Privacy Policy
The purpose of the yuke.jp privacy policy is to provide the natural person - the data subject - with information about the purpose, scope, protection, and retention period of personal data processing at the time of data collection and when processing the data subject's personal data.
The yuke.jp long link shortening service is operated by me, its creator - Eriks Remess. The data controller is Eriks Remess. Privacy and personal data requests should be sent to info@yuke.jp. Facebook Messenger may be used for general support, but privacy and personal data requests should be sent by email.
How and what personal data we collect
Personal data is any information by which you could be identified.
When visiting yuke.jp, the web server log stores:
- visit time;
- your IP address.
In addition to entries in the web log:
- When creating a new short link, the short link database stores:
- creation time;
- your IP address;
- the chosen or generated short link;
- the provided long link;
- account ownership, if the short link was created while signed in;
- optional link settings, such as stats visibility, expiration, UTM values, preview metadata, and destination rules, if configured.
- When visiting a previously created short link, the short link visit database stores:
- visit time;
- your IP address;
- the visited short link;
- limited routing/statistics context, such as detected platform, Latvia/non-Latvia country bucket, and matched destination rule.
- When using an account, the account database stores:
- your email address and email verification status;
- optional passkey credential data needed for passwordless sign-in;
- optional API key metadata, permissions, and derived key hashes;
- a pending account-deletion confirmation request, including the account email address, confirmation-code hash, selected short-link action, request time, and expiry time; the confirmation code itself is not stored in the database;
- account and profile audit events, including action names, IP addresses, user agents, request IDs, and action-specific details such as sign-ins, email verification, passkey changes, API key changes, account-deletion requests, and owned short-link changes.
- When requesting an email sign-in or verification link, the rate-limit database stores your IP address and request time.
- When a short-link password is submitted, security rate-limit records may store your IP address, the short-link identifier, and the attempt time. These records do not contain the submitted password.
- When submitting a short-link report through the
/reportform, the following is sent to the operator by email:- your first name, last name, and email address;
- the reported short URL and selected reason;
- the message text, if provided;
- your IP address and its Latvia/non-Latvia country bucket;
- the reported short link's destination, its creator's IP address, and that address's Latvia/non-Latvia country bucket, if the creator IP address is available.
Why is the IP address stored?
- When creating a new short link, it is used to identify the user. It helps find other short links possibly created by the same user. If information is received that a short link leads to a website containing malware or phishing (stealing third-party access credentials), it is possible to quickly identify other similar links and block access to them.
- When visiting a short link or the home page, the IP address is used to register a unique visit, unless the Global Privacy Control signal is enabled.
- When using an account, the IP address is stored in account audit events to help investigate security-relevant changes.
- When requesting an email sign-in or verification link, the IP address is used for a short rolling rate limit that prevents automated or excessive email requests.
- When a short-link password is submitted, the IP address is used to limit password guessing across links and visitors. These security limits apply even when the Global Privacy Control signal is enabled.
- When submitting a short-link report, the IP address is used for rate limiting, documenting the report's source, and investigating possible misuse.
Why and on what legal basis is personal data processed?
- Short-link creation, redirection, account management, passkeys, API keys, QR codes, statistics, link options, and destination rules are processed because this is necessary to provide the yuke.jp service requested by the user.
- IP addresses, visit logs, account audit events, rate limits, and safety checks are processed based on the legitimate interest of securing the service, preventing abuse, enforcing the Terms of Use, and investigating malware, phishing, spam, gambling links, or other misuse.
- Short-link reports and the contact details they contain are processed based on the legitimate interest of receiving and investigating reports of harmful or illegal content, protecting the service, and contacting the reporter when necessary.
- Cookies listed below are used only to provide service functionality, security, account state, and language or consent preferences.
- Personal data may also be processed when needed to comply with legal obligations or to protect legal rights and service security.
Which data is required and which is optional?
- To create and serve a short link, the long URL, the chosen or generated short link, and request metadata such as IP address are required. Without this data, the short link cannot be created, redirected, secured, or checked for abuse.
- Email address is required for account features, account-deletion confirmation, and the short-link reporting form. Without an email address, account-owned short links, profile management, passkeys, and API keys cannot be used, an account deletion cannot be confirmed, and a short-link report cannot be submitted.
- The reporting form requires a first name, last name, email address, short URL, and reason. Message text is required only when “Other” is selected; it is optional for every other reason.
- Passkeys, API keys, custom aliases, link settings, preview metadata, UTM values, and destination rules are optional. If they are not provided or configured, the related optional feature is not used.
- For anonymous short-link changes or deletion, and for privacy or data requests, identity or ownership information may be required. If enough information is not provided, the request may not be possible to complete.
How are safety checks performed?
Submitted long URLs and the final redirect targets found after following redirects may be checked before a short link is created or updated. Destination domains may be sent to a safety-check provider. The Safe Browsing integration uses local hash lists and hash-prefix confirmation; full submitted URLs are not sent through that Safe Browsing check.
Password-protected short links
Password protection is an optional access-control setting for an already-created short link. The account owner can enable it in the link settings. It restricts access through that short link from the moment it is enabled; it does not restrict direct access to the destination URL.
We process the entered password to set or check this protection. The database stores a one-way password hash and a random value used to create it (a salt), rather than the readable password. Password hashes are not included in API responses, including responses to the owner. A visitor must provide the password to open a protected link.
