Privacy policy
How artissavvy.kr and cut.pe.kr handle your information.
Effective 2026-08-01
Effective date: 1 August 2026
This policy covers the website artissavvy.kr and the short-link domain cut.pe.kr.
The Android apps published by Artissavvy have their own separate privacy policies. They do not communicate with this site's servers. You can find each app's policy on its page.
1. Nothing is collected while you read
App pages, documentation, privacy policies, and the support page are readable without signing in. The site uses no analytics and no advertising SDK, and does not retain access logs as personal data. There are no tracking cookies.
The KakaoPay QR on the support page is drawn by this site. No image is loaded from Kakao or anywhere else, so simply viewing the page sends them nothing. Once you scan it or follow a button through to KakaoPay or PayPal, their policies apply.
There are, however, records kept without an account. The IP address of the request is recorded when you attempt to sign up, when you request a password reset, and when a sign-in fails.
The first two send an email, so repeating them could be used to fill someone else's inbox; the record exists to count attempts. Failed sign-ins are recorded to stop people trying passwords against other people's accounts — as failures pile up, the wait from that address grows (up to 24 hours) and clears once the attempts stop. A successful sign-in erases that account's failures.
Unsuccessful attempts are counted too — otherwise the limit could be worn down by simply retrying.
An address that keeps at it can be blocked by an administrator. In that case the address, the reason, and any end date are kept.
These records do not include the email address used, and are deleted automatically after 3 days.
2. What an account requires
An account is needed only for short links. This is everything that is asked for:
| Item | Purpose |
|---|---|
| Email address | Sign-in identity, verification email |
| Password | Sign-in verification (see section 4) |
No name, phone number, date of birth, or address is collected.
3. What accumulates as you use the service
- Short links: destination URL, code, note, creation time, expiry time
- Click count and last-clicked time: one number and one timestamp per link
- A record of link creation: to stop spam and bulk creation, each new link briefly records the account, the IP address used, and the destination site name. These are deleted automatically after 3 days. Deleting your account does not remove them early — otherwise the limits could be reset by deleting and re-creating an account
- URL check results: so the same address is not sent out repeatedly, results are remembered for a while. What is stored is an irreversible form of the address, the site name, and the verdict — not the address itself
- Sign-in sessions: each sign-in creates a session on the server. What it holds is when it was created and when it expires; signing out or resetting your password removes it. No device information or location is kept
- Password reset requests: a temporary value and an expiry time are stored on the account, and become void once used or expired
For visitors who follow a short link, no IP address, browser information, or referrer is collected. Who clicked is not recorded — only how many times, and when it was last opened.
4. Passwords are stored so they cannot be reversed
Passwords are never stored as written. Each account gets its own random value mixed in, and only the output of a well-established one-way function is kept.
One-way means there is no method to recover the original password from what is stored. The developer cannot see your password and cannot tell it to you. Changing your password replaces the stored value; the old one does not remain.
5. Two-factor information
If you enable two-factor authentication, the secret shared with your authenticator app is stored. Verifying codes requires that value, so it cannot be handled one-way like a password. It is kept encrypted instead, is never included in any API response, and is not visible in the admin screen.
The one-time recovery codes issued alongside it are stored only in a form that cannot be reversed. They cannot be viewed again after the screen that shows them, and each works once.
6. Cookies
Signed-in users get one session cookie. It keeps you signed in and is not used for advertising or analytics. The server keeps only that session's timestamps alongside it (section 3).
- Not readable from JavaScript
- Sent only over an encrypted connection
- Limited on cross-site requests
- Expires automatically after a period of inactivity
Signing out removes it.
7. Third parties
Personal data is never sold or shared for advertising. These are used only as the service requires:
| Party | What is sent | Purpose |
|---|---|---|
| Recipient address and message body | Verification and password-reset email | |
| Google Safe Browsing | The destination URL being shortened | Checking for malware and phishing |
| Cloudflare | Domain name lookups | Domain name resolution |
URL checking happens when a link is created or its destination changed. The address is sent to Google at that point. No account details and nothing about who created it is sent with it. Results for the same address are remembered briefly so it is not asked repeatedly.
8. Where data is kept, and for how long
Data is stored within the Republic of Korea. It is not transferred abroad or replicated to external cloud services.
- Accounts and links: kept until the account is deleted
- Deleting an account also deletes its short links, which then stop resolving
- Email addresses of closed accounts: the address alone is kept for 30 days so the same address cannot immediately sign up again, then deleted automatically
- Email addresses of accounts removed for misuse: the address and the reason are kept to prevent re-registration. Get in touch and we will look into it
9. Your choices
At any time you can:
- View your account details and links — Dashboard
- Edit, disable, or delete links — Dashboard
- Enable or disable two-factor authentication — Dashboard › Security
- Change your password — "Forgot your password?" on the sign-in screen. Setting a new one signs you out on every other device
- Delete your account — Dashboard › Account, whenever you like
10. Acceptable use
Short links may not be used for illegal content, phishing, spam, or malware. If we find such use, links may be disabled and the account deleted without prior notice, and we will report it to the authorities where required.
11. Changes
If this policy changes, the effective date at the top is updated.
12. Contact
- Developer: Artissavvy
- Email: artissavvy.dev@gmail.com