Skip to content

Privacy Policy

Last updated: July 23, 2026

This policy explains what data in.bio collects, why, who processes it, and what your rights are. The data controller is InBio, Inc., a Delaware C corporation, 1111B S Governors Ave STE 39177, Dover, DE 19904, United States (“InBio”, “we”). The short version: we collect what the service needs to work, we never store raw visitor IP addresses in analytics, and we don’t sell data to anyone.

1. Data we collect

Account data. Email address, name, and a hashed password (or your Google account identifier if you sign in with Google). Billing status and plan come from our payment provider; we never see or store your card number.

Content you create. Links, destination URLs, titles, tags, folders, QR code designs, UTM templates, and API tokens you generate. For anonymous (no-account) links we also keep a hashed, irreversible fingerprint of the creator’s IP address, used solely for rate limiting and abuse prevention.

Click analytics. When someone opens a short link we record: a timestamp, the country (derived at our edge provider from the network request), device type, browser and operating system family (parsed from the user agent), and the referrer domain. To count unique visitors we compute a one-way hash of the visitor’s IP address with a secret key that rotates daily, so the same visitor cannot be recognized across days and the raw IP address is never written to our analytics database. Visitors sending the Do Not Track header are excluded from analytics.

Technical logs. Standard server and security logs (which may contain IP addresses) retained briefly for security and debugging, and error reports sent to our monitoring service when something breaks.

2. What we use it for

  • Running the service: redirects, dashboards, QR codes, and the analytics you see for your links.
  • Security: rate limiting, bot filtering, phishing and abuse prevention.
  • Billing and account email (verification, password resets, subscription receipts).
  • Fixing bugs, via error monitoring with limited request context.
  • Understanding overall site traffic through cookieless web analytics — no advertising trackers, no cross-site profiles.

We do not sell personal data and there is no ad tech on this site.

3. Services that process data for us

  • Cloudflare (US) — CDN, DNS, TLS, bot protection (Turnstile), and hosting for our documentation and agent endpoints. All traffic passes through Cloudflare’s edge.
  • Akamai / Linode (US) — the servers and database the application runs on.
  • Stripe (US) — payments and subscriptions. Card data goes directly to Stripe and is governed by Stripe’s own privacy policy.
  • Resend (US) — delivery of transactional email.
  • Sentry (US) — error monitoring; error reports can include request metadata such as IP address and user agent.
  • Ahrefs Analytics — cookieless, aggregate website analytics.
  • Google (US) — only if you choose “Sign in with Google”.
  • Telegram — internal operational alerts to our team (for example “new account registered”), which can include an account email address.

Data is processed in the United States. By using the service you consent to this transfer.

4. Cookies

We set only functional cookies: a session cookie and a CSRF token (both required for the app to work); Cloudflare may set its own security cookies. Our web analytics is cookieless, and we set no advertising or cross-site tracking cookies — which is why there is no cookie banner.

5. Retention

  • Raw click events: 90 days, then deleted; aggregated daily statistics are kept.
  • Anonymous links and their data: deleted after 30 days unless claimed.
  • Account data: kept while the account exists; deleted within 30 days of account deletion.
  • Invoices and billing records: kept as long as tax law requires.
  • Server logs: rotated on a short schedule (days, not months).

6. Your rights

You can access and update your data in Settings, export your links as CSV, and delete your account (which deletes your links and analytics). Where GDPR, UK GDPR, or CCPA applies, you additionally have the rights to access, rectify, erase, restrict, port, and object — email hello@in.bio and we will respond within 30 days. You may also lodge a complaint with your local supervisory authority.

7. If you clicked an in.bio link

The link owner sees only the aggregate statistics described in section 1 — never your IP address or identity. Destination sites have their own privacy practices we do not control; you can inspect any short link before visiting it at in.bio/preview/<slug>.

8. Security

TLS everywhere (including between our edge and origin servers), hashed passwords, scoped API tokens, daily-rotating analytics keys, nightly database backups, and least-privilege access to production. No system is perfect; if a breach affects your data we will notify you without undue delay.

9. Children

The service is not directed at children under 13, and we do not knowingly collect their data.

10. Changes

If we make material changes to this policy we will notify account holders by email and post a notice on the site at least 14 days before the change takes effect.

11. Contact

InBio, Inc., 1111B S Governors Ave STE 39177, Dover, DE 19904, United States. Privacy questions or requests: hello@in.bio, or use the contact page.