Overview
aidrop.it runs software written by its Users and publishes it at addresses other people can open. That makes two things possible which this policy is about: harm done to other people through something a User deployed, and harm done to the platform itself and to the other Users sharing it.
The Terms and Conditions already say the Owner may deny access, terminate contracts, and report misconduct to the competent authorities. This policy is the concrete version of that clause: what the Owner treats as abuse, what happens when it is found, and how to report it. Where the two documents overlap, the Terms govern.
What the Owner treats as abuse
The list below is not exhaustive. It describes the conduct the Owner acts on most often, in the terms of what this Service actually does.
Using the Service to reach or harm other systems
- Port scanning, credential stuffing, brute-force attempts, or vulnerability probing against systems the User does not own or is not authorised to test.
- Participating in, originating, or coordinating a denial-of-service attack.
- Sending unsolicited bulk email, operating a mail relay for third parties, or any comparable messaging abuse.
- Operating an open proxy, an anonymising relay, or a tunnel offered to third parties.
Deception at an address the Owner provides
- Phishing, credential harvesting, or any page that collects payment details or sign-in details under a false identity.
- Impersonating a real person, company, public body, or the Owner itself — including a site built to be mistaken for one of them.
- Storefronts, listings, reviews, or records presented as genuine when they are not.
This applies to addresses the Owner issues and to a User's own domain pointed at a deployment on the Service.
Malicious software
- Hosting, building, or distributing malware, ransomware, spyware, or credential stealers.
- Operating command-and-control infrastructure for any of the above.
Security research and defensive tooling are not abuse. What separates them is authorisation and intent, and the Owner may ask a User to demonstrate both.
Taking capacity that belongs to other Users
Except on plans that include a runtime cluster of the User's own, applications run on infrastructure shared with other Users, and a plan's processor and memory are a single allowance.
- Cryptocurrency mining, and any comparable workload run for the value of the computation rather than as part of the User's own product.
- Reselling the runtime as generic compute, storage, or bandwidth to third parties.
- Deliberately circumventing a plan's limits, including by creating multiple accounts to obtain repeated trials.
- Any workload that destabilises a shared node or degrades the Service for other Users, whether or not it was intended to.
Unlawful content and content the Owner will not carry
- Material that sexually exploits or endangers children. This is reported to the competent authorities as well as removed.
- Content that incites violence or terrorism, or that facilitates trafficking in people, weapons, or controlled substances.
- Material that infringes another party's intellectual property, where the Owner receives a valid complaint.
- Content that targets a private individual for harassment.
What may not be stored on the Service
- Credentials, access tokens, or personal data obtained without authorisation, including in a Project's context or its connected sources.
- Data a User has no lawful basis to process.
What the Owner does about it
The response is chosen to match the harm, and more than one measure may apply.
- A request to fix it. Where the harm is not ongoing, the Owner will normally contact the User first and give a reasonable period to correct the problem.
- Stopping the application. The deployment is stopped and its address stops answering. The Project, its code, and its data remain.
- Removing the content or the deployment. The offending deployment is removed. Any custom domain pointed at it stops resolving to the Service.
- Suspending the account. Sign-in and the API are blocked while the matter is reviewed.
- Deleting the Project or the account. Used where the abuse is severe, deliberate, repeated, or unlawful.
- Reporting. Where the law requires it, or where there is a risk to a person's safety, the Owner reports the matter to the competent authorities and may preserve relevant records for them.
Where harm to other people or to other Users is under way, the Owner may act immediately and explain afterwards.
Deletion is final
The Owner keeps no backups of User data and makes no restore promise. A managed database can be exported by its owner on demand, and the Owner retains no copy of that export. This is stated plainly here because it is the part with no remedy: once a Project, a deployment, or an account is deleted, what it held is gone, and the Owner cannot return it — not on request, not on appeal, and not by mistake.
For that reason, deletion is reserved for the cases listed above rather than used as a first response, and a User whose account is at risk will be told wherever telling them does not itself cause harm.
Reporting abuse
Anyone may report suspected abuse of the Service, whether or not they are a User, by writing to info@aidrop.it with the word abuse in the subject.
A report is most useful when it includes:
- the address or link where the behaviour can be seen;
- what was observed, and when, with timestamps and a time zone where possible;
- any evidence — headers, logs, screenshots — that lets the Owner verify it;
- how to reach the reporter for follow-up questions.
Reports are reviewed by a person. The Owner does not disclose the identity of a reporter to the reported User except where the law requires it.
If the Owner has acted against you
A User whose Project or account has been restricted may reply to the notice they received, or write to info@aidrop.it, explaining what happened and what has been corrected. The Owner will review the matter and, where the measure was mistaken or the cause has been removed, restore access.
Restoring access does not restore deleted data, for the reason given above.
Changes to this policy
The Owner may update this policy as the Service changes or as new forms of abuse appear. The date of the latest update is shown on this page. Continued use of the Service after a change constitutes acceptance of it.