Trust

How Brevily is run, and what it keeps

Every line here describes what the product does today. Where something is missing, the page says so instead of promising it.

1 cookieon a visitor, first-party, on the short link’s own domainIt tells a returning visitor from a new one. Nothing follows anyone to the next site.
No profilesof the people who clickClick data is never sold. It goes only where the link’s owner sends it.
Web Riskchecks every new destinationGoogle Web Risk plus Brevily’s own heuristics, and again while a link is in use.
Dodo Paymentsis the merchant of recordIt takes the payment and adds the tax. Brevily never sees a card number.

What a click records

A click is counted, described in a few words and passed on. Nothing about the person who clicked is kept beyond that.

What is recorded

The time, the link, where it sent the visitor, the country, the device type, operating system and browser family, the referring site, and whether the click came from a QR code. The IP address is stored encrypted for abuse investigation only, never shown to the link’s owner, and is blanked after 90 days.

One cookie, on the link’s own domain

A signed first-party cookie, __Host-sv, on the short link’s domain tells a returning visitor from a new one, to count unique visitors; it lasts a year. There is no cross-site cookie, unless the link’s owner adds retargeting pixels: then that platform’s pixel loads on a one-second page before the redirect.

Crawlers are counted apart

Bots are not people. Known crawlers are recognised from the user agent and kept apart, in the numbers and in anything forwarded. A chat app fetching a link for its preview counts as a crawler, never as a visit.

No profiles, nothing sold

Click data is never sold and builds no profile of anyone. It goes only where the link’s owner sends it: their analytics, exports, reports, webhooks and Google Analytics forwarding.

How long it stays

Free shows daily totals only, for 30 days. Pro shows each click for 60 days and daily totals for 180 days. Business shows each click for 180 days and daily totals for 365 days. Single clicks are kept at least seven days on every plan, because the daily totals are built from them. What a plan stops showing is hidden at once and deleted 30 days later, so an upgrade in between shows it again.

Where it travels

Answered at the edge, in the data centre nearest the visitor. The click then goes through a queue into the primary database, so a slow database never slows a redirect down.

Anyone can check a link before clicking it

A short link hides its destination, and phishing relies on that. Every Brevily link can be looked at first — and every new destination is checked with Google Web Risk and Brevily’s heuristics when the link is made, and again while it is in use.

  1. Add a + to the end

    brvl.uk/q3-launch becomes brvl.uk/q3-launch+. In any browser, on any device.

  2. Read the page it stops on

    The full destination, when the link was made and its last safety check. Nothing is loaded from the destination.

  3. Then decide

    Continue to the destination, or report the link in one click. Looking is not counted as a click.

Nothing to install, no script on any website. The preview is served by the redirect itself, so it works on every Brevily link, for everyone, and the link’s owner cannot switch it off.

  1. Without the +brvl.uk/q3-launchGoes straight to northwind.com, and counts as a click.
  2. With a +brvl.uk/q3-launch+Stops on a preview page instead: the full destination, when the link was made and its last safety check. Not counted as a click.

Two kinds of link keep their destination back: one with a password asks for the password first, and one with a click limit shows where it goes only when it is followed.

Click or tap the + above to see the page it opens.

https://brvl.uk/q3-launch+

Where this link goes

You added a +, so this page shows the destination instead of sending you there. Nothing has been loaded from it.

Destinationhttps://northwind.com/campaigns/2026/q3-launch/landing?utm_source=newsletter&utm_medium=email&utm_campaign=q3
Short linkbrvl.uk/q3-launch
Created2 September 2026
Destination checksNot listed on the blocklists checked. Last checked 30 September 2026.
Continue to northwind.comReport this link

Checks say what is known, not that a page is safe. A destination can change after it is checked, so read the address before you continue.

An example: the page the redirect edge serves for brvl.uk/q3-launch+. Nothing is loaded from the destination until you choose to continue.

What gets a link stopped

When a destination is harmful

A flag belongs to the destination, not to one link, so a harmful page cannot be reached through a second link to it.

A flag stops every link to it

When Google Web Risk or a Brevily reviewer flags a destination, every link to it, in every organisation, shows a warning page instead of redirecting, and no new link can point there. Each owner is told by email.

Reports are read by a person

Anyone can report a link, with no account. A person reviews every report. Reports from three different connections send the destination for an immediate safety check, but a report alone never stops a link.

Lifted by review, not by editing

Editing a flagged link does not lift the flag. Its owner changes the destination and asks for a review; a reviewer lifts or keeps it, and the owner is emailed the decision.

Checked again while in use

Every 30 days while its links are clicked, and where it lands is watched in between — daily in its first week, then weekly — with a change of landing site checked at once. A check with no answer is retried in 15 minutes and never blocks a link on its own.

Report a link · Acceptable use

Accounts and access

Who can sign in, how, and what a key can do.

Signing in

A password with a strength floor, a passkey, or a Google, GitHub or Microsoft account where the sign-in page offers it. Two-factor with an authenticator app and recovery codes is on every plan. Single sign-on through the organisation’s own identity provider is on Business.

Changing how you sign in

Your current password first for a new email, password, two-factor setting, recovery codes, passkey or personal API key — and each change is emailed to you, as is a sign-in from a new device.

Sessions

Only a hash is stored of the opaque session token your browser holds. Signing out, or being deactivated, ends the session at once; other sessions can be ended from your profile.

API keys

A key never holds more than its maker, and nothing once that person leaves. It belongs to the organisation or to one person, never a group; its secret is shown once and stored encrypted; it expires after 30 to 365 days (90 unless you choose), or never if you say so.

At rest

Passwords hashed; secrets, emails and IP addresses encrypted. Anything that must be searchable is matched through a keyed digest, so a copied table cannot be reversed against a list of common values.

Brevily staff

Staff sign in with a second factor. Every change they make in an organisation is in its audit log, where it reads as Support. On Pro and Business, an organisation can read and export its own audit log.

Your data leaves when you say

Nothing is held back to keep you, and nothing lingers after you go.

Export

Every link, deleted ones included, and every day’s click totals download as CSV at any time, from Organisation settings.

Delete

The owner asks, confirmed with their password, and can cancel until the day. After 30 days its people are erased, keys revoked and links deleted; billing and audit records stay, as the law requires.

Payments

Dodo Payments, the merchant of record, takes the payment, adds the tax that applies where you are and issues the invoice. Card details go to Dodo, never to Brevily.

Who else handles data

The service providers that receive any of it, and what each receives. The data processing terms say how a new one is announced and how to object.

Provider What for What it receives
Cloudflare Serves every redirect and page, queues clicks, caches link data, sends email Link data, clicks in transit, the address an email goes to
Dodo Payments Merchant of record: payments, tax and invoices Billing name, address and payment details
Google Web Risk Checks destinations against lists of unsafe sites Destination URLs only, never who made the link

What Brevily does not have yet

Said plainly, so nobody has to find out later.

Certifications

No SOC 2 report and no ISO 27001 certificate. If procurement needs one, ask before relying on either.

A bug bounty

No paid bounty. Report a vulnerability to security@brevily.com; nobody who reports one in good faith and allows reasonable time to fix it will be pursued.

A service level

No uptime promise and no SLA. The status page shows what is happening now and over the last 90 days.

Something not answered here?

Security and procurement questions reach a person.