VibeDeploy← Back to home

Acceptable Use Policy

Version 2026-09 · Last updated: 7 September 2026

This Acceptable Use Policy (“AUP”, “Policy”) governs what may and may not be published, stored, transmitted or done using the VibeDeploy hosting platform (the “Service”), operated by Tnet Comm.V, a company registered in Belgium under VAT number BE0770401120 with its registered office at Waterbosstraat 39, 3290 Diest, Belgium (“VibeDeploy”, “we”, “us”, “our”).

This Policy forms an integral part of our Terms of Service and is incorporated into them by reference. By creating an account, deploying content, or otherwise using the Service, you agree to this Policy. Where this Policy and the Terms of Service conflict on a question of permitted use, this Policy prevails. Capitalised terms not defined here have the meaning given in the Terms of Service.

1. Scope: services and users covered

1.1 Services covered

VibeDeploy is a web hosting and deployment platform for static websites, single-page applications and other web-based projects, published from a developer's tooling or from an AI assistant. This Policy applies to every part of the Service, including:

  • Hosting and public serving of deployed websites on platform subdomains and on custom domains
  • Deployment pipelines, build tooling, staging environments and deploy history
  • Custom domain management, DNS handling and TLS certificate provisioning
  • Domain registration and renewal ordered through us as reseller
  • The dashboard, the public API, API keys, webhooks and the Model Context Protocol (MCP) interface
  • Ancillary features such as form relay email, site analytics, snapshots, backups and stored source files
  • Support channels, including email, and any account or billing correspondence

The vibedeploy.be, vibedeploy.eu and ai-hosted.com storefronts are the same platform, operated by the same legal entity, Tnet Comm.V. This Policy applies identically to all of them.

1.2 Users covered

This Policy binds everyone who uses the Service, whether or not they hold an account:

  • Account holders, whether consumers, sole traders, companies or non-profit organisations
  • Team members and invited collaborators acting under an account, in any role (owner, admin, member, viewer)
  • Agencies, freelancers and resellers who deploy or operate sites on behalf of their own clients
  • Automated agents, including AI assistants, CI systems and scripts, that act through an API key, an OAuth grant or the MCP interface on your behalf
  • Any third party or sub-user to whom you grant access to your account, your sites, or your deployment credentials

If you use the Service on behalf of an organisation, you confirm that you are authorised to bind that organisation, and “you” means both you and that organisation.

2. Permitted use

The Service is intended for publishing and operating lawful websites and web applications, for example: business and portfolio websites, product and marketing pages, documentation, web applications and internal tools, client work delivered by agencies and freelancers, prototypes, and personal projects.

Permitted use means use that:

  • Complies with all applicable laws and regulations, and with this Policy and the Terms of Service
  • Stays within the resource, storage, bandwidth and site limits of your subscription plan
  • Respects the rights of third parties, including intellectual property, privacy and personality rights
  • Does not damage, overload, degrade or compromise the Service, our infrastructure, or other users
  • Is honest about who you are and what your website does

You are responsible for everything published, transmitted or executed under your account, including content generated by an AI tool acting on your instructions. Automatic generation does not transfer responsibility: content deployed under your account is your content.

3. Prohibited use

The following are prohibited on the Service. The list describes categories, not an exhaustive enumeration; conduct of a comparable nature is equally prohibited.

3.1 Illegal content and activity

  • Any content or activity that is illegal under Belgian law, European Union law, or the law applicable to you or your visitors
  • Child sexual abuse material (CSAM) or any content that sexually exploits or endangers minors. We treat this with the highest priority, remove it immediately, preserve evidence and report it to the competent authorities
  • Content that incites terrorism or violent extremism, or that facilitates human trafficking, forced labour, or the exploitation of vulnerable persons
  • Sale or facilitation of the sale of illegal drugs, controlled substances, prescription medicines without a licence, weapons, ammunition, explosives, endangered species, stolen goods, or forged identity or official documents
  • Money laundering, terrorist financing, sanctions evasion, or the concealment of the origin of funds
  • Unlicensed provision of regulated services, including financial, payment, insurance, medical or legal services requiring authorisation you do not hold

3.2 Fraud, deception and impersonation

  • Phishing pages, credential-harvesting forms, fake login screens, or any page designed to obtain passwords, payment card data, one-time codes, banking credentials or identity documents by deception
  • Impersonating a bank, payment provider, public authority, courier, marketplace, employer, any other organisation, or any natural person
  • Fake webshops, non-delivery schemes, bait-and-switch offers, fake invoices, advance-fee fraud, romance or investment scams
  • Counterfeit goods, replica products, or the sale of illegitimate licences, keys or credentials
  • Pyramid schemes, Ponzi schemes, chain letters, matrix schemes, get-rich-quick programmes, and misleading multi-level marketing recruitment
  • Deceptive claims about earnings, health outcomes, investment returns, or the performance or origin of a product or service
  • Deceptive subscription practices, including hidden recurring charges, obstructed cancellation, or unclear pricing
  • Testing stolen or generated payment card data (card testing), or any page or endpoint built to validate stolen credentials
  • Using VibeDeploy branding, our name or our logo in a way that suggests endorsement or affiliation that does not exist

