Document libraryکتابخانه‌ی اسناد

What users must not doکارهای ممنوع

What users are not allowed to do with the VPN.کاربر با وی‌پی‌ان چه کارهایی نباید بکند.Acceptable Use Policy

Draft — not final. Do not publish until our lawyer approves it.پیش‌نویس است و هنوز نهایی نیست؛ تا تأیید وکیل منتشر نشود.

It still has 21 gaps, shown in yellowهنوز ۲۱ جای خالی دارد که زرد نشان داده شده [OPEN: …] · What to fill inچه چیزی پر شود

The text below is in English — the official text.متن زیر انگلیسی است؛ متن رسمی همین است.
Technical detailsجزئیات فنی
draftپیش‌نویس
IDشناسهPOL-AUP-001
Versionنسخه0.3
OwnerمسئولLegal Lead (to be appointed) with CTO
Counsel reviewبررسی وکیلnone
Next reviewبررسی بعدی2026-10-09
Fileفایلknowledge-base/05-Policies-Public/drafts/POL-AUP-001_ACCEPTABLE_USE_POLICY_v0.3-draft.md

Acceptable Use Policy — draft

Prepared for review by licensed counsel. Not legal advice. Part B is the proposed public text; Parts A and C are internal.

Part A — Drafting brief (internal)

ItemValue
Question presentedWhat uses of the Services are prohibited, how does HidzoVPN learn of and act on abuse, and how can a user appeal — without describing traffic monitoring that the Privacy Policy does not permit?
Key constraintThe published Terms (§6, EV-002) say "we use automated tools to monitor for violations", which contradicts the no-monitoring position (RSK-028). This policy describes abuse controls that do not inspect traffic content: complaints from third parties, rate limits, port restrictions, account and payment signals [ENGINEERING: confirm the actual controls — roadmap #27 "Abuse Handling Design"]
SourcesToS v2.0 §§8–10 (EV-302)

Part B — Proposed public text

Acceptable Use Policy

Version: 1.0 [OPEN] · Effective: [OPEN: date]

This Acceptable Use Policy is part of our Terms of Service. It applies to everyone who uses HidzoVPN, with or without an account [ENGINEERING: first-launch acceptance screen that covers guest users]. It is issued by HidzoVPN, Inc., a Florida corporation.

1. What you may not do

Except as permitted by our Vulnerability Disclosure Policy, you may not use HidzoVPN, or help or allow anyone else to use it, to:

  1. break any law that protects other people, their property, networks or systems, or any law of the United States [COUNSEL (consumer and OFAC): scope — see Part C.1; a global "any law" rule would treat use of a VPN where VPNs are restricted as a breach];
  2. create, access, store, share or promote child sexual abuse material, or exploit or endanger a child in any way;
  3. commit or help commit fraud, phishing, identity theft, money laundering or unauthorized payments;
  4. send spam or other unsolicited bulk messages;
  5. create, distribute or control malware, ransomware, spyware, botnets or other malicious code;
  6. gain or attempt to gain unauthorized access to any account, device, network or system, including by credential stuffing or brute-force attacks;
  7. scan, probe or test the security of any system without its owner's permission;
  8. take part in denial-of-service attacks or other attacks that overload or disrupt a network or service;
  9. infringe copyright, trademarks or other rights of others, including by sharing content you are not authorized to share;
  10. harass, threaten or incite violence against any person, or support terrorism;
  11. collect data from websites or services in a way that breaks the law;
  12. use the Services in a way that places an unreasonable load on our network or degrades it for other users;
  13. interfere with or attack HidzoVPN's servers, apps, accounts or billing systems, get around plan or device limits, or modify our apps to remove or bypass advertising in the Free Service [OPEN — BRF-2026-001 D4];
  14. resell, share publicly or provide access to the Services as a commercial service without our written permission; or
  15. use the Services after we have suspended or closed your account.

2. File sharing (P2P)

[ENGINEERING: state the method. If P2P is limited by blocking ports: "We may block ports commonly used for peer-to-peer file sharing on some servers. We do not inspect the content of your traffic to do so." If limiting P2P requires classifying or inspecting traffic, this section and Section 3 must be rewritten to describe it — RSK-028.] Where peer-to-peer file sharing is available, you may use it only for content you have the right to share.

3. How we become aware of abuse

We monitor the health and security of our systems. We do not monitor the content of your traffic or the websites you visit [ENGINEERING: attestation required; must match Privacy Policy §3.3]. We learn of possible abuse from:

  • complaints from network operators, hosting providers, rights holders, other users and authorities;
  • automated protections that do not inspect the content of your traffic, such as limits on connection rates, blocked outbound ports (for example, ports commonly used to send spam) and limits on simultaneous connections [ENGINEERING: list the controls actually in place]; and
  • account, device and payment signals, such as repeated failed sign-ins or chargebacks.

