Legal

Acceptable use policy

A short policy, because a service that cannot read what it stores has no business pretending to enforce a long one.

Draft — not yet in force

This document is a working draft published for transparency. It has not completed legal review, is not incorporated into any agreement, and creates no rights or obligations. The definitive version will be published before general availability. For terms you can rely on today, contact legal@PLACEHOLDER_DOMAIN.example.

Prohibited uses

  • Content that is unlawful in the jurisdiction of any provider holding its shards, including child sexual abuse material, which we will report and act on without qualification.
  • Use of the service to distribute malware, to host command-and-control infrastructure, or to stage an attack on a third party.
  • Attempts to circumvent quotas, rate limits, metering, or billing, including provisioning credentials to evade caps.
  • Attacks against the service itself, against storage providers, or against other customers — as distinct from good-faith security research under our disclosure policy.
  • Reselling the service in a way that obscures the responsible party from us, where that prevents us meeting a legal obligation.
  • Content stored specifically to exhaust provider capacity or to manipulate the storage market rather than to be retained and retrieved.

How enforcement actually works

We should be direct about our position. Content is encrypted before it reaches us and we hold no filenames or content types, so we cannot scan for prohibited material and will not claim to. Enforcement is therefore complaint-driven and account-based: we act on reports from rights holders, law enforcement, storage providers, and the public, and our remedies are account-level — suspension of a credential and refusal to serve or repair the associated objects.

We consider this the correct trade-off rather than an unfortunate limitation. A provider that can inspect your data to police it can also inspect it for other reasons, and be compelled to. We would rather have narrower enforcement powers and a service that is structurally incapable of surveillance.

Reporting abuse

Reports go to legal@PLACEHOLDER_DOMAIN.example. Include whatever identifies the account or object to us — a credential identifier, an object key, or the context in which you encountered it. We acknowledge reports and tell you the outcome where we lawfully can.

Law enforcement requests

We respond to valid legal process in the jurisdictions that bind us. We will produce what we hold — account records, placement metadata — and we will tell you what we hold before you ask, which is on the privacy notice. Where permitted, we notify the affected customer before responding.