The handful of things that actually reduce the chance of losing an account.
Use a password manager and a password unique to this account. Passwords are stored as bcrypt hashes at cost 12, which protects them at rest but cannot protect a password reused on a site that has already been breached.
Sign-in issues a signed cookie rather than a server-side session row, so Settings → Security usually has no session list to show you and no device to sign out. That is a privacy property rather than a gap: there is nothing stored about where you signed in from. What it costs is a remote kill switch — a cookie stays valid until it expires, which is why the two levers that matter are keeping the password unique and turning on two-factor authentication.
Give teammates the narrowest role that works. Viewer is a complete answer for someone who only reads reports.
Scope API keys tightly and delete the ones you are no longer using.
Treat a webhook secret like a password — it is what proves a payload came from us.
We will never ask for your password
Nobody from Paddek will ask for your password, an API key or a webhook secret — not by email, not in a support thread. A message that does is not from us; forward it to [email protected].
What happens to a URL between pasting it in and the link going live, and why some destinations are refused.
The URL is parsed and normalised. Decimal, octal, hexadecimal and IPv4-mapped IPv6 encodings of an address are resolved rather than taken at face value.
Private, loopback, link-local and carrier-grade NAT ranges are rejected, so a short link cannot be aimed at something inside a network.
The registrable domain is checked against the operator blocklist.
Heuristics flag the patterns that phishing links share, and where a Safe Browsing key is configured the destination is checked against it too.
The same checks run again on the redirect path, because a destination that was clean at creation can be compromised afterwards.
If a legitimate destination is refused, tell us at [email protected] with the exact URL. Blocklist entries are reviewed by a person.
Anyone can report a link, with or without an account, and here is what happens next.
Use the report form at /report — no account required — or write to [email protected]. Include the full short URL; a screenshot of the landing page helps.
Reports go to a review queue. A small number of reports does not take a link down by itself.
Repeated reports move a link to a flagged state where visitors see a warning before continuing. The link still resolves.
A human review, or a destination domain on the blocklist, blocks the link outright: it stops redirecting and returns an explanation.
When a reviewer flags or blocks a link, its owner is emailed the short URL, the report category and any reviewer note, with a reply address that reaches the abuse team — so a false positive can be appealed.
Links caught by a blocklist entry against a whole destination domain are not notified one by one. If a link of yours stops working and you were told nothing, that is the case to ask us about.
What we hold about you, and how to ask for a copy or a deletion.
Write to [email protected] from the address on the account. Requests are handled by a person.
Deleting your account removes your links, Bio Pages, QR codes and account record. Because click rows store no IP address and the visitor hash cannot be reversed, there is no visitor identity left behind to erase.
Deleting an account breaks its links
Every short link the account owns stops resolving. If those links are printed on something, transfer them or set an expiry redirect before you delete.
Where to send it, what is in scope, and the safe-harbour commitment.
Send findings to [email protected] with enough detail to reproduce: the request, the response and the impact.
The security page carries the full scope, the rules of engagement and the safe-harbour statement. In short: test only against your own account, do not degrade the service for anyone else, do not access other people’s data, and give us a reasonable window before publishing.
Did this leave something unanswered?
Tell us what you were trying to do — it is how these articles get written.