Acceptable Use Policy
Last Modified: May 30, 2026 · Version 2026-05-30
This Acceptable Use Policy ("AUP") sets out the activities and content that are not allowed on Clustra. It expands §7 of the Terms of Service and is part of those Terms. Capitalised terms used here have the same meaning as in the Terms.
1. Purpose & Scope
Clustra is a shared platform. The rules below exist to keep the Service safe and reliable for everyone, to protect people from harm, and to keep Clustra and its users on the right side of the law. This AUP applies to:
- Every Account and every Workspace on the Service.
- Every Workspace Administrator, Editor, and Viewer, and any third party they let into a Workspace.
- Every API call, integration, and automation that touches Clustra under your credentials.
Workspace Administrators are responsible for the conduct of the members they invite and for the content their Workspace stores or transmits. If you do not control the conduct of someone using your Workspace, you should not let them in.
2. Prohibited Content
You will not upload, transmit, store, or share content that:
- Sexually exploits or endangers children — content that sexually exploits or abuses minors, including child sexual abuse material (CSAM), is strictly prohibited. We have zero tolerance for this content and will report it to the relevant authorities (including the U.S. National Center for Missing & Exploited Children where applicable) and preserve evidence as required by law.
- Promotes terrorism, mass violence, or serious self-harm — including content that incites, glorifies, or recruits for terrorism or organised violence, or that promotes suicide, self-harm, or eating disorders to a vulnerable audience.
- Incites hatred or targeted harassment — content that attacks people based on race, ethnicity, national origin, religion, caste, gender, gender identity, sexual orientation, disability, or serious medical condition.
- Is defamatory, threatens, or harasses individuals — including stalking, doxxing, non-consensual intimate imagery, or coordinated targeting campaigns.
- Infringes intellectual property — content that violates copyrights, trademarks, trade secrets, or other proprietary rights of any person.
- Violates privacy or publicity rights — non-consensual sharing of personal information that a reasonable person would consider private.
- Is unlawful in the jurisdiction it is published or processed in — including, where applicable, content prohibited under the U.S. Digital Millennium Copyright Act, the EU Digital Services Act, the UK Online Safety Act, and the Nigeria Cybercrimes Act.
- Contains malicious code — viruses, worms, trojans, ransomware, cryptominers, keyloggers, or any other code designed to interfere with, gain unauthorised access to, or damage any system or data.
3. Prohibited Activities
3.1 Abuse of the Service
- Reverse engineering, decompiling, disassembling, or attempting to derive source code from the Service, except to the extent applicable law prohibits us from restricting that activity.
- Renting, reselling, sublicensing, or making the Service available to anyone other than the members of your Workspace, except as expressly permitted by us in writing.
- Misrepresenting your identity or your association with any person or organisation, including by creating Accounts with false information.
- Using the Service in a way that fraudulently induces another person to disclose credentials, payment information, or personal data (phishing, business-email-compromise, romance scams, fake support, etc.).
- Building or training a competing product or service using Customer Content of other customers, or scraping, harvesting, or extracting data from the Service for that purpose.
3.2 Resource & rate-limit abuse
- Sending automated traffic that exceeds the documented rate limits or that materially degrades the Service for other users.
- Hosting content or running workloads whose purpose is to consume free-tier resources without a legitimate intent to use the Service for its stated purpose.
- Using the Service as a cryptocurrency mining platform, an open relay, an open proxy, or a node in a botnet or any other unauthorised network.
- Using the Service primarily for bulk file storage or as a content distribution network for content unrelated to your Workspace's legitimate use of the Service.
3.3 Circumvention
- Bypassing or attempting to bypass authentication, authorisation, rate limits, billing, seat counts, plan entitlements, or any other technical control.
- Creating multiple Accounts to circumvent suspensions, bans, free-tier limits, or trial-period restrictions.
- Using the Service in a manner inconsistent with the documented purpose of an API or feature.
4. Security & Integrity
- You will not access, or attempt to access, Accounts, Workspaces, data, or systems that you are not authorised to access.
- You will not probe, scan, or test the vulnerability of the Service or any related system or network, except as permitted by §13.2 of the Security Policy.
- You will not interfere with or disrupt the integrity, performance, or availability of the Service, including by denial-of-service or amplification attacks.
- You will not introduce malware, backdoors, or other harmful code, and you will not store such code in a Workspace in a manner that could cause it to be executed by other users.
- You will not interfere with our logging, monitoring, alerting, or audit-trail systems, or attempt to disguise the origin or attribution of your activity on the Service.
