Platform Integrity
Abuse & Moderation Policy
Effective Date: January 1, 2025 ? Last Revised: May 2026 ? Operator: DigiMktg Co. LLC, Illinois, USA
To report suspected misuse of PhantomLink, contact us directly. Include as much context as possible — we review every report.
Policy Purpose & Scope
1.1 This Abuse and Moderation Policy ("Policy") establishes the framework by which DigiMktg Co. LLC ("Operator") identifies, evaluates, and responds to reports of misuse of the PhantomLink platform ("Service"). This Policy applies to all users of PhantomLink.app and any associated mobile applications.
1.2 This Policy is intended to serve multiple functions: to inform users of what constitutes prohibited conduct; to establish a clear and accessible process for reporting suspected abuse; to define the Operator's response obligations and limitations; and to demonstrate to platform partners, app store reviewers, and regulatory bodies that the Operator maintains a good-faith, documented moderation process.
1.3 This Policy is incorporated by reference into the PhantomLink Terms of Service located at PhantomLink.app/legal. In the event of any conflict between this Policy and the Terms of Service, the Terms of Service shall govern.
1.4 The Operator reviews and updates this Policy periodically. The "Last Revised" date at the top of this document reflects the most recent material revision.
Platform Philosophy & The Privacy Balance
Our position: Privacy is a legitimate and constitutionally protected right. The overwhelming majority of PhantomLink users are journalists, professionals, individuals with personal privacy needs, and people who simply prefer that their communications not persist indefinitely. This platform exists to serve those users. It is not built to shield criminal conduct.
2.1 Legitimate Privacy vs. Criminal Cover. PhantomLink is designed to protect the privacy of lawful communication — not to provide operational cover for criminal activity. These are fundamentally different use cases. The platform's minimal-retention architecture serves the former. It does not and cannot serve as a shield against all consequences of criminal conduct, as users remain subject to investigation through means outside the Operator's control.
2.2 Open Platform with Defined Limits. The Operator's preference is to maintain an open, minimally restricted platform that respects user privacy and does not require registration or identity verification for ordinary use. This openness is a feature, not a vulnerability. It is maintained in good faith and is contingent on users operating within the boundaries established in this Policy and the Terms of Service.
2.3 Operator's Moderation Posture. The Operator does not proactively monitor, read, or screen message content. Messages are encrypted and self-destructing by design; proactive monitoring is technically impossible in the ordinary course. The Operator's moderation function is therefore reactive — triggered by user abuse reports, law enforcement contact, and pattern-level infrastructure anomalies — rather than content-based screening.
2.4 Platform Integrity Commitment. The Operator is committed to taking reasonable and technically feasible action in response to credible reports of abuse. The existence of this Policy and the Operator's enforcement of it are conditions of the Service's continued operation as an open privacy platform. Systematic abuse of the platform by any individual or group will result in access restrictions applied at the infrastructure level.
Zero-Tolerance Categories
3.1 The following categories of conduct represent absolute violations of this Policy and the Terms of Service. There are no exceptions, mitigating circumstances, or appeal processes for confirmed conduct in these categories. The Operator will take the most aggressive technically feasible response and will cooperate fully with law enforcement to the extent technically possible:
- Child sexual abuse material (CSAM) or any sexual content involving persons under the age of 18 in any form whatsoever
- Sextortion — coercion, threats, or demands using intimate or sexual imagery or the threat thereof
- Planning, coordination, incitement, or facilitation of terrorism, domestic terrorism, mass violence, or acts of genocide
- Human trafficking — recruitment, control, transport, or exploitation of persons for labor or sexual purposes
- Credible, specific threats of imminent physical violence or death directed at an identified individual or group
- Non-consensual intimate imagery (NCII) — distribution of private sexual images without the subject's consent
- Extortion or blackmail — demands for money, property, or conduct under explicit or implicit threat of harm or exposure
- Coordination of illegal arms trafficking or distribution of weapons of mass destruction materials
3.2 Upon receipt of a credible report of conduct falling within the zero-tolerance categories above, the Operator will: immediately attempt to destroy any message still within the system; block infrastructure-level access associated with the reported activity to the extent technically feasible; and refer the matter to appropriate law enforcement authorities and relevant reporting bodies including the National Center for Missing and Exploited Children (NCMEC) CyberTipline for CSAM-related reports, without requiring further investigation or confirmation.
