Legal

Privacy Policy

What Blinkhop collects and why: no cookies, no trackers, no IP addresses stored with links or clicks, aggregated click counts only, and your rights under the GDPR.

About this policy

Last updated
October 11, 2026
Applies to
blinkhop.com, zou.sh, the API and MCP
Questions
Use the contact form
On this page

This Privacy Policy explains what data Blinkhop collects when you use blinkhop.com, zou.sh short links, our API and our MCP server, why we collect it and how long we keep it. The short version: as little as possible. We set no cookies, use no trackers or ads, and never store IP addresses with the links you create or the clicks they get.

Blinkhop (“we”, “us”) is responsible for this data, as the “controller” under the EU and UK GDPR. For any privacy question or request, use the form on /contact.

At a glance

What we collect Why How long
Short links: destination URL, code, creation time, how the link was made To run the link and its public preview As long as the link exists
Click counts per day by country, referrer domain and device type To show link statistics As long as the link exists
IP addresses, in memory only Rate limits and abuse prevention Up to 24 hours after your last request
Website request log: time, page, response status and size (no IP address) Troubleshooting Up to 15 days
Early-access list: email, chosen plan, date To tell you when accounts open Until accounts launch, or sooner if you ask
Contact forms: email, topic, message, date To answer you Up to 24 months
Abuse reports: link code, optional reason, date To act on harmful links As long as the reported link’s record exists

1. What we collect

When you visit blinkhop.com

Our web server keeps a minimal request log of pages on blinkhop.com: the date and time, the page requested, the response status and its size. It records no IP address, no browser user agent and no referring page. Requests sent by the shortener form aren’t logged at all. If a request fails because of a serious problem on our side, technical details, which may include a network address, can appear in an error log. We use these logs only for troubleshooting and delete them after 15 days at most.

The Paste button reads your clipboard on your device; we only receive the link you shorten.

A redirect sets no cookies, and the visitor’s IP address isn’t stored. We only add one to the link’s counts for that day:

  • the country, as a two-letter code that Cloudflare works out from the IP address;
  • the referring website’s domain (for example news.example.com), never the full address;
  • the device type: mobile or desktop.

We also update the link’s total clicks and the time of its latest click. We read the browser’s user agent to tell people from bots and phones from computers, then discard it.

We store the destination URL, the short code or custom ending, the creation time and how the link was created (website, API or MCP). We don’t store your IP address or anything else that identifies you.

Links are public by design: anyone who has or guesses a short link can see its destination, creation date and total clicks. Don’t shorten URLs that contain personal information or private sharing links.

When you use the API or MCP server

The API and the MCP server store the same link data as above, and we keep no access logs for them. With MCP, we receive what your AI assistant sends in its tool calls, such as a URL to shorten, never your conversation.

Whenever you create links or send reports, your IP address is held in memory to enforce rate limits. This memory is never written to disk.

When you join the early-access list

We store your email address, the plan you chose and the date, and use them only to contact you about accounts.

When you use a contact form

The forms on /contact and /security store your email address, your name if you give it, the topic, your message and the date, so we can answer you. The form on /abuse works like a link report (see below) and doesn’t ask for your email.

A report sent from a link’s + preview page, the abuse form or the API stores the link code, the reason you give (optional) and the date. We don’t ask who you are.

2. What we don’t collect

  • No cookies. Blinkhop sets no cookies on the website, on short links, or in the API and MCP server.
  • No trackers. No analytics scripts, tracking pixels, social widgets or ad networks. Fonts and images are served from our own domain.
  • No IP addresses with links or clicks. IP addresses never reach our database, and our request logs don’t record them.
  • No fingerprinting. We don’t combine browser or device signals to recognize you, and we don’t build profiles.
  • No selling. We don’t sell or rent personal data, and we don’t share it with advertisers or data brokers.
Purpose Legal basis under the GDPR
Creating links and answering API and MCP requests Performance of our Terms of Service (Art. 6(1)(b))
Redirecting visitors and producing aggregated click statistics Legitimate interests: running the service and offering simple statistics (Art. 6(1)(f))
Rate limits, server logs, blocklist checks and abuse reports Legitimate interests: keeping Blinkhop and its users safe (Art. 6(1)(f))
Early-access list Your consent (Art. 6(1)(a)), which you can withdraw at any time
Answering contact form messages Legitimate interests: replying to you (Art. 6(1)(f))

We also keep or disclose data when the law requires it (Art. 6(1)(c)). We make no automated decisions that have legal or similarly significant effects on you: our blocklist checks destinations, not people.

