Privacy notice
What we collect, why, how long we keep it, and your rights.
Last updated 24 September 2026. Brevily is operated by Psionic Ventures LLP ("we", "us"). Read this page with our Terms of service, Privacy notice and Acceptable use policy.
We are the data fiduciary (under India's Digital Personal Data Protection Act, 2023) and the data controller (under the UK and EU GDPR, where they apply) for the personal data described below. Our registered details are in the footer of every page.
1. The short version
We collect three kinds of data: what you give us to run an account, what we record when someone clicks one of your links, and the ordinary technical logs any web service keeps. We do not set a cross-site cookie on the people who click your links, we do not build profiles of them, and we do not sell data to anyone.
2. Data about you, our customer
What: your name, email address, organisation name, and the password hash for your account. If you buy a paid plan, your billing name, billing address, GST registration where you give one, and the last four digits and brand of your payment instrument. We never see or store your full card number — that goes directly to our payment provider.
Why: to give you an account, to bill you, to provide support, and to tell you about material changes to the service. The lawful basis is performance of our contract with you, and our legitimate interest in running and securing the service.
How long: while your account is open, and for seven years after it closes for anything needed to satisfy Indian tax and company law. Support correspondence is kept for two years.
3. Data about people who click your links
When someone follows one of your short links we record the time, the destination it was sent to, the country and, where the network address allows, the region and city the request came from, the device type, operating system and browser family, the browser's user-agent string, the referring site where the browser sends one, and a truncated, hashed identifier used only to count unique visitors. We record the IP address in encrypted form for abuse investigation, and it is never used for analytics or shown to you.
What we do not do: we do not set a cookie that follows anyone across sites, we do not build advertising profiles, and we do not resolve a visitor to a named individual. This is why using Brevily does not, by itself, oblige you to add a consent banner — but the destination you send people to may have its own obligations, and that is yours to assess.
Why: so that you get click analytics, and so that we can detect and stop abuse of the service. For the analytics, we act as a processor on your behalf; you are the controller of your links' click data and our Data processing terms apply. For abuse detection we act as a controller on our own legitimate interest in keeping the service from being used to hurt people.
How long: raw click records for the retention window of your plan, shown on the pricing page. Aggregated daily counts for longer, because they carry no identifier. Encrypted IP addresses for 90 days.
4. Destinations you link to
We fetch a destination when a link is created, and again on a schedule, to check that it resolves and is not listed on the malware and phishing blocklists we query. We store the response status, the page title and description where they are public, and the result of the check. We do not archive the page and we do not use its content for anything other than showing you that the link works.
5. Technical logs
Our servers keep ordinary request logs containing IP address, user agent, path and timestamp, for security, debugging and capacity planning. They are kept for 30 days and then deleted.
6. Who we share data with
We use a small number of processors, each bound by contract to use the data only as we instruct:
- our payment provider, for taking payment and issuing invoices;
- our cloud infrastructure and content-delivery provider, for hosting and for serving redirects at the edge;
- our transactional email provider, for account and billing email;
- the malware and phishing blocklist services we query, which receive the destination URL, not your identity.
We will disclose data to a public authority where we are legally obliged to. We will not do so on an informal request. If we receive an order that covers your data, and the law allows us to tell you, we will.
We do not sell personal data, and we do not share it for advertising.
7. Where data is held
Our primary database is hosted in [region], and redirects are served from edge locations worldwide, which means a click may be processed in the region it came from before the record reaches our database. Where data leaves India or the European Economic Area, we rely on the transfer mechanisms our providers offer, including standard contractual clauses.
8. Your rights
Depending on where you live you have some or all of these rights: to know what we hold, to get a copy, to correct it, to have it deleted, to restrict or object to processing, and to withdraw consent where consent is the basis. You also have the right to nominate someone to exercise these rights on your behalf if you die or become incapacitated, as provided by the DPDP Act.
Write to privacy@brevily.com and we will respond within 30 days. We may ask you to verify your identity first.
If you are unhappy with our answer you may complain to the Data Protection Board of India, or to your local supervisory authority if you are in the UK or EEA.
9. Grievance officer
Under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, our grievance officer is:
- Name: [Grievance officer name]
- Email: privacy@brevily.com
- Address: as published in the footer of this site
We acknowledge a grievance within 24 hours and resolve it within 15 days.
10. Security
Passwords are stored hashed, never in plain text. Secrets are encrypted at rest. Personal identifiers that need to be searchable are stored encrypted alongside a keyed digest, so a stolen table cannot be reversed against a list of common values. Access to production data is limited to the people who need it and is logged. Report a vulnerability to security@brevily.com; we will not pursue anyone who reports one in good faith and gives us reasonable time to fix it.
11. Children
Brevily is not for children. We do not knowingly process the personal data of anyone under 18. Tell us at privacy@brevily.com if you believe we have, and we will delete it.
12. Changes
We will post any change here and update the date at the top. If a change materially affects how we use your data we will email you before it takes effect.