Shareth policies

Privacy Policy

1. Scope and contact

This Privacy Policy explains how Shareth collects, uses, discloses, and retains information when you use our websites, short links, QR codes, pastes, profiles, APIs, and related services. The owner of Shareth is the controller of personal information described here unless another arrangement is stated.

Privacy questions and rights requests can be sent to [email protected]. We may need to verify your identity before completing a request.

2. Information you provide

We collect account details such as your name, @handle, email address, password credential (stored as a secure hash), preferences, and communications with us. We also process content you choose to create, including destination URLs, titles, pastes, profile details, QR labels, custom aliases, reports, and API-token metadata.

Do not submit sensitive personal information that is unnecessary for the Service. API-token secrets are shown once; we store a one-way hash rather than the complete token.

3. Information collected when the Service is used

We receive technical and usage information needed to deliver and secure the Service, such as request time, requested resource, device category, general referrer domain, browser class, status, and security signals. Our infrastructure and reverse-proxy logs may temporarily contain IP addresses, user-agent strings, and request details for reliability, debugging, and abuse prevention.

For product analytics, Shareth derives a rotating, one-way visitor key from limited request signals. Raw IP addresses and complete user-agent strings are not stored in the analytics-event table. A derived visitor key is not intended to identify a person, but we still protect it as usage data.

4. How we use information

We use information to:

  • provide, route, render, and manage shares, profiles, QR codes, accounts, and APIs;
  • authenticate users, prevent fraud and abuse, enforce policies, and protect the Service;
  • calculate privacy-minded analytics and understand product performance;
  • send account verification, password reset, security, service, and opted-in product messages;
  • respond to support, legal, privacy, and safety requests; and
  • comply with law, resolve disputes, and establish or defend legal claims.

5. Legal bases

Where data-protection law requires a legal basis, we rely on performance of our contract to provide requested features; legitimate interests in operating, securing, improving, and understanding the Service; consent where requested for optional communications or similar processing; and compliance with legal obligations. You may object to processing based on legitimate interests, but we may have compelling reasons to continue.

6. URL sharing, public posting, and protected content

New links and pastes are not posted in Shareth Discover. Anyone who obtains an unprotected share’s URL can still open it. If you choose “Post to Shareth,” your public username, the share title, and related public metadata can appear in Discover, and the share may be indexed, copied, embedded, or reshared. Password-protected or signed-in-only content remains subject to recipient behavior and security risks. Removing a post does not erase copies already made by others.

Adding a share to your public profile is separate from posting it in Discover. Profile links expose their labels, descriptions, and linked destinations to profile visitors, but do not place those shares in site-wide discovery. Suggestions shown in your own profile builder are based on your active, unprotected links.

7. When we disclose information

We disclose information to vendors that help host, secure, deliver, monitor, and support Shareth, including server infrastructure, Cloudflare, database and email-delivery components. They may process information only for their contracted purpose and under appropriate safeguards.

We may also disclose information when required by law; to protect users, the public, Shareth, or others; with your direction; or in connection with a financing, merger, acquisition, reorganization, or sale of assets subject to appropriate confidentiality. We do not sell personal information or share it for cross-context behavioral advertising.

8. Cookies and local storage

Shareth uses essential cookies or comparable storage for sign-in, session security, preferences, and request integrity. We do not currently use third-party advertising cookies. Blocking essential cookies may prevent account features from working.

9. Retention

We keep account and content data while your account or share remains active and as needed to provide the Service. Raw analytics events are scheduled for deletion after 45 days; aggregated daily analytics may be retained longer because they are less granular and support historical reporting. Security and proxy logs are retained for a limited period appropriate to operational needs.

Deleted information may remain temporarily in backups or be retained when reasonably necessary for fraud prevention, legal compliance, disputes, or enforcement. When no longer needed, it is deleted or de-identified.

10. Security

We use administrative, technical, and organizational measures designed to protect information, including credential hashing, restricted database access, scoped tokens, transport encryption, and security monitoring. No system is perfectly secure. Use a unique password, keep tokens private, and report suspected compromise to [email protected].

11. Your choices and rights

You can post or remove shares from Discover, change profile content, notification preferences, and tokens from the dashboard. Settings also provides a machine-readable account export and permanent account deletion. You may contact us to request access, correction, deletion, restriction, portability, or an objection where applicable.

Residents of the EEA, United Kingdom, California, and other regions may have additional statutory rights. California residents may request information about collection, deletion, correction, and non-discrimination. Because Shareth does not sell personal information or share it for cross-context behavioral advertising, there is no sale or sharing to opt out of under that model. Authorized-agent requests must include legally sufficient authorization.

12. International processing

Shareth and its providers may process information in countries other than your own. Where required, we use recognized safeguards for international transfers. Local authorities may have lawful access rights in the destination country.

13. Children

Shareth is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided information in violation of applicable law, contact [email protected] so we can investigate and delete it as appropriate.

14. Global Privacy Control and Do Not Track

Shareth does not use personal information for cross-context behavioral advertising. Where applicable law requires us to recognize a browser-based opt-out signal such as Global Privacy Control, we will treat the signal as an opt-out for the browser or account to the extent relevant. There is no uniform industry response to older Do Not Track signals.

15. Changes

We may update this Policy as the Service and law change. We will post the revised date and provide additional notice for material changes when appropriate. Continued use after an update is subject to the revised Policy, but we will seek consent if law requires it.