Privacy Policy
Last updated: March 30, 2026
This Privacy Policy explains how Fishball App (“we”, “us”, “our”) collects, uses, and protects your personal data when you use the dynm.link service (“Service”). It applies to both registered users and visitors who interact with links created through the Service.
1. Data Controller
Fishball App is the data controller for personal data processed through the Service.
Contact: privacy@dynm.link
2. What Data We Collect
2.1 Account Data (registered users)
When you create an account, we collect:
- Email address: Used for authentication and account notifications.
- Name and username: Chosen by you during setup. Your username determines your subdomain (e.g.
yourname.dynm.link).
We do not collect passwords. Authentication is handled through email-based magic links or third-party sign-in providers (Google and GitHub). When you sign in with a third-party provider, we receive your email address and display name from that provider. We do not receive or store your provider password.
2.2 Microlink Data
When you create a microlink, we store:
- The content you provide (URLs, markdown text, bio page content, file metadata, text snippets).
- Metadata: title, description, thumbnail, slug, expiry date, creation and modification timestamps.
- For password-protected links (Pro): a cryptographic hash of the password. We never store passwords in plain text.
2.3 Uploaded Files
For file-type microlinks, we store the uploaded file in cloud storage (Cloudflare R2). We record the file name, MIME type, and file size. Files are permanently deleted when the associated microlink is deleted or your account is closed.
2.4 Click Analytics (Pro and Business tiers)
When someone clicks a microlink with analytics enabled, we collect:
- Timestamp of the click.
- Approximate geolocation: Country and city, derived from the visitor’s IP address.
- Device information: Device type (mobile, desktop, tablet), operating system, and browser.
- HTTP referrer: The page the visitor came from.
- Unique visitor hash: A one-way hash combining the IP address, user agent, and date, used to count unique visitors. We do not store raw IP addresses in analytics.
Click analytics data is retained for 90 days, after which it is automatically deleted.
2.5 Email Captures (Pro tier, Bio pages only)
If a microlink owner enables the email capture widget on a bio page, visitors who voluntarily submit their email address will have that email stored and associated with the microlink. This data is accessible only to the microlink owner.
2.6 Payment Data
Payment processing is handled by Stripe. We store your Stripe customer ID and subscription status. We do not store your card number, expiry date, or CVC. Stripe’s privacy policy governs the handling of your payment information.
2.7 Technical Data
When you use the Service (including visiting our website), we may process:
- Browser type and version.
- Device type and operating system.
- Pages visited and features used within the Service.
- Error logs and performance data.
3. How We Use Your Data
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Account data | Provide the Service, authenticate you, send transactional emails | Contract performance |
| Microlink data | Host and serve your microlinks | Contract performance |
| Uploaded files | Store and serve file downloads | Contract performance |
| Click analytics | Provide analytics dashboards to microlink owners | Legitimate interest of microlink owners in understanding their audience |
| Email captures | Provide captured emails to microlink owners | Consent of the visitor submitting their email |
| Payment data | Process subscriptions and billing | Contract performance |
| Technical data | Maintain, secure, and improve the Service | Legitimate interest in operating a reliable service |
We do not use your data for advertising. We do not sell your personal data to third parties.
4. Click Tracking and Non-User Privacy
When you click a dynm.link microlink, we may collect limited data about your visit (see Section 2.4) even if you do not have a dynm.link account.
Why we collect this data: To provide analytics to the microlink owner and to detect abuse (phishing, malware, spam).
Legal basis: Legitimate interest. We have assessed that the limited data collected (approximate location, device type, referrer) does not outweigh the privacy interests of visitors, particularly because:
- We do not store raw IP addresses in analytics records.
- We use one-way hashing for unique visitor counting that cannot be reversed to identify individuals.
- Analytics data is automatically deleted after 90 days.
- The data is not used for advertising, profiling, or cross-site tracking.
Your rights: If you are a visitor and wish to exercise your data protection rights, see Section 8.
5. Data Sharing and Sub-processors
We share personal data only with the following third-party services, each of which processes data on our behalf:
| Sub-processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Cloudflare | Infrastructure (hosting, CDN, database, file storage, DNS) | All service data | Global (Cloudflare network) |
| Authentication (OAuth sign-in) | Email address, display name (received from Google during sign-in) | United States | |
| GitHub | Authentication (OAuth sign-in) | Email address, display name (received from GitHub during sign-in) | United States |
| Stripe | Payment processing | Email, subscription details, payment information | United States, EU |
| Forward Email | Transactional email delivery (magic link sign-in) | Email address | United States |
We have data processing agreements in place with each sub-processor. We do not share your data with any other third parties unless required by law.
6. International Data Transfers
Your data may be processed in countries outside your country of residence, including the United States and other locations where Cloudflare operates.
For transfers of personal data outside the European Economic Area (EEA) or the United Kingdom, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions where applicable.
- Sub-processor compliance with equivalent data protection standards.
7. Data Retention
| Data | Retention Period |
|---|---|
| Account data | Until you delete your account |
| Microlink data | Until the microlink expires or is deleted, or your account is closed |
| Uploaded files | Until the associated microlink is deleted or your account is closed |
| Click analytics | 90 days from the click event |
| Email captures | Until the microlink owner deletes them or their account is closed |
| Payment records | As required by tax and financial regulations (typically 6 years) |
| Anonymous microlinks | 30 days from creation (then permanently deleted) |
When you delete your account, we permanently delete all your microlinks, uploaded files, analytics data, email captures, and associated content. This process is irreversible.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your data (“right to be forgotten”).
- Restriction: Request that we restrict processing of your data.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interest.
- Withdraw consent: Where processing is based on consent, withdraw it at any time.
Registered users: You can delete your account and all associated data through the Service at any time.
Link visitors (non-users): To exercise your rights regarding click analytics data, contact us at privacy@dynm.link. Note that because we do not store raw IP addresses, we may be unable to identify your specific records without additional information from you.
To exercise your rights: Contact us at privacy@dynm.link. We will respond within 30 days (or within the timeframe required by applicable law).
Complaints: If you believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner’s Office (ICO) at ico.org.uk.
9. Cookies and Tracking Technologies
The dynm.link dashboard uses token-based authentication (Bearer tokens stored in your browser’s local storage) rather than cookies for session management.
When you sign in with a third-party provider (Google or GitHub), a temporary session cookie is set on the API domain during the authentication redirect. This cookie is used once to complete the sign-in process and is not used for ongoing session management.
We do not use advertising cookies or third-party tracking scripts.
When you click a shortened link, no cookies are set on your browser by dynm.link.
10. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child under 16, please contact us at privacy@dynm.link and we will delete it promptly.
11. Security
We take reasonable measures to protect your data, including:
- Encrypted connections (HTTPS) for all communications.
- Cryptographic hashing for password-protected links and visitor deduplication.
- Token-based authentication with no plain-text credential storage.
- Cascading deletion of all associated data when accounts or microlinks are removed.
No system is perfectly secure. If you discover a security vulnerability, please report it to security@dynm.link.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.
13. Contact
For questions about this Privacy Policy or to exercise your data protection rights:
Email: privacy@dynm.link