Acceptable Use Policy
BITFOO LLC · Version 1.0 · Effective
Guide to the document
In Plain Language
A short summary of what follows. It is here to help you understand the policy, not to replace it.
- Most of this is what you'd expect. Don't break the law, don't attack anyone, don't spam, don't host material that harms people. If you run a normal business on our infrastructure, none of this will ever come up.
- You're responsible for everything on your account — including what your own customers and users do. If you run a platform, their conduct is your conduct as far as we're concerned.
- Some uses need a conversation first. Not because they're wrong, but because they need the right infrastructure and the right expectations. The list is in Section 7. Ask us; we're not looking for reasons to say no.
- A few things are absolute. Material that sexually exploits children, promotes terrorism, or incites violence or hatred against people for who they are. No approval process, no exceptions.
- We protect the network first. If something you're running is actively harming other people, we'll stop it immediately and talk to you afterward. Everything else gets notice and a chance to fix it.
- Our IP reputation is shared. We run our own network. If mail from your account gets our address space blocklisted, it affects every client we have — which is why the email rules are stricter than you might expect.
- We don't read your data. We may look when we're investigating a specific problem or when the law requires it. We don't monitor, and we don't want to.
- If we suspend you, we'll tell you why. You can ask us to reconsider. We won't promise to change our mind.
This summary is not part of the policy and has no legal effect. It is simplified and leaves things out. The numbered sections below are the actual terms, and they govern in full. Where this summary and the policy differ, the policy applies.
The policy
1. Purpose and Scope
1.1 This Acceptable Use Policy (“Policy”) governs use of all services provided by BITFOO LLC (“Bitfoo,” “we,” “us”). It forms part of our Terms of Service and, where the two conflict, this Policy takes precedence — because it protects our infrastructure, our other clients, and third parties.
1.2 Who this binds. This Policy applies to you as our client, and to everyone who uses services through your account: your employees, contractors, customers, end users, and anyone you permit access. You are responsible for their conduct as if it were your own.
1.3 Our infrastructure. We operate our own network and address space, and deliver services over facilities provided by more than one infrastructure supplier. Those suppliers impose their own acceptable use requirements. Where a supplier’s requirements are stricter than this Policy for the infrastructure your service runs on, the stricter requirement applies to you. We may place your services on, or move them between, our networks and suppliers, and may apply network-specific restrictions where a supplier requires it.
1.4 This list is not exhaustive. We cannot anticipate every way our services might be misused. The prohibitions below are examples of what is unacceptable, not a complete catalogue. We reserve the right to act on conduct that is not listed here but that is harmful, unlawful, or exposes us or our clients to risk.
1.5 Copyright complaints are handled under our DMCA and Copyright Policy. Abuse reporting procedures are set out in Section 9.
2. Prohibited Content
2.1 Absolutely prohibited. The following may never be stored, hosted, transmitted, or linked to through our services, under any circumstance, with no approval available:
-
Child sexual abuse material, and any content that sexually exploits or depicts the sexual exploitation of a minor. See Section 12.3.
-
Content promoting, facilitating, or celebrating terrorism or violent extremism.
-
Content facilitating human trafficking, forced labor, or the sexual exploitation of any person.
-
Content inciting violence or hatred against a person or group on the basis of race, color, ethnicity, national origin, religion, disability, sex, gender identity, or sexual orientation.
-
Non-consensual intimate imagery, and any sexual content depicting a person who has not consented to its creation or distribution.
-
Content depicting non-consensual sexual acts or extreme violence.
2.2 Also prohibited. The following may not be stored, hosted, transmitted, or distributed:
-
Malware, ransomware, worms, rootkits, exploit kits, botnet infrastructure, and command-and-control systems.
-
Phishing pages, credential-harvesting systems, and fraudulent replicas of other organizations’ sites or services.
-
Stolen financial data, stolen credentials, stolen personal data, and tooling for carding or account takeover.
-
Counterfeit goods, and content offering them.
-
Marketplaces or services facilitating the sale of illegal drugs or controlled substances.
-
Content that infringes copyright, trademark, patent, trade secret, or other intellectual property rights.
