How Brevily is run, and what it keeps
Every line here describes what the product does today. Where something is missing, the page says so instead of promising it.
What a click records
A click is counted, described in a few words and passed on. Nothing about the person who clicked is kept beyond that.
What is recorded
The time, the link, where it sent the visitor, the country, the device type, operating system and browser family, the referring site, and whether the click came from a QR code. The IP address is stored encrypted for abuse investigation only, never shown to the link’s owner, and is blanked after 90 days.
One cookie, on the link’s own domain
A signed first-party cookie, __Host-sv, on the short link’s domain tells a returning visitor from a new one, to count unique visitors; it lasts a year. There is no cross-site cookie, unless the link’s owner adds retargeting pixels: then that platform’s pixel loads on a one-second page before the redirect.
Crawlers are counted apart
Bots are not people. Known crawlers are recognised from the user agent and kept apart, in the numbers and in anything forwarded. A chat app fetching a link for its preview counts as a crawler, never as a visit.
No profiles, nothing sold
Click data is never sold and builds no profile of anyone. It goes only where the link’s owner sends it: their analytics, exports, reports, webhooks and Google Analytics forwarding.
How long it stays
Free shows daily totals only, for 30 days. Pro shows each click for 60 days and daily totals for 180 days. Business shows each click for 180 days and daily totals for 365 days. Single clicks are kept at least seven days on every plan, because the daily totals are built from them. What a plan stops showing is hidden at once and deleted 30 days later, so an upgrade in between shows it again.
Where it travels
Answered at the edge, in the data centre nearest the visitor. The click then goes through a queue into the primary database, so a slow database never slows a redirect down.
Anyone can check a link before clicking it
A short link hides its destination, and phishing relies on that. Every Brevily link can be looked at first — and every new destination is checked with Google Web Risk and Brevily’s heuristics when the link is made, and again while it is in use.
-
Add a + to the end
brvl.uk/q3-launch becomes brvl.uk/q3-launch+. In any browser, on any device.
-
Read the page it stops on
The full destination, when the link was made and its last safety check. Nothing is loaded from the destination.
-
Then decide
Continue to the destination, or report the link in one click. Looking is not counted as a click.
Nothing to install, no script on any website. The preview is served by the redirect itself, so it works on every Brevily link, for everyone, and the link’s owner cannot switch it off.
- Without the +brvl.uk/q3-launchGoes straight to northwind.com, and counts as a click.
- With a +brvl.uk/q3-launch+Stops on a preview page instead: the full destination, when the link was made and its last safety check. Not counted as a click.
Two kinds of link keep their destination back: one with a password asks for the password first, and one with a click limit shows where it goes only when it is followed.
Click or tap the + above to see the page it opens.
Where this link goes
You added a +, so this page shows the destination instead of sending you there. Nothing has been loaded from it.
Checks say what is known, not that a page is safe. A destination can change after it is checked, so read the address before you continue.
When a destination is harmful
A flag belongs to the destination, not to one link, so a harmful page cannot be reached through a second link to it.
A flag stops every link to it
When Google Web Risk or a Brevily reviewer flags a destination, every link to it, in every organisation, shows a warning page instead of redirecting, and no new link can point there. Each owner is told by email.
Reports are read by a person
Anyone can report a link, with no account. A person reviews every report. Reports from three different connections send the destination for an immediate safety check, but a report alone never stops a link.
Lifted by review, not by editing
Editing a flagged link does not lift the flag. Its owner changes the destination and asks for a review; a reviewer lifts or keeps it, and the owner is emailed the decision.
Checked again while in use
Every 30 days while its links are clicked, and where it lands is watched in between — daily in its first week, then weekly — with a change of landing site checked at once. A check with no answer is retried in 15 minutes and never blocks a link on its own.
Accounts and access
Who can sign in, how, and what a key can do.
Signing in
A password with a strength floor, a passkey, or a Google, GitHub or Microsoft account where the sign-in page offers it. Two-factor with an authenticator app and recovery codes is on every plan. Single sign-on through the organisation’s own identity provider is on Business.
Changing how you sign in
Your current password first for a new email, password, two-factor setting, recovery codes, passkey or personal API key — and each change is emailed to you, as is a sign-in from a new device.
Sessions
Only a hash is stored of the opaque session token your browser holds. Signing out, or being deactivated, ends the session at once; other sessions can be ended from your profile.
API keys
A key never holds more than its maker, and nothing once that person leaves. It belongs to the organisation or to one person, never a group; its secret is shown once and stored encrypted; it expires after 30 to 365 days (90 unless you choose), or never if you say so.
At rest
Passwords hashed; secrets, emails and IP addresses encrypted. Anything that must be searchable is matched through a keyed digest, so a copied table cannot be reversed against a list of common values.
Brevily staff
Staff sign in with a second factor. Every change they make in an organisation is in its audit log, where it reads as Support. On Pro and Business, an organisation can read and export its own audit log.
Your data leaves when you say
Nothing is held back to keep you, and nothing lingers after you go.
Export
Every link, deleted ones included, and every day’s click totals download as CSV at any time, from Organisation settings.
Delete
The owner asks, confirmed with their password, and can cancel until the day. After 30 days its people are erased, keys revoked and links deleted; billing and audit records stay, as the law requires.
Payments
Dodo Payments, the merchant of record, takes the payment, adds the tax that applies where you are and issues the invoice. Card details go to Dodo, never to Brevily.
Who else handles data
The service providers that receive any of it, and what each receives. The data processing terms say how a new one is announced and how to object.
| Provider | What for | What it receives |
|---|---|---|
| Cloudflare | Serves every redirect and page, queues clicks, caches link data, sends email | Link data, clicks in transit, the address an email goes to |
| Dodo Payments | Merchant of record: payments, tax and invoices | Billing name, address and payment details |
| Google Web Risk | Checks destinations against lists of unsafe sites | Destination URLs only, never who made the link |
What Brevily does not have yet
Said plainly, so nobody has to find out later.
Certifications
No SOC 2 report and no ISO 27001 certificate. If procurement needs one, ask before relying on either.
A bug bounty
No paid bounty. Report a vulnerability to security@brevily.com; nobody who reports one in good faith and allows reasonable time to fix it will be pursued.
A service level
No uptime promise and no SLA. The status page shows what is happening now and over the last 90 days.
Something not answered here?
Security and procurement questions reach a person.