Reportable Conduct
4.1 Beyond the zero-tolerance categories in §3, the following conduct is reportable and subject to Operator review and action at the Operator's discretion:
- Harassment and targeted abuse — Use of the Service to systematically harass, stalk, intimidate, or cause emotional distress to an identified individual
- Cyberbullying — Use of the Service to bully, demean, or psychologically harm any person, particularly minors
- Fraud and financial scams — Use of the Service to transmit phishing content, impersonate financial institutions, or conduct advance-fee fraud or similar financial deception schemes
- Malware distribution — Use of the Service to transmit links to or instructions for malicious software, ransomware, spyware, or other harmful code
- Identity theft facilitation — Use of the Service to transmit stolen personal identifying information or to coordinate identity theft operations
- Drug trafficking coordination — Use of the Service to coordinate the sale, distribution, or supply of controlled substances in violation of applicable law
- Impersonation — Use of the Service to impersonate law enforcement, government officials, medical professionals, or other individuals or institutions in a manner intended to deceive or harm
- Automated abuse — Use of bots, scripts, or automated tools to circumvent rate limiting, flood the Service, or conduct any form of automated attack against the platform or its users
- Systematic spam — Use of the Service to conduct large-scale unsolicited message campaigns
- Doxxing — Use of the Service to distribute private personal information about an individual without their consent and with intent to harm
4.2 The Operator reserves the right to determine in its sole discretion whether reported conduct falls within the categories described in this section and what response, if any, is appropriate under the circumstances.
How to Submit an Abuse Report
5.1 Submission Method. Abuse reports must be submitted by email to [email protected] with the subject line "ABUSE REPORT". This ensures reports are routed to the correct review queue and not lost in general correspondence volume.
5.2 What to Include. To enable the Operator to take the fastest and most effective action possible, abuse reports should include the following information to the extent available:
- The full Phantom Link URL associated with the reported message, if available and not yet expired
- A description of the reported conduct and why you believe it violates this Policy
- Any contextual information about how the link was received (e.g., via text, email, social media platform)
- Whether the reported conduct involves an imminent threat to physical safety — reports involving imminent threats will be escalated immediately
- Whether you have already contacted law enforcement regarding this matter
- Your contact information, if you are willing to be contacted for follow-up (not required)
Important: If you are in immediate physical danger or have knowledge of an imminent threat to life, contact emergency services (911 in the United States) before submitting an abuse report to the Operator. The Operator's abuse review process is not a substitute for emergency law enforcement response.
5.3 Anonymous Reporting. Consistent with the Service's privacy architecture, abuse reports may be submitted anonymously. Anonymous reports will be reviewed and acted upon where technically feasible. However, the Operator may be limited in its ability to follow up or provide a response to anonymous reporters.
5.4 Third-Party Reports. Abuse reports may be submitted by persons other than the direct recipient of a reported message, including law enforcement agencies, legal counsel, advocacy organizations, and platform partners.
What Happens After You Report
6.1 Review Process. All abuse reports are reviewed by the Operator upon receipt. The Operator's response process proceeds as follows:
Report received and categorized. Zero-tolerance reports are immediately escalated. All other reports are queued for review in order of receipt and severity.
The Operator determines whether the reported Phantom Link still exists in the system and whether any technically feasible action is available. Messages already destroyed per their timer or trigger cannot be retrieved; however, reports may still inform future abuse-prevention decisions.
Based on the category of reported conduct and technical availability, the Operator determines the appropriate response from the range of actions described in §7.
Determined actions are implemented. For zero-tolerance categories, action is taken immediately upon credible report without waiting for investigation completion.
Where a reporter has provided contact information, the Operator will provide a confirmation of receipt and, where appropriate, a general description of action taken. Specific details of enforcement actions are not disclosed.
Where the reported conduct warrants law enforcement involvement and the Operator possesses any relevant information, the matter is referred to appropriate authorities. See §9.
6.2 Response Timeframe. The Operator endeavors to acknowledge and review abuse reports as soon as commercially reasonable. Zero-tolerance category reports are escalated and acted upon as rapidly as technically feasible. Response times may be extended during high-volume periods, platform incidents, or circumstances beyond the Operator's control.
6.3 No Guarantee of Outcome. The Operator does not guarantee any specific outcome in response to an abuse report. The technical limitations of the minimal-retention architecture (see §8) mean that in many cases the reported message will already have been automatically destroyed before the Operator can take action. The Operator's receipt of an abuse report and initiation of review does not constitute a guarantee that any particular action will or can be taken.
