
Short.io
Short.io turns long URLs into branded short links on your own domain, with real-time click analytics, dynamic QR codes and a REST API. A permanent free plan covers 1,000 branded links without a credit card.
What is Short.io?
Short.io is a white-label link shortener operated by Short.cm Inc, a Delaware corporation. Instead of publishing a generic short link, you point your own domain at the service and every shortened URL carries your brand; a free s.gy subdomain is available if you would rather not bring a domain. The company reports 13 billion links created, 100 billion clicks tracked, 1.2 million active users and coverage in more than 180 countries, from a fully distributed team of twelve people across four countries.
The product organises itself around six pillars. Analytics record a real-time click stream with more than thirty data points per click, broken down by device, browser, referrer and geography down to city level. Custom domains come with free automated SSL from Let's Encrypt; you can connect an existing domain by DNS, buy one inside the app from 7 USD a year, or start on the free subdomain. QR codes are dynamic, so a printed code can be repointed later without reprinting, and they export to PNG, SVG and PDF with custom colours and logos. API access exposes more than fifteen REST endpoints, official JavaScript, Node.js, iOS and Android SDKs, bulk operations and webhooks, serving around five million calls a day. Link management adds folders, tags, search, CSV bulk editing and a UTM builder. Team collaboration brings Admin, User and Read-only roles, shared analytics and SAML 2.0 single sign-on on the upper tiers.
Several features are AI-assisted: slug generation, an in-product assistant, and AI QR codes that Google's Gemini models repaint as artwork while keeping them scannable. Each plan carries a monthly AI usage allowance, from 1 to 100 USD.
Link-level controls include password protection, expiration, click limits, cloaking, referrer hiding and encrypted links. The infrastructure runs on AWS with six points of presence, a 99.9% uptime SLA and peak capacity above 200,000 redirects per second. Short.io holds ISO 27001 certification and SOC 2 Type II compliance, and publishes a trust centre.
What it does
- Create branded short links on your own custom domain, with free automated SSL
- Track clicks in real time by country, city, device, browser and referrer
- Generate dynamic QR codes whose destination can be changed without reprinting
- Create, edit and manage links programmatically through a REST API and official SDKs
- Route visitors by country, region, city or operating system, including mobile deep links
- Run A/B tests and build UTM-tagged campaign links
- Work as a team with roles, shared folders and SAML single sign-on
When to use Short.io / When not to
A quick filter to help you decide if Short.io is the right fit.
When to use Short.io
- Marketing teams running multi-channel campaigns who need UTM tagging, A/B tests and click attribution in one place
- Agencies managing several clients, since each account can carry its own branded domain and separate analytics
- Developers and engineering teams integrating link creation into their own products through the REST API and SDKs
- Bloggers, affiliate marketers and freelancers who want readable, on-brand links on the permanent free plan
- Regulated organisations in finance, healthcare or the public sector that require ISO 27001, SOC 2 Type II, a DPA or a HIPAA BAA
When not to use Short.io
- Organisations whose procurement requires a verifiable registered office, as no postal address is published anywhere on the site
- Compliance teams that must document whether customer data feeds AI model training, a question the site never answers
- Small teams on a tight budget who need several seats, because multi-user access only starts on the 48 USD/month Team plan
- Anyone under 18, since the terms require legal majority to open an account
- Users in Cuba, Iran, North Korea or the Crimea, Donetsk and Luhansk regions, which the sanctions clause excludes
How to use Short.io
A typical end-to-end flow, from setup to results.