Password-protected links have private statistics only. The owner can view them through the service; other visitors cannot. Private statistics still involve the visit-data processing described above. A visit is recorded in short-link statistics only after successful password verification and subject to the existing visit-recording exclusions. Failed attempts can appear in security rate-limit records and web server logs.
Protected destinations are not disclosed through public statistics. The service operator can still access stored destinations and investigate misuse. Password protection does not encrypt the destination URL or the destination's content and is not a replacement for encrypted communication. Anyone who opens a link can share its destination directly. Adding protection later cannot retract a destination that was previously disclosed.
The password is required on every visit. We do not use an unlock cookie or save an access grant in the browser. The form uses the security cookies listed below to prevent forged submissions.
How long is collected personal data stored?
Personal data is stored in the European Union (EU) on self-managed cloud infrastructure.
- Information entered in the web server log is deleted approximately one week after the entry is made.
- Created short links are not automatically deleted and do not expire by default. An optional expiration setting can stop redirection without deleting the stored short link.
- A created short link may be deleted if its creator has requested it.
- Account data, passkeys, API key metadata, and account audit events are stored until the account is deleted.
- Revoked passkeys and API keys are retained as revoked records until account deletion so they cannot continue to be used.
- An account-deletion confirmation code is valid for 15 minutes. Its database request is discarded if the email cannot be delivered and otherwise remains until a newer request replaces it or the account is deleted; an expired code is not accepted.
- Email sign-in and verification token records contain the account identifier, email address, token hash, creation and expiration times, and time of use. Tokens are single-use and valid for 15 minutes. A scheduled database task removes expired records, including used tokens, every five minutes in batches of up to 1,000. Backlogs or cleanup failures can delay removal; records are not necessarily erased at the exact moment they expire.
- Email-link rate-limit entries affect requests only during the rolling 5-minute window. Expired entries are removed during subsequent rate-limit cleanup.
- Password-attempt rate-limit entries affect attempts only during a rolling 15-minute window. Successful verification releases its attempt reservations. Expired entries are removed during subsequent rate-limit cleanup; they are not necessarily erased at the exact moment the window ends.
- A short-link password hash is retained with the stored link settings. Changing or removing the password replaces or removes the current hash. Expiration or blocking does not itself erase the stored link settings. Copies in backups are subject to the backup retention period below.
- When an account is deleted, account data, passkeys, API keys, pending deletion requests, and account audit events are deleted. Password-protected short links are always deleted with the account. The user can also select deletion of their other owned short links. If they do not, those other generated and custom short links stay live and become anonymous/unowned. For retained links without password protection, private statistics become public, while disabled statistics remain disabled.
- Report-form submissions are not stored in the short-link database. They are sent to the operator's email and retained only as long as necessary to assess the report, prevent misuse, contact the reporter, comply with legal obligations, or protect legal claims.
- Deleted data may remain in self-managed backups for up to one month before backup rotation removes it.
- Access to a created short link is denied (blocked) if:
- it leads to a website containing malware;
- it leads to a phishing website (stealing third-party access credentials);
- it leads to an online gambling website;
- it is used in spam.
- Blocked short links are deleted three months after their creation. This period is chosen so that the short links cannot be recreated immediately after blocking and their creator cannot continue malicious activity.
What cookies are used and for what purposes?
Cookies are used only for service functionality, security, account state, and service preferences. There are no analytics, tracking, third-party, or optional cookies.
- __Secure-cookieconsent - contains the cookie notice status;
- __Secure-locale - stores the user's selected language (locally);
- __Secure-csrf and __Secure-csrf.s - protection against CSRF requests;
- __Host-auth - stores the signed account sign-in state;
- __Host-auth-register - temporarily stores passkey registration challenge state;
- __Host-auth-login - temporarily stores passkey login challenge state;
- __Host-auth-email-change - temporarily stores proof that a verified email change was confirmed with a passkey.
Who receives personal data?
Personal data is not sold and is not used for analytics or tracking. It is not shared with third parties for their own purposes. Limited data may be processed by service providers needed to run the service, such as EU cloud infrastructure, email delivery, and safety-check providers. Data may also be disclosed if required by law or when needed to protect rights, service security, or users.
How can you manage your data?
Signed-in users can manage their owned short links at /mans: if a short link was created while signed in, they can change its long URL and delete the short link themselves. Email, passkeys, API keys, and the account itself can be managed at /mans/profils. Account deletion requires recent identity verification and a code sent to the account email address. Password-protected short links are always deleted with the account; the user chooses whether their other owned short links are also deleted. A confirmation email is sent after account deletion. If a short link was created anonymously, its long URL can be changed or the short link can be deleted by writing to info@yuke.jp. Identity or ownership may need to be verified before personal data, account data, or anonymous short links are changed, exported, or deleted.
You may request access, correction, deletion, restriction, objection, and data portability where these rights apply. If processing is based on consent, you may withdraw that consent. Requests are handled as soon as possible and within one month. Some requests may be limited or refused when data must be retained for security, abuse prevention, legal claims, or legal obligations. You also have the right to lodge a complaint with the competent data protection supervisory authority.
Automated decision-making
yuke.jp does not use GDPR Article 22 automated decision-making. Operational safety checks may still block unsafe destinations or refuse short-link creation, and destination rules may route visits according to configured link behavior.
Changes
We have the right to change this policy from time to time. Last updated on September 16, 2026.