-
Content that harasses, threatens, stalks, or intimidates a specific person, including doxxing.
-
Content designed to defraud or materially deceive.
2.3 Legal baseline. Except for Section 2.1, which applies without exception, the baseline standard is the law of the United States. We will additionally remove or restrict access to content where a jurisdiction in which the content is accessible requires it, or where a competent authority or court so orders.
2.4 Adult content. Legal, consensual adult content involving only adults is not prohibited, but is a restricted use requiring prior approval under Section 7. Hosting it without approval is a violation of this Policy. Section 2.1 applies to it in full and without exception.
3. Prohibited Conduct
3.1 You must not:
-
Provide false, misleading, or incomplete registration, billing, or contact information, or operate an account under an alias intended to conceal identity.
-
Use our services in furtherance of fraud, deception, or any unlawful scheme.
-
Impersonate any person or organization, or misrepresent your affiliation with one.
-
Use our services in violation of applicable sanctions or export control laws. See our Terms of Service.
-
Resell or provide our services to any person or entity we have refused, suspended, or terminated, or to any operator listed in the Spamhaus Register of Known Spam Operations (“ROKSO”). We refuse service to ROKSO-listed operators and to businesses under their control.
-
Circumvent, or attempt to circumvent, any limit, quota, isolation boundary, or access control applied to your account.
-
Abuse our provisioning, reboot, or automation systems, including by repeated or automated use intended to disrupt.
-
Direct abusive, threatening, or harassing conduct at our staff or our service partners.
4. Network and Security
4.1 Prohibited activity. You must not:
-
Access, or attempt to access, any system, account, network, or data you are not authorized to access.
-
Probe, scan, or test the vulnerability of any third party’s system or network.
-
Participate in, launch, or contribute to any denial-of-service or distributed denial-of-service attack.
-
Intercept, sniff, or monitor traffic not intended for you.
-
Forge, spoof, or falsify any IP address, MAC address, packet header, or routing information. IP source address spoofing is prohibited.
-
Interfere with, degrade, or attempt to disrupt service to any other user, host, or network.
-
Access or attempt to access another client’s data, whether or not access controls prevented it.
4.2 Open resolvers and amplification services. You must not operate an open recursive DNS resolver, or any DNS, NTP, SSDP, memcached, or similar service configured to respond to unrestricted third-party requests. These services are routinely exploited to amplify denial-of-service attacks, and the resulting traffic appears to originate from our address space. We may null-route or suspend any service found to be operating as an amplifier, immediately and without prior notice.
4.3 Address space and routing. All IP addresses assigned to you remain under our control. No ownership or portability of any assigned address is granted or implied, and we may reassign, renumber, or reclaim addresses as operationally required.
Where we announce address space on your behalf, you may only request announcement of address space that you demonstrably control. You must provide authorization documentation on request and keep your registry and routing records accurate and current. Requesting or causing announcement of address space you are not authorized to announce is a serious violation and grounds for immediate termination without notice or refund. Minimum prefix sizes, authorization requirements, and announcement withdrawal timelines are set out in our Service Terms.
4.4 Reverse DNS. Where you are able to set reverse DNS records for addresses assigned to you, the hostname’s forward DNS record must already resolve to that address. Records must not be deceptive, must not impersonate another organization, and must not be offensive. We may reset or remove any record that does not meet this standard.
4.5 Blacklisting. Causing any Bitfoo IP address, address range, or domain to be listed on a public or private blocklist, spam reputation list, or threat-intelligence feed is itself a violation of this Policy, independent of the underlying conduct. Because we operate our own address space, such listings affect every client we serve and cannot be resolved by moving infrastructure.
4.6 Attack traffic. Where a service you operate attracts denial-of-service or other attack traffic that degrades or threatens service for others, we may filter, rate-limit, null-route, or suspend that service, and may require you to migrate to a different product or, where it cannot be adequately mitigated, to leave our network. We will inform you as soon as reasonably practicable. This is not a failure to provide the service.
