2026-08-27
中文版本:可接受使用政策 · Related: Terms of Service · Privacy Policy · Refund Policy
Effective date: 27 August 2026 Last updated: 27 August 2026
Report an abusive link: cjh@knowuv.com with ABUSE at the start of the subject line — see section 5 for what to include and how fast we act.
1. Why this policy exists
A short link hides its destination. That is the point of the product, and it is also exactly why link shorteners are attractive to people running phishing campaigns, distributing malware, and laundering traffic to fraudulent sites.
We treat that as our problem, not the internet's. This policy sets out what is not allowed on KnowUV and — more importantly — the controls we actually run to enforce it. It forms part of the Terms of Service and applies to every account, every link, every landing page and every API call.
2. Prohibited content and conduct
You must not create, distribute, or point a KnowUV link at anything in this section. This applies to the immediate destination, to anything reached through a further redirect, and to anything encoded in a QR code we generate for you.
2.1 Deception and fraud
- Phishing — pages imitating a bank, payment provider, government service, employer, courier, marketplace or any other party to obtain credentials, one-time codes, card numbers or identity documents
- Impersonating any person, business, or public body, or misrepresenting your affiliation with one
- Investment, cryptocurrency, forex, "guaranteed returns", advance-fee, romance and job-offer scams
- Fake stores, fake shipping notices, fake invoices, fake refunds, fake prize notifications
- Counterfeit goods, pirated media, cracked software, or stolen credentials and data
2.2 Malicious software and attacks
- Malware, ransomware, spyware, keyloggers, cryptominers, or unwanted software of any kind
- Drive-by downloads, exploit kits, or pages designed to attack the visitor's browser or device
- Command-and-control endpoints, exfiltration endpoints, or infrastructure supporting an attack
- Using KnowUV links to relay, amplify or obscure traffic in a denial-of-service attack
2.3 Unsolicited messaging
- Spam — bulk unsolicited email, SMS, instant messages, comments, or social posts, whether you send it or someone you pay sends it for you
- Messaging people who did not opt in, or who opted out
- Sending in a way that evades a platform's rules, filters, or rate limits
2.4 Illegal and harmful material
- Child sexual abuse material, or any content that sexualises a minor — reported to authorities and terminated without notice or appeal
- Human trafficking, forced labour, or the sale of people or organs
- Terrorist content, violent extremism, or incitement to violence
- Content promoting self-harm, suicide, or eating disorders
- Illegal weapons, explosives, controlled substances, or prescription drugs sold without a prescription
- Unlicensed gambling, or gambling directed at jurisdictions where it is prohibited
- Non-consensual intimate imagery, doxxing, stalking, or targeted harassment
- Content that infringes copyright, trade marks or other intellectual property
- Anything unlawful in the People's Republic of China, in your jurisdiction, or in the jurisdiction of the people you send the link to
2.5 Technical abuse of the Service
- Concealing a destination from our review — including cloaking, serving different content to our review infrastructure than to visitors, time-delayed swapping of a destination after approval, or chaining through another shortener to break the chain of review
- Creating accounts to evade a suspension, a quota, or a disabled link
- Automated bulk registration, credential stuffing, or scraping the Service
- Probing, scanning or load-testing our infrastructure without written permission
- Circumventing rate limits, quotas, metering, or billing
- Reselling raw redirect capacity as an anonymous or unmoderated shortening service
3. How we enforce this
These are the controls we actually run. We publish them at this level of detail so that customers, partners and payment providers can assess us — while withholding the thresholds and heuristics that would help someone evade them.
3.1 Review before a link goes live
A link whose destination is not already trusted does not resolve to that destination until it has been reviewed. It is created in an under review state and serves a holding page instead. Review is normally automated and typically completes within minutes. There is no window in which an unreviewed link quietly works.
3.2 Automated destination analysis
For each destination under review we:
- Load the page in an isolated, sandboxed browser from our own infrastructure — never from a visitor's device
- Follow the redirect chain and record where it actually ends up, so a clean-looking first hop does not launder a malicious final destination
- Decode QR-code destinations. Where a link's destination is supplied as a QR image, we decode the image — including denoising to recover degraded codes — and review the decoded URL, not the picture. Hiding a destination inside an image does not bypass review.
- Capture the rendered text and a screenshot, and classify both with a content-analysis model against the categories in section 2. Screenshot analysis is what catches material — pornography, gambling, scam layouts — that is invisible in page text alone.
- Escalate to a human where the page fails to load, times out, or the assessment is not clear-cut. Ambiguity is resolved by a person, not by defaulting to "allow".
Links assessed as violating are disabled and tagged with the reason.
3.3 Continuous review
Approval is not permanent. A link may be re-reviewed at any time — on a schedule, when its destination changes, or when we receive a report. A destination that turns malicious after approval is caught by re-review, not by luck.
