Trust & Safety

How BittyShort protects links and accounts

Our safeguards combine automated destination checks, visitor reports, administrative review, and account security controls. No automated system is perfect, so we provide clear reporting and appeal paths.

Unsafe-link prevention

BittyShort checks eligible destinations when links and QR codes are created and during redirects. Depending on administrator configuration, checks can use Google Safe Browsing or URLhaus data. Suspected phishing, malware, fraud, and policy violations may be blocked for review.

Reports, review, and appeals

Reports are protected by bot and CAPTCHA controls, recorded for administrator review, and receive a reference. Confirmed unsafe links can be disabled. If you believe a link was blocked incorrectly, contact us with the link and relevant evidence so it can be reviewed.

Account protection

Accounts support two-factor authentication, role and team permissions, security activity records, request rate limits, and automated bot controls. Use a unique password, enable 2FA, and review account activity regularly.

Privacy and retention

BittyShort stores account, link, and analytics data needed to provide and protect the service. Reporter IP addresses may be stored or irreversibly hashed according to configuration. Cookie choices are available where enabled. See the published privacy policy for current rights, retention terms, and contact details.

Responsible disclosure

If you find a security vulnerability, contact us privately with reproduction steps, affected URLs, and potential impact. Do not access other users data, disrupt the service, or publish details before we have had a reasonable opportunity to investigate.

Incidents and service status

Material service or security incidents will be communicated through the website or direct account contact when appropriate. A dedicated public status page is not currently available; contact support if you suspect an active outage.