Who we are
AllID is an independently operated service based in Dublin, Ireland. For questions about your data, use the contact form.
What we collect
You give us:
- Your handle (public — it's your URL).
- Your email address (private, encrypted at rest, used to sign you in and contact you about your account).
- Anything you put on your profile pages — display name, bio, links, images, theme settings. What's visible depends on the profile's visibility setting: Public profiles are visible to anyone and may appear in search results. Unlisted profiles are reachable by anyone who has the link but are not listed or indexed by search engines. AllID-members-only profiles show their links only to visitors signed in to AllID. Private profiles are visible only to you when signed in.
We collect automatically when you use the product:
- Sign-in events (when, from what device, from what country).
- Views of your public profile pages and clicks on the links you publish. Each one is recorded as a row holding the time, a country code, the referring site, coarse device/browser/OS categories, and the day-rotating hashed IP described under "How long we keep it" — never a name, an email, or an address. We show you the totals; we cannot tell you who a visitor was, and neither can anyone reading the raw rows.
- Basic technical data: browser type, language, region.
When you contact us:
- Anything you send through the contact form — your name and email if you provide them, the subject, the message itself, and which page you sent it from. We keep these for 24 months so we can follow up and see repeat issues, then delete them.
- Anything you send through the in-app feedback widget — your description, an optional screenshot, and the page you were on. Same 24-month retention.
If you sign in with Google:
- Google confirms your identity and tells us your email address and a stable account identifier, so we can match you to your AllID account. We don't receive your Google password, your contacts, or anything else.
We do not collect:
- Passwords. Sign-in is a passkey, Google, or a one-time code emailed to you — there is no password to type, and we never see your authenticator's private key.
- Browsing history outside AllID.
- Sensitive categories (health, politics, religion, sexuality, biometrics) unless you put them on your own public profile.
Why we collect it
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Operating your account, showing your profile, processing your sign-ins | Email, handle, profile contents, sign-in events | Contract |
| Showing you analytics for your own profile and links | Aggregated visit + click counts | Contract |
| Preventing fraud and abuse — blocking impersonation, spam, account takeover | Sign-in events, region of request, audit logs | Legitimate interest |
| Transactional email (sign-in codes, security alerts, account changes) | Email address | Contract |
| Funding the free service through advertising shown on the link redirect interstitial | Destination link category, coarse region of the request, and ad-interaction signals. Today all of this is first-party; if we add a third-party ad partner that reads information from the visitor's browser, we will ask for consent first where the law requires it | Legitimate interest (first-party); consent where required (third-party) |
| Complying with the law when we have to | Whatever the law requires | Legal obligation |
We do not sell your personal data. We do not share your account credentials, password material, sign-in events, or transactional email contents with advertisers.
Advertising on the link redirect interstitial
AllID is free to use because every short-link click passes through a brief interstitial before sending the visitor to the destination. That space is reserved for advertising and is a core, always-on part of the service — it is what will fund hosting, analytics, the global edge, and continued development.
What this means in practice:
- Ads appear only on the redirect interstitial for
allid.me/r/...short links. They are not shown on your profile page, on your dashboard, on the analytics views, or in your account. - The interstitial is reserved for advertising in any form — sample placeholders, in-house promotions, first-party promoted listings, or ads served by third-party ad networks — and we may use this space across all of these formats, change formats, swap or add ad partners, and run promotions at any time at our discretion.
- Today the interstitial runs no third-party ad scripts. What it shows is served by us, and nothing on it reports to an outside advertising network.
- When we do bring in third-party ad partners, they and we may use information such as the destination link's category, the coarse region of the visitor's request, the visitor's device and browser characteristics, the referrer, and the visitor's interaction with the interstitial, to make ads relevant and measure their performance. A third-party partner would also be able to collect information directly from the visitor's browser as the interstitial loads, under its own privacy practices, and use it to profile the visitor for advertising within the limits of applicable law. Where the law requires the visitor's consent before that happens, we will ask for it first. We would never transfer your account credentials to an ad partner, and we do not sell your personal data.
- There is no user-level opt-out for the redirect-interstitial ad — it is part of the free tier on the same terms as for every other user.
- Phone-call, email, and similar direct-action link types do not show an interstitial — they route the visitor straight through.
Our Terms of Service spell out the commercial side of this arrangement.
Who we share it with
We use a small number of trusted vendors to run the service. Each only sees the data they need to do their job.
| Vendor | What they see | Where |
|---|---|---|
| Cloudflare (edge) | Edge traffic (IPs, request paths, basic device fingerprint) — used for performance, DDoS protection, and bot filtering | Global edge |
| Cloudflare R2 (storage) | Every file the product stores: profile avatars and backgrounds, link icons, generated QR codes, feedback screenshots, archived analytics, and the export file we build when you ask for your data | EU |
| Cloudflare Turnstile | Signals from your browser at signup, used to tell a person from a bot. No account data is sent | Global edge |
| Fly.io | Origin servers and the database — where the application runs and your account data lives | EU (Frankfurt) |
| Only if you choose "Continue with Google": Google confirms your identity to us and learns that you signed in to AllID. We receive your email address and a stable account identifier, nothing more | Global | |
| MaxMind | We use MaxMind's GeoLite2 database to translate IPs into country codes. The lookup happens inside our servers — your IP is not sent to MaxMind | n/a |
| SendGrid (Twilio) | Your email address and the contents of the transactional email we send | US |
| Sentry | Crash reports and error traces (scrubbed for PII) | EU |
No vendor outside this list processes your data, and we do not sell it to anyone.
Where we store your data
Everything is stored in the European Union. Our database and application servers run in Frankfurt, and the files you upload are held in EU object storage. This is true for every account regardless of where you sign up from.
