Acceptable Use Policy
Version 1.2, in force from 2 September 2026
The legal documents are kept in English only. One wording is the wording that governs; a translation would be a second one, and two texts drift apart.
1What this policy is for
This policy is part of the Terms of Service and applies to everything you, your agents and anyone you give access do on a server you rent from us, and to your use of this site.
Most of it is not our invention. We rent the machines from an infrastructure provider and the models come from Anthropic, and both of them set rules we have to keep. So the first two sections below are their rules passed on to you: what they forbid us, we forbid you. The rest is what running autonomous agents adds, and the countries we are not allowed to serve.
Breaking this policy is a serious breach and lets us suspend the server or end the agreement immediately, without a refund. See section 9.
2Rules that come from our hosting provider
The servers run on Hetzner Online GmbH infrastructure in Germany and Finland. You must not do anything on your server that their terms forbid, and these are the ones that matter:
- No attacks. No denial of service or distributed denial of service, no flooding, no participation in a botnet and no running of command and control infrastructure.
- No scanning other people's networks. Port scans, vulnerability scans, brute force and any other probing of networks or IP addresses that are not yours are out. Holding the owner's permission is not enough on its own: section 7 says what we need before any of this may run on a server of ours.
- No spoofing. No fake source IP addresses, no changing the hardware (MAC) address of the machine, no false sender details and no disguising where traffic came from.
- No abusable services. No open mail relays, open resolvers or anything else that can be used for reflection or amplification against a third party.
- No spam. No unsolicited bulk mail and no unsolicited advertising to third parties, whatever you call it. See section 6 on sending mail at all.
- No mining. No mining, farming or plotting of cryptocurrencies, and no operation of blockchain nodes or validators. This one catches people out because the machine is idle and it seems harmless; it is prohibited outright.
- No illegal or indecent content. No material that is unlawful where it is hosted or where you are; no child sexual abuse material of any kind; no extremist or unconstitutional content; no incitement to hatred or violence; no pornographic or obscene material; no gambling; nothing that endangers the morals of children or young people.
- No attacks on people. No defamation, no insults and no disparagement of people or groups of people.
- Nothing that infringes. No breach of copyright, trade mark or any other third party right, and no distribution of malware, phishing kits or stolen data and credentials.
- No hogging. No use that degrades the platform for other customers or takes resources beyond what your plan provides.
Their full rules are the ones that bind in the end, and they can change them: terms and conditions and system policies. You agree to keep them as they stand from time to time, as if they were addressed to you. Where an abuse complaint reaches us with a deadline on it, we have to act inside that deadline, which is why section 9 lets us move fast.
3Rules that come from Anthropic
The server runs Claude Code against your own Anthropic account, so your use of the models is governed by your agreement with Anthropic. You must keep their Usage Policy and the terms your account is under, and hold anyone using your server to them too. Among other things that means no use of the models to attack systems, to build weapons, to generate child sexual abuse material, to run influence or fraud operations, to impersonate people or to conduct unlawful surveillance.
In addition:
- Do not try to defeat, bypass or trick the safety measures in the models or in Claude Code.
- Do not use output to train a competing model, and do not scrape or reverse engineer the service to build one.
- Do not share your Anthropic credentials with us. We do not want them and we will not take them.
- Do not resell access to your account, or the server as an AI service to third parties, unless we have agreed it in writing.
We build and support the service around Anthropic. Other harnesses will run on the machine and we do not support them, and using one does not release you from anything in this policy.
4Rules that come with running agents
An agent runs while you are asleep, which is the point of the product and also the risk in it. Everything an agent does under your account is treated as done by you.
- Do not point agents at systems you have no right to use. Respect other sites' terms, their robots rules and their rate limits, and do not use an agent to get round a paywall, a login or an API quota.
- No mass account creation, credential stuffing, scalping, ticket sniping or automated abuse of another service's signup or checkout.
- No bulk unsolicited messaging on any channel, including email, Telegram, WhatsApp and social networks, and nothing that breaks the platform's own rules for automation.
- Where the law requires you to disclose that someone is talking to a machine, disclose it. Do not have an agent claim to be a named real person.
- Keep a human in the loop where the decision matters: health, credit, employment, housing, insurance, legal outcomes and anything else with a serious effect on a person.
- Put your own limits on spend and on rate. We do not cap what your agents do and we are not liable for what they cost you.
5Sanctions and export control
We are established in Europe and bound by EU and UK sanctions law, including Regulation (EU) 833/2014 and Regulation (EC) 765/2006 as amended, and the UK Russia (Sanctions) (EU Exit) Regulations 2019 as amended. Those rules restrict the supply of software, IT services and cloud services to certain people and places, and they are the reason for this section. It is a condition of the agreement.
