Trim.pageTrim.page

Privacy Policy

Effective date: 2026-09-12

trim.page (the "Service") complies with Korea's Personal Information Protection Act and other applicable law, and processes personal information as described below. The Service is currently in beta.

1. Personal information collected

Pursuant to Article 30(1) of the Personal Information Protection Act (§30(1)), the Service collects the following. (1) Members: the email address, name, and profile image provided via Google login. (2) Links and preview card content registered by members (destination URL, title, description, image, and any edited image uploaded). (3) Usage records, access logs, cookies, and IP address. (4) Non-member reporters: the reply email address typed into the report form (optional — without it we cannot send you the outcome), the report reason and details, and a reporter fingerprint used to tell whether the same person filed repeatedly (derived from the IP address and browser type at the time of the report; the raw IP address is not stored). Reporters are data subjects distinct from members, so these items are never included in a member's data download. (5) Collected automatically when a short link is clicked: the target link identifier (alias), the share channel, the referring site host, the country of access, the event type (redirect or crawler card impression), and the audience type (human, social crawler, or search crawler). Click analytics does not store the IP address and contains no personally identifying value. (6) Collected when a screen in the app fails to render, so that the operator learns of it: the app surface, the screen path where the error occurred (the server strips any query string), a short error summary, a stack fingerprint used to group identical errors, and the browser type (User-Agent). Error reports are not stored in a database; they are used only for operational logs and operator alerts, and never contain user email addresses, destination URLs, or authentication tokens. (7) When a blocked account withdraws: an identity hash used to tell whether the same login later signs up again (an HMAC of the sign-up email address keyed with a server secret; the raw address is not stored and cannot be recovered from the hash). This is the minimum record needed to enforce our repeat-infringer account termination policy, and it is not created when an account that was not blocked withdraws. (8) API key usage counters: the key identifier, the name of the tool called, the UTC date, and the number of calls that day. Request bodies and destination URLs are not included. (9) When a member withdraws and had created at least one link that month: an identity hash (an HMAC of the sign-up email address keyed with a server secret; the raw address is not stored and cannot be recovered from the hash), the month in question, and the number of links created that month, used to carry the free monthly creation limit over if the same login signs up again within the same month. This is the minimum record needed to stop repeated withdrawal and re-registration from resetting the free limit, and it is not created when no link was made that month.

2. Purpose of processing

Collected personal information is processed only for member identification and authentication, providing the Service (creating links, editing previews), preventing fraudulent use, handling reports, and compiling statistics to improve the Service.

3. Retention period

Personal information is retained until the purpose of collection is achieved or the member withdraws, except where applicable law requires a different retention period, in which case it is retained for that period and then destroyed. Safety, enforcement, and operational records are deleted on a regular schedule once the following periods have elapsed: link reports after 180 days, link status change history after 730 days, account status change history after 730 days, unverified domain ownership tokens after 30 days, administrator access records after 730 days, notification delivery records after 365 days, withdrawn (anonymised) accounts after 30 days, blocked identity hashes after 730 days, and monthly create counts carried across withdrawal after 62 days. When a member withdraws, the following happens immediately: uploaded edited images and domain ownership records are deleted outright, API keys are revoked immediately and can no longer authenticate anything, links and cards are taken private immediately, so an address already shared no longer opens and they appear on no read path in the Service, and account details (email, name, profile image) are anonymised immediately. Remaining data - the anonymised account row, the privatised link and card rows, and the revoked API key rows - is removed entirely once the retention period above (30 days) has elapsed. That final removal is not yet on an automatic schedule: it is carried out in the operator's periodic purge, and we will update this sentence when an automatic schedule is added. One exception: a short address (alias) that has already been issued is never re-issued to another user even after deletion — this prevents an address already shared with the world from one day pointing somewhere else, and the retained record holds no personally identifying information. Only when a blocked account withdraws, a single identity hash is kept separately for the period above; that record contains no raw email address and the address cannot be recovered from it. Click analytics data is retained under Cloudflare Analytics Engine's retention policy and contains no personally identifying information.

