Acceptable use policy
Version 1.0. Last updated .
This policy applies to everything you run on, store on or serve from Shotcup, including artifacts on shotcup.page, through the website, the API, the MCP server or the SDK. It is part of our terms of service.
Not allowed
You may not use Shotcup, its API, its MCP server or its artifact links for:
- Mining
- Mining or validating cryptocurrency, or any proof-of-work computation for its own sake.
- Proxying
- Using runs or artifacts as a proxy, VPN, relay or tunnel for other traffic, or to hide where requests come from.
- Phishing and deception
- Pages, documents or images that impersonate others, collect credentials or mislead people, including hosted HTML and SVG artifacts.
- Malware
- Creating, hosting or distributing malware, exploits or tools whose purpose is to cause harm.
- Scanning and attacks
- Scanning, probing or attacking networks or systems, ours or anyone else's, without the owner's permission.
- Spam
- Sending, generating or hosting unsolicited bulk messages.
- Multiple accounts
- Opening several accounts, or sharing one, to get around plan limits, rate limits or an enforcement action.
- Resource abuse
- Deliberately exhausting limits, generating load to degrade the service, or circumventing the sandbox's limits.
- Illegal content
- Anything illegal, including child sexual abuse material, terrorist content and fraud, or anything that infringes someone else's rights, such as copyright, trade marks or privacy.
- Harming people
- Harassing, threatening or exposing people's private information, or content that incites violence or hatred.
- Sanctions
- Using Shotcup if you are subject to UK, EU, US or UN sanctions, or on behalf of someone who is.
Helping or encouraging someone else to do any of these is not allowed either.
Report abuse or illegal content
Anyone can report an artifact, a page or behaviour on Shotcup that they believe is illegal or breaks this policy. Email abuse@shotcup.dev with:
- the exact link (URL) of the artifact or page, or the run id;
- what the content is and why you believe it is illegal or breaks this policy;
- your name and email address (you may leave them out when reporting child sexual abuse material); and
- a statement that you believe in good faith that your report is accurate and complete.
We confirm that we received your report, review it promptly and carefully, and tell you what we decided. Reports of child sexual abuse material or of a threat to someone's life or safety are dealt with first, and we pass them to the relevant authorities where required. Authorities can contact us at the same address, in English.
What we do about it
We act on reports, on the automatic limits of the service and on our own checks. What we do depends on how serious the problem is, and can be one or more of:
- removing content or disabling an artifact link;
- refusing runs or lowering an account's limits;
- suspending the account: its API keys are revoked, its runs are refused and every artifact link it created stops working;
- closing the account.
For clearly illegal content or a serious risk to others or to the service, we act at once and without warning. We keep the records of an account we act against for as long as the case needs, so it can be reviewed.
Statement of reasons. When we restrict your content or account, we email you a statement saying what we did and how far it reaches, the facts it is based on, whether automated means were involved, which rule in this policy or which law it relies on, and how you can appeal. We leave this out only where the law forbids it or it would hinder an investigation.
Appeals. If you disagree with a decision, as the account holder or as the person who reported the content, reply to our message or email abuse@shotcup.dev within six months. A person, not an automated system, reviews the appeal and we tell you the outcome. We restore content or an account when we find we were wrong. You can also go to court.
Report a security issue
Send security issues to security@shotcup.dev. Please give us a reasonable time to fix an issue before you disclose it, and do not access other people's data, degrade the service or run tests beyond what is needed to show the issue.
Changes to this policy
We may update this policy as the service and the law change. Each version has a number and a date at the top of this page, and we tell account holders about material changes in advance, as the terms describe. Questions about this policy: support@shotcup.dev.