You confirm, each time you use the service, that:
- You are not a legal entity established in Russia or Belarus, you are not majority owned or controlled by one, and you are not acting for or on behalf of one.
- You are not using the service from Russia, Belarus, Iran, North Korea or Syria, or from Crimea and Sevastopol or the non government controlled areas of the Donetsk, Luhansk, Zaporizhzhia and Kherson regions of Ukraine, or from any other country or territory subject to comprehensive EU or UK sanctions from time to time.
- You, your company, your owners and your directors are not on an EU or UK sanctions list, are not owned 50 percent or more or otherwise controlled by someone who is, and are not acting on the instructions of someone who is.
- You will not make the service, or anything you get through it, available to any of the above, directly or indirectly.
- You will not use the service for a military end use, or in connection with nuclear, chemical, biological or missile technology.
- You will not use a VPN, proxy, nominee, intermediary or false statement to get round this section. Doing that is fraud against us as well as a breach of this policy.
Being a Russian or Belarusian citizen is not in itself a problem, and none of this is about nationality. It is about where a company is established, where the service is used from, and who is on a list.
We may ask you for evidence of any of this, including proof of where a company is registered, and we may suspend the service while we wait for it. If any of it stops being true you must tell us at once, and we will end the agreement under clause 11 of the Terms of Service.
6Security, and sending mail
The server is yours to run and that includes keeping it safe. Keep what you install patched, do not leave services open to the internet without a reason, do not run software you know to be vulnerable, and keep your own keys and credentials to yourself. If your server is compromised, tell us as soon as you know.
Leave our management account in place. Your server carries an account belonging
to us, next to your own, which is how support and automated maintenance reach the machine. Do
not remove, rename, disable or restrict it or its key, and do not configure the server so that
it cannot be used — no locking it out in sshd, the firewall or sudo.
There is a file on the server explaining what the account is for and how to see everything it
has done; section 8 of the terms is the full version.
This is the one thing on a machine that is otherwise entirely yours that we ask you not to
change.
If you send mail from the server, the reputation of an IP address is shared and one sender ruins it for everyone. So: only mail people who asked for it, keep an unsubscribe link in anything that looks like a mailing, set up the sender records for your own domain, and stay inside any volume limit we give you. We may block outbound mail on a server that is generating complaints.
7Information security work
Security work is prohibited by default. Unless we have agreed it with you in writing beforehand, you must not use a server you rent from us for any of this:
- Scanning, probing, enumeration or fingerprinting of hosts, networks, domains or accounts.
- Penetration testing, red teaming, adversary simulation or any other attempt to gain access to a system, whoever owns it.
- Developing, compiling, hosting, testing or distributing exploits, malware, ransomware, rootkits, phishing kits, botnets or command and control tooling.
- Password cracking, credential stuffing, credential testing or the processing of stolen or leaked credential sets.
- Interception, sniffing or manipulation of traffic that is not yours, and anonymisation or relay infrastructure run to hide the origin of any of the above.
- Bug bounty work, vulnerability research and security tooling development, including where the target has invited it.
This is stricter than "get permission first", and deliberately so. We rent small machines on shared infrastructure whose provider treats this traffic as abuse whoever authorised it, an abuse report against one of our addresses costs every customer on it, and we have no way to tell an authorised test from an attack by looking at the traffic. So the permission that matters here is ours, and the target's permission is something we will ask you for rather than something that answers the question by itself.
If this is your work, ask us. Write to hello (at) combobulating (dot) ai and tell us what the work is, who authorised it, against what scope, and for how long. We answer within 24 hours. Plenty of this is lawful, ordinary and worth doing, and where we can host it we will say so in writing and say what the limits are.
Only that written answer is permission, it covers only what it names, and we can withdraw it if the traffic causes us a problem. Starting before you have it, or reading silence as a yes, is a breach of this section.
Keeping your own server secure is not security work and needs no permission: patching it, configuring its firewall, rotating your own keys and scanning software you are about to install are all part of section 6.
8Reporting abuse
If something on our infrastructure is harming you, write to hello (at) combobulating (dot) ai with the IP address, what happened and when, in UTC, and any logs you have. We read every report and we act on the ones that are real. If you are reporting on behalf of a rights holder, say what right you hold and where.
9What happens if you break these rules
Depending on what happened and how urgent it is, we may warn you, ask you to fix it by a deadline, throttle or block the traffic in question, suspend the server, or end the agreement immediately with no refund. Where an attack is running, where the content is plainly illegal, or where our infrastructure provider gives us a deadline, we act first and explain afterwards.
We report to the authorities what we are obliged to report, and we keep what we are obliged to keep. Nothing in this policy obliges us to monitor what you do, and nothing in it means we have.
Questions, requests and notices under this document: hello (at) combobulating (dot) ai
The other documents: Terms of Service Privacy Policy