Skip to main content

Acceptable use

Last updated: August 27, 2026

Mole hands out hostnames that point at machines we do not operate. The relay does not read content. Enforcement is identity and report, not inspection. The same list covers short links and tunnels. Short links store a destination, so a destination check is cheap. Mole cannot inspect tunnel bytes.

Prohibited
#

Do not use mole or short links for phishing, malware distribution, unsolicited bulk, or any illegal content. Do not use a reserved name or slug to impersonate another party.

No general monitoring
#

We do not prescreen, monitor, or edit tunnel bytes. We do not undertake to seek facts indicating illegal activity. We keep the discretion to suspend an account, terminate an account, or quarantine a hostname.

Reports
#

Name the public hostname. Mail to abuse@turtletech.us reaches an operator mailbox. That address is not a claim that tunnel bytes are read.

On a loopback mole-relay --dev dashboard:

POST /api/v1/abuse/report
{"hostname":"app.example.test"}

That persists DIR/abuse/<id>.json and quarantines the name. A new visitor hop resets. Opening the origin like the reporter is not required. There is no public tunnel hostname yet. On --dev, the report path is the intake.

Window
#

On --dev, a report quarantines the name before the next visitor hop. A report does not require the operator control secret.

Retention
#

Reservation metadata answers who held a hostname on a date. Tunnel bytes are not retained.