Privacy

AllID is built so you can show up as yourself online without giving up control. This page explains what data we collect, why we collect it, and what you can do about it. We keep it short because privacy policies should be readable.

Last updated: 27-Jul-2026

Who we are

AllID is an independently operated service based in Dublin, Ireland. For questions about your data, use the contact form.

What we collect

You give us:

We collect automatically when you use the product:

When you contact us:

If you sign in with Google:

We do not collect:

Why we collect it

PurposeData usedLegal basis (GDPR)
Operating your account, showing your profile, processing your sign-insEmail, handle, profile contents, sign-in eventsContract
Showing you analytics for your own profile and linksAggregated visit + click countsContract
Preventing fraud and abuse — blocking impersonation, spam, account takeoverSign-in events, region of request, audit logsLegitimate interest
Transactional email (sign-in codes, security alerts, account changes)Email addressContract
Funding the free service through advertising shown on the link redirect interstitialDestination link category, coarse region of the request, and ad-interaction signals. Today all of this is first-party; if we add a third-party ad partner that reads information from the visitor's browser, we will ask for consent first where the law requires itLegitimate interest (first-party); consent where required (third-party)
Complying with the law when we have toWhatever the law requiresLegal obligation

We do not sell your personal data. We do not share your account credentials, password material, sign-in events, or transactional email contents with advertisers.

Advertising on the link redirect interstitial

AllID is free to use because every short-link click passes through a brief interstitial before sending the visitor to the destination. That space is reserved for advertising and is a core, always-on part of the service — it is what will fund hosting, analytics, the global edge, and continued development.

What this means in practice:

Our Terms of Service spell out the commercial side of this arrangement.

Who we share it with

We use a small number of trusted vendors to run the service. Each only sees the data they need to do their job.

VendorWhat they seeWhere
Cloudflare (edge)Edge traffic (IPs, request paths, basic device fingerprint) — used for performance, DDoS protection, and bot filteringGlobal edge
Cloudflare R2 (storage)Every file the product stores: profile avatars and backgrounds, link icons, generated QR codes, feedback screenshots, archived analytics, and the export file we build when you ask for your dataEU
Cloudflare TurnstileSignals from your browser at signup, used to tell a person from a bot. No account data is sentGlobal edge
Fly.ioOrigin servers and the database — where the application runs and your account data livesEU (Frankfurt)
GoogleOnly if you choose "Continue with Google": Google confirms your identity to us and learns that you signed in to AllID. We receive your email address and a stable account identifier, nothing moreGlobal
MaxMindWe use MaxMind's GeoLite2 database to translate IPs into country codes. The lookup happens inside our servers — your IP is not sent to MaxMindn/a
SendGrid (Twilio)Your email address and the contents of the transactional email we sendUS
SentryCrash reports and error traces (scrubbed for PII)EU

No vendor outside this list processes your data, and we do not sell it to anyone.

Where we store your data

Everything is stored in the European Union. Our database and application servers run in Frankfurt, and the files you upload are held in EU object storage. This is true for every account regardless of where you sign up from.

Two things happen outside the EU, and only these two: our email provider is US-based (so a transactional email to you passes through the US), and Cloudflare's global edge terminates the connection nearest you before forwarding the request to Frankfurt. Both are covered by the transfer safeguards in our agreements with them.

We would like to offer regional residency — keeping Indian accounts in India and US accounts in the US — and the application is built to support it, but it is not switched on today. We'll update this page before it is.

How long we keep it

Deleting your account is not instant by design: it starts a 30-day grace period you can cancel from Settings, and the permanent erase runs after that. Worst case, from clicking delete to the last backup expiring, is about 60 days.

Recently visited profiles

If you're signed in, your dashboard keeps a private list of the profiles you've recently looked at — which profile, when you last visited it, and how many times. Only you can see this. Profile owners are never told who visited. We deliberately store nothing else about the visit: no IP address, no browser or device information, and no referrer.

We keep at most your 20 most recent entries, and any entry you haven't revisited in 180 days is pruned automatically. You can erase this yourself at any time: remove a single profile from the list, or use "Clear history" on your dashboard to wipe the whole list in one action.

Bookmarked profiles

If you're signed in, you can bookmark any profile you can see, and it appears in a private list on your dashboard. We store which profile you bookmarked and when. Only you can see this. Profile owners are never told who bookmarked them. As with recently visited profiles, we store nothing else: no IP address, no browser or device information, and no referrer.

Bookmarks do not expire and are not pruned — they stay until you remove them. Remove one by tapping its bookmark icon again. Deleting your account erases them, and a bookmarked profile that is deleted or made private disappears from your list automatically.

Cookies

We use a small number of cookies. All of them are first-party and serve the site itself — keeping you signed in, remembering choices you made, and attributing a visit to the right profile. None are advertising or cross-site tracking cookies, and none are shared with third parties, so there is no consent banner to click through.

CookieWhat it doesLifetime
__Host-allid_sessionKeeps you signed in. Holds an opaque token, not your identity30 days, rolling
__Host-allid_signup_tokenHolds your place partway through signupThe signup attempt
__Host-allid_pending_emailCarries the email address you typed from the sign-in form to the "check your inbox" page, so we never put it in a link. Signed, and readable only by us10 minutes
__Host-allid_passkey_authTies a passkey sign-in attempt to the browser that started it. Holds a random value, not your identity5 minutes
csrftokenBlocks another site from submitting forms as you1 year
allid_last_methodRemembers which sign-in method you used last, so the login page can lead with it. Contains no personal data180 days
alid_ownerLets us recognise you looking at your own profile so your own visits are excluded from your view counts30 days
allid_refSet only if you arrive via someone's referral link, so their referral is credited if you sign up30 days
alid_srcSet when you open a QR-code link, so the profile owner's scan count is right. Records which profile was opened, not who opened it10 minutes
analytics_filterSet only on your own analytics page, so the filters you pick are still there when you come back. Holds which profile or link you filtered to, nothing else30 days
__cf_bm, cf_clearanceSet by Cloudflare to filter bots and remember that you passed a challengeUp to 30 minutes / 1 year

Your browser may also keep your theme choice in local storage. That never leaves your device.

Your rights

Under GDPR, India's DPDP Act, and California's CCPA, you can:

Security

No system is unbreakable. If we ever suffer a breach that affects you, we'll notify you within 72 hours, as the law requires.

Children

AllID is not intended for children under 13 (or under the digital-consent age in your country, whichever is higher). If we learn a minor has signed up, we'll remove the account.

Changes

When we change this policy in a way that affects you, we'll email you at least 14 days before the change takes effect.

Contact

Two routes, both monitored: the contact form, or support@allid.me. There is no separate privacy-only address — anything about this policy, your data, or a rights request goes to the same place either way. We aim to respond within 5 working days, and always within the one month the GDPR allows for a rights request.