$ toss.is privacy
Privacy & data
What is stored
When a link is created, toss.is stores the destination URL, available destination title and description, creation time, and creator IP address. Each redirect records the time, visitor IP address, country resolved from local GeoIP data, and user agent.
Abuse reports store the reported toss.is URL, selected reason, optional details, reporter IP address, user agent, and submission time.
Why it is used
This data is used to operate short links, provide private link status, investigate abuse, and troubleshoot the service. Private management URLs are required to view a link's status or remove it.
Data sharing
GeoIP lookup uses data stored on this server; visitor IP addresses are not sent to an external GeoIP API.
When an HTTPS Open Graph preview image is displayed, your browser requests it directly from the image host without a referrer. The image URL and image data are not stored by toss.is. For HTML links, toss.is may also render and store one 1920×1080 webpage screenshot on this server; it is available only through the private management URL and is removed when the link is deleted.
Google Analytics is used on public pages to measure aggregate site visits. Google may receive standard browser and visit information under its own policies. Private management pages are excluded so private management URLs and their tokens are not sent to Google Analytics. Analytics page views omit URL query values and referrer values.
Private management URLs
A management URL grants access to link status and removal controls. Keep it private and do not send it by email or include it in an abuse report.