Privacy Policy
Last updated: June 2026
What we store
When you shorten a URL with Nigga Link, we store the destination URL you provided and assign it a short code (either a random one or the custom link text you chose). That's it.
- ✓ Destination URL
- ✓ Short code, including custom link text if you chose one
- ✓ Creation timestamp
- ✓ Anonymous click counter (a number, no details)
- ✓ Your IP address, held in server memory for up to 60 seconds for rate limiting only (max 10 requests per minute), never written to disk or database
- ✓ IP address and browser info captured in Vercel's infrastructure logs, retained per Vercel's policy
- ✗ Any cookies
- ✗ Any session data
- ✗ Analytics or tracking data
Custom link text
If you choose your own link text, it becomes part of a public URL. Please do not include personal data (such as names, email addresses or phone numbers) in custom link text. We treat custom text as content you chose to publish, not as personal data we collect.
Click statistics
Anyone who knows a short link can view its click count and creation date by appending a plus sign (for example /abc+). The statistics consist of a single anonymous counter. We do not record who clicked, when individual clicks happened, or where visitors came from.
QR codes
QR codes are generated entirely in your browser. The image never touches our servers and nothing about it is stored or transmitted.
Redirects
When someone visits a short link, they are immediately redirected via a server-side HTTP redirect. We do not set cookies, load third-party scripts, or display an intermediate consent page because we collect no personal data during the redirect. The only thing that happens is that the anonymous click counter increases by one.
GDPR basis
Our legal basis for processing destination URLs and operating the rate limiter is legitimate interest (Art. 6(1)(f) GDPR): providing the shortening service and protecting it against abuse. Beyond the short-lived rate limiting described above, we do not process personal data as defined under GDPR.
Data location
The database is stored in MongoDB Atlas on AWS eu-west-1 (Ireland), within the EU. Application infrastructure runs on Vercel's global edge network, meaning requests may be processed on nodes outside the EU before reaching our database.
Sub-processors
We rely on two infrastructure providers that act as data processors under GDPR:
- Vercel (hosting and edge network) Privacy Policy
- MongoDB Atlas (database) Privacy Policy
Your rights and link removal
Under GDPR you have the right to access, rectify and erase data concerning you (Art. 15 to 17 GDPR). Since we store no personal data beyond what is described above, the most relevant request is removal of a short link, for example one whose custom text or destination concerns you. To request removal, open an issue on GitHub with the short code in question and we will delete it.
Free tools
The tools available at /tools are designed to run entirely in your browser wherever possible:
- QR Code Generator — the QR image is generated client-side and never leaves your device. No data is sent to our servers.
- UTM Link Builder — all URL construction happens in your browser. No data is sent to our servers.
- Password Generator — passwords are generated using your browser's built-in
crypto.getRandomValuesAPI and never transmitted anywhere. - IP Address Checker — your browser makes a request to
/api/ip, which reads your IP from the incoming request headers and returns it. The IP is not stored or logged by us beyond Vercel's standard infrastructure logs (see Sub-processors above).
No third-party sharing
Beyond the sub-processors listed above, we do not share any data with third parties, run analytics, or use advertising services of any kind.