Acceptable Use Policy
Last updated 2026-07-18
This Acceptable Use Policy ("AUP") applies to everyone who accesses hosted.devdocs.ai and its subdomains, and is incorporated into our Terms of Service by reference. Because tenant sites share the *.hosted.devdocs.ai domain and its sending and browsing reputation, one workspace's abuse can affect every other workspace. That is why enforcement here is faster and less forgiving than a typical hosting agreement.
1. Prohibited content
You may not publish, host, connect as a source, or otherwise process through the Service, content that:
- Depicts child sexual abuse material. We report this to the National Center for Missing and Exploited Children (NCMEC) and terminate the workspace immediately, with no prior notice.
- Contains malware, exploit code, or is designed to compromise the security of a visitor's device or account.
- Is used for phishing, including impersonating a brand by name, logo, or subdomain ("typosquatting") to deceive visitors.
- Infringes another party's copyright, trademark, or other intellectual property right.
- Violates applicable law in a way that creates material legal risk for DevDocs or other tenants.
2. Prohibited conduct
- Scraping or bulk-downloading tenant documentation outside the routes designated for machine access (the workspace's .md export routes and its llms.txt / llms-full.txt files, where published).
- Reselling, sublicensing, or otherwise offering the Service, or access to it, to a third party as a hosting or documentation platform.
- Evading rate limits, spend ceilings, credit balances, or other technical limits by any automated or manual means.
- Attempting to access, read, or modify another workspace's content, configuration, or usage data ("tenant isolation"). This includes forging or manipulating the hostname a request presents.
- Using the AI assistant as a general purpose model endpoint: sending it questions unrelated to the workspace's own content, or attempting to extract system instructions, other tenants' content, or the underlying model's raw behavior.
- Using connected sources or publishing credentials to pull or publish material you are not authorized to process.
3. Enforcement
We aim to be proportionate. For most issues, the ladder below applies in order, and we tell you which step you are on:
- Notice: we describe the issue and ask you to fix it, with a reasonable deadline.
- Throttle: reduced rate limits or a lowered spend ceiling while the issue is open.
- Suspend: the workspace stops serving (technically, its cache is invalidated and re-authorization is required) until the issue is resolved.
- Terminate: the workspace is removed and its slug is retired, serving a 410 Gone response rather than being reassigned to another tenant.
For child sexual abuse material, malware, phishing, or brand-typosquatting that puts the shared *.hosted.devdocs.ai reputation at risk, we may skip directly to suspension or termination without prior notice, because the harm to other tenants accrues immediately.
Suspension or termination for cause does not entitle Customer to a refund of any fees already paid.
4. DMCA and copyright complaints
If you believe content hosted on a workspace infringes your copyright, send a notice to abuse@devdocs.ai, or submit it through POST https://hosted.devdocs.ai/api/dmca, including: identification of the copyrighted work, identification of the allegedly infringing material and its URL, your contact information, a statement of good faith belief that the use is unauthorized, a statement that the notice is accurate under penalty of perjury, and your signature (physical or electronic).
Each valid notice is recorded against the responsible workspace. A workspace that accumulates repeated valid notices is suspended and, on a further notice, terminated, consistent with a repeat-infringer policy. Intake records a receipt; removing or suspending a workspace is a staff action after review.
We do not currently have a registered DMCA agent with the U.S. Copyright Office, so notices sent through the statutory agent process may not reach us through that channel. Send notices directly to abuse@devdocs.ai or the intake endpoint above; we act on them the same way regardless of channel. A workspace owner who believes a notice was made in error may submit a counter-notice to the same address.
5. Response targets, not a service level agreement
We target acknowledging abuse@devdocs.ai reports within one business day and CSAM, malware, and phishing reports as soon as we become aware of them, generally within hours. These are targets we work toward, not a contractual service level agreement, and they do not modify the no-warranty terms in the Terms of Service.
6. Reserved addresses and trademark
Certain workspace names are reserved and unavailable for self-serve registration, including names that could impersonate DevDocs or a well-known brand, and the RFC 2142 operational addresses (abuse, postmaster, hostmaster, webmaster), reserved so no workspace can appear to receive mail on our behalf. Use of the DevDocs name, logo, or the hosted.devdocs.ai domain to imply endorsement or affiliation you do not have is prohibited.
7. Reporting abuse
Report any of the above to abuse@devdocs.ai. Please include the workspace subdomain and as much detail as you can. Security vulnerabilities in the platform itself: security@devdocs.work or /.well-known/security.txt.