4. How long we keep data

  • Links and their aggregated statistics: as long as the link exists. Links don’t expire, and disabled links stay in our records so the same destination can’t be shortened again.
  • Abuse reports: as long as the reported link’s record exists, to review past decisions and spot repeat abuse.
  • IP addresses for rate limits: in memory only, for up to 24 hours after your last request.
  • Server logs: deleted automatically after 15 days at most.
  • Early-access list: until accounts launch and we’ve told you, then deleted, or sooner if you ask.
  • Contact form messages: up to 24 months, then deleted.

5. Who processes data for us

Cloudflare provides the CDN, TLS encryption and DDoS protection in front of all our domains. Every request passes through Cloudflare, which processes it, including your IP address, on our behalf under its data processing addendum. We’ve switched off its bot challenges, so it sets no cookies in normal operation; during an attack, it may set a strictly necessary security cookie.

Blocklist sources. Every night, we download public lists of phishing and malware domains from URLhaus (abuse.ch) and the Phishing.Database project. We send them no data about you or your links, so they’re data sources, not processors.

Everything else, including our database and server logs, runs on a server we manage. We don’t share personal data with anyone else, unless the law requires it.

6. International transfers

Your requests go through the Cloudflare data center nearest to you, which may be outside the European Economic Area (EEA) or the UK. Cloudflare, Inc. is based in the United States. As of October 2026, its data processing addendum protects transfers out of the EEA, the UK and Switzerland with the EU-U.S. Data Privacy Framework and the European Commission’s Standard Contractual Clauses.

7. Your rights

Under the GDPR and similar laws, you can ask us to:

  • give you access to your personal data and a copy of it;
  • correct it;
  • delete it;
  • restrict how we use it, or object to uses based on legitimate interests;
  • send it to you in a portable format;
  • stop using it based on your consent, for example by removing you from the early-access list (this doesn’t affect past use).

To exercise any of these rights, use the form on /contact. It’s free, and we answer within one month. We may ask you to confirm the request comes from you, for example by writing from the email address you gave us.

One honest limit: links and clicks aren’t tied to IP addresses or accounts, so we usually can’t tell which ones are yours. We can act on data linked to your email address, and we’ll review any request about a specific link, such as one that exposes your personal information.

You can also complain to your local data protection authority.

8. Children

Blinkhop is not directed at children under 16, and we don’t knowingly collect their personal data. If you’re under 16, please don’t join the early-access list or send us personal details. If you think a child has given us personal data, tell us through /contact and we’ll delete it.

9. Security

We protect the data we keep with:

  • Encryption in transit: HTTPS is enforced on all our domains, with TLS 1.2 or newer.
  • Data minimization: we collect as little as we can, and IP addresses never reach our database.
  • Isolation: the link service runs as a dedicated, unprivileged system user that can only write to its own data folder.
  • Hardened pages: security headers on our sites, and a strict Content Security Policy on zou.sh pages.
  • Responsible disclosure: you can report vulnerabilities through /security.

No system is perfectly secure, but the less data we keep, the less there is to protect.

10. Changes to this privacy policy

We’ll post any update on this page and change its date. Significant changes will also appear in the changelog. If we ever want to use your early-access email for something new, we’ll ask for your consent first.

Other policies

  • Legal

    Acceptable Use Policy

    What you can't do with Blinkhop and zou.sh links: forbidden destinations and behavior, how we enforce the rules, and how to report a link or appeal a decision.

  • Legal

    Terms of Service

    The rules for using Blinkhop: free zou.sh short links, the API and MCP server, early-access plans, your responsibility for links, and when we disable them.

Plain rules, no surprises.

No ads, no selling of data, no tracking cookies. If something is unclear, ask us.