What we keep, and what we do not.
This is the list, not a policy generator. If we add a paid plan or change retention, we will change this page first.
Who
CME United runs tnyx.us. Mail and questions go to tnyx@cmeunited.com. There is not a separate privacy office.
Your account
We store your email, name, a password hash, optional authenticator secret, backup codes, and an API key if you use one. We send verify, reset, and sign-in mail as TNYX from tnyx@cmeunited.com through our existing mail provider.
Your links
We store the destination URL, slug, optional title and UTMs, QR colors and logo, and whether the link is active. Those stay on your account. The long URL is yours.
Clicks
Each redirect stores the time, the HTTP referrer, the user agent, and a SHA-256 hash of the visitor IP. We do not store the raw IP. We do not look up location. We do not sell click rows or use them for advertising. Campaign UTMs are your tags for your analytics, not ours.
Custom hostnames
If you add one, we store the hostname and the TXT token we asked you to publish, plus when it verified.
Cookies
Signed-in pages use a session cookie (HttpOnly, SameSite Lax; Secure on https). That is how we know it is you. There is no advertising cookie.
How long
We have not set an automatic delete-after date. While you have an account, the rows stay so the short URL and the export still work. We will write a retention period here before we start deleting click history. You can export links and click rows while signed in.
Who else sees it
The people who already operate this server. The mail provider sees the address we send to. We do not sell accounts or click data. We will not pretend a warrant or a serious abuse report cannot reach us.