Draft framework · not in force

Acceptable Use Policy

A review framework for the prohibited-use definitions, evidence requirements, and enforcement procedures required by Bitfoo’s final acceptable-use policy.

Review status: Awaiting legal review

1. Purpose and scope

Explain which customers, users, services, and content are covered and how this policy relates to the Terms of Service.

Information required before approval:

  • Covered services and users
  • Customer responsibility for downstream users
  • Relationship with product-specific limits

2. Illegal and harmful activity

Define prohibited unlawful, fraudulent, abusive, exploitative, or dangerous use with counsel-approved scope.

Information required before approval:

  • Applicable legal and jurisdictional standards
  • Fraud, phishing, malware, exploitation, and unauthorized-access categories
  • Threats, harassment, and safety escalation

3. Network and platform abuse

Address attacks, scanning, interference, circumvention, and activity that threatens the service or other users.

Information required before approval:

  • Unauthorized scanning and access rules
  • Denial-of-service and resource-abuse standards
  • Security-research authorization route if offered

4. Content and intellectual property

Define prohibited content categories and the process for copyright or trademark reports.

Information required before approval:

  • Illegal-content and rights-infringement standards
  • Complete DMCA agent and notice procedure if applicable
  • Counter-notice and repeat-infringer process

5. Email and messaging

Set requirements for consent, sender identity, complaint handling, and abuse prevention.

Information required before approval:

  • Unsolicited and bulk-message rules
  • Applicable anti-spam requirements
  • Compromised-account and blocklist response process

6. Resource and service integrity

Explain prohibited resource behavior using published product limits rather than vague unlimited-use language.

Information required before approval:

  • Shared-hosting resource and process boundaries
  • VPS network and platform-integrity requirements
  • Mining, proxy, scraping, or automation rules if applicable

7. Investigation and enforcement

Describe reports, evidence review, urgent action, notice, remediation, suspension, and termination.

Information required before approval:

  • Proportionate enforcement stages
  • Emergency and legal-request handling
  • Appeal or remediation process

8. Reporting violations

Publish the information needed for abuse, security, and rights-holder reports.

Information required before approval:

  • Verified abuse and security contacts
  • Required timestamps, identifiers, logs, and declarations
  • Privacy and confidentiality handling