- Paste a long URL into the shortening field on the home page to get an instant .s.gy link, no account needed
- Create a free account - no credit card is requested
- Choose your domain strategy: keep the free s.gy subdomain, buy a domain inside the app from 7 USD a year, or connect a domain you already own
- If you connect your own domain, apply the DNS settings from the setup guide and let the free SSL certificate issue automatically
- Create your first branded links, giving them custom slugs, tags and folders
- Add UTM parameters with the built-in builder so campaigns report correctly in your analytics
- Import or bulk-create links from CSV, or automate creation through the REST API and SDKs
- Install the Chrome, Firefox or Edge extension, or use the '/shorten' Slack command, to shorten from anywhere
- Connect analytics and marketing tools such as Google Analytics, Google Tag Manager, Meta Pixel or AdRoll
- Invite teammates with Admin, User or Read-only roles, and configure SAML single sign-on on the higher plans
Pros & Cons
Pros
- A genuinely usable permanent free plan: 1,000 branded links, five custom domains, 50,000 tracked clicks a month and API access
- Custom domains are available from the free tier upward, with automatic SSL at no cost
- Strong security posture: ISO 27001 certified, SOC 2 Type II compliant, with a public trust centre and annual third-party audits
- Compliance paperwork is available rather than promised: standard DPA, SCCs, UK IDTA and a HIPAA BAA
- The subprocessor list is published in full, naming each vendor, its purpose and the data shared
- A mature API with official SDKs across four platforms, handling around five million calls a day
- An established, profitable vendor with more than a decade on the market and no dependence on outside funding
Cons
- No postal address is published anywhere on the site, in any of the usual legal locations
- The company's own founding year is inconsistent across its pages, and no verifiable incorporation date exists
- The site never states whether customer data is used to train AI models, although prompts reach three separate AI providers
- No Article 27 EU representative is designated, despite the claim of GDPR compliance
- No documented way to exclude your data from AI training
- Free, Hobby and Pro plans include a single user; team access only begins at 48 USD a month
- Prices are absent from the main pricing cards, which render in JavaScript, and appear only in the comparison table
Pricing & Plans
Short.io offers a permanent free plan, not merely a time-limited trial: it includes 1,000 branded links, five custom domains and 50,000 tracked clicks per month, and requires no credit card. The lowest paid entry point is the Hobby plan at 5.00 USD per month. Paid tiers rise to 18 USD for Pro, 48 USD for Team and 148 USD for Enterprise, all quoted monthly. Annual billing is advertised as saving 17%, a seven-day free trial is offered on the paid plans, and prices can be displayed in nineteen currencies.
- 1 user
- 5 custom domains
- 1
- 000 branded links
- 1
- 000 link automations
- 50
- 000 tracked clicks/month
- 1 user
- 7 custom domains
- 2
- 500 branded links
- 100
- 000 tracked clicks/month
- 200 conversions/month
- 100 MB storage
- 1 user
- 10 custom domains
- unlimited branded links and tracked clicks
- 10
- 000 automations/year
- 1 GB storage
- 14 USD/month AI allowance
- adds password protection
- unlimited users
- 50 custom domains
- 100
- 000 automations/year
- 10 GB storage
- 35 USD/month AI allowance
- adds city and region targeting
- mobile deep links
- unlimited custom domains and automations
- 200 GB storage
- 100 USD/month AI allowance
- adds multiple teams
- SAML single sign-on
- raw data export to S3 and a dedicated IP
- additional API capacity at 50 USD/month per 50 requests per second
- and in-app domain purchase from 7 USD/year
Data, GDPR & hosting
A consolidated view of how Short.io handles your data.
GDPR overview
GDPR coverage is concrete and documented. The policy page is titled "Privacy Policy and GDPR", was last updated in August 2026, and claims compliance with the GDPR, CCPA and other international regimes. It lists the six data subject rights - access, rectification, erasure, restriction, portability and objection - with a stated 30-day response window and a dedicated contact at privacy@short.io. Legal bases are named: contract, legitimate interest, consent and legal obligation. Transfers out of the EEA rely on the European Commission's Standard Contractual Clauses, and UK transfers on the IDTA or UK Addendum. A standard DPA is available, a full subprocessor table is published, and a HIPAA BAA can be executed. One gap stands out: no Article 27 EU representative is designated anywhere on the site.
Who owns the data?
The privacy policy states plainly that Short.cm Inc does not sell personal data. The company collects account details, the links you create, click statistics, the prompts you submit to its AI features, technical identifiers and billing data. You keep the right to access, correct, export and erase that data, and you can delete your account from the dashboard at any time. Intellectual property in the service itself stays with the vendor. One clause deserves attention: any feedback or feature request you send becomes non-proprietary and non-confidential, granting the company a perpetual, worldwide, irrevocable and royalty-free licence to use it without compensation.
Reuse rights
Your links, analytics and exports remain yours to reuse freely: Short.io places no restriction on what you do with the click data you generate, and it can be exported as CSV, JSON or raw S3 feeds on the higher plans. The vendor's own reuse is bounded by stated purposes: running and improving the service, processing payments, powering AI-assisted features, fighting fraud and meeting legal obligations. Prompts sent to the AI features travel to third-party providers to produce a response, and destination URLs are shared with security vendors for malware and phishing checks. Note that AI-generated QR artwork is served from a public URL so it stays scannable. What you may not do is resell, sublicense or redistribute the service itself.
