Privacy Policy
Last updated 2026-09-02
memo.link turns long links into short ones you can say out loud. This policy explains what we do with personal data, in plain terms and without the usual padding.
The short version: we collect your email address, and almost nothing else. There are no tracking cookies, no advertising pixels, and no record of individual visits to your links, anywhere in the product, on any plan.
Who is responsible
Gabriele Morano, Rome, Italy is the data controller.
Contact for anything in this policy: privacy@admin-memo.link
No Article 27 representative is appointed, and none is required: the controller is established in Italy, which is within the EU.
What we collect, and why
| What | Why we have it | Our legal basis |
|---|---|---|
| Your email address | It is your only credential, we send you a code to sign in | Performance of a contract |
| Your display name and bio, if you add them | You chose to publish them on your own page | Performance of a contract |
| Which language you prefer | So your dashboard and our emails to you are in it | Performance of a contract |
| Your time zone, if you set one | So a link you schedule changes at the hour you meant, not ours | Performance of a contract |
| The browsers you connect through our extension, a name like "Chrome on macOS", and when each was last used | So you can see what has access to your account and disconnect it | Performance of a contract |
| The links you create, addresses, labels, destinations | This is the service | Performance of a contract |
| Abuse reports about a page | Keeping a link service from being used for fraud | Our legitimate interest |
We do not ask for your name, your phone number, your address, or your date of birth. We have no use for them.
What we deliberately do not collect
This is the part most policies leave vague, so here it is precisely.
We do not log visits to your links. When someone opens one of your links we add one to a counter and record the date. We do not store who they were, where they were, what browser they used, or which page sent them. There is no per-visit record in our systems to look up, hand over, or lose.
We do not set tracking cookies. Public pages set no cookies at all. Signing in sets one cookie so you stay signed in, nothing else. The main site keeps a preference you have set, your theme, and an accent colour you chose, in your browser's localStorage, so the page paints the right way before it loads; it holds nothing but those choices and never leaves your browser. A colour you were merely given at random is kept only for the visit and is gone when the tab closes. The main site also shows a short notice saying this, it is information, not a request for consent, since nothing here needs one, and remembers that you dismissed it. On a phone or a tablet it also remembers what you did with the offer to install memo.link on your home screen, so the offer stops asking.
We do not use advertising or analytics services. No Google Analytics, no Meta pixel, no third-party advertising or analytics script anywhere on this site or on your pages. Nobody can add one to their own page either; the product has no mechanism for it.
Our own counting is described above and is the whole of it: totals on a page, incremented when somebody reaches an address and again if they tap through to where it leads. It sets nothing on the device and identifies nobody, and there is no per-visit record for it to belong to.
Two third parties run code in your browser, both only on the main site and never on your pages:
Cloudflare Turnstile, on the sign-in form. It checks you are not a script requesting sign-in codes in bulk. To do that it reads your IP address, the technical fingerprint of your browser's secure connection, and your browser's User-Agent string. It stores nothing on your device, no cookie, no local storage.
Sentry, which tells us when something breaks. It is error reporting, not analytics, it records nothing when the product is working. Reports are stripped before they leave: no IP address, no cookies, no request contents, nothing you typed, and no session recording. When something goes wrong on one of your pages the report is made on our servers, not in the visitor's browser, and it does not include which address was being opened, an unlisted address is meant to stay unguessable, and a crash is no reason to hand it to a third party.
Neither is present on your pages, so people opening your links never meet either of them.
We do not sell or share personal data. Not to advertisers, not to data brokers, not to anyone. There is no opt-out to offer because there is nothing to opt out of.
Emails we send you
Three kinds, and no marketing among them:
| When | |
|---|---|
| Your sign-in code | Each time you sign in |
| An explanation | If we suspend something you created, restore it, warn visitors about where one of your links leads, or reclaim a name, saying what and why so you can contest it |
| A notice | Before we change this policy or our terms in a way that affects you |
If you report a page
You do not have to sign in to report something, and we do not record who you are, there is no reporter identity in our systems.
What you write is kept for 12 months after we resolve it, and it is shown to the person you reported: once when we explain why something was removed, and again if they download their data. That is why the form asks you to describe the content and leave out personal details about yourself or anyone else.
