Legal
Acceptable Use Policy
The things you may not do with The Deployer. This policy is part of our Terms of Service and applies to your account, the free public repository check, our MCP server and API keys, and the apps you deploy with us.
1. Harmful and unlawful content
Do not use The Deployer to build, deploy or distribute:
- malware, ransomware, spyware or other malicious code;
- phishing pages, or anything designed to trick people into handing over credentials, payment details or personal data;
- tools or pages for stealing credentials or session tokens;
- spam or unsolicited bulk messages, including through email services we help you set up;
- content that is illegal where you or your users are, including content that exploits children, infringes intellectual property, or harasses or threatens people.
2. Attacks and unauthorised access
- Do not scan, probe or test systems you do not own or have written permission to test. This includes using the apps you deploy to scan other networks.
- Do not launch or take part in denial-of-service attacks.
- Do not access, or try to access, accounts, systems or data you are not authorised to use.
- Do not connect repositories, cloud accounts or credentials that you are not authorised to use, or submit them to the public repository check.
Good-faith security research on The Deployer itself is welcome within our Vulnerability Disclosure Policy.
3. Resource and free-plan abuse
- Do not create multiple accounts, or rotate emails or repositories, to get around plan limits or quotas.
- Do not use the free public repository check in an automated or bulk way, or to get around its rate limits.
- Do not mine cryptocurrency on resources that are not yours, or use our control plane (including builds that run there) for anything other than building and deploying your app.
- Do not deliberately run workloads designed to exhaust shared resources on our side, such as builds or requests that loop without end.
4. Using The Deployer itself
- Do not interfere with the service, bypass its limits or security controls, or access other users' data.
- Do not copy, resell or reverse engineer the service except where the law allows it.
- Do not break the terms of your cloud provider, code host or any other third party whose service you connect.
5. Sanctions and export controls
Do not use The Deployer in breach of sanctions or export-control laws that apply to you or to us, or on behalf of a person or organisation those laws prohibit us from serving.
6. What we do when rules are broken
We may stop an action, remove a public check result, suspend an API key, or suspend or close an account that breaks this policy. Where we reasonably can, we will tell you first and explain why, unless the law or the safety of others prevents it.
We do not delete resources in your cloud account. If an app you deployed is causing harm, your cloud provider may act on it under its own terms.
7. Reporting abuse
To report abuse involving The Deployer, write to hello@thedploy.com. To report a security vulnerability, write to hello@thedploy.com. An app deployed with The Deployer runs in its owner's cloud account, so abuse by the app itself can also be reported to that cloud provider.