Privacy
What Kurz does with your data
This describes what the software on kurz.fyi actually does. Last updated 6 October 2026.
Who runs this
kurz.fyi is a public demo of the open source Kurz project, run by its maintainer. Questions, access and deletion requests: [email protected]. Anyone who self-hosts Kurz is responsible for their own copy.
What is collected, and from whom
If you have an account: your email address; a password only if you set one (stored hashed, never readable); your Google account id and email if you sign in with Google; and what you create: short links, bio pages, forms, the responses and images they receive, saved templates and palettes, and the apps you connect. A session cookie (kurz_session, not readable by scripts) keeps you signed in. There are no advertising or analytics cookies and no tracking scripts.
If you open a short link or click a link on a bio page: the owner of the link sees statistics about the click. We record the IP address, your browser string and the page you came from, plus country and region (provided by Cloudflare) and the browser and platform derived from them.
If you answer a form: what you type and the images you choose, which only the form owner can see, plus country, browser, platform and the kind of site you came from. Your IP address is not stored. Images are converted and kept in private storage. The owner of the form decides what to ask and is responsible for how they use the answers, so do not enter passwords or card numbers in a form.
If you book an appointment through a form: your name, email address, the service, the dates and times you choose, and anything you type in the form (for example a phone number or a note). Only the owner of the form can see it. The owner decides how to use it and is responsible for it, so do not enter sensitive information in a note. Your IP address is not stored. Bookings are kept until the owner deletes them or deletes their account; ask the owner, or write to us, if you want yours removed. If you give your email, you can follow, cancel or confirm your booking from links in the emails.
Booking owners
If you use Kurz to take bookings, you are the one responsible for your customers’ data. Tell them what you collect and why, answer their requests, and do not use Kurz for anything that needs guarantees of delivery or availability. See how this service works.
The calendar feed, if you turn it on, is a secret address: anyone who has it can read the names and times of your confirmed bookings. You can replace or revoke it from your account page at any time.
Who else receives data
- Cloudflare (free plan) provides the domain name (DNS), passes visits through to the site and runs a bot check on sign-in and on forms, so it sees your IP address and browser details.
- Resend sends emails, including sign-in codes and booking messages (confirmations, requests, reminders, waiting list notices), so it receives the recipient’s email address and the message text. Sending is limited per day and per month; when the limit is reached, booking emails are delayed or not sent, and the same information stays available inside Kurz.
- Browser push services (for example Google, Mozilla or Apple) deliver push notifications if you turn them on. They receive your device’s push address and an encrypted message, and they can see that a message was sent and when. Messages never contain your customers’ names or contact details.
- Google receives the destination URL of links to check them with Safe Browsing, and your sign-in details if you choose Sign in with Google.
- Sentry receives error reports with request bodies, cookies, IP addresses and what people typed removed.
- AI apps you connect (for example Claude or ChatGPT) receive what you allow on the consent screen. If you allow reading responses, what respondents typed is sent to that service. You can disconnect any app from your account page.
We do not sell data and do not use it for advertising.
How long it is kept
| IP address, browser string (user agent) and referring page of a click | 90 days, then erased |
| Country, region, browser and platform of a click | Kept, as statistics without an identity |
| Calls made by connected AI apps (tool name, result, time, never the content) | 90 days |
| Your account, links, bio pages, forms and responses | Until you delete the account, then 30 days offline before permanent deletion |
| Sign-in codes | 15 minutes |
| Bookings (name, email, phone, note, dates) | Until the owner deletes them or the account is deleted |
| Notifications inside Kurz | 90 days |
| Booking emails queued but not sent | Up to 24 hours, then dropped |
| Push subscriptions (browser address and keys) | Until you remove the device or the browser invalidates it |
Your choices
- Get a copy: Account, Email me my data (a JSON file sent to your address), and Export on a form’s responses page (Excel or CSV).
- Delete everything: Account, Delete account. Your content goes offline at once and is permanently deleted after 30 days; signing in again before then cancels it.
- Correct or remove items: edit or delete links, pages, forms and responses from the dashboard at any time.
- Other requests, or if you answered a form or clicked a link and want something removed: write to [email protected]. You can also complain to your data protection authority.
Changes
When what Kurz collects changes, this page changes with it, and the history is public in the project’s repository.