Acceptable use policy
Last updated 27 August 2026
The problem this policy exists to address
Any service that redirects arbitrary URLs can be used to disguise a destination, which makes it useful for phishing. We would rather say plainly what is not allowed than pretend the risk does not exist.
Prohibited destinations
A dynamic code must not point at:
- Anything designed to deceive people about who they are dealing with, including credential-harvesting pages impersonating a business or service
- Malware, or software installed without informed consent
- Content that is unlawful where you or we operate
- Material that sexually exploits children, which we report to the relevant authorities
- Another URL shortener or redirect chain intended to obscure the eventual destination
Prohibited use of the service
- Circumventing rate limits, quotas or plan restrictions, including through multiple accounts
- Creating codes with a destination you intend to change to something prohibited later
- Reselling access without a written agreement
- Automated bulk creation beyond your plan’s limits
- Attempting to enumerate codes belonging to other accounts
What we deliberately do not build
These are design decisions, not missing features:
- No anonymous dynamic redirects — a verified email is always required
- No URL cloaking or any feature intended to defeat security scanners
- No advertising interstitials, and no redirecting your codes anywhere you did not choose
- No fingerprinting of the people who scan your codes
Enforcement, and appeals
Automated checks run on every destination when it is set and periodically thereafter. A flagged destination may be quarantined, which means the code shows a neutral warning rather than forwarding. It is not deleted.
Automated checks are wrong sometimes, and declaring a legitimate business malicious is its own kind of harm. Every quarantine can be appealed from the warning page itself, and every appeal is read by a person rather than resolved automatically.
Reporting abuse
Security vulnerabilities: security@scanlight.org. We will acknowledge within 3 working days and will not pursue action against good-faith research that respects user privacy and avoids service degradation.