4.7 Your security obligations. You must maintain the security of your own services, including keeping operating systems, applications, plugins, and dependencies patched and current. You are responsible for all activity originating from your account, including activity resulting from a compromise. A compromised service that is attacking others, sending spam, or hosting harmful content will be treated as a violation and acted on accordingly, whether or not you knew about it.
4.8 Testing your own services. You may conduct vulnerability scanning, penetration testing, or load testing against your own services only, and only with our prior written approval. Requests must state the testing window, the source IP addresses, and the scope. Testing shared infrastructure, our control plane, our network equipment, or any other client’s services is prohibited and will be treated as a security violation. Approval requests go to support@bit.foo.
4.9 Our security measures. We may scan services on our network for known malware, known vulnerabilities, and signs of compromise, and may act on what we find under Section 10.
5. Email and Outbound Messaging
We operate our own address space. A blocklisting caused by one account affects every client we have and travels with us across every network we use. That is why this section is stricter than you may be used to.
5.1 Consent. You must not send unsolicited bulk or commercial email. Confirmed opt-in is required for all bulk sending — the recipient must have taken a positive action to subscribe and confirmed it. You must retain evidence of consent and produce it on request.
5.2 Prohibited lists. You must not send to purchased, rented, harvested, scraped, or third-party-supplied mailing lists, however they are described.
5.3 Authentication. If you send outbound mail, you must publish valid SPF records and sign your mail with DKIM. We recommend publishing a DMARC record, and recommend starting at p=none while you confirm every sending source is properly authenticated. Moving to p=quarantine or p=reject before doing so will cause legitimate mail to be rejected.
5.4 Technical prohibitions. You must not operate an open mail relay or open proxy; forge, falsify, or omit message headers or envelope information; use an unsubscribe mechanism that does not function; or fail to honor an unsubscribe request promptly.
5.5 Your own abuse handling. If you send mail on behalf of others, or operate a service that sends mail, you must maintain a monitored abuse address, and must be able to receive, investigate, and act on complaints promptly.
5.6 Sending limits. Outbound volume limits applicable to your service are stated in its Service Description. Exceeding them may result in throttling, review, or suspension. Higher limits may be available on request with justification.
5.7 Outbound port 25. Outbound SMTP is available by default on web hosting services. It is closed by default on unmanaged services and may be opened on request, subject to review of your intended use.
5.8 Dedicated sending addresses. Where we provide a dedicated address for sending, warm-up requirements and complaint and bounce thresholds are set out in the Service Description and must be followed.
6. Resource Use
6.1 Resource limits — including processor, memory, storage, input/output, inodes, bandwidth, processes, and connections — are stated in your Service Description. We meter and enforce different resources on different services; the applicable limits are those stated for the service you purchased.
6.2 You must not consume resources in a manner that degrades service for others, whether or not you are within your stated allocation.
6.3 Shared hosting. Shared hosting is designed for websites. The following are not permitted on shared hosting and require a VPS or dedicated service:
-
Scheduled tasks running more frequently than every 15 minutes.
-
Persistent background processes, daemons, or long-running scripts.
-
Media transcoding or video encoding.
-
Using the account primarily as file, backup, or archive storage not connected to a hosted website.
-
Public file-upload endpoints without moderation.
-
Proxy, tunnelling, or relay scripts.
-
Game servers.
-
Cryptocurrency mining, which is prohibited on shared hosting in all cases and regardless of any approval under Section 7.
6.4 Virtual servers. Where a service is provided on a shared-processor tier, sustained utilization at or near full allocation for extended periods may trigger review. Our normal response is to offer a dedicated-processor tier rather than to suspend. Whether a tier is shared or dedicated is stated in its Service Description.
6.5 We may throttle, suspend, or require an upgrade where usage exceeds applicable limits, and may charge for excess usage where the Service Description provides for it.
7. Restricted Uses Requiring Approval
7.1 The uses below are permitted, but require our written approval before you begin. Operating them without approval is a violation of this Policy.
We publish this list so you know where you stand before you buy. Approval is not a formality, but it is also not adversarial — most requests are approved.
7.2 Restricted uses:
-
Adult content that is legal, consensual, and involves only adults.
