Acceptable use policy

Last updated: 2026-09-14

Summary

Emojery is a small, free, donation-funded service. The rules below exist so one person counts as one vote, the API stays available for everyone, and the reaction counts mean something. By signing in to Emojery you agree to follow them. Reading reactions anonymously is unrestricted; the rules apply to signed-in accounts and to anyone calling the API.

The reasoning behind several of these rules, especially the one-account-per-person and disposable-mail checks, is explained in How sign-in works.

1. One person, one account

Each person gets one Emojery account. Running multiple accounts to vote more than once on the same item, to inflate counts, or to evade rate limits and lockouts is not allowed. Additional provider accounts, or the same person on several providers, used to create additional identities count as multi-accounting.

2. No automation or bots

Reactions must come from a human action in a real browser. Scripted clicks, headless bots, paid or coordinated voting campaigns, and any tool that submits reactions on behalf of users without their direct, per-reaction consent are not allowed.

3. Use each endpoint the way it is published

The public endpoints. These are the status feed and the README badges. They are open for any legitimate use, including third-party clients and research. Stay within the rate limits they enforce: a 429 response means you have exceeded them and must back off before retrying. Mass scraping that ignores those limits, distributed scraping that fans the same workload across many IPs to defeat them, and unauthenticated write attempts are not allowed. The planned data API will publish its own quotas before its first endpoint goes live.

The extension endpoints are not a public API. Signing in, submitting a reaction, reading your own reactions, and sending a report are served for the Emojery extension published in the stores. The extension is GPL-3.0 and you are free to read it, study it, and change it; what the license covers is the code, not access to the hosted service the operator runs and pays for. A modified build, a fork, or any other client points at a backend of its own, which the repository documents as a build-time setting. If you want to reach ours instead, ask first: the API page says how, and an unapproved client calling those endpoints is a violation of this policy whether or not any single request looks ordinary.

4. Do not circumvent anti-abuse measures

Server-side abuse controls exist so the counts are not bot-driven. Probing them, evading them, or shaping traffic to slip past them is a violation even if no individual request would otherwise be illegitimate. The extension is GPL-3.0 and you are free to read, study, modify, and redistribute the code; this rule covers active circumvention of the server-side defenses, not source-level inspection.

5. Do not react on illegal or harmful targets

Submitting a reaction is a server-side write that we cache against a public URL. Do not use Emojery to interact with, draw attention to, or aggregate counts on:

We will remove reactions and aggregate entries that point at such targets on receipt of a credible report, and suspend the accounts behind them.

6. Do not abuse the report channel

The in-extension Report tab is for genuine bug reports and abuse notifications about the page you're on — new-site suggestions belong in a site request issue, and other product requests belong in a feature request issue. Sending spam, fake reports, or threatening content through the report channel is a violation and will lead to suspension.

7. Do not interfere with the service

No denial-of-service traffic, no amplification, no attempts to exhaust shared resources, and no probing or scanning outside the terms of our security policy. Security research is welcome and that page says what is in scope, what to avoid, and what you get in return for reporting privately — read it first, then open a private security advisory. Research that stays inside those terms is not a violation of this rule.

Enforcement

For clear violations we suspend or terminate the offending account by its hashed identifier. Termination decrements every aggregate counter that account previously contributed to, the same way a user-initiated deletion does. The account's provider-id hash is retained afterwards (even if the account is later deleted) so a termination can't be shed by deleting and re-registering the same provider account. We do not operate an appeals queue and we do not pre-announce enforcement actions.

Sustained or large-scale abuse, such as botnets, coordinated multi-accounting operations, or attempts to disrupt the service, may also be reported to the relevant network providers and, where applicable, to law-enforcement authorities.

Reporting abuse

The fastest way to report abuse, including reactions on illegal targets, is the Report tab in the extension popup — open it on the affected page so the URL is captured automatically. You can also open an issue on GitHub for non-urgent matters.

Complaints about a target

Emojery hosts no page content. A reaction points at somebody else's URL, and what we hold is a count, a per-user record, and a pseudonymous entry in a public log. That leaves 3 possible outcomes for a complaint, and it is fairer to state them up front than to let you find out after writing one:

Copyright. The pages Emojery reacts to are not ours, so a notice under the DMCA or its Canadian equivalent generally belongs with the host of the material. Where the material is something Emojery itself publishes (copy on this website, an asset shipped in the extension, or content in the public log), send the complaint through the privacy and legal issue template. Include the work affected, the URL where it appears, enough for us to see that you hold the right or act for whoever does, and a way to reach you. There is no separate copyright agent to escalate to; the operator reads these directly.

What happens next. A complaint is acknowledged within 5 business days, and answered with either the action taken or the reason it was refused. Complaints that turn out to be a way to suppress reactions someone dislikes are refused and, if they keep coming, ignored — the same rule the report channel gets in section 6.

Changes

We may revise this policy as the service evolves. The "Last updated" date above reflects the most recent change. Material changes will be surfaced in the extension settings on next launch; continued use after that point counts as acceptance of the revised policy. If you disagree, delete your account from the popup's Account tab — see the privacy policy for what that removes.