Privacy Policy
This policy explains the information LYHYT processes when you create short URLs, follow them, or contact the service administrator.
URL creation data
When a short URL is created, LYHYT stores the destination URL, generated short code, creator IP address, a hashed session identifier, creation time, expiry time, status, and hit count. Timestamps are stored as Unix time values.
Rate limiting
Temporary rate-limit records contain a hashed session identifier, IP address, and creation time. These records are used to enforce the service limits and are removed by the cleanup process after they are no longer needed.
Contact and URL reports
If you use the Contact form, the information you enter, together with your IP address, browser user-agent string, and submission time, is sent by email to the service administrator through the configured SMTP server. LYHYT does not keep a separate local database inbox for contact-form messages.
Session cookie
LYHYT uses a PHP session cookie for basic security features, rate limiting, and form protection. The cookie is not used to create an advertising profile.
Bot protection
LYHYT uses Cloudflare Turnstile on public forms to help distinguish legitimate visitors from automated abuse. Turnstile processes browser and security signals needed for this purpose, and the resulting token is verified with Cloudflare before the form is accepted. See Cloudflare's Turnstile Privacy Addendum for details. Turnstile is currently configured in Invisible mode, so verification normally has no visible widget.
Google Analytics
LYHYT uses Google Analytics on public pages to understand general site usage, such as page visits and interaction patterns. Google may process device, browser, network, and usage information according to its own privacy terms. Admin and installer pages are not included in this tracking.
Short URL visits and statistics
When a valid short URL is opened, LYHYT increases its lifetime hit counter and a monthly aggregate statistics counter before redirecting the visitor. The statistics do not store a visitor IP address, browser identity, or a separate per-visit history.
Retention
Short URL records normally expire after 14 days and are deleted by the cleanup cron job. Aggregate service statistics can remain after a short URL expires so the administrator can compare overall URL and hit activity over time. Server logs and email messages may have separate retention periods controlled by the hosting and email providers or the service administrator.
Contact
Questions about this policy can be sent through the Contact page.