Legal

Terms of Use

How you can use the Cortalim redirect service and API. Read this as the acceptable-use part — it sits alongside our Terms & Conditions and Privacy Policy.

Last updated: 2026

Cortalim is a product of VisNavigans Inc.. When you make a code, use the API, or send someone through one of your links, you agree to the rules below. They exist to keep the service fast and trustworthy for everyone who relies on it. Normal use — creating codes, pointing them, reading your own analytics, sending real people through them — is exactly what the service is for. These rules are about the extremes, not the everyday.

Fair use of the service and API

Every scan of one of your codes reaches our servers and gets sent on to wherever the code points. That has to stay quick for everyone, so a few limits keep it healthy.

  • The API is capped at 120 requests per minute per key. Go over and you'll get a 429 response and can retry after a short wait. Higher limits come with the Pro and Business plans — if you need more, tell us.
  • Don't scrape or enumerate codes that aren't yours. Guessing short codes to read where they point, or pulling analytics you don't own, isn't allowed.
  • Don't automate abuse. No scripted redirect floods, no inflating scan counts with fake traffic, and no using a code as an open redirector to launder someone else's links.

What you may not point a code at

A short link is only as trustworthy as where it lands. You may not point a Cortalim code or short link at:

  • Malware, spyware, or anything that tries to install itself on a visitor's device.
  • Phishing pages, or sites built to steal logins, card numbers, or identities.
  • Content that is illegal where your audience is. We follow the law of the places our users are in.

If a code starts sending people somewhere harmful, we can switch that redirect off without waiting.

Your codes belong to you

The codes you create are yours. We don't resell them, and we don't hand your short code to anyone else.

If your plan lapses, your codes are not deleted. A scan shows a simple fallback page instead of your link, and the code stays reserved for you. Come back and you reclaim it exactly as it was — same short code, same history. This is the no-hostage guarantee. It's a promise, not a setting we can quietly change on you.

Your API keys are yours to protect

An API key acts as you. Anyone holding it can create and change codes on your account, so keep it secret — out of client-side code, out of public repositories, out of screenshots. If you think a key has leaked, rotate it. You're responsible for what happens under your key, so roll it and let us know at support@cortalim.com if you suspect it's exposed.

Suspension for abuse

If a code or an account breaks these rules — points at malware, hammers the API to abuse it, or scrapes other people's codes — we can suspend the code or the account. Where it's an honest mistake or a one-off, we'll aim to tell you why and give you a chance to put it right. Your codes stay reserved during a suspension; the no-hostage promise still holds.

See something that looks wrong? Report it to support@cortalim.com.

A note on the QR standard

The QR code format itself is an open standard, published and free for anyone to use. Cortalim doesn't own it and doesn't try to. What we add is the dynamic layer on top: the short link a code carries, the ability to change where it points after it's printed, the routing, the bot filtering, and the analytics. The square of black and white is open. The service behind it is ours to run well.

Questions

Anything about acceptable use goes to support@cortalim.com. For everything else, reach us at hello@cortalim.com.