Privacy policy
What we collect
When you create an AppRoute account, we process account details, authentication and team membership, billing status, and the links and routing rules you configure. If you add a custom domain, we store the host name, DNS-verification records and status, and provider routing/TLS metadata needed to connect and operate that domain. Vercel processes requests for those customer domains because it hosts and routes the AppRoute application.
When you open a short link we collect the signal needed to route your click and produce analytics for the link's owner: a hashed IP, a hashed User-Agent, the requested URL, and the rule that matched. From the User-Agent and request headers we derive device type and model, operating system and browser (with versions), country, region, timezone, browser language, and the referring site. Where our hosting provider supplies them, we also record an approximate city and network-derived coordinates, rounded to two decimal places, to show recent clicks on a globe. We do not request GPS or browser location access, and we do not store your raw IP address.
We also generate two opaque identifiers so the owner can see sessions rather than disconnected clicks: a visitor identifier (a salted hash of the hashed IP + User-Agent, scoped to that one owner) and a session identifier (a random token in the functional `ar_sess` cookie that groups your clicks within 30 minutes). Neither is linked to your name or account. If the link's URL contains an advertising click ID (for example ttclid, fbclid, or gclid), we store that value so the owner can reconcile it with their ad platform. We do not collect names, email addresses, precise location, or any other personal identifier from a redirect.
When you use a live AI writing tool, we send the prompt and the options you choose to Cloudflare so it can generate the requested result. AppRoute does not put the raw prompt, generated text, public handle, profile URL, or calculator values into product analytics. After analytics consent, we may record non-content operational metadata such as the tool, platform, mode, completion state, result count, copy or download action, calculation type, and smart-link CTA destination. Public social analytics features may send the public handle or profile URL you enter to Apify to collect a bounded sample of publicly available posts; private account data is not requested.
Why we collect it
We use it strictly to: (a) decide which destination to redirect you to, (b) produce per-link aggregate analytics for the AppRoute customer whose link you clicked, and (c) detect abuse such as automated traffic floods.
Your rights
GDPR and CCPA grant you the right to access, correct, port, and delete personal data we hold about you. Email info@getapproute.com and we will respond within 14 days.
- Right of access — copy of data we hold
- Right to rectification — correct inaccuracies
- Right to erasure — delete on request
- Right to portability — machine-readable export
- Right to object — to processing on legitimate interest
How long we keep it
Raw, hashed click events are retained for 90 days for debugging and abuse review, after which only aggregate counts remain. Aggregates are retained for the lifetime of the link, plus 12 months after deletion.
AppRoute does not add free-tool prompts, generated text, public handles, profile URLs, or calculator values to its product analytics store. The tools gateway keeps generated results for up to 24 hours to make an admitted request idempotent. It keeps provider-usage and request-status records for up to 35 days to enforce daily and monthly limits and reconcile uncertain provider charges. The HMAC-derived abuse-control identifier is removed after its UTC daily limit window ends. Provider-side processing and retention are governed by the Cloudflare or Apify terms listed on our sub-processors page.
Contact
Privacy questions: info@getapproute.com. EU representative: AppRoute GmbH, c/o info@getapproute.com.