3.3 Malware and security abuse

  • Hosting, distributing, or linking to malware, ransomware, spyware, stalkerware, keyloggers, exploit kits, or any other malicious code
  • Command-and-control infrastructure, drop sites for exfiltrated data, or redirect chains serving a malicious campaign
  • Port scanning, vulnerability scanning, penetration testing, brute-force attacks, or credential stuffing against systems you do not own or are not authorised in writing to test
  • Attempting to breach, probe or circumvent the isolation, authentication, rate limits, resource quotas, billing controls or other security controls of the Service, or to access another customer's data or infrastructure
  • Publishing tools whose predominant purpose is to compromise systems, harvest credentials, or defeat security measures

Legitimate, coordinated security research on your own sites is welcome. Report platform vulnerabilities to legal@vibedeploy.be. Do not test against other customers.

3.4 Spam and messaging abuse

  • Sending or facilitating unsolicited bulk email, SMS or messaging, including through our form relay feature
  • Operating an open mail relay, a mailing-list system without verified opt-in, or a landing page supporting a spam campaign
  • Search engine spam, link farms, doorway pages, cloaking, scraped or auto-generated content published purely for ranking manipulation, and private blog networks
  • Harvesting email addresses or phone numbers for unsolicited contact

3.5 Harmful, abusive and infringing content

  • Content inciting violence, hatred or discrimination on the basis of race, ethnicity, national origin, religion, disability, gender, sexual orientation, age or any other protected characteristic
  • Harassment, threats, doxxing, non-consensual intimate imagery, or content promoting self-harm, eating disorders or suicide
  • Defamatory content, or content that violates the privacy or personality rights of an identifiable person
  • Content that infringes copyright, trademarks, patents, database rights, design rights or other intellectual property, including pirated software, cracked licences, and tools that circumvent technical protection measures
  • Sexual content involving minors or lacking the consent of the persons depicted, in any form

3.6 Infrastructure and resource abuse

  • Cryptocurrency mining, proof-of-work computation, or distributed computing workloads, whether in our infrastructure or in visitors' browsers
  • Conducting or facilitating denial-of-service attacks, network flooding, amplification or reflection attacks
  • Operating open proxies, VPN exit nodes, anonymisation relays, URL shorteners for cloaking, or traffic-laundering services
  • Using the Service primarily as a file dump, backup target, content delivery network for unrelated properties, or general-purpose compute platform rather than for web hosting
  • Workloads that materially degrade service quality for other users, or that are engineered to consume resources beyond your plan
  • Creating multiple accounts or sites to circumvent plan limits, trial limits, pricing, or a suspension or termination decision

3.7 Privacy and data protection violations

  • Collecting or processing personal data through a deployed site without a valid legal basis, transparent information, and the safeguards required by the GDPR and applicable national law
  • Deploying tracking, fingerprinting or profiling that ignores the consent requirements applicable to your visitors
  • Publishing personal data, credentials, payment data or confidential information without the right to do so
  • Uploading data subject to special protection (health, biometric, financial account or government identity data) without the security measures and legal basis its processing requires

4. Restricted and high-risk activities

Some activities are lawful but carry elevated legal, regulatory or payment risk. They are not permitted by default. You must disclose them to us in writing at legal@vibedeploy.be before deploying, and may only proceed with our written approval, which we may refuse or withdraw at our discretion. Restricted categories include:

  • Adult or pornographic content, adult services, and dating or companionship services
  • Gambling, betting, lotteries, casino-style games, sweepstakes and prize competitions
  • Cryptocurrency exchanges, token sales, wallets, staking, mining pools and other virtual asset services
  • Financial services, lending, debt collection, credit repair, investment advice, trading signals and forex
  • Pharmacies, telemedicine, nutraceuticals, supplements, cannabis and CBD products, tobacco, vaping and alcohol sales
  • Weapons, ammunition, knives and related accessories, where lawful in the relevant jurisdiction
  • Ticket resale, travel aggregation with prepayment, escrow services and money transfer
  • Political campaigning, political advertising, and content subject to election law
  • Services aimed at children under 13, and any site processing children's personal data at scale
  • Any activity that a payment provider, card scheme or acquirer classifies as high risk or prohibited

Where we approve a restricted activity, approval is limited to the site, the content and the jurisdictions described in your disclosure. You must hold every licence, registration and age-verification measure the activity requires, and you must tell us without delay if your licence position changes.

Regardless of approval, no restricted activity may be operated in breach of Section 3 or Section 5 of this Policy.

5. Compliance with laws, sanctions and export controls

5.1 General legal compliance

You must comply with all laws and regulations applicable to you, to your content, and to the people who use your sites. This includes, without limitation, Belgian and EU law, consumer protection and distance-selling rules, e-commerce information duties, advertising and unfair commercial practice rules, tax obligations, the GDPR and the ePrivacy rules, the Digital Services Act (Regulation (EU) 2022/2065), intellectual property law, and any sector-specific licensing regime that applies to your activity.

