---
doc_id: POL-AUP-001
title: Acceptable Use Policy — draft with drafting notes
type: policy-public
status: draft
version: 0.3

date: 2026-09-25
created: 2026-09-25
last_reviewed: 2026-09-25
next_review: 2026-10-09
law_checked: 2026-09-25
owner: Legal Lead (to be appointed) with CTO
reviewers: [hidzo-counsel-reviewer (AI), U.S. consumer counsel]
counsel_needed: yes
counsel_status: none
jurisdictions: [GLOBAL, US]
related: [POL-TOS-002, POL-PRIV-002, POL-LE-001, POL-VDP-001, POL-DEL-001, POL-REF-001, POL-ID-001]
sources: [EV-002, EV-106, EV-231, EV-236, EV-302, EV-303]
supersedes: POL-AUP-001 v0.2 (2026-09-25)
print: true
confidentiality: INTERNAL — LEGAL (Part B becomes PUBLIC on publication)
---

# Acceptable Use Policy — draft

> **Prepared for review by licensed counsel. Not legal advice.** Part B is the proposed public text; Parts A and C are internal.

## Part A — Drafting brief (internal)

| Item | Value |
|---|---|
| Question presented | What uses of the Services are prohibited, how does HidzoVPN learn of and act on abuse, and how can a user appeal — without describing traffic monitoring that the Privacy Policy does not permit? |
| Key constraint | The published Terms (§6, EV-002) say "we use automated tools to monitor for violations", which contradicts the no-monitoring position (RSK-028). This policy describes abuse controls that do not inspect traffic content: complaints from third parties, rate limits, port restrictions, account and payment signals `[ENGINEERING: confirm the actual controls — roadmap #27 "Abuse Handling Design"]` |
| Sources | ToS v2.0 §§8–10 (EV-302) |

## Part B — Proposed public text

# Acceptable Use Policy

**Version:** 1.0 `[OPEN]` · **Effective:** `[OPEN: date]`

This Acceptable Use Policy is part of our Terms of Service. It applies to everyone who uses HidzoVPN, with or without an account `[ENGINEERING: first-launch acceptance screen that covers guest users]`. It is issued by
HidzoVPN, Inc., a Florida corporation.

## 1. What you may not do

Except as permitted by our Vulnerability Disclosure Policy, you may not use HidzoVPN, or help or allow anyone else to use it, to:

1. break any law that protects other people, their property, networks or systems, or any law of the United States `[COUNSEL (consumer and OFAC): scope — see Part C.1; a global "any law" rule would treat use of a VPN where VPNs are restricted as a breach]`;
2. create, access, store, share or promote child sexual abuse material, or exploit or endanger a child in any way;
3. commit or help commit fraud, phishing, identity theft, money laundering or unauthorized payments;
4. send spam or other unsolicited bulk messages;
5. create, distribute or control malware, ransomware, spyware, botnets or other malicious code;
6. gain or attempt to gain unauthorized access to any account, device, network or system, including by credential stuffing or brute-force
   attacks;
7. scan, probe or test the security of any system without its owner's permission;
8. take part in denial-of-service attacks or other attacks that overload or disrupt a network or service;
9. infringe copyright, trademarks or other rights of others, including by sharing content you are not authorized to share;
10. harass, threaten or incite violence against any person, or support terrorism;
11. collect data from websites or services in a way that breaks the law;
12. use the Services in a way that places an unreasonable load on our network or degrades it for other users;
13. interfere with or attack HidzoVPN's servers, apps, accounts or billing systems, get around plan or device limits, or modify our apps to remove or bypass advertising in the Free Service `[OPEN — BRF-2026-001 D4]`;
14. resell, share publicly or provide access to the Services as a commercial service without our written permission; or
15. use the Services after we have suspended or closed your account.

## 2. File sharing (P2P)

`[ENGINEERING: state the method. If P2P is limited by blocking ports: "We may block ports commonly used for peer-to-peer file sharing on some servers. We do not inspect the content of your traffic to do so." If limiting P2P requires classifying or inspecting traffic, this section and Section 3 must be rewritten to describe it — RSK-028.]` Where peer-to-peer file sharing is available, you may use it only for content you have the right to share.

## 3. How we become aware of abuse

We monitor the health and security of our systems. We do not monitor the content of your traffic or the websites you visit `[ENGINEERING: attestation required; must match Privacy Policy §3.3]`. We learn of possible abuse from:
- complaints from network operators, hosting providers, rights holders, other users and authorities;
- automated protections that do not inspect the content of your traffic, such as limits on connection rates, blocked outbound ports (for
  example, ports commonly used to send spam) and limits on simultaneous connections `[ENGINEERING: list the controls actually in place]`; and
- account, device and payment signals, such as repeated failed sign-ins or chargebacks.

