What Linkora stores when someone clicks
Owners want to know whether a link was used. They do not need a dossier on every visitor. The click row is limited on purpose.
Stored for a click
- The link id and the time.
- Whether the request looked human, like a known bot, like a prefetch, or like an automated client.
- The referrer host only. The path and query of the referring page are discarded because they often contain tokens.
- A truncated user agent, used for the bot check and then kept so the classification can be audited.
- An HMAC of the IP address when IP storage is set to hash. The raw address is not written to the database.
There is no canvas fingerprint, no third-party analytics cookie, and no advertising tag on the redirect. The dashboard headline uses human clicks. Bot, prefetch, and automated requests are visible as a separate count so a monitoring probe does not look like an audience.
How long it stays
The IP hash has its own retention timestamp, set from the active configuration when the click is recorded (30 days in a default install). A scheduled retention job clears the hash when that time passes. Click rows themselves are deleted after the configured click retention. Turning IP storage off means new clicks store no hash at all. An owner can also ask for the hashes on their links to be cleared immediately from the account page.
What you can take with you
A signed-in user can export JSON of the account, links, and click metadata. The export omits password hashes, multi-factor secrets, and IP hashes. Deleting the account anonymizes the email and password immediately. Destinations of deleted links are cleared later by the retention job unless a legal hold or an open abuse report applies.