Two things happen outside the EU, and only these two: our email provider is US-based (so a transactional email to you passes through the US), and Cloudflare's global edge terminates the connection nearest you before forwarding the request to Frankfurt. Both are covered by the transfer safeguards in our agreements with them.
We would like to offer regional residency — keeping Indian accounts in India and US accounts in the US — and the application is built to support it, but it is not switched on today. We'll update this page before it is.
How long we keep it
- Account data: for as long as your account is active. Delete your account and we remove your personal data within 30 days of the deletion completing, except where law requires us to keep it longer (e.g. audit-trail rows that prove a deletion happened).
- Sign-in events and audit logs: 12 months, then deleted. These are the tamper-evident security record described below, so they are kept for the full period even if you'd rather they weren't.
- Click and view telemetry: individual events stay queryable for 13 months, then are moved to compressed archive storage; aggregated counts are kept indefinitely. Neither contains your name, email, or a raw IP.
- Hashed IPs: the raw IP is never written down. What we store is a keyed hash whose secret changes at midnight UTC, so the same visitor cannot be followed from one day to the next.
- Backups: rolling 30-day window. Deletions reach backups within the same window.
Deleting your account is not instant by design: it starts a 30-day grace period you can cancel from Settings, and the permanent erase runs after that. Worst case, from clicking delete to the last backup expiring, is about 60 days.
Recently visited profiles
If you're signed in, your dashboard keeps a private list of the profiles you've recently looked at — which profile, when you last visited it, and how many times. Only you can see this. Profile owners are never told who visited. We deliberately store nothing else about the visit: no IP address, no browser or device information, and no referrer.
We keep at most your 20 most recent entries, and any entry you haven't revisited in 180 days is pruned automatically. You can erase this yourself at any time: remove a single profile from the list, or use "Clear history" on your dashboard to wipe the whole list in one action.
Bookmarked profiles
If you're signed in, you can bookmark any profile you can see, and it appears in a private list on your dashboard. We store which profile you bookmarked and when. Only you can see this. Profile owners are never told who bookmarked them. As with recently visited profiles, we store nothing else: no IP address, no browser or device information, and no referrer.
Bookmarks do not expire and are not pruned — they stay until you remove them. Remove one by tapping its bookmark icon again. Deleting your account erases them, and a bookmarked profile that is deleted or made private disappears from your list automatically.
Cookies
We use a small number of cookies. All of them are first-party and serve the site itself — keeping you signed in, remembering choices you made, and attributing a visit to the right profile. None are advertising or cross-site tracking cookies, and none are shared with third parties, so there is no consent banner to click through.
| Cookie | What it does | Lifetime |
|---|---|---|
__Host-allid_session | Keeps you signed in. Holds an opaque token, not your identity | 30 days, rolling |
__Host-allid_signup_token | Holds your place partway through signup | The signup attempt |
__Host-allid_pending_email | Carries the email address you typed from the sign-in form to the "check your inbox" page, so we never put it in a link. Signed, and readable only by us | 10 minutes |
__Host-allid_passkey_auth | Ties a passkey sign-in attempt to the browser that started it. Holds a random value, not your identity | 5 minutes |
csrftoken | Blocks another site from submitting forms as you | 1 year |
allid_last_method | Remembers which sign-in method you used last, so the login page can lead with it. Contains no personal data | 180 days |
alid_owner | Lets us recognise you looking at your own profile so your own visits are excluded from your view counts | 30 days |
allid_ref | Set only if you arrive via someone's referral link, so their referral is credited if you sign up | 30 days |
alid_src | Set when you open a QR-code link, so the profile owner's scan count is right. Records which profile was opened, not who opened it | 10 minutes |
analytics_filter | Set only on your own analytics page, so the filters you pick are still there when you come back. Holds which profile or link you filtered to, nothing else | 30 days |
__cf_bm, cf_clearance | Set by Cloudflare to filter bots and remember that you passed a challenge | Up to 30 minutes / 1 year |
Your browser may also keep your theme choice in local storage. That never leaves your device.
Your rights
Under GDPR, India's DPDP Act, and California's CCPA, you can:
- See your data — export everything we hold on you from your settings page (Settings → Export my data). We email you a one-time link to a JSON file within minutes; the link expires 15 minutes after it is issued, and you can request up to 5 exports a month.
- Correct your data — change your display name, profile contents, and email address yourself in Settings. Your handle is part of your public URL, your QR codes, and your search listing, so changing it is not self-serve: ask through the contact form and we'll do it.
- Delete your account — Settings → Danger zone → Delete account. Hard-delete after a 30-day grace period; cancel any time within that window.
- Restrict or object to processing — use the contact form.
- Lodge a complaint with a supervisory authority. In Ireland that's the Data Protection Commission (dataprotection.ie).
Security
- Email and phone numbers are encrypted at rest using authenticated encryption.
- Password sign-in is switched off entirely. You sign in with a passkey, with Google, or with a one-time code we email you, and you can add an authenticator app (TOTP) as a second factor.
- Sessions are server-side; we never put bearer tokens in URLs.
- We run audit logs as a tamper-evident hash chain so any backwards edit is detectable.
- All traffic is HTTPS-only with modern ciphers; we do not accept plaintext.
No system is unbreakable. If we ever suffer a breach that affects you, we'll notify you within 72 hours, as the law requires.
Children
AllID is not intended for children under 13 (or under the digital-consent age in your country, whichever is higher). If we learn a minor has signed up, we'll remove the account.
Changes
When we change this policy in a way that affects you, we'll email you at least 14 days before the change takes effect.
Contact
Two routes, both monitored: the contact form, or support@allid.me. There is no separate privacy-only address — anything about this policy, your data, or a rights request goes to the same place either way. We aim to respond within 5 working days, and always within the one month the GDPR allows for a rights request.