Skip to main content
street/l
HomeLog in

Data and retention

Privacy without surveillance analytics.

Street keeps the information needed to operate controlled redirects, secure workspaces, and honor deletion—while leaving raw visitor addresses and destination query values out of product events.

Applies to
Street Release 1
Last updated
August 29, 2026

On this page

  1. 1. Scope
  2. 2. Account and workspace data
  3. 3. Redirect and security data
  4. 4. Service providers
  5. 5. Retention
  6. 6. Your choices
  7. 7. Contact

1. Scope

This notice describes the information Street processes to provide, secure, support, and improve Release 1. Street does not sell personal information or provide customer-facing visitor analytics in Release 1.

2. Account and workspace data

Street processes your name, verified email, authentication account, sessions, workspace name and timezone, link configuration, internal link names, destinations, schedules, limits, lifecycle state, and management audit events.

Authentication and security records support verification, password recovery, session revocation, abuse investigation, and account deletion. Passwords are handled through Better Auth and are not available to Street operators as plaintext.

3. Redirect and security data

An accepted or rejected redirect event may include the link and workspace identifiers, decision, reason category, request method, UTC timestamp, and a bounded client category. The durable enforcement count records how many redirects Street issued.

  • Product access events do not store raw IP addresses.
  • Destination query values and fragments are not logged.
  • Abuse controls may retain a daily rotated HMAC of a truncated IP for up to seven days.
  • Full user-agent material is retained for no more than seven days.

4. Service providers

Street uses Vercel for application hosting and platform security, Neon for PostgreSQL, Resend for transactional email, Google for sign-in and destination reputation checks, and Cloudflare for progressive anti-automation challenges. Providers process only the information needed for their service and security role.

5. Retention

  • Redirect access events: 30 days.
  • Rate-limit HMAC windows and full user agents: up to seven days.
  • Management audit events: 400 days unless a legal hold applies.
  • Deleted destination and private link name: removed after the 30-day restore window.
  • Account profile data: removed after the 30-day deletion cancellation window unless legal or security retention applies.
  • Public identifier tombstones and minimal de-identified ownership or policy evidence: retained to prevent address reuse and stale-link takeover.

6. Your choices

You can edit workspace and link information, revoke sessions, disable or delete links, and request account deletion through Street. Some retained tombstone, security, audit, or legal-hold evidence cannot be removed because it protects public-address integrity and the service.

For an access, correction, or deletion question, use the support page. Street may ask you to verify your identity before acting on a request.

7. Contact

Privacy questions can be sent to jerrydblount@gmail.com. Do not include passwords, authentication tokens, or private destination query values in email.

Street Release 1 · controlled short links

TermsPrivacySupport