Privacy Policy

Last updated: September 30, 2026

At Flyn ("we", "our", "us"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our link management platform at flyn.to (the "Service").

1. Information We Collect

Account Information

When you create an account, we collect your email address and display name. You can sign in with Google or with your email and a password. Passwords are handled by our authentication provider, Supabase, which stores them only as one-way hashes, never in readable form. We also email one-time links and codes to confirm your address and to reset a password.

Links You Create

When you create a short link, we store its destination URL, its slug and domain, and any title, tags, expiry date, notes and settings you add, together with its click counts. You can edit or delete your links at any time.

AI Assistants and Apps You Connect

If you connect an AI assistant or another app to your Flyn account through our MCP server (for example ChatGPT, Claude or Cursor), you allow it to act for you: it can create, view, edit and delete your links, read their click analytics and generate QR codes, and it receives the results of the requests it makes. It never receives your Flyn password. When an app connects by signing in to Flyn, we keep a record of the connection (the app's name, when it connected and when it was last used) and store the sign-in tokens it uses only as one-way hashes. Those access tokens expire after one hour, an app you stop using loses its sign-in after 90 days, and you can disconnect it at any time under Settings, then Connected Apps, which ends its access immediately. An app you connect with an API key instead keeps working until you revoke that key under Settings, then API Keys. What an app does with the data it receives is governed by that app's own privacy policy.

Chrome Extension

If you use the Flyn Chrome extension, it sends Flyn the address of the tab you are on when you open it on a web page, so it can shorten that page, plus any address you paste, right-click, or select to shorten, with the slug and domain you choose. When you ask for a QR code, the short link is sent to api.qrserver.com, a third-party service that draws the QR image. The extension keeps your access key, settings, and recent links in Chrome's own storage; signing out removes them and revokes the key. Apart from a link or text you right-click to shorten, it does not read the content of the pages you visit, and it contains no analytics. Flyn's use of information received from the Flyn Chrome extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Link Analytics Data

When someone clicks a short link created through Flyn, we collect:

  • Timestamp of the click
  • Approximate geographic location (country and city, derived from IP address)
  • Device type, operating system, and browser
  • Referrer URL (the page the click came from)

We do not collect or store the clicker's IP address beyond the initial geo-lookup. IP addresses are never stored in our analytics database.

Usage Data

We collect standard web analytics about how you use the Flyn dashboard: pages visited, features used, and session duration. This helps us improve the product.

2. How We Use Your Information

  • To provide and maintain the Service
  • To display click analytics for your short links
  • To send transactional emails (login codes, account alerts)
  • To send product update emails, which you can unsubscribe from at any time
  • To improve the Service based on usage patterns
  • To prevent abuse, fraud, and security threats. When a short link is created, we check its destination with Google Web Risk and our own blocklists, and our server may load the destination page to look for malware and phishing.

3. What We Never Do

  • We never sell your data to third parties
  • We never share personal information with advertisers
  • We never use your data for targeted advertising
  • We never store clicker IP addresses beyond the initial lookup

4. Data Sharing

We may share data only in these limited circumstances:

  • Service providers: Cloud hosting (Supabase, Vercel), product analytics (PostHog, EU region, with input fields masked in session recordings), Google (Web Risk checks of link destinations, and Google sign-in if you choose it), and email services that process data on our behalf, including MailerCloud for product emails
  • Apps you connect: AI assistants and other apps you connect to your account receive the data their requests return, as described above
  • Legal compliance: If required by law, regulation, or valid legal process
  • Business transfers: In connection with a merger, acquisition, or sale of assets (with prior notice)

5. Data Retention

Account data is retained while your account is active. Analytics data is retained for up to 2 years. Sign-in tokens for connected apps are deleted automatically after they expire or are revoked. You can request deletion of all your data at any time by contacting us.

6. Security

We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest, regular security audits, and access controls. All data is hosted in SOC 2 compliant data centers.

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data ("right to be forgotten")
  • Export your data in a portable format
  • Restrict or object to processing

To exercise any of these rights, email us at [email protected].

8. Cookies

Essential cookies handle authentication and session management. These are always on, because signing in does not work without them.

Analytics cookies are optional and off by default. If you accept them, we load Google Analytics and PostHog to understand how the site is used. If you decline, or simply ignore the banner, neither is loaded and no analytics cookies or identifiers are created. You can change your mind at any time by clearing this site's data in your browser, which makes the banner appear again.

We do not run advertising pixels on this website, and we do not sell or share your data with advertisers.

9. Children's Privacy

Flyn is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice in the Service. Your continued use after changes constitutes acceptance.

Contact

If you have questions about this Privacy Policy, contact us at [email protected].