Skip to content

feat: add Usage Policy page#23

Merged
acoshift merged 1 commit into
mainfrom
feat/usage-policy
Jun 30, 2026
Merged

feat: add Usage Policy page#23
acoshift merged 1 commit into
mainfrom
feat/usage-policy

Conversation

@acoshift

@acoshift acoshift commented Jun 30, 2026

Copy link
Copy Markdown
Member

What

Adds a public Usage Policy (Acceptable Use Policy) page at /usage-policy, plus a footer link beside "Privacy policy".

  • New content/usage-policy/index.md — renders through the existing single.html "Legal" template (same as the Privacy Policy: Ink page-hero + .prose article).
  • Footer "Company" column now lists Usage policy above Privacy policy.
  • Frontmatter sets a real title so the browser tab / OG title isn't blank (the page header: still drives the <h1>).

Why

The platform had no acceptable-use terms anywhere. This document defines what customers may and may not run on a shared Kubernetes PaaS, our enforcement rights, and customer responsibility for their own apps and end users. It is scoped as an Acceptable Use Policy — it supplements, and does not replace, the Privacy Policy and a future Terms of Service.

A short, plain-language summary that links here is being added to the console separately.

Screenshots

Light Dark
light dark

Policy highlights

  • Lines drawn around intent and harm, not blanket bans on normal dev tooling (security tools, crawlers, proxies are explicitly allowed against systems you own).
  • Prohibited-use catalogue: mining, DoS/amplification, scanning, malware/C2, stalkerware, abusive relays (public Tor exit nodes disallowed; private VPN / good-faith Tor bridge allowed), spam/mail abuse, telephony fraud, phishing, sybil farms, synthetic-media abuse.
  • Illegal-content section with zero-tolerance CSAM handling, IP/piracy takedown-on-notice, and Thailand-specific framing (Computer Crime Act B.E. 2550, PDPA, court/regulator orders).
  • Feature-specific rules (registry, custom domains/CDN, disks, invite-only email, service accounts/API keys, internal TCP services), fair-use & billing integrity, a security-research safe harbour, data-protection roles (customer = controller, Moon Rhythm = processor), and graded enforcement.

Notes / judgment calls

  • Age threshold pinned to 20 to match the Privacy Policy.
  • References to a Terms of Service are written as soft pointers ("where published") since none exists in the repo yet.
  • The Privacy Policy references a "Data Protection Officer" it never names — worth reconciling in a follow-up so the two docs stay consistent.

Built locally with hugo --gc --minify (6 pages, clean).

@deploys-app
deploys-app Bot temporarily deployed to pr-23 June 30, 2026 03:44 Destroyed
@deploys-app

deploys-app Bot commented Jun 30, 2026

Copy link
Copy Markdown

Preview deleted (PR closed).

@acoshift
acoshift merged commit a48724f into main Jun 30, 2026
1 check passed
@acoshift
acoshift deleted the feat/usage-policy branch June 30, 2026 04:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant