Version 1.0.0-draft · not in force · sha256 3a7a863f37d999db…
Acceptable Use Policy
DRAFT — REQUIRES REVIEW BY QUALIFIED COUNSEL IN [JURISDICTION] BEFORE USE. Not legal advice. Not a substitute for a lawyer.
Version: 1.0.0-draft · Status: not in force · Baseline: GDPR-grade
What we will not assess, and will never certify
We refuse assessment, log the refusal, and do not issue a mark for applications that:
- Distribute malware, spyware, stalkerware or ransomware;
- Conduct phishing or harvest credentials;
- Facilitate child sexual abuse material or any sexual content involving minors;
- Facilitate the sale or manufacture of weapons or illicit substances;
- Offer financial services requiring a licence the operator does not hold, including unlicensed deposit-taking, lending, investment advice or virtual-asset services;
- Impersonate a real institution, public authority, payment provider or individual;
- Scrape or repackage third-party services in breach of those services' terms;
- Exist to deceive users about who is behind them, what data they collect, or what they do with it;
- Target or profile a private individual without a lawful basis;
- Are designed to evade detection, sanctions, or lawful process.
This list is not exhaustive. We may refuse anything we judge to fall within its spirit.
How it is applied
- At intake, automatically, from the application's stated purpose, category and observable behaviour.
- At review, by the human reviewer, who may refuse on the same grounds.
- After certification, if the application changes into something on this list, the mark is revoked.
What happens when we refuse
We record the refusal and its ground in an append-only log, tell you which ground applied, and refund any fee for the assessment we did not perform. You may appeal under the Appeals & Corrections Policy. We do not publish refusals.
Behaviour on the platform
You must not attempt to obtain a mark for an application you do not control, submit an authorisation warranty you know to be untrue, interfere with the assessment of another customer's application, attempt to influence a score by any means other than fixing the application, or attempt to extract our rubric internals, prompts or reviewer identities.