We do not record the websites you visit, the content of your traffic or your DNS queries `[ENGINEERING: attestation EV-201, EV-202; claims register entry required — CLM-034]`. We keep connection information only as described in Sections 3.3 and 11 of our Privacy Policy. `[ENGINEERING: complete — "We therefore cannot link a VPN server IP address and time to a particular user" / "We can link a VPN server IP address and time to a user only within X minutes of the connection" — must match the Law Enforcement Guidelines §3; register as a claim in the Claims Register]`

## 4. What we may do

Depending on how serious the problem is, whether it has happened before and the law, we may: warn you; limit or block certain functions or ports; block a device or payment method `[ENGINEERING and COUNSEL: retention of blocked identifiers — Privacy Policy §11]`; suspend your access; or close your account. Some of these measures are applied by automated rules; a person reviews every appeal. Where reasonable and lawful, we will tell you first and give you a chance to fix the problem. We act without advance notice when this is necessary to
prevent harm, protect security, comply with the law or respond to serious abuse. Where we obtain actual knowledge of apparent child sexual abuse material, we report it to the National Center for Missing & Exploited Children as U.S. law requires `[COUNSEL: whether HidzoVPN is a "provider" under 18 U.S.C. §2258E]`.

If we reasonably determine that you have seriously broken this policy and close your paid account for that reason, you are not entitled to a refund, except where the law requires one `[COUNSEL: EU/UK unfair-terms review]`.

## 4A. Repeat infringement

We will terminate, in appropriate circumstances, the accounts of users who repeatedly infringe copyright `[COUNSEL (copyright): a repeat-infringer policy that can be reasonably implemented under the Company's logging model — 17 U.S.C. §512(i)(1)(A)]`.

## 5. Reporting abuse

To report abuse of our Services, email `[OPEN: abuse@hidzovpn.com — mailbox to be created]` with the IP address, date, time and time zone, and a description. We may not be able to act on reports that do not include this information.

## 6. Appeals

If you think we have restricted or closed your account by mistake, email support@hidzovpn.com with the subject "Account Appeal", your account email or, if you use HidzoVPN without an account, the installation identifier shown in the app, and an explanation. We will review your appeal and reply `[OPEN: within X business days]`. An appeal does not lift an urgent restriction
while it is reviewed.

## 7. Security research

If you find a security vulnerability in our Services, please follow our Vulnerability Disclosure Policy `[OPEN: link — POL-VDP-001]`. Testing
that follows that policy is not a breach of this Acceptable Use Policy.

## 8. Changes

We may update this policy. We will publish the new version with its effective date.

## Part C — Drafting notes (internal)

### C.1 Basis and consistency
| Element | Basis | Label |
|---|---|---|
| Prohibited uses | ToS v2.0 §8 (EV-302); Apple Guideline 5.4 ("VPN apps must not violate local laws") | Verified (EV-106) as to Apple |
| No-monitoring description (§3) | Must match Privacy Policy §3.3 and engineering attestation (EV-201–205); replaces published Terms §6 (RSK-028); P2P blocking method determines whether §3 is accurate | `[ENGINEERING]` |
| Scope of "breaking the law" (§1 item 1) | A global "any law" rule would cover use of a VPN where it is restricted, while the Company serves users in restrictive markets (RSK-014; RSK-010); sanctions duties belong in the Terms (§26), not in user prohibitions (RSK-044) | `[COUNSEL]` |
| Repeat-infringer policy (§4A) | 17 U.S.C. §512(i)(1)(A) (adopted, reasonably implemented, communicated to subscribers) | Reported (EV-236) |
| Restrictions and complaint handling for a mere-conduit provider | DSA Art. 14(1), (4); Recital 29 names VPNs | Reported (EV-236); Recital Verified (EV-231) |
| "No limits" marketing vs rate limits and port blocks | CLM-020 (OPEN) | Internal — fix marketing in the same release |
| CSAM reporting (§4) | 18 U.S.C. §2258A(a)(1) (report to NCMEC CyberTipline on actual knowledge), (f) (no duty to monitor), (h) (1-year preservation after a report) | Reported (EV-236); applicability `[COUNSEL]` |
| Abuse mailbox (§5) | Operational; hosting providers expect a monitored abuse contact | Internal |

### C.2 Limits of this analysis
Verified first-hand: Apple Guideline 5.4. Not verified: 18 U.S.C. §2258A text and applicability. Not reviewed: foreign content-regulation laws
that may impose obligations on VPN providers (e.g. licensing countries — see the country database). Counsel required: U.S. consumer; criminal-law
counsel for §4 reporting duties.

### C.3 Review log
| Date | Reviewer | Verdict | Notes |
|---|---|---|---|
| 2026-09-25 | Drafted | — | v0.1 from ToS v2.0 §§8–10 |
| 2026-09-25 | hidzo-counsel-reviewer (AI) | REVISE (9 Majors) | v0.2: P2P method bracket; connection-record wording aligned with PP; scope of item 1; repeat-infringer §4A; NCMEC wording; guest assent; automated decisions and human review (DSA); load and advertising items; appeal by installation ID; abuse@ propagation |
| 2026-09-25 | hidzo-counsel-reviewer (AI) — cross-document final audit; research memos EV-232–235 | REVISE (set: 1 Blocker, 8 Majors) | v0.3: cross-document redlines X-01–X-31 applied where they concern this document; authority labels updated from first-hand and research-memo checks (EV-238–264) |