Data retention & training
Hosting summary
Short.io's US and global service runs on Amazon Web Services in the United States, which places the data under US jurisdiction. A standby disaster-recovery cluster is maintained with Hivelocity in Dallas, Texas, so the service can be restored if the primary region fails. Replicas sent there are encrypted at rest and the network links carrying them are encrypted in transit; the disk-encryption keys stay sealed in each server's firmware TPM and are never shared with Hivelocity, so its staff cannot read the stored data. Redirect traffic is served from six points of presence - North Virginia, Frankfurt, Milan, Sao Paulo, Seoul and Bangkok - in an active-active multi-region setup with sub-30-second failover. Data is encrypted with AES-256 at rest and TLS 1.2 or above in transit. Recovery objectives are stated as under one hour for RPO and under four hours for RTO. Transfers out of the EEA rely on Standard Contractual Clauses.
Where Short.io works
Country-level availability.
Not available in
Things to keep in mind
Risks and trade-offs to weigh before adopting Short.io.
- AI-generated QR artwork is served from a public URL so that it stays scannable, which means the prompt you wrote and the link it encodes are not private
- Destination URLs of the links you create are shared with Google Web Risk, SURBL and Netcraft for malware and phishing checks
- The vendor takes no published position on whether your data trains AI models, and offers no documented opt-out, while three AI providers receive your prompts
- Feedback and feature requests you submit become non-proprietary, granting the company a perpetual, worldwide, royalty-free licence with no compensation
- Phone verification routes your number through Meta's WhatsApp, Telegram or Twilio depending on your country
- Links created on the free s.gy domain sit on infrastructure the vendor owns, with usage rights limited to the test period, so treat them as disposable rather than permanent
- Liability is capped at twice the fees paid over twelve months and disputes fall under Delaware law, which may be remote for non-US customers
Setup & Integrations
Technical difficulty
Very low to moderate, depending on how far you go. Shortening a link on the home page needs no account at all, and signing up requires no credit card. Using the free s.gy subdomain or buying a domain inside the app involves no configuration whatsoever. Connecting a domain you already own is the only step needing technical work: you apply DNS records from a setup guide, and SSL is then issued automatically. Automation through the API or SDKs assumes developer skills, and SAML single sign-on requires configuration on your identity provider.
Deployment
Apps stores
Integrations
Supported languages
Behind Short.io
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Is there a free plan, or only a trial?
Can I use my own domain on the free plan?
What analytics does Short.io provide?
Is there an API?
What security certifications does Short.io hold?
Can Short.io sign a DPA or a HIPAA BAA?
Where is my data hosted?
Does Short.io use my data to train AI models?
How long is my data kept?
Is there a minimum age?
Should you pick Short.io?
Short.io is a mature, unusually well-documented link shortener. A decade on the market, profitable since 2019 and reporting 13 billion links created, it is not a project at risk of disappearing. Its free plan is genuinely useful rather than decorative, since custom domains and API access are included from the first tier, and its compliance package - ISO 27001, SOC 2 Type II, a standard DPA, a HIPAA BAA and a fully published subprocessor list - is stronger than most tools of this size offer.
The reservations are about transparency rather than capability. The company publishes no postal address anywhere on its site, and its own pages disagree on the year it was founded, so no verifiable incorporation date exists. More consequential for anyone running a data protection review: although prompts, link content and destination URLs pass through OpenAI, Google Gemini and AWS Bedrock, the site never states whether customer data is used to train models, and documents no way to opt out. No Article 27 EU representative is designated either, which sits awkwardly beside an explicit GDPR compliance claim.
Pricing is fair but the shape matters: Free, Hobby and Pro each include a single user, so any genuine team collaboration starts at 48 USD a month. For an individual creator, an affiliate marketer or a developer wiring links into a product, the free and low tiers are excellent value. For a regulated organisation, the certifications will satisfy security review while the AI-training silence and the missing legal identity are the two questions worth putting to the vendor in writing before signing.
- Choosing a selection results in a full page refresh.
- Opens in a new window.