-
Any service that permits, or may result in, third parties uploading or publishing sexually explicit content — including file-sharing services, image hosts, paste sites, dating platforms, and social or community platforms. This is subject to the same notice and approval standard as adult content, because our infrastructure suppliers differ in what they permit.
-
Cryptocurrency mining. Not available on shared hosting in any case.
-
Cryptocurrency exchanges, wallets, custody, and trading platforms.
-
VPN and proxy services.
-
Tor exit nodes.
-
Torrent trackers and seedboxes, for lawful content only.
-
Bulk or transactional email sending as a primary business, including email service providers and newsletter platforms.
-
Online gambling, casino, betting, lottery, and sweepstakes services, which must hold all required licences.
-
Security research services, penetration testing platforms, and vulnerability scanning tools offered as a service.
-
Machine learning training or inference workloads at high sustained utilization.
-
Lending, foreign exchange, and investment or brokerage platforms.
7.3 Prohibited financial services. Debt relief, debt settlement, debt negotiation, debt consolidation, and credit repair or credit counselling services are prohibited and no approval is available.
7.4 Permitted with conditions. The following do not require prior approval, but carry the stated conditions:
-
IRC servers — permitted. Servers connecting to global IRC networks are permitted, but we ask that you tell us first so we can accommodate the traffic profile and avoid an avoidable suspension. Section 4.6 applies where a server attracts attack traffic.
-
File-sharing, image hosting, paste, dating, and social platforms — permitted, provided you maintain and enforce your own acceptable use policy that is at least as protective as this one. Section 7.2 applies if explicit content is possible on your service.
-
Cannabis and CBD, firearms and ammunition, and pharmacy or nutraceutical businesses — permitted, provided the business is lawfully registered and holds all licences and authorizations required in every jurisdiction in which it operates.
-
Streaming and media distribution, and game servers — permitted.
-
Announcing your own address space through our network — permitted, subject to Section 4.3.
7.5 How to request approval. Open a ticket, or email support@bit.foo, with a detailed description of your intended use and any supporting documentation. Depending on the request, we may require identity verification, business registration or licensing documents, a call, a deposit or prepayment, different pricing, or periodic review. We will confirm any approval in writing and record its scope.
7.6 Scope and withdrawal. Approval covers only the use case described in your request. If what you do changes materially, you must tell us and seek approval again. We may withdraw approval where the use case has changed, where circumstances have changed, or where the arrangement is no longer workable, and will give reasonable notice where we can.
7.7 Our discretion. This list is not exhaustive. We may treat any use as requiring approval, and may decline any request, at our discretion.
8. Resellers
8.1 If you provide services to your own customers using our services, this Policy binds both you and them. You are responsible for their conduct.
8.2 You must maintain and enforce your own acceptable use policy with your customers that is at least as protective as this one.
8.3 Where a customer of yours violates this Policy, we may act against that customer’s service, against your account as a whole, or both, at our discretion.
8.4 You must obtain our approval before providing any service in a category listed in Section 7.2 to your own customers.
8.5 You must not represent yourself as Bitfoo, as our agent, or as accredited by any registry or authority by which you are not accredited.
9. Reporting a Violation
9.1 Where to report. Abuse reports: abuse@bit.foo. Copyright complaints: dmca@bit.foo, under our DMCA and Copyright Policy.
9.2 What a report must contain. So that we can investigate:
-
Your name, organization, and a contact email address.
-
The IP address, domain, or full URL involved.
-
The date and time of the activity, including the timezone.
-
The type of abuse.
-
Supporting evidence — full message headers for spam, log excerpts with timestamps for network abuse, screenshots or archived copies for content.
-
A statement that the report is made in good faith, and, where you act for a rights holder or organization, a statement of your authority to do so.
Reports without an IP address or a timestamp with timezone usually cannot be investigated, because we cannot identify which service was responsible.
9.3 What we do. We review every report we receive. Our targets are:
-
Acknowledgement within 24 hours.
-
Action on verified critical reports within 4 hours — active phishing, malware distribution, outbound attack traffic, and network abuse.
-
Action on verified standard reports within 24 hours.
These are targets, not guarantees.
