Draft framework · not in force
Acceptable Use Policy
A review framework for the prohibited-use definitions, evidence requirements, and enforcement procedures required by Bitfoo’s final acceptable-use policy.
Review status: Awaiting legal review
1. Purpose and scope
Explain which customers, users, services, and content are covered and how this policy relates to the Terms of Service.
Information required before approval:
- Covered services and users
- Customer responsibility for downstream users
- Relationship with product-specific limits
2. Illegal and harmful activity
Define prohibited unlawful, fraudulent, abusive, exploitative, or dangerous use with counsel-approved scope.
Information required before approval:
- Applicable legal and jurisdictional standards
- Fraud, phishing, malware, exploitation, and unauthorized-access categories
- Threats, harassment, and safety escalation
3. Network and platform abuse
Address attacks, scanning, interference, circumvention, and activity that threatens the service or other users.
Information required before approval:
- Unauthorized scanning and access rules
- Denial-of-service and resource-abuse standards
- Security-research authorization route if offered
4. Content and intellectual property
Define prohibited content categories and the process for copyright or trademark reports.
Information required before approval:
- Illegal-content and rights-infringement standards
- Complete DMCA agent and notice procedure if applicable
- Counter-notice and repeat-infringer process
5. Email and messaging
Set requirements for consent, sender identity, complaint handling, and abuse prevention.
Information required before approval:
- Unsolicited and bulk-message rules
- Applicable anti-spam requirements
- Compromised-account and blocklist response process
6. Resource and service integrity
Explain prohibited resource behavior using published product limits rather than vague unlimited-use language.
Information required before approval:
- Shared-hosting resource and process boundaries
- VPS network and platform-integrity requirements
- Mining, proxy, scraping, or automation rules if applicable
7. Investigation and enforcement
Describe reports, evidence review, urgent action, notice, remediation, suspension, and termination.
Information required before approval:
- Proportionate enforcement stages
- Emergency and legal-request handling
- Appeal or remediation process
8. Reporting violations
Publish the information needed for abuse, security, and rights-holder reports.
Information required before approval:
- Verified abuse and security contacts
- Required timestamps, identifiers, logs, and declarations
- Privacy and confidentiality handling