This Acceptable Use Policy explains what you can’t do with Blinkhop, how we enforce it, and how to report a link or appeal a decision. It’s part of our Terms of Service and applies to every zou.sh link, whether it was created on the website, through the API, through the MCP server or by an AI agent working for you.
Short links only work if people can trust them. A zou.sh link hides its destination until someone opens it, so every link must lead somewhere safe and legal, and must be shared honestly. We may update this policy as new kinds of abuse appear; the date on this page shows the latest version.
1. Forbidden destinations
Don’t create links to, or use links to promote:
- Phishing. Pages that trick people into giving away passwords, payment details, wallet keys or other personal information, such as fake login, delivery or payment pages.
- Malware. Viruses, ransomware, spyware, malicious apps or browser extensions, drive-by downloads, and anything else that harms devices or uses them without consent.
- Scams and fraud. Fake shops, fake giveaways, investment and crypto schemes, fake tech support, advance-fee fraud and other attempts to cheat people out of money or data.
- Spam campaigns. Any destination promoted through unsolicited bulk messages: email, text messages, direct messages, comments or forum posts. We disable links used in spam, wherever they lead.
- Illegal content. Content or goods that are illegal, such as stolen data or accounts, counterfeit goods, pirated software and media, illegal sales of drugs or weapons, terrorist content, or intimate images shared without consent.
- Child sexual abuse material (CSAM). We have zero tolerance. We disable these links immediately, block the destination and report them to the relevant authorities.
- Harassment. Content meant to threaten, bully or intimidate someone, or that exposes their private information (doxxing).
- Impersonation. Pages or custom endings that pretend to be another person, brand or organization, or Blinkhop itself, in a misleading way. For example,
zou.sh/yourbank-loginpointing to a page your bank doesn’t run. - Evading other services’ bans. Using zou.sh links to bring back content, accounts or websites that another platform has removed or banned.
2. Forbidden behavior
Even when the destination is fine, don’t:
- Automate abuse. Create links faster than our rate limits allow, flood the API or the MCP server, or scan zou.sh codes at scale to collect destinations.
- Rotate IP addresses to evade limits. Spread requests over proxies, VPN servers, cloud machines or botnets to multiply your quota. Using Tor or a VPN for privacy is welcome. Using them to get around our limits isn’t.
- Hide destinations with link chains. Chain short links or redirects, for example a zou.sh link to another short link that leads somewhere else, so that our checks or your visitors can’t see where the link really ends up.
- Use zou.sh to slip past spam filters. Create many links to the same destination, for example with random parameters or custom endings, to get around the filters of email providers, messaging apps or social networks.
- Attack the service. Probe, overload or try to break Blinkhop. Good-faith security research is welcome when you report it through /security.
- Abuse the report system. Send false or mass reports to get legitimate links disabled.
3. How we enforce this acceptable use policy
We combine automatic checks with reports from anyone who spots a bad link:
- Automatic blocklist. When a link is created, its destination is checked against a list of about 390,000 phishing and malware domains, refreshed every night from two open sources: URLhaus (abuse.ch) and the Phishing.Database project. Listed domains are refused. We also refuse links with embedded credentials (
user:pass@), links to private or local network addresses, and zou.sh links. Read more about link safety. - Reports. Anyone can report a link (see section 4). We review reports and act on those that break this policy.
- Disabling links. A disabled link stops redirecting, and its preview page no longer shows the destination. Visitors see a “This link was disabled” page with HTTP status 410 (Gone), which tells browsers, apps and search engines that the link was removed. We also block that exact destination URL from being shortened again.
- Other measures. We may refuse requests, block traffic that abuses the service, and disable every link that’s part of the same campaign.
We don’t put warning pages in front of normal links, and we don’t review every link by hand. Our checks reduce risk but can’t catch everything, which is why reports matter.
4. How to report a link
If a zou.sh link leads somewhere harmful, tell us. You don’t need an account.
- From the link itself. Add
+to the end of the link, likehttps://zou.sh/launch+. The preview page shows the destination without opening it. Open “Report this link”, add a reason if you like, and send it. We don’t ask who you are. - From our abuse page. Use the form on /abuse, for example if you’d like a reply.
- From code. Security teams and tools can report through the API:
curl -X POST https://api.blinkhop.com/v1/reports \
-H "Content-Type: application/json" \
-d '{"short_url": "https://zou.sh/7Kp2x", "reason": "Fake bank login page"}'
The most useful reports include the full short link and what’s wrong with it, such as “fake login page” or “malware download”. Please leave out personal information we don’t need.
To report a security vulnerability in Blinkhop itself, use /security instead.
5. How to appeal
If we disabled your link or refused your destination and you think we made a mistake, write to us through /contact. Include:
- the short link, or the destination URL that was refused;
- why you believe it follows this policy;
- your connection to the destination, for example that you run the site;
- anything that has changed, such as a site that was cleaned up after a hack.
We’ll review your appeal and reply to the email address you give us. If we got it wrong, we’ll restore the link. We may not share every detail of our decision, so that we don’t help others get around our checks.
If your domain is on one of the open blocklists we use, also ask that source to review it: URLhaus and Phishing.Database each have their own process. Our copy updates every night, so once a domain is removed at the source, the block lifts after our next update.