Terms & conditions
Last updated: 29 July 2026.
1. Service
Urlgate provides domain classification, blocklist aggregation, optional parental DNS features, and a public JSON lookup API (“the Service”). The Service may be used together with The Vig or as a standalone filtering front-door. Features and availability may change as we iterate.
2. Accounts
Access to filter administration requires an email magic link and mandatory authenticator (TOTP) two-factor authentication. You are responsible for protecting your mailbox and authenticator device. Do not share DoH profile tokens or Android Private DNS hostnames publicly.
3. Public lookup & navigate APIs
The endpoints GET/POST /api/v1/lookup, POST /api/v1/navigate
(open default), and POST /api/v1/navigate/<token>
(per-filter; token is secret) are available without an API key. Lookup returns
mega-list classification; navigate returns the single URL a WebView should load
(SafeSearch rewrite, block page, or echo). By using them you agree to:
- Reasonable request rates suitable for interactive or light automation use.
- Not run bulk scraping, flooding, or denial-of-service against the Service.
- Treat results as advisory — classifications can be wrong, incomplete, or delayed.
- Not imply Urlgate endorses or partners with your product solely because you call the public API.
We may throttle, block, or change the public API without notice if abuse or capacity
requires it. Authenticated POST /api/v1/check
(API key) is intended for private integrations such as The Vig.
4. Acceptable use
You agree not to:
- Abuse the public lookup API, authenticated check API, or DNS endpoints (flooding, scraping beyond reasonable use).
- Attempt to bypass or undermine filtering for devices you do not administer.
- Use the Service to violate applicable law or third-party rights.
- Probe, attack, or overload infrastructure hosting Urlgate.
5. Filtering accuracy
Blocklists are assembled from third-party sources and our own policy. Classifications can be wrong, incomplete, or delayed. Urlgate does not guarantee that every unwanted domain is blocked or that every legitimate domain is allowed. You remain responsible for how you apply results in your products and networks.
6. API and DNS availability
We aim for reliable uptime but do not warrant uninterrupted service. Downstream products (including The Vig) should treat Urlgate as advisory and implement fail-open or fallback behaviour where appropriate.
7. Data
We store account email, authentication material (hashed magic-link tokens; encrypted TOTP secrets), filter configuration, and aggregated list data. Public and authenticated checks may be logged for operations, abuse detection, and analytics (host, verdict, categories, coarse client metadata). Do not send secrets or personal data in lookup URLs. See your deployment’s privacy practices for production hosting specifics.
8. Third-party lists
Upstream list providers retain their own licences and terms. Urlgate redistributes merged host data for filtering purposes; you should review those providers’ terms for your jurisdiction and use case.
9. Limitation of liability
To the fullest extent permitted by law, Urlgate and its operators are not liable for indirect, incidental, or consequential damages arising from use of the Service, including false positives/negatives, DNS misconfiguration, API misuse, or dependency outages.
10. Changes
We may update these terms by posting a revised version on this page. Continued use after changes constitutes acceptance of the updated terms.
11. Contact
For operational questions about a deployment you run, contact the server operator. Product documentation lives at /docs.