Privacy Policy
Your privacy is important to us. This general Privacy Policy applies across T.LY and explains how T.LY (“we,” “us,” or “our”) collects, uses, shares, and protects information when you use our website, https://t.ly, or any related T.LY service, including short links, QR codes, link management, analytics, APIs, browser extensions, the mobile app, BeforeTap for iOS, the T.LY URL Shortener Google Sheets add-on, and custom domains.
1. Information We Collect
We only collect personal information when it’s necessary to provide you with a service, improve our platform, or comply with legal obligations. This may include:
- Email address (for account creation or support)
- IP address and device/browser information
- Billing and subscription information (if applicable)
- URLs you shorten, destinations you route traffic to, tags, descriptions, expiration settings, passwords or privacy settings you add to links, QR codes you create, custom domains you connect, and related link metadata
- QR code customization information, including colors, styles, and optional logo images you choose to upload or attach to a QR code
- Analytics and usage information related to your links, QR codes, OneLinks, custom domains, and account, such as clicks, scans, referrers, approximate location, browser, platform, language, and timestamps
- Cookies, session tokens, authentication state, and usage data needed to keep you signed in and secure the service
- Information you provide when contacting support or making privacy, billing, abuse, or account requests
- Security, fraud, abuse, and compliance signals, such as click patterns, referrers, reports, blocklist matches, and automated risk scores
We collect this information by fair and lawful means, with your knowledge and consent where required, and when necessary to provide, secure, monitor, and enforce the service.
2. Mobile Apps
The T.LY URL Shortener iOS and Android apps are companion apps for T.LY accounts. They let signed-in users create, edit, view, and share short links, QR codes, and analytics from a mobile device.
The Android app uses the T.LY login page in an embedded WebView so you can sign in with the same account security options available on the website, including Google sign-in and two-factor authentication. The Android app does not offer account creation inside the app. Web session cookies are stored by Android WebView/CookieManager and are used to keep you signed in and authenticate API requests. You can sign out from the app to clear the app's local session state.
The mobile apps may process account profile information, link and QR code data, analytics returned by the T.LY API, URLs shared to the app, clipboard URLs when you choose to shorten them, app settings such as dark mode or display preferences, and optional images you select for QR code logos. The apps do not use this information for third-party advertising.
BeforeTap for iOS
BeforeTap is a separate link-inspection app for iPhone and iPad that works without a T.LY account. It does not show ads, run analytics, or include third-party SDKs. When you inspect a URL or a QR code containing a URL, BeforeTap sends that URL to T.LY's link-tools services to resolve redirects and return the requested report. T.LY may process the URL to provide redirect, metadata, DNS, SSL, WHOIS, source, risk-score, and server-screenshot features and to operate, secure, and troubleshoot those services. T.LY does not use inspected URLs for BeforeTap advertising, analytics, or user profiling.
T.LY's servers normally contact the submitted URL and its redirect destinations to build the report. Those sites receive network information from T.LY's servers. If the T.LY tools service is unavailable, BeforeTap may resolve the redirect path directly from your device. In that case, destination sites may receive your public IP address, a basic app user-agent string, the time of the request, and other standard network information.
BeforeTap stores its settings and up to 50 recent inspections on your device. You can delete individual history entries or clear the full history in the app. Camera access is used only when you choose to scan a QR code. Photos you select are processed on the device to find a QR code and are not uploaded by BeforeTap. The clipboard is read only after you tap Paste; the app does not monitor it in the background.
If you open an inspected destination or another external link, the receiving website or app handles that request under its own privacy terms. If you contact support, T.LY receives the information you include so we can reply. T.LY handles server-side data under the retention, security, sharing, and user-rights terms described below.
QR Scanner & Creator for Android
QR Scanner & Creator is a separate Android app that works without a T.LY account. Camera images, photos you select, QR and barcode contents, creator drafts, and scan history are processed on the device and are not sent to T.LY. Camera access is used for live scanning. Optional location access is used only when you choose to add your current location to a location QR code.
History, creator drafts, and settings are stored in the app's private storage. Android Auto Backup or device transfer may copy this local data according to your Android backup settings. You can delete individual records or clear history in the app. Clearing the app's data or uninstalling it removes local app data; backup copies are controlled through your device or Google backup settings.
The app uses the bundled Google ML Kit barcode-scanning SDK. Google says this SDK may collect app and device information, per-installation identifiers, performance metrics, API configuration, event types, and error codes for diagnostics and usage analytics. This diagnostic data is encrypted in transit and is not shared with third parties by ML Kit. The SDK does not send barcode images, barcode input data, or scan results to Google. QR Scanner & Creator does not enable ML Kit's auto-zoom feature.