4. Destruction of personal information

When personal information becomes unnecessary — for example, because the retention period has elapsed or the purpose of processing has been achieved — the Service destroys it without delay. Destruction is carried out by deleting the corresponding rows in the managed cloud database (Cloudflare D1) and the corresponding objects in object storage (Cloudflare R2); deleted data is no longer served through any of the Service's read paths. Because the physical storage media are operated by our processor (Cloudflare), the Service does not itself perform media-level destruction such as low-level formatting. Personal information printed on paper is destroyed by shredding or incineration. Where other laws require continued retention, the relevant personal information is moved to a separate database or otherwise stored apart from other information until the retention period expires, after which it is destroyed.

5. Third-party disclosure and outsourced processing

The Service does not disclose users' personal information externally as a general rule. To operate the Service's infrastructure, processing is outsourced as follows. (1) Cloudflare, Inc. — content delivery (Pages), D1/KV/R2 storage, Cloudflare Analytics Engine (click statistics), bot verification (Turnstile: when the report form is submitted, the visitor's IP address and browser type are sent to Cloudflare), and email delivery (Cloudflare Email Service: this is not yet enabled, so no notification emails are sent today. Once it is enabled and link review or block notices are sent to a member's sign-up email address, the recipient address and the notice body will be transmitted, and this policy will be updated at that time). (2) Google LLC — sign-in authentication (Google OAuth: we receive the email address, name, and profile image) and destination safety lookups (Google Web Risk: the destination URL entered by the user is transmitted for a reputation lookup; that URL may be a private document address the user created). (3) Slack Technologies, LLC — delivery of operator alerts (only the link identifier, alias, status, and reason, plus the app surface, screen path, error summary, and stack fingerprint of app error reports, are sent; user email addresses and destination URLs are never included). Given the nature of this outsourcing, personal information may be transferred overseas.

6. Overseas transfer of personal information

In accordance with the Personal Information Protection Act, the Service discloses overseas transfers in the order recipient, items transferred, destination country, purpose, method, and retention period. (1) Recipient: Cloudflare, Inc. (contact: privacy@cloudflare.com) / Items: access logs and IP address, the links, cards, and uploaded images a user stores, click analytics data (alias, share channel, referring site host, country of access, event type, audience type), the visitor's IP address and browser type during bot verification (Turnstile), and the recipient address and body of notification emails (email delivery is not yet enabled; this applies from the moment it is) / Destination: the United States and other countries where Cloudflare's global network is located / Purpose: operating CDN, storage, Cloudflare Analytics Engine (click statistics), bot verification (Turnstile), and email delivery (Cloudflare Email Service, once enabled) infrastructure / Method: transmission over the network / Retention: until the outsourcing agreement ends or the purpose is achieved. (2) Recipient: Google LLC (contact: https://policies.google.com/privacy) / Items: the email address, name, and profile image at sign-in, and the destination URL submitted for a safety lookup / Destination: the United States / Purpose: sign-in authentication (Google OAuth) and reputation lookups that block phishing or malicious destinations (Google Web Risk) / Method: transmission over the network (HTTPS) / Retention: until each service's processing purpose is achieved. (3) Recipient: Slack Technologies, LLC (contact: privacy@slack.com) / Items: operator alert bodies (link identifier, alias, link status, status change reason, background task failure class, and the app surface, screen path, error summary, and stack fingerprint of app error reports) / Destination: the United States / Purpose: notifying the operator of reports, blocks, outages, and app errors / Method: transmission over the network (HTTPS webhook) / Retention: per the alert channel's message retention policy.

7. Installation, operation, and refusal of cookies and other automatic data-collection tools

The Service uses only the minimum cookies required to keep you signed in and to protect the sign-in flow. We do not use advertising, tracking, or behavioural-analytics cookies, and we do not share cookies with third-party ad networks. Three cookies are actually used. (1) tp-auth-token: the login session token. It is set with the HttpOnly attribute, so browser scripts cannot read its value; it is sent only to our server (valid for 24 hours). (2) tp-session-hint: a display-only cookie holding nothing but the session expiry time (a number of seconds). It carries no personal data and no token value, and is used solely so the app can show your sign-in state immediately. (3) tp-oauth-state: a single-use temporary cookie that prevents forgery (CSRF) of the Google sign-in flow; it expires within 10 minutes. Users may allow or refuse cookies through their web browser settings; if cookies are refused, features that require sign-in cannot be used. To manage cookies, use the privacy or security settings menu of the browser you are using to block or delete cookies.