Actions the Operator May Take
7.1 In response to confirmed or credible reports of policy violations, the Operator may take any one or more of the following actions at its sole discretion, without prior notice to the party whose access is affected:
- Immediate message destruction — Where a reported message still exists within the system, the Operator may trigger immediate permanent destruction of that message ahead of its scheduled timer
- URL invalidation — Invalidation of the reported Phantom Link URL so that it returns a not-found response regardless of whether message content has already been destroyed
- Infrastructure-level access blocking — Implementation of Cloudflare-level blocking rules targeting network identifiers associated with the reported activity, to the extent technically feasible and consistent with the minimal-retention architecture
- Rate limit reduction — Reduction of the message limit or implementation of additional verification requirements applied at the infrastructure level
- Platform-wide access restrictions — In cases of systematic or widespread abuse, implementation of additional access controls, verification requirements, or temporary service restrictions affecting all users
- Law enforcement referral — Referral of the matter to applicable law enforcement authorities with such information as the Operator possesses consistent with §9 and §12 of the Terms of Service
- NCMEC CyberTipline report — Mandatory reporting to the National Center for Missing and Exploited Children for any matter involving suspected CSAM, as required by 18 U.S.C. § 2258A
- Cooperation with legal process — Full cooperation with any properly issued subpoena, court order, or other legal process to the extent technically possible consistent with the minimal-retention architecture
7.2 Proportionality. The Operator will generally seek to apply the least restrictive effective response appropriate to the severity and nature of the reported conduct. However, for zero-tolerance category violations, the Operator will apply the most aggressive technically feasible response without regard to proportionality considerations.
7.3 No Appeal for Zero-Tolerance. Actions taken in response to zero-tolerance category violations (§3) are not subject to appeal or reversal. Actions taken in response to other reported violations may be reviewed upon written request to [email protected], subject to the Operator's sole discretion.
Technical Limitations on Moderation
Honest disclosure: The same minimal-retention architecture that protects legitimate users also limits what the Operator can do in response to abuse reports. This section explains those limitations plainly.
8.1 Destroyed Messages Cannot Be Recovered. Once a message has been destroyed — whether by timer expiration, read-trigger, or manual destruction — its content is permanently and irreversibly gone. The Operator cannot read, recover, preserve, or produce destroyed message content under any circumstances, including in response to abuse reports or law enforcement demands.
8.2 No Pre-Delivery Content Screening. The Operator does not screen, read, or moderate message content prior to delivery. Messages are encrypted at rest and not proactively reviewed by the Operator in the ordinary course. Moderation is therefore exclusively reactive.
8.3 No Persistent User Identity. Because the current Service requires no registration, the Operator cannot in most cases identify or permanently block a specific individual from the Service. Infrastructure-level blocking targets network identifiers that may be shared, dynamic, or easily changed.
8.4 No Persistent Message History. The Operator does not maintain a permanent history of destroyed messages. While a message is active, the Service stores only the temporary operational fields needed to deliver and delete that message. Aggregate analytics and counters are not used to identify message senders or recipients.
8.5 Third-Party Infrastructure Data. Certain data that may be relevant to abuse investigations — including IP address logs — may exist in the independent records of third-party infrastructure providers such as Cloudflare. The Operator does not control this data. Law enforcement with appropriate legal process may seek such data directly from those providers.
8.6 Good Faith Effort. Notwithstanding the technical limitations described in this section, the Operator commits to making a genuine good-faith effort to take every technically feasible action in response to credible abuse reports, particularly those involving zero-tolerance categories. The existence of technical limitations does not reduce the Operator's commitment to platform integrity.
Law Enforcement Referrals
9.1 The Operator will refer abuse matters to law enforcement in the following circumstances: (a) any credible report involving a zero-tolerance category violation (§3); (b) any report involving a credible, specific threat of imminent physical harm to an identified person; (c) any matter where the Operator independently determines, in its reasonable judgment, that law enforcement involvement is warranted in the public interest; or (d) any matter where applicable law imposes a mandatory reporting obligation.
9.2 Law enforcement referrals will be made to the appropriate federal, state, or local agency based on the nature of the reported conduct and the apparent jurisdiction. For CSAM matters, mandatory reports will be made to the NCMEC CyberTipline as required by 18 U.S.C. § 2258A regardless of other law enforcement referrals.
9.3 The Operator will provide law enforcement with any information within the Operator's actual possession that is relevant to the reported matter. Given the minimal-retention architecture, this information will in most cases be extremely limited. Law enforcement should also direct appropriate legal process to third-party infrastructure providers as described in §8.5 and in §12 of the Terms of Service.
9.4 The Operator's referral of a matter to law enforcement does not guarantee any particular investigative outcome and does not create any obligation on the part of the Operator beyond the referral itself.
Child Safety Policy
10.1 Zero Tolerance. The Operator maintains an absolute zero-tolerance policy for any use of the Service involving child sexual abuse material (CSAM), exploitation of minors, or any conduct targeting, grooming, or harming persons under the age of 18. There are no exceptions to this policy under any circumstances.