When you choose to open a scanned link, shorten a URL with T.LY, or share an exported file, the receiving app or website handles that data under its own privacy terms.
3. Google Sheets Add-on
The T.LY URL Shortener Google Sheets add-on uses Google authorization limited to the spreadsheet where you open the add-on. It reads URLs from the cells you select or, when you explicitly choose the whole-sheet option, from the current sheet. It writes the resulting short links into the adjacent column or replaces the original URLs when you select that option. It does not access other spreadsheets in your Google Drive.
When you connect the add-on, T.LY receives the account authorization needed to create and read links through the T.LY API. The selected destination URLs are sent to T.LY to create short links, and the resulting link records are handled under this Privacy Policy and your T.LY account. The add-on stores its OAuth connection in Google Apps Script User Properties associated with your Google account. T.LY does not use Google Sheets data for advertising or sell it to third parties.
The add-on does not use AI or machine-learning models, does not integrate with third-party AI services, and does not transfer Google Workspace user data to AI providers. Google Workspace user data received through the add-on is not used to train, create, or improve AI or machine-learning models.
The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect the add-on from the T.LY account section at any time. Disconnecting stops future API access for the add-on, but does not delete short links or data already created in your T.LY account or spreadsheet. To request deletion of T.LY account data, contact [email protected].
4. How We Use Your Information
We use the information we collect to:
- Provide and maintain the T.LY service
- Communicate with you about your account or support requests
- Create, manage, route, and analyze short links, QR codes, OneLinks, custom domains, and related account features
- Authenticate users, maintain sessions, and protect accounts
- Prevent abuse or fraud on our platform
- Detect, investigate, block, disable, or report phishing, scams, malware, spam, impersonation, deceptive redirects, and other harmful activity
- Analyze and improve our service
- Comply with legal obligations
We do not sell your personal information to third parties.
5. Data Retention and Security
We retain personal data only as long as necessary to fulfill the purposes above. We use HTTPS, access controls, and commercially acceptable safeguards to protect your information against unauthorized access, disclosure, alteration, or destruction. You can also enable two-factor authentication (2FA) to add an extra layer of account security.
6. Sharing of Information
We do not share personally identifiable information publicly or with third parties, except in the following cases:
- With your explicit consent
- With trusted service providers who help us operate the service (payments, email, analytics, and abuse prevention)
- As required by law or to respond to valid legal requests
- To detect, prevent, investigate, or address fraud, phishing, malware, scams, spam, impersonation, abuse, security issues, or legal claims
- With security vendors, blocklist providers, hosting providers, domain registrars, payment processors, law enforcement, regulators, affected platforms, affected brands, or other relevant parties when we believe sharing is reasonably necessary to protect users, the public, T.LY, or third parties
7. Abuse Prevention and Link Safety
T.LY uses commercially reasonable safety measures to help detect and block abusive links. These measures may include automated scans, AI review, third-party security tools, public and private blocklists, manual review, rate limits, warning pages, and user reports.
When we investigate abuse, we may preserve and review information connected to a link, account, domain, API token, QR code, report, click, or destination. This may include URLs, destination details, IP addresses, timestamps, user agents, referrers, account information, payment identifiers, and related technical records.
No abuse-prevention system catches every bad link. T.LY does not guarantee that every short link, QR code, destination URL, custom domain, or third-party website is safe, lawful, accurate, or free from harmful content.
8. Cookies and Tracking
We may use cookies or similar technologies to improve user experience, understand usage patterns, and deliver relevant content. You can control cookie preferences through your browser settings.
Our mobile apps and embedded WebView login flows may use cookies and similar local storage to sign you in, maintain your session, prevent abuse, and secure API requests.
9. Third-Party Links
Our website and services may contain or redirect to third-party websites, apps, files, services, offers, payment pages, login pages, downloads, or other destinations. Many of these destinations are submitted, created, or controlled by users or other third parties, not T.LY. We are not responsible for the content, security, claims, transactions, or privacy practices of those destinations. Read their policies and use caution before providing personal information, passwords, payment details, or other sensitive data.
10. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Object to or restrict certain processing
- Withdraw consent at any time
To exercise these rights, please contact us at [email protected].
11. Children's Privacy
Our service is not intended for children under the age of 18. We do not knowingly collect personal information from children.
12. reCAPTCHA
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised “Last updated” date. Continued use of our services after changes implies acceptance of the new terms.
14. Contact Us
If you have any questions about how we handle user data and personal information, please contact us at:
Email: [email protected]
Last updated: 7/15/2026