5. No Spam or Unsolicited Communications
- You will not use the Service to send unsolicited commercial or bulk messages.
- Outbound email and notifications you trigger through the Service must comply with the law of the recipient's jurisdiction, including the U.S. CAN-SPAM Act, the EU and UK ePrivacy Directive implementations, Canada's CASL, and the Nigeria Cybercrimes Act.
- Mailing lists must be opt-in. Every commercial message must identify the sender accurately and offer a working unsubscribe option.
- You will not impersonate other users, employees of Clustra, or any third party in messages sent from the Service.
6. Children's Safety
The Service is not directed to children under 16 (or under 13 where U.S. COPPA applies). You will not use the Service to collect, store, or process personal data of children below those ages, and you will not invite anyone you know to be below the applicable age into a Workspace. Suspected CSAM is removed immediately, the responsible Account is terminated, and the matter is reported to the relevant authority.
7. Privacy & Data Abuse
- You will not use the Service to violate any person's privacy, including by uploading personal data you do not have a lawful basis to process.
- You will not use the Service to enrich profiles, build people-search databases, or perform surveillance of individuals without a clear lawful basis.
- You will not export Customer Content of another customer or Workspace except as expressly permitted.
- You will not use the Service to train artificial-intelligence or machine-learning models on third-party personal data without the lawful basis and disclosures required by applicable privacy law.
- If you are using the Service to process special categories of personal data (for example health data) or other regulated data (for example financial or children's data), you must have your own compliant arrangements in place, including any required consents and impact assessments.
8. Automation & AI Use
- Use of bots, scrapers, or other automation against the Service must respect documented API contracts and rate limits and must not impersonate human activity to defeat abuse controls.
- You will not use the Service to generate or distribute content that misleadingly impersonates a real person, including by creating non-consensual deepfakes or synthetic media used for fraud.
- You will not use the Service to generate disallowed content described in §2.
- You are responsible for the outputs of any automation or AI you run through the Service and for ensuring those outputs comply with this AUP and applicable law.
9. Sanctions & Export Controls
You will not use the Service in any way that violates U.S., U.K., EU, U.N., Nigerian, or other applicable sanctions or export-control laws. You will not provide access to the Service to any sanctioned person or entity, and you will not use the Service to transmit controlled technology to a destination or person to which export is prohibited.
10. Reporting Violations
If you believe someone is using Clustra in violation of this AUP, please report it:
- Abuse and acceptable-use violations: abuse@clustra.org
- Security vulnerabilities: security@clustra.org
- Suspected CSAM: abuse@clustra.org — do not attach or forward the underlying material; share the location (workspace, URL, or message reference) and a brief description so we can review and preserve evidence lawfully.
- Copyright complaints: include the information required by §512(c) of the U.S. Digital Millennium Copyright Act (identification of the work, the allegedly infringing material, contact information, a good-faith statement, and a statement under penalty of perjury) and send to legal@clustra.org.
Reporting in good faith does not, by itself, expose you to retaliation. Submitting a report you know to be false may itself violate this AUP and the law.
11. Enforcement
Where we believe this AUP has been violated, we may, at our discretion and proportionate to the violation:
- Remove or restrict access to the offending content.
- Disable an integration, API token, or feature.
- Limit rates, seat counts, or other usage allowances.
- Suspend the affected Account or Workspace.
- Terminate the affected Subscription or Account in accordance with the Terms.
- Preserve evidence and disclose information to a competent authority where required by law or to prevent imminent harm.
We will give reasonable notice and an opportunity to address the issue where we can do so without compromising security, the safety of any person, or our ability to comply with a legal obligation. For serious or unlawful conduct (including CSAM, severe security threats, and clear fraud) we may act immediately and without prior notice.
Enforcement actions by Clustra are without prejudice to any other rights or remedies we may have under the Terms, the law, or otherwise. Nothing in this AUP requires us to monitor Customer Content, and the absence of action in any case does not waive our right to act in another.
12. Updates
We may update this AUP as the law, the threat landscape, and our product evolve. When we do, we will update the version and effective date at the top of this page. Material changes are announced through the channels described in §18 of the Terms of Service. Continued use of the Service after the effective date constitutes acceptance of the updated AUP.
Contact
Abuse: abuse@clustra.org
Security: security@clustra.org
Legal: legal@clustra.org
This AUP is provided for informational purposes and does not constitute legal advice. If a specific rule above conflicts with mandatory law in your jurisdiction, that law prevails to the minimum extent necessary.