Acceptable Use Policy
Last Updated: March 23, 2026 · Effective: March 23, 2026
This Acceptable Use Policy ("AUP") governs your use of the bah.is Services. We act on the spirit, not merely the letter, of this policy. Violation may result in link removal, Account suspension, or permanent termination.
1. Prohibited Content
Security Threats
- Phishing, spoofing, or credential harvesting websites
- Malware, ransomware, spyware, viruses, trojans, or other malicious software
- Exploit kits, vulnerability scanners, or tools for unauthorized access
- Cloaking destination URLs through additional redirect services
Fraud & Deception
- Scams, pyramid schemes, multi-level marketing fraud, or Ponzi schemes
- Impersonation of any person, entity, or bah.is employee
- Deceptive marketing, fake reviews, or misleading advertising
- Social engineering attacks or pretexting
Illegal Activities
- Drug trafficking, illegal weapons sales, or counterfeit goods
- Human trafficking, exploitation, or forced labor
- Illegal gambling (where prohibited by applicable law)
- Terrorism, terrorist financing, or content promoting terrorist organizations
- Child sexual abuse material (CSAM) — reported immediately to NCMEC and law enforcement
Hate & Harassment
- Content attacking individuals or groups based on race, gender, ethnicity, national origin, religion, sexual orientation, disability, or medical condition
- Non-consensual intimate imagery or privacy violations
- Doxxing, stalking, or coordinated harassment
Platform Abuse
- Click fraud or artificial inflation of analytics
- Bot traffic, bulk link creation exceeding rate limits, or spam campaigns
- Reverse-engineering or decompiling the Services
- Using the Services to build a competing URL shortening service
- Any activity designed to overburden or impair our infrastructure
2. Prohibited Conduct
- Sending bulk unsolicited messages (spam) using Shortened Links
- Sharing Account credentials or allowing unauthorized multi-user access
- Creating multiple Accounts to circumvent enforcement actions
- Attempting unauthorized access to our systems or other users' Accounts
- Using automated means to access the Services in violation of rate limits
- Interfering with the integrity or performance of the Services
3. Automated Monitoring & Detection
bah.is employs automated systems to detect and prevent abuse, including:
- Google Safe Browsing API for real-time URL classification
- Internal heuristic scoring based on link behavior patterns
- Rate limiting at all API and web endpoints
- Community reports from users
Automated systems may produce false positives. We provide a fair appeals process (see Section 5).
4. Enforcement Actions
Actions are proportional to severity:
Level 1 — Warning
Notification to Account holder. Request to remove or modify offending content.
Level 2 — Link Action
Disable or block the offending Shortened Link(s). Display a warning interstitial.
Level 3 — Account Suspension
Temporary suspension (7-30 days). Restriction of link creation.
Level 4 — Permanent Termination
Permanent ban. Forfeiture of pre-paid fees. IP blocking.
Level 5 — Legal Action
Report to law enforcement. CSAM reported to NCMEC. Pursue legal remedies.
Actions may be taken without prior notice in cases involving imminent safety risks, illegal activity, or severe violations.
5. Reporting Violations
- Email: abuse@bah.is
- Online: bah.is/report-abuse
- CSAM: Report to abuse@bah.is AND CyberTipline.org
If your content was incorrectly flagged, email abuse@bah.is with subject "Appeal: [your link]". We review appeals within 5 business days.
6. Cooperation
bah.is cooperates with law enforcement (subject to valid legal process), ISPs, industry groups (Google Safe Browsing, PhishTank), and copyright holders (see DMCA Policy).