WURL.us · APLogica, Inc.
Privacy notice
Updated
WURL.us is a short-link service operated by APLogica, Inc. This notice explains the information WURL handles when you create an account, shorten a URL, or follow a WURL link. Contact support@dealsman.com with privacy questions or requests.
Information we handle and why
- Accounts and sign-in. We store your name, email address, workspace membership, account status, and sign-in records to provide and protect your account. Passwords are stored as password hashes. For passkeys, we store a public credential, its label, and registration and last-use dates. WURL does not receive your fingerprint, face scan, device PIN, or passkey private key.
- Links. We store destination URLs, short codes, labels, settings, ownership, and creation information. Link records can include the creator’s IP address. A short link is intended to be shared: anyone who has it may follow it or inspect its destination. Shortening a URL does not make the destination private.
- Link activity. We count visits and referrals. Managed-link analytics can include a referring domain, time, device category, browser, operating system, language, available country information, and campaign parameters. Visitor estimates use a keyed hash derived from IP address and browser information that changes monthly. This is a pseudonymous identifier. The analytics event does not store the raw IP address used to calculate it. For unowned public links, referral records may contain the referring URL supplied by the browser, rather than only its domain.
- Security and operations. Server logs can include IP addresses, request paths and query strings, browser information, errors, and timestamps. Account-abuse controls also use hashed network and mailbox identifiers, verification records, and review decisions to limit duplicate signup, spam, and misuse.
Workspace members with access to link management can view their workspace’s link records and analytics. Authorized service operators can access operational information for support, maintenance, and abuse review.
Google sign-in
Google sign-in is optional. When you choose Google, WURL requests basic identity information: your name, email address, email-verification status, and Google account identifier. We use this to authenticate you, connect the correct WURL account, and protect signup. Your name and email are stored with your WURL account; the Google identifier is stored while Google is connected.
WURL does not request access to your Gmail messages, Google Drive files, contacts, or calendar. The integration does not store Google access or refresh tokens. Google identity information is used for account access and protection, not advertising.
You can disconnect Google in Account → Sign-in methods. Add another working sign-in method first if Google is your only one. Disconnecting removes the Google connection; it does not delete your WURL account, name, email, or links. You can also manage WURL’s access in your Google account.
Storage, security, and retention
WURL uses HTTPS, access controls, encrypted destination storage, and encrypted database backups. These protections do not turn publicly shared links into private documents.
- Email-verification links and browser receipts for newly created links expire after 24 hours. Expired records are removed by scheduled cleanup. A browser receipt can become unavailable sooner if its browser session is lost.
- Temporary account-abuse events expire after 30 days. Rate-limit records expire with their applicable windows.
- Detailed managed-link analytics is scheduled for cleanup after 400 days. Aggregate link counts and referral records can remain with the link.
- Routine web-server logs rotate on a 7–14 day cycle. Account records, saved links, administrative history, and operational backup copies do not all have an automatic expiry. Deleting a live record does not immediately remove copies from existing backups.
The retention periods above describe the current service. Account and link records remain until removed through account tools or an operational process. Contact us about information that you want accessed, corrected, or deleted.
Your choices and requests
You can shorten a link without registering. An account lets you keep and manage your own links. You can update your display name, manage sign-in methods, and delete managed links through your account. You can decline Google sign-in and use a passkey or password.
For account deletion, an email-address correction, or a copy of account information, contact support@dealsman.com. Include the account email or affected WURL and describe your request; do not send passwords or passkey secrets. We may need to confirm account or link ownership before disclosing or changing records. Depending on where you live, applicable privacy law may provide additional rights, including the right to contact a data-protection authority.
Changes to this notice will appear here with an updated date. See also the Terms of service.