Privacy
Last updated September 2026
Seenify tracks who opens a link. That means personal data, so here is exactly what is collected, who is responsible for it, how long it is kept, and how to get it removed. In plain English, not in small print.
This service is operated by Tara Barge. Questions, requests and complaints go to info@seenify.app, and we aim to answer within 30 days.
Two different roles
Which part of this policy applies to you depends on how you arrived here, because Seenify handles two separate kinds of data in two different capacities.
- Account holders. If you signed up, we decide what to collect about you and why. In data-protection terms we are the controller, and section one applies.
- People who opened a link. If someone sent you a Seenify link, they chose to track it and they decide what happens with the result. They are the controller; we only hold the data on their behalf, as their processor. Section two applies, and it matters because it changes who you ask for deletion.
1. If you have an account
What we hold
| Data | Why |
|---|---|
| Email address | It is your identity here. Sign-in links are sent to it, and it is the only way we can contact you. |
| Sign-in tokens | Stored only as a hash, single-use, expire in 20 minutes. |
| Session records | Keeps you signed in. The cookie holds a random value; we store only its hash. |
| Account timestamps | When you joined and last signed in, so dormant accounts can be identified. |
| Plan | Which plan you are on, so limits can be applied. |
| Your links | The destination URL, your private label and note for each one, and the codes. |
We do not ask for your name, your company, a phone number or a password, because the service does not need them. There is no analytics script, no advertising pixel and no third-party tracker anywhere on this site.
Our lawful basis
Holding your email and running your account is necessary to perform our contract with you — you asked for the service and this is what delivering it requires. We do not rely on consent for it, and we do not use your address for marketing unless you separately ask us to.
Deleting it
There is a Delete your account button at the bottom of your dashboard. It removes your account, your links, every open those links recorded and every email address collected at your gates. It is immediate, it cannot be undone, and your links stop resolving the moment you confirm. You do not need to email anyone or wait for us.
You can also delete any single link at any time, which takes its entire open history with it.
2. If you opened someone's link
The short version
The person who sent you the link decided to track it. To have your data removed, ask them — they can delete the link, which erases everything it recorded, including your email address. If you would rather not deal with them, write to info@seenify.app and we will act on it.
What gets recorded when you open a link
- The email address you typed, if the link asked for one. It is shown to the person who sent you the link. It is not added to any mailing list, sold, or shared with anyone else.
- A visitor fingerprint. Your IP address, browser user-agent and language are combined with a secret salt, hashed with SHA-256, and truncated. Only that short hash is stored. Your IP address is never written to our database and the hash cannot be reversed back into one. Its only job is to tell a repeat visit apart from a new one.
- Approximate location — city and country, derived by Cloudflare from the network your request came through. It is coarse and often wrong by some distance.
- Your browser, operating system and device type, and the raw user-agent string they were read from.
- The referring page, if your browser sent one.
- The time of each open, and whether our filters judged the request to be an automated scanner rather than a person.
Automated scanners
Corporate mail systems open every link in an email before it reaches the recipient. Those requests are recorded and flagged so they can be excluded from the counts the sender sees. They are machine traffic, not you.
The lawful basis for this
The sender determines this, not us, and for most it will be legitimate interests — knowing whether a document they sent was read. The email address you type is given voluntarily, with the page telling you before you type it what it is used for. If you object to any of it, the routes in the box above are open to you.
Your rights
If you are in the UK or EU you have the right to access the data held about you, to have it corrected or erased, to object to it being processed, and to complain to a supervisory authority — in the UK, the Information Commissioner's Office. We will pass any request to the sender where they are the controller, and act on it ourselves where we can.
Cookies
Two, both strictly necessary, neither used for advertising or shared with anyone.
| Cookie | What it does |
|---|---|
| dr_s | Keeps an account holder signed in. A random value, valid 30 days, cleared on sign-out. |
| dr_id | Set after you enter your email at a gate, so you are not asked again on the next link. It holds your own email address, signed so it cannot be forged. Valid one year; clearing your cookies removes it. |
Who else touches the data
- Cloudflare — hosting, the database, and the network your request travels over. Data is stored in Cloudflare's distributed infrastructure.
- Resend — delivers sign-in emails. They see the email address a sign-in link is sent to. Nothing about your links or their opens is sent to them.
That is the complete list. No analytics provider, no advertising network, no data broker, no AI training.
How long it is kept
Open records and gate emails live until the link or the account is deleted — there is no automatic expiry, because the sender may want the history of a raise that ran for months. Sign-in tokens are cleared within a day of expiring. Sessions are cleared when they expire or on sign-out. Deleting an account removes everything listed in this policy that belongs to it.
Security
Everything is served over HTTPS. Sign-in tokens and session identifiers are stored only as hashes, so a copy of the database could not be replayed as a sign-in. Raw IP addresses are never stored. Access to the production database is limited to the operator of the service.
No system is perfect. If you find a security problem, please tell us at info@seenify.app before telling anyone else, and we will work with you on it.
Changes
If this policy changes in a way that affects what is collected or who it is shared with, account holders will be emailed before it takes effect. Smaller corrections will just update the date at the top.
Contact
Tara Barge
info@seenify.app