What happens when someone opens your link
Opening a link necessarily involves your visitor's device contacting our hosting provider, which sees their IP address in order to deliver a response, as every website does. We do not store it and it does not reach our database. Our provider's own transient logs are covered by their agreement with us.
They then see a page from us showing your address and where it leads, and they tap to continue. Before showing it, our servers ask Google Safe Browsing whether that destination is known to be dangerous, and warn them if it is. The same happens for the destinations listed on a page of links. That question is asked by us and not by their browser, it carries the destination and nothing about them, and the answer is reused for an hour, so it is a question about an address rather than a record that somebody visited it.
Nothing about your visitor is stored at any point in that, which is the same thing this page says everywhere else. It is written out here because this is the section people read when they want to know what actually happens.
Who else processes data for us
| Provider | What they do | Where |
|---|---|---|
| Supabase | Stores the database and handles sign-in | European Union |
| Vercel | Runs the website and routes traffic | European Union (functions); global edge network |
| Resend | Delivers the email we send you, including your sign-in code | United States, processing in the European Union |
| Aruba S.p.A. | Holds the mailboxes you can write to us at | Italy (EEA) |
| Cloudflare | Turnstile, the anti-bot check on the sign-in form | Global |
| Sentry | Error reports, scrubbed of anything identifying | European Union |
| Google Safe Browsing | Checks whether a destination is known to be malicious, when you save it, and again when somebody opens it | United States |
The Safe Browsing check sends the destination, never anything about you, and never anything about the person looking at it. It happens when you save a link and again whenever one of your destinations is shown to somebody, so that a page which turned bad after you saved it can be caught. Answers are reused for an hour, which means it is a question about an address rather than a record of a visit.
Each of these acts on our instructions under a data processing agreement.
How long we keep things
| What | How long |
|---|---|
| Your account and your links | Until you delete them |
| Abuse reports | 12 months after they are resolved, then erased |
| Visit counters | Until you delete the link, there is no visit history to age |
| The browsers you connect | Until you disconnect them or delete your account |
| An address you started claiming but never signed in for | The email you gave is erased within a day; the name is simply released |
Deleting your account
You can delete your account at any time from your settings.
Deletion is immediate and cannot be undone. Your email address, your profile, your links and your counters are erased. Every address you created stops working, including any you have printed on something, put on a sign, or given to people. We will say this clearly before you confirm, because for this product it is a bigger deal than for most.
None of your subdomain names is given to anyone else for 30 days afterwards, every one of them, if you hold more than one. That is not us keeping your data, the names are released, not retained, it is so that anything you printed does not suddenly lead to a stranger's page.
It is not held for you either, and cannot be: erasing your account removes everything that marked the name as yours, so during those 30 days there is nobody we could give it back to.
Keeping it safe
Data is held by Supabase in the European Union, encrypted in transit and at rest. Access to production data is limited to people who need it. We do not hold payment details, because we do not take payments.
If memo.link ever closes
Our intention is to tell you before it happened, give you time to export everything, and then delete what remains. We mention it because this product invites you to print addresses on physical things, and you deserve to know there is a plan rather than a silence.
That is an intention rather than a promise, and our Terms say so in the same words, there are circumstances in which we could not give notice, and committing to it would be committing to something we might not be able to do. Your right to export your data does not depend on it.
Your rights
If you are in the EU, the UK, or a country with comparable law, you have the right to:
- See what we hold about you, most of it is visible in your account already
- Correct anything wrong
- Delete your account and data
- Take your data with you in a machine-readable file, from your settings, everything your account holds, including any reports made about your pages
- Object to processing based on legitimate interest
- Complain to your data protection authority
Write to privacy@admin-memo.link. We will answer within one month. If a request is unusually complex we may need longer, the law allows up to two further months, and if that happens we will tell you within the first month and say why. You do not need to explain why you are asking, and asking costs you nothing.
California
We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not in the preceding twelve months. California residents have the same access and deletion rights described above; the mechanism is the same address.
Children
memo.link is not for anyone under 16. We do not knowingly collect data from children, and if we learn we have, we will delete it.
Changes
If we change this policy in a way that affects you, we will email you, we have your address, and this is one of the few things worth using it for.