3.4 Rate limits and quotas
Every account has a daily and monthly link-creation limit and a daily visit limit, enforced server-side. There is a per-domain daily cap on top of the per-account limits, so a single destination cannot be blasted across many accounts. Limits are deliberately conservative for new and unverified accounts and are raised on request once we know who you are. Requests over a limit are refused, not queued.
3.5 Account accountability
Accounts are verified by phone number or email before use. Higher limits and sensitive features require further verification. Every link is attributable to a verified account, and every visit is logged with its timestamp, IP address, approximate location, and user agent — which is what makes an abuse report actionable and a law-enforcement request answerable.
3.6 Traffic filtering
Automated crawler and scanner traffic is filtered at resolution time. Optional owner-configured controls — geographic restriction rules, password gates, SMS phone verification, and view-count caps — further limit who can reach a destination. Geographic rules fail closed: a visitor we cannot place is refused, not admitted.
3.7 Kill switch
Any link can be disabled immediately. Disabling it broadcasts a cache-invalidation signal that every serving process receives and acts on, so the link stops resolving across the whole fleet within seconds — we do not wait for a cache entry to expire on its own.
We are honest about the limits of all this. Automated review is very good and it is not perfect. Determined, well-resourced actors evade detection systems, including ours. That is precisely why section 5 exists and why we treat inbound reports as a first-class signal rather than a nuisance.
4. What happens if you breach this policy
Depending on severity, history, and whether the breach looks deliberate, we may:
- Disable the link and notify you with the reason
- Reduce your limits or require additional verification
- Suspend the account pending investigation
- Terminate the account. Unused credit and unexpired plan time are forfeited — see the Refund Policy, section 5.3
- Report to authorities, and to affected platforms, registrars, banks and anti-phishing bodies
Immediate termination without prior notice applies to child sexual abuse material, terrorist content, malware distribution, and phishing campaigns. For these we act first and correspond afterwards.
5. Reporting abuse
Anyone can report a KnowUV link. You do not need an account, and you do not need to identify yourself.
Email cjh@knowuv.com with ABUSE at the start of the subject line — that tag is what pulls your report to the front of the queue. Include as much of this as you have:
- The full short link, including the code (e.g.
https://knowuv.com/sl/XXXXX) - What is wrong with it — phishing, malware, spam, scam, illegal content, something else
- Where you encountered it (an SMS, an email, a social post) — a screenshot helps
- Any header or message evidence, if you are reporting spam
- How to reach you, if you want an outcome notification — optional
Please do not visit a suspected malicious link to gather evidence. Send us the URL; loading it is our job, and we do it in a sandbox.
Our commitments
| Acknowledge your report | 1 business day |
| Investigate | Immediately on receipt for phishing and malware; within 2 business days otherwise |
| Disable a verified malicious link | Within 4 hours of verification, and always within 24 hours of a verified report |
| Tell you the outcome | On request, once we have acted |
Staffed hours are 08:00–22:00 China Standard Time (UTC+8), Monday to Friday. Reports of active phishing and malware are triaged outside those hours.
Law enforcement and trust-and-safety teams: contact cjh@knowuv.com with "LAW ENFORCEMENT" in the subject. We respond to valid legal process, preserve records on request, and will discuss a direct escalation channel with platform and anti-phishing partners.
6. Appeals
If we disabled your link or account and you believe we got it wrong, write to cjh@knowuv.com with the short code and the destination, and tell us why the assessment is mistaken. A human reviews every appeal — you are entitled to a human decision, to state your case, and to contest the outcome. We aim to answer within 2 business days, and we reinstate where we were wrong.
Appeals are not available for child sexual abuse material or terrorist content.
7. Changes
We will update this policy as abuse patterns change, and we may do so without prior notice where a new threat requires it. The current version always lives at this URL, and the "Last updated" date above tells you when it last moved.
8. Contact
All enquiries go to one mailbox: cjh@knowuv.com
We are a small team, so a single address reaches us fastest. To help us triage, start your subject line with one of these tags:
| Tag | Use it for |
|---|---|
ABUSE | Phishing, malware, spam or another abusive link — triaged first |
SECURITY | Vulnerability reports |
PRIVACY | Data access, correction, deletion and other privacy rights |
REFUND | Refund requests and billing questions |
APPEAL | A link or account you believe we disabled in error |
SUPPORT | Everything else |
Staffed 08:00–22:00 China Standard Time (UTC+8), Monday to Friday. Reports tagged ABUSE are triaged outside those hours.
Operator: Wuhan Zhizhizhi Trading Co., Ltd. (武汉市知之智商贸有限公司), Wuhan, Hubei Province, People's Republic of China.