Privacy Policy
Last updated: August 9, 2026
TL;DR
We store temporary short code mappings for 24 hours so redirects can work. CreepyLink is not an analytics shortener: creators do not get click tracking dashboards, visitor profiles, passwords, account tokens, or payment data. CreepyLink does not collect passwords, does not host malware, and does not create phishing pages. Google Analytics, Microsoft Clarity, Monetag, other third-party advertising vendors, and hosting providers may still process IP address, browser information, cookies, web beacons, device signals, interaction events, or operational logs.
1. Information We Collect
Short answer: The target URL you submit, temporary redirect metadata needed to make the link work, and basic operational signals handled by hosting, analytics, advertising, or security providers.
Long answer: When you create a creepy link, we store:
- A temporary mapping between a short code and your target URL (the destination URL you submit)
- This mapping expires automatically after 24 hours
- Rate-limit counters that help prevent abuse of the generator
- IP address, browser information, device type, and basic request metadata used by hosting, security, and rate-limit systems
- Basic page, device, browser, cookie, web beacon/pixel, and interaction signals from Google Analytics and Microsoft Clarity
- Advertising cookies, IP address, browser/device signals, page interaction signals, and related data from Monetag or its advertising partners when an eligible advertising experiment is enabled
We do NOT:
- Provide creator-facing click tracking or visitor analytics dashboards
- Collect passwords, login details, payment details, account tokens, or private credentials
- Provide a visitor credential collection flow or phishing page builder
- Host malware, software payloads, or forced-download content
- Create phishing pages that imitate banks, email providers, or other login portals
- Give link creators a recipient tracking or analytics product
- Sell generated-link data or share recipient-level tracking with link creators
Boundary: Credentials, short code mappings, and operational logs are different categories. CreepyLink does not collect passwords or visitor credentials, but short code mappings and basic operational logs (including IP address and browser information) may still exist so redirects, abuse prevention, hosting, advertising, analytics, and security checks can work.
2. How We Use Information
We use the temporary short code mapping only to send a generated CreepyLink to the destination URL you provided. We use rate-limit counters to reduce spam and abuse. We do not use generated-link data to give creators analytics dashboards, build retargeting lists, sell click data, or identify individual recipients.
3. Difference From Analytics Shorteners
Some URL shorteners are built around click tracking, campaign attribution, referrer reports, geographic dashboards, or permanent branded links. CreepyLink is different: it is a short-lived prank and security-awareness redirect tool. The suspicious appearance is the feature, not visitor surveillance.
4. Data Storage
Short link mappings are stored in secure, encrypted cloud storage (Vercel KV). All data automatically expires and is permanently deleted after 24 hours. We cannot recover expired links.
5. Official Domain and Third-Party Services
This policy describes the CreepyLink tool served at creepylink.online. Do not assume similarly named domains are operated by the same service or share the same data practices.
CreepyLink may use the following third-party services:
- CDN providers for delivering static assets (fonts, scripts)
- Hosting provider for serving the website
- Google Analytics for aggregate traffic and page usage measurement
- Microsoft Clarity for aggregate session, interaction, and usability diagnostics
- Monetag for labeled Direct Link and In-Page Push advertising on eligible redirect or error pages when the corresponding experiment feature flag is enabled
These third-party vendors may process IP address, browser information, cookie identifiers, web beacons or similar pixels, page views, interaction events, ad verification signals, or operational logs. That is different from providing link creators with recipient-level tracking dashboards.
This Privacy Policy page is intentionally served without Monetag, Google Analytics, or Microsoft Clarity tags so visitors can review these disclosures before interacting with optional advertising or analytics services elsewhere on the site.
When an advertising experiment is enabled, Monetag and its advertising partners may use cookies, web beacons, IP address, device or browser information, referral information, and interaction signals to select, deliver, measure, prevent fraud, or limit advertising. CreepyLink does not send the target URL, short code, full query string, email address, or a CreepyLink user identifier in its own advertising experiment events.
You can block or clear advertising cookies through your browser settings. You can also review Monetag's Privacy Policy for information about its processing and data-protection contact options.
6. Your Rights
Generated link mappings are temporary and expire automatically. If you need to report a malicious link, send the full generated URL and context to the abuse channel so the report can be reviewed.
7. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
8. Contact Us
If you have any questions about this Privacy Policy, please contact us at privacy@creepylink.online. For abuse reports, use abuse@creepylink.online