Legal
Acceptable Use Policy
Short links make a destination harder to evaluate before clicking, so the rules here are enforced on where a link goes, not only on what you typed into the form. This page sets out what is prohibited, how it is enforced and how to appeal.
Last updated
This document is a starting point, not legal advice. It has not been reviewed by a lawyer, it is not tailored to any jurisdiction, and it may not satisfy the obligations that apply to your business. Have counsel review and adapt it before you rely on it.
Three values are still placeholders and must be replaced in src/config/brand.ts:
- brand.legal.entityNameCurrently [Your registered company name] — the contracting party named throughout the document.
- brand.legal.addressCurrently [Your registered business address] — the registered address for legal notices.
- brand.legal.governingLawCurrently [Your governing jurisdiction] — the governing law and the courts that hear a dispute.
Scope
This policy applies to everything you do through Paddek: the short links you create, the destinations they point at, the Bio Pages you publish, the custom domains you connect, the QR codes you generate and the requests you make through the API. It applies whether the content is served on one of our domains or on a domain of your own.
It is part of the Terms of Service. A link shortener is a redirection tool, and redirection is exactly what makes a malicious destination harder for a person to evaluate before they click. That is why the rules below exist and why they are enforced on the destination, not only on what you typed into our form.
Where a rule below is stated absolutely, it is absolute. Intent, satire, security research and “it was only a test” do not create exceptions on a live production URL that real people can click.
Phishing and Credential Harvesting
You may not use the service to:
- link to a page that imitates a sign-in screen, payment form, tax portal, delivery notice, bank, wallet or any other trusted service in order to collect credentials, one-time codes, card numbers, recovery phrases or identity documents;
- host or link to a page that impersonates Paddek itself, including fake billing notices, fake abuse warnings and fake account-recovery flows;
- impersonate another person, company, brand, public body or their staff, including by using a slug, Bio Page username, avatar or display name designed to be mistaken for theirs;
- conceal a malicious destination. Cloaking — serving a benign page to our checks, to a preview crawler or to a first visit, and the real page to everyone else — is a violation in its own right, independent of what the real page contains. So is chaining redirects through third-party services to obscure where a link ends up.
Phishing links are disabled as soon as they are confirmed, without prior notice, and the account is suspended pending review. This is the category where the harm is immediate and irreversible for the person who clicked.
Malware and Unwanted Software
You may not link to or distribute malware, ransomware, spyware, stalkerware, keyloggers, cryptocurrency miners that run without the visitor’s knowledge, browser hijackers, or software bundled with anything the visitor did not ask for and cannot decline.
You may not link to exploit kits, drive-by download pages, or content designed to trigger a vulnerability in a visitor’s browser or operating system.
Security researchers and malware analysts: do not use short links to distribute live samples. Use a channel where the recipient has explicitly opted in and knows what they are receiving.
Fraud and Deceptive Commerce
You may not use the service in connection with:
- advance-fee fraud, fake invoices, fake refunds, fake support desks or fake delivery notifications;
- investment schemes that guarantee returns, pyramid or Ponzi structures, matrix schemes, and “giveaway” scams that ask the victim to send funds first;
- counterfeit goods, forged documents, stolen account credentials, stolen payment data, or services that create fake reviews, engagement or traffic;
- any offer whose material terms — price, recurrence, cancellation, identity of the seller — are hidden from the buyer until after they have paid.
Spam and Unsolicited Bulk Messaging
You may not use links created here in unsolicited bulk email, SMS, DMs, forum posts, comment sections, review sections or messaging-app broadcasts. If the recipient did not ask to hear from you, do not put our links in front of them.
You may not create links at automated volume for the purpose of distributing them across many destinations to evade spam filtering, and you may not use the API to generate throwaway links for that purpose. Plan rate limits are a technical control, not a licence to send up to them.
Legitimate marketing to a list that opted in, with a working unsubscribe, is fine. That is most of what the product is for.
Illegal Goods, Services and Content
You may not link to content that is illegal where you are, where we operate, or where a substantial part of your audience is. That includes, without limitation:
- controlled substances, prescription medicines sold without a prescription, and precursor chemicals;
- weapons, ammunition, explosives and their components where the sale is regulated or prohibited;
- human trafficking, forced labour and commercial sexual exploitation;
- content that incites or provides operational assistance for terrorism or mass violence;
- unlicensed gambling in jurisdictions where it requires a licence;
- markets for stolen data, hacking-for-hire, or denial-of-service services.
Child Sexual Abuse Material
Zero tolerance, no exceptions, no appeal. Any link to child sexual abuse material, or to content that sexualises a minor in any form, results in the immediate termination of the account and preservation of the associated records.
Confirmed material is reported to the appropriate law enforcement authorities and child protection organisations. We do not notify the account holder before making that report.
This applies equally to content that grooms, solicits or facilitates access to minors. There is no context in which this is permitted here.
Harassment and Targeted Abuse
You may not use the service to:
- target an individual with threats, intimidation, sexual harassment or a sustained campaign of abuse;
- publish or link to someone’s private information without their consent — home address, phone number, government identifiers, financial details, medical information, or intimate images;
- distribute non-consensual intimate imagery, or content produced to sexually humiliate a real person;
- incite others to harass a person or a group, or coordinate brigading against them;
- promote violence against, or the exclusion of, people on the basis of a protected characteristic.
