Acceptable use policy
Last updated: 2026-09-14
Summary
Emojery is a small, free, donation-funded service. The rules below exist so one person counts as one vote, the API stays available for everyone, and the reaction counts mean something. By signing in to Emojery you agree to follow them. Reading reactions anonymously is unrestricted; the rules apply to signed-in accounts and to anyone calling the API.
The reasoning behind several of these rules, especially the one-account-per-person and disposable-mail checks, is explained in How sign-in works.
1. One person, one account
Each person gets one Emojery account. Running multiple accounts to vote more than once on the same item, to inflate counts, or to evade rate limits and lockouts is not allowed. Additional provider accounts, or the same person on several providers, used to create additional identities count as multi-accounting.
2. No automation or bots
Reactions must come from a human action in a real browser. Scripted clicks, headless bots, paid or coordinated voting campaigns, and any tool that submits reactions on behalf of users without their direct, per-reaction consent are not allowed.
3. Use each endpoint the way it is published
The public endpoints. These are the status feed and the README badges. They are open for any legitimate use, including third-party clients and research. Stay within the rate limits they enforce: a 429 response means you have exceeded them and must back off before retrying.
Mass scraping that ignores those limits, distributed scraping that fans the same workload across many IPs to defeat them, and unauthenticated write attempts are not allowed. The planned data API
will publish its own quotas before its first endpoint goes live.
The extension endpoints are not a public API. Signing in, submitting a reaction, reading your own reactions, and sending a report are served for the Emojery extension published in the stores. The extension is GPL-3.0 and you are free to read it, study it, and change it; what the license covers is the code, not access to the hosted service the operator runs and pays for. A modified build, a fork, or any other client points at a backend of its own, which the repository documents as a build-time setting. If you want to reach ours instead, ask first: the API page says how, and an unapproved client calling those endpoints is a violation of this policy whether or not any single request looks ordinary.
4. Do not circumvent anti-abuse measures
Server-side abuse controls exist so the counts are not bot-driven. Probing them, evading them, or shaping traffic to slip past them is a violation even if no individual request would otherwise be illegitimate. The extension is GPL-3.0 and you are free to read, study, modify, and redistribute the code; this rule covers active circumvention of the server-side defenses, not source-level inspection.
5. Do not react on illegal or harmful targets
Submitting a reaction is a server-side write that we cache against a public URL. Do not use Emojery to interact with, draw attention to, or aggregate counts on:
- Child sexual abuse material (CSAM) or any content sexualising minors.
- Doxxing pages, non-consensual intimate imagery, or stalking targets.
- Direct threats, incitement to imminent violence, or coordinated harassment campaigns.
- Content that is illegal in the jurisdiction hosting the data (EU or US, depending on your assigned region).
We will remove reactions and aggregate entries that point at such targets on receipt of a credible report, and suspend the accounts behind them.
6. Do not abuse the report channel
The in-extension Report tab is for genuine bug reports and abuse notifications about the page you're on — new-site suggestions belong in a site request issue, and other product requests belong in a feature request issue. Sending spam, fake reports, or threatening content through the report channel is a violation and will lead to suspension.
7. Do not interfere with the service
No denial-of-service traffic, no amplification, no attempts to exhaust shared resources, and no probing or scanning outside the terms of our security policy. Security research is welcome and that page says what is in scope, what to avoid, and what you get in return for reporting privately — read it first, then open a private security advisory. Research that stays inside those terms is not a violation of this rule.
Enforcement
For clear violations we suspend or terminate the offending account by its hashed identifier. Termination decrements every aggregate counter that account previously contributed to, the same way a user-initiated deletion does. The account's provider-id hash is retained afterwards (even if the account is later deleted) so a termination can't be shed by deleting and re-registering the same provider account. We do not operate an appeals queue and we do not pre-announce enforcement actions.
Sustained or large-scale abuse, such as botnets, coordinated multi-accounting operations, or attempts to disrupt the service, may also be reported to the relevant network providers and, where applicable, to law-enforcement authorities.
Reporting abuse
The fastest way to report abuse, including reactions on illegal targets, is the Report tab in the extension popup — open it on the affected page so the URL is captured automatically. You can also open an issue on GitHub for non-urgent matters.
Complaints about a target
Emojery hosts no page content. A reaction points at somebody else's URL, and what we hold is a count, a per-user record, and a pseudonymous entry in a public log. That leaves 3 possible outcomes for a complaint, and it is fairer to state them up front than to let you find out after writing one:
- We can remove the Emojery side. Reactions and aggregate entries pointing at an illegal or harmful target are removed on a credible report, and the accounts behind them suspended — rule 5 above.
- We cannot remove the page. The content sits on the host platform. A takedown belongs with that platform or its hosting provider; nothing we do to a counter affects what is published there.
- We cannot erase the log. A removal is carried out by appending a public revocation to the append-only transparency log; the original entry stays, reversed. The property that makes counts verifiable is the same one that makes the record permanent — that is the design, not a refusal to help.
Copyright. The pages Emojery reacts to are not ours, so a notice under the DMCA or its Canadian equivalent generally belongs with the host of the material. Where the material is something Emojery itself publishes (copy on this website, an asset shipped in the extension, or content in the public log), send the complaint through the privacy and legal issue template. Include the work affected, the URL where it appears, enough for us to see that you hold the right or act for whoever does, and a way to reach you. There is no separate copyright agent to escalate to; the operator reads these directly.
What happens next. A complaint is acknowledged within 5 business days, and answered with either the action taken or the reason it was refused. Complaints that turn out to be a way to suppress reactions someone dislikes are refused and, if they keep coming, ignored — the same rule the report channel gets in section 6.
Changes
We may revise this policy as the service evolves. The "Last updated" date above reflects the most recent change. Material changes will be surfaced in the extension settings on next launch; continued use after that point counts as acceptance of the revised policy. If you disagree, delete your account from the popup's Account tab — see the privacy policy for what that removes.