Privacy
Last updated 4 October 2026
Who we are
enkelt.design (CVR 45871290), Lille Bygade 13, 2635 Ishøj, Denmark, runs ouicu and is the controller of the data below. Contact: [email protected].
ouicu is in beta. This page describes the service as it opens to beta users, and changes here are dated above.
What we keep and why
- Account: name, email and a password hash, or the Google or GitHub account id. To provide the service (contract).
- Sessions: IP address and browser, for the website and the command line tool. For security (legitimate interest).
- Your shares: the names you use, the sites you upload, API key hashes, hashes of the passwords you put on links, counts of requests and bytes per share, site and month (for the plan's data allowance), and the IP address the command line tool connected from. To provide the service and its plan limits (contract), and to answer the police about illegal content (legal obligation).
- Last versions: on plans that keep a link working while your computer is offline, the last version of each page a visitor received, as long as the visitor sent no cookies and the page set none and was not marked private. To provide the service (contract).
- Visitor emails: on Hobby and Pro, we email you when someone opens your links. For that we keep each visitor's first page of a day at a link: the time, the page they opened (not what follows a ? in its address), the country and the kind of device, their email address if they had to prove it (see below), and a one-way fingerprint of their network for that day and link, so each visitor counts once a day. To leave out your own visits, we compare it with the networks you used ouicu from in the last 30 days. What we will not email you about is deleted at once. To provide the service (contract).
- Abuse checks: sign-up uses Cloudflare Turnstile. ouicu reads the start of each page a preview sends, and the Report button looks at the page again once it has run, for signs of phishing (a password or card field with a bank or brand in the title); only those signs are sent, never what anyone types. And Cloudflare checks images on previews against lists of known child sexual abuse material. A person at ouicu looks at every match. To stop phishing, abuse and illegal content (legitimate interest, legal obligation).
- Reports: if you report a preview, the address, what you wrote, your name and email, and the IP address you sent it from. We send you a receipt and our decision; the person who shared the preview is not told who reported it. To deal with the report (legal obligation) and keep the form from being misused (legitimate interest).
- Payments: if you pay for a plan, which plan, its status and renewal date, and Polar's ids for you and the subscription. Polar, our merchant of record, takes the payment and keeps the card; we never see it. To provide the plan you pay for (contract).
- Teams: if you start or join a team on Pro, its name, who is in it, who owns it and when each person joined. If you own one, the email addresses you invite and when: we email each a link that works for 7 days, keep only a one-way fingerprint of the link, and forget the invitation a day after it stops working. Everyone in a team sees the names and email addresses of the others, the names reserved in the team, and the shares and sites under them with who started each. Visitor emails and the last requests of a share or site stay with the person who shared it. If the owner pays through Polar, we tell Polar the number of seats beyond those Pro includes, under the owner's account. To provide the service (contract).
- Beta requests: if you email us to join the beta, your address and message. To answer you (legitimate interest).
We send no marketing email to anyone who has not asked for it.
People who open a link
When someone opens a link you shared, the request passes through ouicu to your computer or your uploaded site. We do not keep what is sent, apart from the last versions above. The person who shared the link sees its last 50 requests on their dashboard: the time, the method and address asked for, the answer (or which of ouicu's own pages was shown, such as the notice or the password page), its size, the country and the kind of device (phone, tablet, computer, bot or unknown), with a number for each visitor, never the IP address. To number visitors, and to stop one visitor from taking more than 250 MB a day from a link, our server keeps a one-way fingerprint of each visitor's IP address beside those requests. All of this is kept in memory only, and goes when our server restarts. For these visitors, the person who shared the link decides what is shared and with whom, and we process the data for them. They are also emailed about (see Visitor emails above). A link can be for some people only (Pro): visitors then type their email address, and if the person who shared it listed it, we email them a link that opens it for a week in that browser, and tell the person who shared it that they opened it. We keep the address with that emailed link for two days, and in the visitor record above. Separately, ouicu keeps its own log of each request to a preview: the time, the address asked for, the answer, the visitor's IP address, country and browser, and the page that linked there. It is for looking into phishing and abuse (legitimate interest) and is deleted after 14 days. Every preview shows a small Report button, added by ouicu, that sets no cookies. Previews on the free plan also show visitors a one-time notice, remembered with a cookie. Cloudflare may keep an image from a preview for up to a minute, so it can be checked.
How long
- Account, names and uploads: until you delete them.
- Uploaded sites on the free plan: 7 days.
- Last versions: until you take one down or stop its share from your dashboard, release the name, or move to a plan without them.
- Visitor records for emails: 30 days after we email you about them.
- Links emailed to visitors: two days.
- A link's last requests on your dashboard: until our server restarts.
- Sessions: until you sign out or they expire.
- The IP address a share connected from: 90 days after the share ends, or a year if it was reported for child sexual abuse. An upload's: 90 days.
- The log of requests to previews: 14 days.
- Server logs: 30 days.
- Encrypted backups: 30 days, or longer for the last few if backups stop.
- Reports: two years after they are dealt with.
- Payments: while you pay, and as the law on bookkeeping asks.
- Teams: until the team is deleted. Invitations: until they are answered or taken back, or a day after their link stops working.
- Beta requests: until the beta ends.
Where
On our server in Denmark, with encrypted backups on our server at Hetzner in Falkenstein, Germany. All traffic passes through Cloudflare, which runs worldwide. Email is sent by Amazon Web Services from Frankfurt. Payments are handled by Polar Software, Inc. in the United States. If you sign in with Google or GitHub, they tell us your name and email address.
Your rights
You can ask to see, correct, delete, restrict or move your data, and object to processing based on legitimate interest. Email [email protected]. You can complain to Datatilsynet (datatilsynet.dk). The terms cover the rest of the service.