← back
Legal / GDPR

Privacy Policy

Last updated: June 2026

What we store

When you shorten a URL with Nigga Link, we store the destination URL you provided and assign it a short code (either a random one or the custom link text you chose). That's it.

  • ✓ Destination URL
  • ✓ Short code, including custom link text if you chose one
  • ✓ Creation timestamp
  • ✓ Anonymous click counter (a number, no details)
  • ✓ Your IP address, held in server memory for up to 60 seconds for rate limiting only (max 10 requests per minute), never written to disk or database
  • ✓ IP address and browser info captured in Vercel's infrastructure logs, retained per Vercel's policy
  • ✗ Any cookies
  • ✗ Any session data
  • ✗ Analytics or tracking data

Custom link text

If you choose your own link text, it becomes part of a public URL. Please do not include personal data (such as names, email addresses or phone numbers) in custom link text. We treat custom text as content you chose to publish, not as personal data we collect.

Click statistics

Anyone who knows a short link can view its click count and creation date by appending a plus sign (for example /abc+). The statistics consist of a single anonymous counter. We do not record who clicked, when individual clicks happened, or where visitors came from.

QR codes

QR codes are generated entirely in your browser. The image never touches our servers and nothing about it is stored or transmitted.

Redirects

When someone visits a short link, they are immediately redirected via a server-side HTTP redirect. We do not set cookies, load third-party scripts, or display an intermediate consent page because we collect no personal data during the redirect. The only thing that happens is that the anonymous click counter increases by one.

GDPR basis

Our legal basis for processing destination URLs and operating the rate limiter is legitimate interest (Art. 6(1)(f) GDPR): providing the shortening service and protecting it against abuse. Beyond the short-lived rate limiting described above, we do not process personal data as defined under GDPR.

Data location

The database is stored in MongoDB Atlas on AWS eu-west-1 (Ireland), within the EU. Application infrastructure runs on Vercel's global edge network, meaning requests may be processed on nodes outside the EU before reaching our database.

Sub-processors

We rely on two infrastructure providers that act as data processors under GDPR:

Your rights and link removal

Under GDPR you have the right to access, rectify and erase data concerning you (Art. 15 to 17 GDPR). Since we store no personal data beyond what is described above, the most relevant request is removal of a short link, for example one whose custom text or destination concerns you. To request removal, open an issue on GitHub with the short code in question and we will delete it.

Free tools

The tools available at /tools are designed to run entirely in your browser wherever possible:

  • QR Code Generator — the QR image is generated client-side and never leaves your device. No data is sent to our servers.
  • UTM Link Builder — all URL construction happens in your browser. No data is sent to our servers.
  • Password Generator — passwords are generated using your browser's built-in crypto.getRandomValues API and never transmitted anywhere.
  • IP Address Checker — your browser makes a request to /api/ip, which reads your IP from the incoming request headers and returns it. The IP is not stored or logged by us beyond Vercel's standard infrastructure logs (see Sub-processors above).

No third-party sharing

Beyond the sub-processors listed above, we do not share any data with third parties, run analytics, or use advertising services of any kind.