Skip to content
SmolClouds

Legal

Acceptable Use Policy

What you can run on SmolClouds, what you cannot, and what happens if a line gets crossed.

Effective date: 5 September 2026

01What this covers

This policy applies to everything you run on SmolClouds and everything your applications do. It forms part of the Terms of Service, and it applies to you, to anyone in your workspace, and to any agent or automation acting on your behalf.

It is written to be read once and remembered, not to catch you out. If something you want to do sits near a line here, ask us first at support@smolclouds.com and we will give you a straight answer.

02What SmolClouds is for

Small, low-to-moderate traffic software: internal tools, dashboards, reports, webhooks, low-traffic APIs, prototypes, and the applications your agents generate.

It is not built to be a general-purpose compute platform, a CDN for large media, or a host for high-traffic consumer websites. Using it as one is not so much forbidden as a poor fit — but where that use harms the platform or other tenants, the rules below apply.

03Illegal and harmful content

You may not use SmolClouds to host, distribute or facilitate any of the following.

  • Anything illegal where you are, where we are, or where your application is served
  • Material that infringes someone else's copyright, trademark or other rights
  • Malware, ransomware, exploit kits, or command-and-control infrastructure
  • Phishing pages, or anything impersonating another person or organisation to deceive
  • Content that sexualises children, incites violence, or harasses a specific person
  • Unsolicited bulk email, or the infrastructure that supports it

04Resource abuse

Plan allowances exist so that hundreds of small applications can share warm runtimes cheaply. These uses break that model and are not permitted regardless of your plan.

  • Cryptocurrency mining, proof-of-work, and distributed computation whose purpose is to consume compute
  • Acting as a proxy, VPN, TOR relay or general traffic-forwarding service
  • Hosting large media for hot-linking, or using the platform as a file distribution network
  • Torrent clients, trackers or seedboxes
  • Load generation, stress testing or benchmarking aimed at systems you do not own
  • Deliberately circumventing plan limits — for example spreading one workload across many free accounts

05Automated and agent deployment

Agents deploying without a human in the loop is the point of this platform, not something we tolerate. But an agent that has misunderstood its instructions can deploy in a loop for hours, and the cost of that lands on the shared platform.

So: rate limits and concurrent build limits apply on every plan, and they are there to protect you as much as us. You may not deliberately work around them.

You are responsible for what your agents do on your account, as if you had done it yourself. If an agent of yours starts a runaway loop, we may pause its deployments before we contact you — we will tell you promptly, and we will not delete anything.

If you are building something that legitimately needs higher deployment throughput, talk to us rather than routing around the limits.

06Platform integrity

Good-faith security research is welcome and is not a violation of this policy. Report what you find to security@smolclouds.com and give us a reasonable chance to fix it; we will not pursue you for research conducted that way.

  • Do not attack, probe or attempt to escape the isolation boundary around your microVM
  • Do not attempt to reach other tenants' applications, data or infrastructure
  • Do not deliberately overload the platform, the router, or a third party through it
  • Do not resell SmolClouds as your own hosting product without a written agreement
  • Do not misrepresent your identity to obtain resources, or create accounts to evade a suspension

07How we enforce this

We would rather talk to you than switch something off. Our normal order is: contact you, ask you to fix it, give you a reasonable period, and only then restrict the service.

We act faster than that only when we have to — when an application is actively harming others, when the law requires it, or when a runaway process is consuming shared capacity. In those cases we may suspend the specific application first and contact you immediately afterwards.

Suspension is targeted at the offending application where we can. Account-level suspension is for repeated or deliberate violations. We do not delete your data as a punishment, and you can always export it.

08Reporting a violation

To report content or behaviour that breaches this policy, write to abuse@smolclouds.com with the URL and enough detail for us to investigate. To report a security vulnerability in the platform itself, write to security@smolclouds.com.

We investigate every report. We do not disclose the reporter's identity to the customer being reported.

09Changes

We update this policy as the platform and the abuse we see change. Material changes are announced to account owners by email before they take effect.

Questions about this document: legal@smolclouds.com

Security reports go to our security page.