Acceptable use policy

Last updated 27 August 2026

Pending legal review. This document was drafted to describe how the service actually works and is accurate to the implemented architecture. It has not been reviewed by a qualified lawyer in the operating jurisdiction, and must be before launch — see OWNER_ACTION_REQUIRED.md in the repository.

The problem this policy exists to address

Any service that redirects arbitrary URLs can be used to disguise a destination, which makes it useful for phishing. We would rather say plainly what is not allowed than pretend the risk does not exist.

Prohibited destinations

A dynamic code must not point at:

  • Anything designed to deceive people about who they are dealing with, including credential-harvesting pages impersonating a business or service
  • Malware, or software installed without informed consent
  • Content that is unlawful where you or we operate
  • Material that sexually exploits children, which we report to the relevant authorities
  • Another URL shortener or redirect chain intended to obscure the eventual destination

Prohibited use of the service

  • Circumventing rate limits, quotas or plan restrictions, including through multiple accounts
  • Creating codes with a destination you intend to change to something prohibited later
  • Reselling access without a written agreement
  • Automated bulk creation beyond your plan’s limits
  • Attempting to enumerate codes belonging to other accounts

What we deliberately do not build

These are design decisions, not missing features:

  • No anonymous dynamic redirects — a verified email is always required
  • No URL cloaking or any feature intended to defeat security scanners
  • No advertising interstitials, and no redirecting your codes anywhere you did not choose
  • No fingerprinting of the people who scan your codes

Enforcement, and appeals

Automated checks run on every destination when it is set and periodically thereafter. A flagged destination may be quarantined, which means the code shows a neutral warning rather than forwarding. It is not deleted.

Automated checks are wrong sometimes, and declaring a legitimate business malicious is its own kind of harm. Every quarantine can be appealed from the warning page itself, and every appeal is read by a person rather than resolved automatically.

Reporting abuse

abuse@scanlight.org

Security vulnerabilities: security@scanlight.org. We will acknowledge within 3 working days and will not pursue action against good-faith research that respects user privacy and avoids service degradation.