Copyright and Trademark Infringement
You may not link to material that infringes someone else’s copyright, trademark or other intellectual property rights, and you may not use the service to operate a piracy index, a stream-ripping front end, or a distribution channel for cracked software.
You may not register a slug, Bio Page username or custom domain configuration whose purpose is to trade on someone else’s trademark.
Rights holders should send notices to [email protected] identifying the work, the specific short link, and a statement of good-faith belief that the use is not authorised. We act on complete notices and we accept counter-notices from the account holder.
Evading Enforcement
You may not:
- create a new account, or use an existing one, to restore access after an account was suspended or terminated;
- re-create a link that we disabled, on this or any other account;
- rotate slugs, domains or destinations in order to stay ahead of a blocklist, ours or anyone else’s;
- use the service to launder a destination that has been blocked by browsers, email providers, security vendors or another platform;
- probe, disable or circumvent our safety checks, rate limits or authentication.
Evasion is treated as an aggravating factor. An account that would have received a warning for a first offence will be terminated instead if the offence was an attempt to get around an earlier enforcement action.
The Owned-Content Proxy
On the Business plan, a link can serve another origin’s content under your branded URL instead of redirecting to it. This is the one feature in the product that could, in principle, be turned into phishing infrastructure — a page that looks like it lives at go.yourcompany.com but is actually served from somewhere else.
You may not use it to serve, mirror or proxy any third party’s content, and in particular you may not proxy anyone’s login page, payment page or account area. That includes pages belonging to a company you have a commercial relationship with.
That rule is not enforced by asking you to agree to it. It is enforced structurally, on every single request:
- the branded domain must be verified by DNS and owned by your account;
- the proxy target must resolve to the same registrable domain as the branded host.
go.acme.commay proxystore.acme.com; nothing onacme.comcan proxy a different registrable domain, whatever the settings say; - the feature must be enabled on the domain, which requires the Business plan;
- the target is re-validated against our SSRF and safety checks on every hop;
- every proxied request writes an audit record.
Because the second rule compares registrable domains and is checked at request time rather than at configuration time, “proxy a bank’s login page” is not one misconfiguration away — it is unrepresentable. You would have to control the bank’s DNS zone to get there, at which point our proxy is not your problem.
Any destination outside your own registrable domain uses an ordinary HTTP redirect, which shows the visitor in their address bar exactly where they have been sent. That difference is deliberate and is not configurable.
Enforcement
We match the response to the harm. In roughly increasing order of severity, we may:
- Warn. For a first, low-harm breach that looks like a mistake, we tell you what is wrong and ask you to fix it.
- Flag a link. When several independent reports arrive about the same link, it is marked suspicious automatically. It still resolves, but visitors see a warning interstitial first. This is deliberately short of a takedown: a handful of reports is well within reach of a coordinated complaint campaign against a competitor, so a machine flags and a human decides.
- Disable the link. The link stops resolving and returns a page explaining that it is no longer available. It never silently redirects somewhere else.
- Suspend the account. Sign-in is blocked while we investigate. A suspension is a hold on the account rather than a verdict on its content, so links already issued keep resolving until they are disabled individually — the step above.
- Terminate the account. Permanent, for severe or repeated breaches and for any attempt to evade an earlier action. Termination does take the content down: every link on the account stops resolving at the same moment.
- Refer to authorities. Where content is criminal, and always in the case of child sexual abuse material.
We give notice and a chance to respond where the circumstances allow it. Where the harm is active — phishing, malware, or content we are legally obliged to remove immediately — we act first and explain afterwards.
Reporting a Link
Anyone can report a link. You do not need an account and you do not need to identify yourself: report a link. You will get a reference number you can quote in follow-up correspondence.
The response to a report is deliberately uninformative. It is identical whether the link exists, was deleted, or never existed, and it never says who owns it. A form that answers “is this short link real?” is a reconnaissance tool, and one that names the owner turns a reporting channel into a harassment channel.
Reports are reviewed by a person. We do not publish a response-time commitment we have not made — what we can say is that reports of phishing, malware and child safety are triaged ahead of everything else, and that the more precisely you describe what you saw, the faster the review goes.
Appeals
If we disabled your link or suspended your account and you believe we got it wrong, write to [email protected] from the email address on the account. Include the short link or account email, and explain what you think we misread.
When we flag or disable a link after a report, we email the address on the account with the short URL, the category reported and any note the reviewer left; replying to that notice reaches the same address. A link that stops working because its whole destination domain went onto the blocklist is not announced link by link, so if one of yours stops resolving and you were told nothing, that is the case to write to us about.
An appeal is reviewed by someone other than whoever took the original action. If we agree we were wrong, we restore the link or the account and tell you so. If we do not, we tell you which rule was breached and what evidence we acted on, subject to not exposing a reporter’s identity.
Child sexual abuse material is the one category with no appeal. Nothing else on this page is final.
See also the Terms of Service and the Privacy Policy. To report a link, use the report form.