10.2 Mandatory Reporting. Pursuant to 18 U.S.C. § 2258A, the Operator is legally required to report any apparent violation of federal child sexual exploitation laws to the National Center for Missing and Exploited Children (NCMEC) CyberTipline. The Operator will comply with this obligation in all cases where it has knowledge or a credible report of such conduct.
10.3 NCMEC CyberTipline. Reports of suspected child sexual exploitation may also be made directly by any person to the NCMEC CyberTipline at www.cybertipline.org or by calling 1-800-843-5678. The FBI's Internet Crime Complaint Center (IC3) at www.ic3.gov also accepts reports of child exploitation offenses.
10.4 Age Minimum. The Service requires all users to be at least 18 years of age. See §10 of the Terms of Service for the full age requirement policy.
10.5 Priority Escalation. All abuse reports that appear to involve minors in any capacity will be treated as priority escalations and processed ahead of the standard review queue regardless of when they are received.
Platform Integrity Reserve
11.1 The Operator reserves the right, exercisable at its sole and absolute discretion, to restrict, suspend, or terminate the Service in whole or in part if the Operator determines that the Service is being systematically misused in a manner that: materially compromises the platform's legal standing or exposes the Operator to significant legal liability; results in a pattern of harm to identifiable victims that the Operator's technical measures are insufficient to address; causes the Service to be de-indexed, de-platformed, or denied services by critical infrastructure or distribution partners; or otherwise threatens the viability of the Service as a legitimate privacy platform.
11.2 In the event of a platform integrity determination under §11.1, the Operator may implement any of the following responses: require user registration or email verification for Service access; reduce message limits to zero pending further review; implement additional identity verification or bot mitigation measures; temporarily suspend new message creation while preserving access to existing messages; or permanently discontinue the Service.
11.3 The Operator's preference is to maintain an open platform. Platform integrity measures are a last resort, not a first response. The Operator will exhaust targeted, proportionate responses before implementing platform-wide restrictions.
Prohibition on Vigilante Action
12.1 Users who submit abuse reports must not take independent action to investigate, expose, retaliate against, or otherwise respond to the party they are reporting. Submitting an abuse report to the Operator is the appropriate and only authorized channel for addressing suspected misuse through this platform.
12.2 The Operator will not facilitate, assist, or provide information in support of any individual's independent investigation of another user. User privacy — including the privacy of users suspected of misuse — is protected by the same minimal-retention architecture that protects all users until and unless appropriate legal process compels otherwise.
12.3 Any user who uses the Service or the abuse reporting process to conduct harassment, doxxing, or retaliation against another party will themselves be subject to the full range of enforcement actions described in §7.
Good Faith Reporting Requirement
13.1 Abuse reports must be submitted in good faith based on a genuine, reasonable belief that the reported conduct constitutes a violation of this Policy or the Terms of Service. The Operator reserves the right to disregard abuse reports that are clearly frivolous, submitted in bad faith, or submitted as a tool of harassment against another user.
13.2 The Operator does not impose penalties on reporters who submit good-faith reports that turn out to be unfounded after review. The absence of verifiable violations does not render a good-faith report improper.
13.3 Users who systematically submit false or bad-faith abuse reports as a tool to disrupt the Service or harm other users will be subject to infrastructure-level access restrictions consistent with §7.
Contact, Response Times & Escalation
14.1 Primary Abuse Contact:
DigiMktg Co. LLC — Abuse & Moderation
Email: [email protected]
Subject Line Required: "ABUSE REPORT"
Operating: PhantomLink.app
State of Incorporation: Illinois, USA
14.2 Response Time Commitments:
- Zero-tolerance category reports — Escalated immediately upon receipt; action taken as rapidly as technically feasible, as rapidly as commercially and technically feasible
- Imminent physical threat reports — Treated as priority alongside zero-tolerance reports; contact emergency services (911) first
- All other abuse reports — Acknowledgment, review, and action determination as soon as commercially reasonable based on severity, volume, and technical feasibility
- Law enforcement & legal counsel — Directed to [email protected]; responses within a commercially reasonable time consistent with §12 of the Terms of Service
14.3 External Reporting Resources. The Operator encourages reporters to also utilize appropriate external reporting resources where applicable:
- CSAM / Child Exploitation: NCMEC CyberTipline — cybertipline.org / 1-800-843-5678
- Internet Crime: FBI IC3 — ic3.gov
- Cyberstalking / Harassment: Cyber Civil Rights Initiative — cybercivilrights.org
- Terrorism / Imminent Threat: FBI tip line — tips.fbi.gov
- Human Trafficking: National Human Trafficking Hotline — 1-888-373-7888
14.4 Submission of a report to an external resource does not substitute for submission to the Operator if you also wish the Operator to take platform-level action. Likewise, submission to the Operator does not substitute for law enforcement reporting where criminal conduct is suspected.