Privacy

Last updated: September 22, 2026

When someone clicks a gozi.to link

We record an anonymous click event: the short link, the visitor's country (from the network, not GPS), device type, browser and operating system family, the referring website's domain, and whether the visitor looks like a bot. We don't store IP addresses, full user-agent strings or any identifier for the visitor, and we don't set cookies on redirects. Click events are kept for 90 days, then only daily totals per link are kept.

When you create a link

We store the destination URL and a keyed hash of your IP address, used only to enforce rate limits and investigate abuse. The hash is deleted after 30 days. Destination URLs are sent to Google Safe Browsing to check for known threats.

Accounts

If you sign in with GitHub or Google, we store your email address, name and profile picture URL from that provider, plus a session cookie that keeps you signed in. We use your email only to identify your account and to contact you about it.

Cookies

Signed-in users get a session cookie and a small cookie that tells our pages you're signed in. There are no advertising or third-party tracking cookies. Our forms use Cloudflare Turnstile to tell humans from bots.

Service providers

Gozi.to runs on Cloudflare, which processes requests and stores our data. Destination URLs are checked with Google Safe Browsing. Sign-in is handled by GitHub or Google, depending on which one you choose.

Your choices

You can delete any of your links at any time. To delete your account and its data, email hello@gozi.to from the address on your account.