Acceptable Use Policy
URly / urly.tr
Authoritative English version • Effective date: [INSERT EFFECTIVE DATE]
This Policy establishes prohibited, restricted and reviewable uses of URLy. It is intended to protect users, third parties, URLy infrastructure and the integrity of Short Links.
1. General rule
You may not use URLy to facilitate unlawful conduct, deception, serious harm, security abuse or activity that materially threatens the Service.
2. Phishing and credential theft
Fake login pages designed to capture passwords, MFA codes, session tokens or recovery codes.
Credential harvesting, authentication bypass or account-takeover campaigns.
Brand or service impersonation intended to collect credentials.
3. Fraud and scams
Investment, payment, romance, employment, delivery, tax, refund or support scams.
Advance-fee fraud, fake invoices, deceptive fundraising or impersonation of financial institutions.
Fraudulent acquisition or sale of personal or financial information.
4. Malware and malicious code
Malware, ransomware, spyware, keyloggers and destructive payloads.
Malicious download pages and drive-by exploitation.
Infrastructure intended to distribute or control malware.
5. Cyber abuse
Unauthorized access, credential stuffing, exploit delivery or persistence.
Botnet command-and-control, malicious scanning or evasion of security controls.
Links designed to facilitate unauthorized intrusion or theft.
6. Spam and automation
Unsolicited bulk messaging and malicious campaigns.
Automated abuse of link creation, analytics or referral systems.
Activity intended to overload, degrade or circumvent Service controls.
7. Drugs and controlled substances
Illegal sale, trafficking or facilitation of controlled substances is prohibited. Legitimate educational, medical, scientific or recovery-related discussion may be reviewed in context.
8. Gambling and betting
Unlawful gambling, betting, casino operations or deceptive gambling schemes are prohibited. Legitimate informational content may be reviewed in context.
9. Weapons and explosives
Illegal sales or facilitation involving weapons, explosives or other prohibited weapons are not permitted. Lawful informational, journalistic or educational material may be considered in context.
10. Terrorism and violent extremism
Content or activity that materially facilitates terrorism, violent extremist recruitment, operational support, financing or violent wrongdoing is prohibited. Neutral reporting, research and historical discussion may be treated differently based on context.
11. Child safety
CSAM, grooming, sexual solicitation of minors, sexualized content involving minors, trafficking and exploitation are prohibited and may trigger immediate restriction and preservation.
12. Sexual exploitation
Non-consensual intimate material, sexual extortion, trafficking and exploitative sexual services are prohibited.
13. Stolen accounts and financial information
The sale or distribution of stolen accounts, credentials, payment-card data, authentication tokens or unlawfully obtained financial information is prohibited.
14. Counterfeit and piracy
Counterfeit goods, deliberate piracy operations and intentional infringement facilitation are prohibited.
15. Impersonation
Deceptive impersonation of brands, governments, law enforcement, financial institutions, employers, public officials or other entities is prohibited where intended to mislead or cause harm.
16. Privacy abuse
Doxxing, unlawful disclosure of personal data, stalking, targeted harassment and publication of sensitive information for malicious purposes are prohibited.
17. Harassment, threats and extortion
Threats, coercion, blackmail, extortion and targeted abusive campaigns are prohibited.
18. Illegal marketplaces
URLy may restrict Short Links that facilitate unlawful marketplaces or transactions.
19. Security-control circumvention
Attempting to evade slug protection, moderation, rate limits, account suspension, authentication or other security controls is prohibited.
20. Context and exceptions
Journalism, research, education, public-interest reporting and legitimate security work may be considered in context. Context does not authorize unlawful conduct.
21. Enforcement
Moderation may result in ALLOW, REVIEW, RESTRICT or BLOCK. Actions may include link restriction, account suspension, API restriction, deletion or other reasonable measures.
22. False reports and appeals
Knowingly false reports may result in enforcement. Users may request reconsideration where a review channel is available.
23. No guarantee
Detection systems are imperfect. A violation may evade detection and legitimate activity may be flagged for review.
High-risk commercial combinations
Certain combinations of terms, domains, destinations and behaviors may be treated as higher risk than isolated words. For example, a general medical term may be permissible while a combination suggesting illicit sale, credential theft, malware delivery or fraudulent acquisition may trigger review or restriction.
Medical and recovery context
Medical, pharmaceutical, addiction-recovery, academic and public-health discussion is not automatically prohibited. Enforcement should distinguish legitimate informational context from unlawful sale, trafficking, counterfeit medicine or deceptive medical claims.
Financial abuse
URLy may restrict links that impersonate banks, payment providers, tax authorities, investment platforms, exchanges or financial professionals where the purpose is deception, credential collection or financial theft.
Government impersonation
Use of official names, logos or language is not automatically prohibited. The risk arises where a Short Link is designed to make users believe they are interacting with an official government or law-enforcement service when they are not.
Adult content
Adult content involving consenting adults may be subject to product, legal or hosting restrictions. Any sexual content involving minors, coercion, trafficking or non-consensual intimate material is prohibited.
Security research
Good-faith security research may be permitted when it does not facilitate real-world harm, unauthorized access or distribution of malicious payloads. Researchers should use the Vulnerability Disclosure Policy.
Copyright context
News reporting, criticism, quotation, education and other lawful uses may require contextual review. A complaint alone does not automatically establish infringement.
Domain reputation
A domain may receive elevated risk because of known abuse signals, suspicious infrastructure, repeated reports or security intelligence. Domain reputation is a risk signal, not by itself a legal finding.
Evasion and obfuscation
Attempts to evade filters through Unicode confusables, homographs, punctuation, spacing, encoding, transliteration or repeated account creation may be treated as aggravating factors.
Enforcement records
URLy may retain limited enforcement and abuse records as described in the retention policy so that repeated abuse can be identified and lawful investigations can be supported.