Acceptable Use
Last updated: September 2026
A link shortener hides the destination behind a short code. That is the entire point of the product, and it is also exactly what makes one attractive to people sending things nobody asked for. This page says plainly what we will not carry, and how we deal with it without breaking the promise that legitimate links never die.
What you must not link to
-
Phishing and impersonation Pages that imitate a bank, a login screen, a delivery service, a government body or any brand in order to collect credentials, card details or identity documents.
-
Malware and unwanted software Anything that installs, drops or drives-by-downloads software the visitor did not ask for, including cryptominers and browser hijackers.
-
Spam and bulk unsolicited messaging Links distributed by unsolicited email, SMS or direct message at scale, whether or not the destination is otherwise lawful.
-
Child sexual abuse material Zero tolerance. Removed on sight and reported to the relevant authorities. There is no appeal.
-
Illegal goods and services Controlled substances, weapons, stolen data, forged documents, or anything else unlawful where you or your visitors are.
-
Harassment and doxxing Targeting an individual, publishing private information without consent, or coordinating abuse.
-
Cloaking and deceptive redirects Serving a different destination to us, to a scanner, or to a moderator than the one real visitors receive.
What you must not do to the service
- Create links by automated means outside the API, or beyond the rate your plan allows.
- Inflate, forge or otherwise tamper with click analytics, yours or anyone else's.
- Point a custom domain at us that you do not control.
- Probe, scan or attempt to bypass rate limits, authentication or the redirect pipeline.
- Resell the free tier as if it were your own shortening service.
Reporting abuse
Email info@fattyurl.com with the full short link and, if you can, what you saw when you opened it. You do not need an account to report a link.
We aim to acknowledge reports within one business day, and to act on credible reports of phishing or malware considerably faster than that.
How this squares with "links never die"
Our promise is that we will never deactivate a working, legitimate link: not to push you onto a paid plan, not because it is old, not because traffic to it got expensive, and not because you stopped paying us. That promise is unconditional in every one of those directions.
It has never covered links that violate this policy. Disabling a phishing page is not the thing we promised never to do — it is the opposite, because the promise exists to make a FattyURL link something a stranger can trust enough to click.
When we do act, we disable the specific link rather than deleting your account or your other links, and we tell you which link and why, at the address on the account. If we got it wrong, reply and we will put it back.
Legal requests
We respond to valid legal process from authorities with jurisdiction over us. We do not hand over user data on an informal request, and where we are permitted to tell you that a request concerning your account was made, we will.