click.
4. Cookies
routly.link uses only cookies that are strictly necessary to operate the product — the session and security (CSRF) cookies that keep you signed in. We do not use advertising cookies, and we load no third-party analytics or tracking scripts on our site. Because these cookies are essential, they cannot be switched off; if you block them in your browser, sign-in will not work.
Our short-link domains set no cookies at all (see section 2), and the routly_id cookie exists only on customer websites that choose to embed our conversion script (see section 3).
5. How we use data
- to provide the service: route link visitors, show analytics, authenticate you, and bill for paid plans;
- to send transactional email (magic links, account notices) — we do not send marketing email without your consent;
- to prevent abuse, e.g. detecting bot traffic and malicious links;
- to comply with legal obligations.
We do not sell personal data, and we do not share it with third parties except the service providers below.
6. Service providers
We use a small number of third-party providers to run the service and share only the data each needs to do its job:
- a payment processor (our merchant of record) for billing;
- an email delivery provider for transactional email such as magic links;
- an object-storage / CDN provider for assets such as avatar images;
- Google / GitHub — optional sign-in providers, used only if you choose them.
Approximate location is derived on our own servers from an offline geolocation database — no visitor data is sent to the geolocation provider. Third-party data and software licenses are listed on our attributions page.
7. Retention and deletion
- Click analytics are retained according to the link owner’s plan and are deleted when the owner deletes the link or their account.
- When you delete your account (Settings → Danger zone), it is deactivated immediately and kept for a 30-day grace period in case you change your mind — signing back in restores it. After 30 days everything is permanently erased: your profile, links, domains, API keys, and the click events your links generated.
8. Your rights
You can view and update your profile in Settings, and delete your account there at any time. Depending on where you live, you may also have rights to access, correct, export, or erase personal data we hold about you, or to object to certain processing. To exercise any of these, email [email protected] and we will respond within the timeframe your local law requires.
9. Security
All traffic is encrypted in transit (TLS). Credentials such as API keys, refresh tokens, and magic-link tokens are stored only as hashes. Access to production systems is restricted to the operators who need it.
10. Where data is processed
Routly is operated from the United States and data is processed on servers we control. If you use the service from outside the US, your data is transferred to and processed in the US.
11. Children
Routly is not directed at children and may not be used by anyone under 13. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.
12. Changes to this policy
We will update this page when our practices change and revise the “last updated” date above. For material changes affecting account holders, we will also give notice by email or in the app.
13. Contact
Lunacria LLC (Wyoming, United States) — [email protected]. See also our Terms of Service.