We do not record the websites you visit, the content of your traffic or your DNS queries [ENGINEERING: attestation EV-201, EV-202; claims register entry required — CLM-034]. We keep connection information only as described in Sections 3.3 and 11 of our Privacy Policy. [ENGINEERING: complete — "We therefore cannot link a VPN server IP address and time to a particular user" / "We can link a VPN server IP address and time to a user only within X minutes of the connection" — must match the Law Enforcement Guidelines §3; register as a claim in the Claims Register]

4. What we may do

Depending on how serious the problem is, whether it has happened before and the law, we may: warn you; limit or block certain functions or ports; block a device or payment method [ENGINEERING and COUNSEL: retention of blocked identifiers — Privacy Policy §11]; suspend your access; or close your account. Some of these measures are applied by automated rules; a person reviews every appeal. Where reasonable and lawful, we will tell you first and give you a chance to fix the problem. We act without advance notice when this is necessary to prevent harm, protect security, comply with the law or respond to serious abuse. Where we obtain actual knowledge of apparent child sexual abuse material, we report it to the National Center for Missing & Exploited Children as U.S. law requires [COUNSEL: whether HidzoVPN is a "provider" under 18 U.S.C. §2258E].

If we reasonably determine that you have seriously broken this policy and close your paid account for that reason, you are not entitled to a refund, except where the law requires one [COUNSEL: EU/UK unfair-terms review].

4A. Repeat infringement

We will terminate, in appropriate circumstances, the accounts of users who repeatedly infringe copyright [COUNSEL (copyright): a repeat-infringer policy that can be reasonably implemented under the Company's logging model — 17 U.S.C. §512(i)(1)(A)].

5. Reporting abuse

To report abuse of our Services, email [OPEN: [email protected] — mailbox to be created] with the IP address, date, time and time zone, and a description. We may not be able to act on reports that do not include this information.

6. Appeals

If you think we have restricted or closed your account by mistake, email [email protected] with the subject "Account Appeal", your account email or, if you use HidzoVPN without an account, the installation identifier shown in the app, and an explanation. We will review your appeal and reply [OPEN: within X business days]. An appeal does not lift an urgent restriction while it is reviewed.

7. Security research

If you find a security vulnerability in our Services, please follow our Vulnerability Disclosure Policy [OPEN: link — POL-VDP-001]. Testing that follows that policy is not a breach of this Acceptable Use Policy.

8. Changes

We may update this policy. We will publish the new version with its effective date.

Part C — Drafting notes (internal)

C.1 Basis and consistency

ElementBasisLabel
Prohibited usesToS v2.0 §8 (EV-302); Apple Guideline 5.4 ("VPN apps must not violate local laws")Verified (EV-106) as to Apple
No-monitoring description (§3)Must match Privacy Policy §3.3 and engineering attestation (EV-201–205); replaces published Terms §6 (RSK-028); P2P blocking method determines whether §3 is accurate[ENGINEERING]
Scope of "breaking the law" (§1 item 1)A global "any law" rule would cover use of a VPN where it is restricted, while the Company serves users in restrictive markets (RSK-014; RSK-010); sanctions duties belong in the Terms (§26), not in user prohibitions (RSK-044)[COUNSEL]
Repeat-infringer policy (§4A)17 U.S.C. §512(i)(1)(A) (adopted, reasonably implemented, communicated to subscribers)Reported (EV-236)
Restrictions and complaint handling for a mere-conduit providerDSA Art. 14(1), (4); Recital 29 names VPNsReported (EV-236); Recital Verified (EV-231)
"No limits" marketing vs rate limits and port blocksCLM-020 (OPEN)Internal — fix marketing in the same release
CSAM reporting (§4)18 U.S.C. §2258A(a)(1) (report to NCMEC CyberTipline on actual knowledge), (f) (no duty to monitor), (h) (1-year preservation after a report)Reported (EV-236); applicability [COUNSEL]
Abuse mailbox (§5)Operational; hosting providers expect a monitored abuse contactInternal

C.2 Limits of this analysis

Verified first-hand: Apple Guideline 5.4. Not verified: 18 U.S.C. §2258A text and applicability. Not reviewed: foreign content-regulation laws that may impose obligations on VPN providers (e.g. licensing countries — see the country database). Counsel required: U.S. consumer; criminal-law counsel for §4 reporting duties.

C.3 Review log

DateReviewerVerdictNotes
2026-09-25Drafted—v0.1 from ToS v2.0 §§8–10
2026-09-25hidzo-counsel-reviewer (AI)REVISE (9 Majors)v0.2: P2P method bracket; connection-record wording aligned with PP; scope of item 1; repeat-infringer §4A; NCMEC wording; guest assent; automated decisions and human review (DSA); load and advertising items; appeal by installation ID; abuse@ propagation
2026-09-25hidzo-counsel-reviewer (AI) — cross-document final audit; research memos EV-232–235REVISE (set: 1 Blocker, 8 Majors)v0.3: cross-document redlines X-01–X-31 applied where they concern this document; authority labels updated from first-hand and research-memo checks (EV-238–264)