9.4 We may acknowledge receipt of a report. We do not disclose the outcome of an investigation or what action was taken, as that concerns our client’s account.
9.5 We may decline to act on reports that are made in bad faith, are automated bulk submissions without substance, or are unsupported by evidence. We review them regardless.
10. Enforcement
10.1 Non-urgent violations. Where a violation is not causing active harm, we will normally notify you and give you a deadline to correct it — usually 24 hours. We may suspend the affected service if it becomes clear the issue is affecting others.
10.2 Active harm. Where conduct is actively harming our network, our clients, or third parties, we will act immediately and without prior notice, and will inform you afterward. This includes live phishing pages, malware distribution, outbound attacks, mail floods, amplification traffic, and compromised systems.
10.3 What we may do. Depending on severity, we may: issue a warning; require corrective action by a deadline; filter, throttle, or null-route traffic; remove or disable specific content; suspend the affected service; suspend your entire account; or terminate.
10.4 No fixed schedule. We do not operate a fixed number of warnings. Our response depends on severity, impact, whether the conduct was deliberate, and whether it has happened before.
10.5 We will tell you why. Where we suspend or terminate a service, or remove content, we will give you a written statement of the reason. We may withhold or delay that statement where providing it would prejudice an investigation, breach a legal obligation, or where we are prohibited from disclosing it.
10.6 Asking us to reconsider. You may ask us to review a decision by opening a ticket or emailing support@bit.foo. We will consider it. We do not guarantee an outcome or that a decision will be changed.
10.7 No refunds. Where a service is suspended or terminated for violating this Policy, prepaid fees are not refunded.
10.8 Costs. Where your account causes us to incur costs in responding to abuse, you are responsible for them. This includes charges levied on us by our infrastructure suppliers, disconnection and reconnection fees, and our time in investigating, mitigating, and obtaining removal from blocklists or reputation lists. We will itemize any charge.
10.9 No waiver. If we do not act on a violation, or do not act immediately, that is not a waiver of our right to act on it later or on any other violation. Tolerating conduct once does not permit it.
11. Investigation and Access
11.1 We do not monitor. We do not routinely review, screen, or monitor client content or traffic, and we have no obligation to do so.
11.2 When we may access. We may access, review, and copy content, logs, and traffic data where reasonably necessary to investigate a suspected violation, to respond to an abuse report, to operate or secure our services, to comply with a legal obligation, or to respond to lawful process.
11.3 Service providers. Investigation may be carried out with the assistance of third-party service providers acting under confidentiality obligations. Categories of service providers are identified in our Privacy Policy.
11.4 Preservation. We may preserve content, logs, and records relating to a suspected violation or suspected unlawful activity, including after a service has been suspended or terminated, where necessary to comply with a legal obligation or to respond to anticipated legal process.
12. Law Enforcement and Legal Obligations
12.1 We cooperate with lawful requests from law enforcement and other competent authorities, and disclose information as required by valid legal process.
12.2 We may report activity we reasonably believe to be unlawful to the appropriate authorities. We may do so without notifying you, and will not notify you where doing so is prohibited or would prejudice an investigation.
12.3 Child sexual abuse material. Where we obtain actual knowledge of apparent child sexual abuse material or related offenses, we report it to the National Center for Missing & Exploited Children as required by United States federal law, preserve the relevant material and records as the law requires, and terminate the account. There is no notice period, no cure period, and no refund.
13. Changes to This Policy
13.1 We may update this Policy. For material changes we will give at least 30 days’ notice by email and by publishing the updated Policy with a new version number and effective date.
13.2 Changes required by law, by a regulator, by an infrastructure supplier, or to address an active security, legal, or operational risk may take effect immediately on publication and notice.
13.3 Corrections, clarifications, and formatting changes take effect on publication.
13.4 Each version carries a version number and effective date, with a change log recording prior versions.
Contact
BITFOO LLC 146 East King St, Unit #1283 Lancaster, PA 17602 United States
Abuse reports: abuse@bit.foo · Copyright: dmca@bit.foo · Approval requests and support: support@bit.foo · Legal: legal@bit.foo · Privacy: privacy@bit.foo