Shortcutly

Last updated: August 29, 2026

Privacy Policy

What information Shortcutly collects, how we use it, and the choices you have about your data.

Account Data

When you create a Shortcutly account we collect your email address, a username, and the authentication data needed to sign you in. Passwords are stored only as salted hashes, never in plain text. If you choose Google sign-in, Google provides identity details and authentication tokens that are stored with your linked account.

You can optionally add profile details: a display name, bio, avatar, website, location, and social handles. Everything except your email address is public and shown on your creator profile.

Content You Post

Shortcuts you submit are public by design: the name, description, icon, category, tags, version history, release notes, and the iCloud link you provide are visible to everyone once approved.

Comments you write on shortcut pages are public and attached to your username. You can edit or delete your own comments at any time.

Usage Data

When a shortcut page is viewed or Get Shortcut is tapped, we store the shortcut, time, and a secret-keyed fingerprint of the network address and UTC date. We never put the raw address in these event tables. The fingerprint changes each day and is used to avoid counting the same address repeatedly; it is not linked to a Shortcutly account. Event rows are deleted after 366 days, while the public lifetime download counter remains.

Like standard web services, our hosting provider processes technical data such as IP address and browser type in server logs to operate and secure the service.

Cookies and Authentication

We set three cookies, and only the last one is yours to decide. The session cookie keeps you signed in after you log in: it is set only once you have an account, and strictly necessary to have one. The cookie_consent cookie remembers whether you accepted or refused the next one, so the banner stops asking; it is kept 13 months after an acceptance, 6 months after a refusal, then the question comes round again. The visitor cookie is set by our analytics provider, Visitors, and only if you accept. It holds a random identifier — no name, no email — so a returning reader can be told from a new one. It is renewed for a year on each visit while your consent lasts, and refusing deletes it.

You can change your choice at any time with the Cookies control below. Visitors also honours your browser's Global Privacy Control and Do Not Track settings — with either switched on, it records nothing at all. Opening any page with ?visitors=false added to the address stores a flag in this browser's local storage that stops all analytics events (and ?visitors=true removes it); that flag does not remove the visitor cookie, which is what Refuse is for. No advertising or cross-site tracking cookies, ever.

You can clear or block cookies in your browser settings, but you will not be able to stay signed in without them.

Analytics

We use Visitors, a privacy-friendly analytics service, to understand how the site is used. Before you answer the cookie banner, and if you refuse, audience measurement still runs without any identifier: the address of the page you open (including anything after the ?), the page that referred you, how long you stay, how far you scroll, links you follow off-site — including the iCloud link behind Get Shortcut — and page-performance timings are counted, and nothing is stored on your device to recognise you next time. Pages whose address carries a one-time link, including password reset, email verification, and newsletter confirmation, are left out of analytics entirely.

Anonymous audience measurement — counting pages and referrers to see what people read, with no identifier and nothing stored to recognise you later — rests on our legitimate interest in knowing whether the site works. Measurement across visits — joining your visits into one journey through the visitor cookie so we can tell a returning reader from a new one — rests on your consent, asked for by the cookie banner and withdrawable at any time from the Cookies control. Visitors does not follow you onto other sites, and we do not run ad tracking of any kind.

Email

We use Resend for account and submission messages. If you enter an address in the newsletter form, we first send a confirmation link and do not enable marketing delivery until that link is used. Confirmed subscribers receive the Friday digest and can unsubscribe from every edition. We store the confirmation challenge digest, generation, status, and timestamps so retries cannot create consent and so a used link can be recognized; the bearer link itself is not stored.

Resend receives the recipient address and message content to deliver these emails. We do not sell addresses or share them for another company’s own marketing.

Who Processes Data for Us

A few trusted services help us run Shortcutly, and each one receives only what its role needs. Vercel hosts the site. Neon runs the Postgres database. Cloudflare stores and delivers shortcut icons and screens authentication forms for bots. Upstash runs rate limiting and the session cache. Resend sends account messages and the weekly digest. Google handles Google sign-in when you choose it.

Visitors (visitors.now) handles audience measurement. It receives the page address, referrer, time on page, scroll depth, outbound link destinations, browser/device and connection type, and page-performance timings, plus the random identifier above if you accepted it; its own handling of that data is described at https://visitors.now/privacy.

Sentry receives error, route, browser/device, and sampled performance diagnostics. We disable its automatic personal-data collection, logs, metrics, and session replay; our manual API reports include a procedure name but no request body or client network address. An email-delivery failure may also include a short, one-way keyed marker derived from the recipient address so repeated failures can be grouped without sending the address itself. Anthropic powers an admin-only drafting tool and receives a bounded server-generated snapshot of public shortcut activity plus names and release notes from the pending moderation queue; it receives no account profile or email data. A Discord webhook alerts admins to a new signup by display name and to a new submission by shortcut name, creator handle, and public shortcut URL.

Data Deletion

You can delete your shortcuts and comments yourself at any time.

Deleting your account removes your profile and cascades to your content in the active database. Your shortcuts, versions, comments, likes, favorites, and follows are deleted with it. Service logs, provider records, and backups may remain until their configured retention periods expire. Newsletter consent is address-based rather than account-based; unsubscribe from an edition or email support@shortcutly.com to request removal of that record. To request account deletion or a copy of your data, email us at support@shortcutly.com.

Your Rights (GDPR)

You can ask us at any time to show you the data we hold about you (access), correct it (rectification), delete it (erasure), hand you a copy you can take elsewhere (portability), or stop certain processing (objection).

Email support@shortcutly.com and we will respond within 30 days. If our answer does not satisfy you, you can lodge a complaint with the CNIL, the French data protection authority, at cnil.fr.

Apple

Shortcutly is an independent community project, not affiliated with, endorsed by, or sponsored by Apple Inc. Apple, iPhone, iPad, Mac, iCloud, and Shortcuts are trademarks of Apple Inc.

Changes and Contact

We may update this Privacy Policy as the service or legal requirements evolve. The "Last updated" date shows when changes were made.

Questions about this policy or how we handle data? Email us at support@shortcutly.com.

PrivacyTerms