8. Rights of data subjects

Users may at any time request to view, correct, delete, or suspend processing of their personal information. Viewing and deletion can be exercised directly in the app: the account menu at the top right offers "Download my data", which immediately downloads a JSON file containing your profile, the links and cards you created, your domain ownership list, API key details (excluding the key value and its hash), this month's usage, and your account and link status change history; the same menu offers "Delete account", which immediately deletes your uploaded images and domain ownership records, immediately revokes your API keys, immediately takes your links and cards private so an address already shared no longer opens, and immediately anonymises your account (the remaining rows are removed entirely on the retention schedule in section 3). The download does not include: click analytics data (it contains no personally identifying value and there is no per-person read path), a non-member reporter's reply email, report contents, or fingerprint (these belong to another data subject), the hash of an API key (an authentication credential), or the email address of the administrator who took an action. The links and status change history in the download file are capped so that the response cannot grow without bound; when a cap is reached, the file marks that section as truncated. If you need history beyond the cap, ask us at the address below. For correction, suspension of processing, and any other request, contact abuse@trim.page.

9. Remedies for infringement of data subject rights

Users may apply for dispute resolution or consultation regarding infringement of their rights to the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Center, and other relevant bodies. For other reports of, or inquiries about, personal information infringement, contact the following organizations. Personal Information Dispute Mediation Committee: 1833-6972, no area code (www.kopico.go.kr). Personal Information Infringement Report Center: 118, no area code (privacy.kisa.or.kr). Supreme Prosecutors' Office Cyber Investigation Division: 1301, no area code (www.spo.go.kr). National Police Agency Cyber Investigation Bureau: 182, no area code (ecrm.cyber.go.kr).

10. Security measures

The Service takes the following technical and administrative measures to safeguard personal information. (1) Access restriction: administrative functions can only be used by a signed-in session belonging to a pre-registered administrator list. (2) Retention of access logs: every administrator API call records the calling administrator's email address, the request method, the request path (query string excluded), the target identifier, the authorisation outcome (granted or denied), and the timestamp in the administrator access log table (admin_audit_log), kept for the retention period stated above. (3) Encryption: all traffic is protected with HTTPS, and API keys are stored only as hashes, never in plaintext. (4) Session protection: the sign-in session token is delivered only in an HttpOnly cookie so browser scripts cannot read it, and state-changing requests are checked against the request Origin.

11. Personal information protection officer

Contact for personal information inquiries and complaints: abuse@trim.page. This is a beta service operated by an independent developer; the business name and registration number will be published here once the service is registered. The name and title of the personal information protection officer will be disclosed at the same time; until then, every inquiry is handled directly at abuse@trim.page.

12. Revision history

This policy has been revised as follows. 2026-08-19: first published. 2026-09-12: updated to match the actual data flows — the collected items now cover non-member reporter details and API key usage counters; the outsourcing and overseas transfer disclosures now name Google LLC (sign-in authentication and destination safety lookups) and Cloudflare's bot verification and email delivery; the retention periods now include administrator access records, notification delivery records, and withdrawn accounts; and the data subject rights section now names the in-app "Download my data" and "Delete account" paths. On the same date, the identity hash used to match a blocked account that signs up again was added to the collected items and retention periods, and email notification was marked as not yet enabled. Also on that date, sections 3 and 8 were rewritten to state what withdrawal actually does - separating the items deleted, revoked, or taken private immediately from the remaining data removed once the retention period elapses, and disclosing that this final removal happens in the operator's periodic purge rather than on an automatic schedule - and the carry-over record that stops withdrawal and re-registration from resetting the free monthly creation limit was added to the collected items and retention periods. The blocked-identity record also dropped the free-text block reason, keeping only the matching hash and the timestamp, and owner notification emails and "Download my data" now carry the reason code instead of the free-text reason. If a revision is unfavourable to users, we announce it in the app and on this page at least seven days before it takes effect.

Report a link →
Terms of ServicePrivacy PolicyAcceptable Use PolicyReport a linkOpen source licenses