Acceptable Use Policy
Effective September 26, 2026
Scribase runs backends for real apps. To keep it safe for everyone, do not use it for spam, malware, phishing, illegal content, attacks on others, or to abuse the email the platform sends for your projects.
1. Scope
This policy applies to everyone who uses Scribase: account holders, their team members, the apps they build, and any agent or tool acting through their credentials. It covers every part of the Service: databases, authentication, storage, realtime, functions, temporary projects, and the email the platform sends for your projects. It forms part of our Terms of Service (https://scribase.com/legal/terms). You are responsible for what your projects and your end users do on the Service.
2. What is not allowed
Do not use Scribase, or let your app or its users use it, to:
- Store, distribute or link to illegal content, including child sexual abuse material, content that infringes copyright or trademarks, or content that violates privacy or data-protection law.
- Host, distribute or control malware, ransomware, spyware, botnets or command-and-control servers.
- Run phishing, credential harvesting, impersonation of another person or brand, or any scam or fraud.
- Send spam or any unsolicited bulk messages, or build lists of people who did not agree to hear from you.
- Attack, scan or probe other systems, or try to get into data, accounts or infrastructure that are not yours, including other Scribase customers and Scribase itself.
- Harass, threaten or incite violence against people, or promote terrorism or violent extremism.
- Mine cryptocurrency, or run workloads designed to consume shared resources rather than serve an application.
- Get around limits, quotas, rate limits, billing or access controls, including by creating many accounts or temporary projects to avoid charges or caps.
- Resell the Service as a standalone hosting product without our written agreement.
3. Email sent for your projects
Scribase can send your app’s account emails for you: sign-in links, one-time codes, address verification, password resets and invitations. This platform email exists for those transactional messages only.
- Do not use platform email for marketing, newsletters, or bulk or unsolicited messages.
- Each project has a daily cap on platform email, shown in the console. The cap is part of the Service, not a target; do not work around it with extra projects or accounts.
- Only send to people who asked for the message, for example by signing up in your app.
- If you need to send more, or send other kinds of email, connect your own mail server in the project’s auth settings. You are then responsible for that sender and must still follow the law and this policy.
- We may lower a project’s cap, pause its platform email, or stop it entirely if we see high bounce or complaint rates, spam reports, or other signs of abuse.
4. Coding agents and automation
You may let coding agents and scripts create and manage projects through the CLI, the API or the MCP server. Whatever an agent does with your credentials or tokens counts as your action under this policy. Give agents scoped, expiring tokens where you can, and review what they create.
5. How we enforce this policy
We do not routinely look at your data. We act on reports, on automated signals such as mail complaints or resource abuse, and where the law requires it. Depending on how serious and how clear the problem is, we may:
- Contact you and ask you to fix it.
- Limit or pause the affected feature, for example platform email, or pause the affected project.
- Remove specific content that is clearly unlawful.
- Suspend or close the account, and report illegal activity to the authorities where required.
Where we can, we tell you first and give you time to respond. We act without notice when there is ongoing harm to people, to other customers or to the Service. If a project is paused, its data is kept while the issue is resolved, and you can still export it unless the law prevents it.
6. Reporting abuse
To report spam, phishing, malware or other abuse coming from a Scribase project, email abuse@scribase.com with the URL, message headers or other details that help us find it. Security vulnerabilities go to security@scribase.com. For anything else, including questions about this policy, email support@scribase.com.
7. Changes
We may update this policy as the Service changes. We will post the new version here with a new effective date and, for material changes, tell account holders in advance through the console or by email.
Related documents