pik.li, a service of InCloud S.r.l., uses a limited number of cookies and similar technologies. This policy lists them all and states the purpose and duration of each. pik.li does not use advertising or profiling cookies, and short-link statistics are collected without storing any information on the device of the person who opens the link.
Necessary
Strictly necessary tools, used without consent pursuant to Article 122 of the Italian Personal Data Protection Code (Legislative Decree No. 196 of 30 June 2003, the “Privacy Code”) and Article 5(3) of Directive 2002/58/EC (ePrivacy). They are set by pik.li unless otherwise indicated.
| Name | Purpose | Duration |
| _pikli_session | Technical session: security token against request forgery, temporary messages, the page to return to after logging in, a copy of the cookie choice made. | Until the browser is closed |
| session_id | Keeps the user logged in. It is signed and can be read only by the server. | Until the browser is closed or, with the “Remember me” option, 14 days |
| pk_aid | Random browser identifier, not linked to the user's identity, used solely to apply usage limits to the browser rather than to the IP address. It is set on the first visit to pik.li, never on the link domains. | 1 year |
| privacy_consent | Stores the choice made in the cookie panel. | 1 year |
| locale | Stores the language; it is set only when the user expressly chooses one. | 1 year |
| theme | Stores the theme saved in Settings by logged-in users. | 1 year |
| unlock_<link> | On the link domains only: remembers that the password of a protected link has been entered, so that it is not requested again. | 1 hour |
| cf_clearance and similar cookies | Set by Cloudflare only when it subjects the browser to a security check, to remember that the check has been passed. It is described in Cloudflare's cookie policy. | Determined by Cloudflare |
Preferences
Subject to consent, the light or dark theme chosen by the user is saved in the browser's local storage (“pikli-theme”). This is the only item in this category that pik.li saves on the user's device. Refusing does not limit the Service: the theme will simply follow the system setting.
Payment for a plan or a domain takes place on the payment provider's website (PayPal or NOWPayments): pik.li pages do not load any resources from those providers. The Google reCAPTCHA anti-bot check does not fall into this category and is described below.
Resources loaded from third parties
Some pages load files from external providers: in order to receive them, the browser transmits the IP address and certain technical data to the providers. Fonts and the charting library are not among these, as they are served from InCloud's servers. None of the providers listed sets advertising cookies through pik.li.
- Cloudflare, Inc.: network and security services protecting every page and every short link; if it subjects the browser to a security check, it sets the technical cookie described above. Place of processing: European Union and United States.
- Google reCAPTCHA: invisible anti-bot check on the login, registration, password recovery, link reporting and home-page link creation forms. Google receives the IP address and technical data about the browser and the interaction with the page, and may set its own cookies. It is loaded before any choice is made about cookies because it is a security measure necessary to protect those forms: making it subject to consent would leave the forms unprotected for anyone who refused.
- PayPal, NOWPayments: for payment, the user is redirected to the providers' respective websites; the providers process payment data in accordance with their own privacy policies and do not load any resources on pik.li.
pik.li does not use analytics or advertising cookies. Short-link clicks are counted on InCloud's servers without storing anything on the Visitor's device: no cookie is set on the link domains, apart from the one-hour unlock cookie for password-protected links. The processing of click data, including the IP address, is described in the Privacy Policy.
How to give or withdraw consent
The shield-shaped button in the bottom corner of every page reopens the panel, so that the choice made can be changed at any time. Cookies and local storage can also be deleted from the browser settings.
Blocking necessary cookies through the browser settings may prevent access to the account or the creation of links. Refusing the optional category has no effect on the operation of the Service.
Controller
The controller is InCloud S.r.l. Its details, the data protection contact and the rights of data subjects are set out in the Privacy Policy.
Definitions and legal references
- Personal data
- Any information relating to an identified or identifiable natural person, whether directly or indirectly.
- Cookies
- Small text files that the browser saves on the user's device on behalf of a website.
- Local storage
- An area of the browser in which a website can save data without using a cookie; pik.li uses it only for the theme, subject to consent.
- Tracking tool
- Any technology (cookies, local storage, identifiers, scripts) capable of storing information on the user's device or of accessing information already stored there.
Last amended: 24 September 2026. This policy has been drawn up in accordance with Regulation (EU) 2016/679 (GDPR), Directive 2002/58/EC (ePrivacy), Article 122 of the Privacy Code and the Guidelines on cookies and other tracking tools adopted by the Garante per la protezione dei dati personali on 10 June 2021. The Italian text is authoritative.