If you sell to consumers, your site must identify the trader, state prices and taxes clearly, and provide the legally required terms, withdrawal information and contact details.

5.2 Sanctions and restrictive measures

The Service may not be used in breach of economic or trade sanctions. You represent and warrant, for as long as you use the Service, that:

  • You, your organisation, your beneficial owners, your directors and your authorised users are not listed on, or owned or controlled by a party listed on, the sanctions lists of the European Union, the United Nations Security Council, Belgium, the United Kingdom, or the United States (including the OFAC Specially Designated Nationals list)
  • You are not located in, ordinarily resident in, or established in a territory subject to comprehensive EU or UN sanctions, and you will not use the Service to provide goods, services, technology or funds to such a territory or to a sanctioned party
  • You will not use the Service to evade, circumvent or facilitate the evasion of any sanction, embargo or restrictive measure

We screen accounts and payments against applicable sanctions lists and may request evidence of identity, beneficial ownership or business activity. We will suspend or terminate any account, and may freeze balances and refuse refunds, where required by sanctions law. Payments are handled by our payment provider, which performs its own sanctions and anti-money-laundering screening; a payment refused on those grounds cannot be reinstated by us.

5.3 Export control

You may not use the Service to publish or distribute technology, software or technical data in breach of applicable export control law, including EU dual-use regulation.

6. Rules governing use of the platform

6.1 Account integrity

One personal account per person. You must register with accurate, current details, keep your billing information correct, enrol and maintain multi-factor authentication, and keep credentials, API keys and recovery codes confidential. You must not share an account to avoid seat or plan limits, and you must not register an account using another person's identity or payment instrument.

6.2 Preventing misuse and fraud

You must take reasonable steps to keep your sites from becoming a vehicle for abuse. In particular you must:

  • Secure any forms, endpoints or upload paths you expose, and protect them against automated abuse and spam
  • Keep dependencies, templates and build tooling reasonably up to date, and remove code you no longer control or understand
  • Not enable open redirects, unrestricted file uploads or unauthenticated content publishing that a third party can abuse
  • Verify that content produced by an AI assistant on your behalf is accurate, lawful and non-infringing before you publish it
  • Act promptly on any abuse notice, security warning or takedown request we forward to you
  • Notify us at abuse@vibedeploy.be if your site or account is compromised or is being abused

6.3 Domains and DNS

Domains registered or connected through the Service must not infringe third-party trademarks, must not be used for typosquatting or impersonation, and must be pointed only at content that complies with this Policy. Registry and ICANN rules, including accurate registrant data, apply in addition to this Policy.

6.4 Fair use of resources

Plan limits on sites, storage, bandwidth, build minutes and API rate are published on our pricing page and in the dashboard. Sustained use beyond those limits, or use that harms platform stability, may lead to throttling, a required plan upgrade, or the measures in Section 8.

6.5 Illegal content notices

Anyone can report illegal or harmful content through our notice-and-action channel at vibedeploy.be/abuse, our point of contact under Article 16 of the Digital Services Act, or by email to abuse@vibedeploy.be. We handle notices in a timely, diligent, non-arbitrary and objective manner, and inform the reporter and the affected customer of our decision, with reasons, where the law requires it.

7. Responsibility for third parties and sub-users

You are fully responsible for the acts and omissions of every person and system that uses the Service through your account, as if they were your own. That includes:

  • Team members and collaborators you invite, in every role, and anyone using credentials issued under your account
  • Clients of agencies, freelancers and resellers. If you deploy or manage sites for third parties, you must impose terms on those parties that are at least as protective as this Policy, you must be able to identify the party responsible for each site, and you must act on abuse notices concerning their sites
  • Contributors and end users who can publish, upload or submit content to a site you operate, including through forms, comment features or user-generated content flows
  • AI assistants, agents, scripts and CI systems acting through your API keys, OAuth grants or the MCP interface. An action taken by an automated agent under your credentials is your action
  • Third-party code, templates, plugins, fonts, media and data you incorporate. You must hold the necessary licences and comply with their terms
  • Third-party services your site calls or embeds. You remain responsible for the legal basis, disclosures and consent required for any data those services receive

Where you act as a data controller for your visitors, our Data Processing Agreement governs our role as processor. Nothing in this Policy makes us responsible for your relationship with your own users or clients.

You will indemnify us, on the terms set out in the Terms of Service, against claims arising from a breach of this Policy by you or by anyone acting through your account.

8. Monitoring and enforcement

8.1 What we monitor

We are a hosting provider and we do not proactively review, edit or approve customer content before it is published, and we are under no general obligation to monitor it. We do, however, reserve the right to:

  • Operate automated abuse, malware, phishing and fraud detection across the platform, and act on signals from security vendors, browser safe-browsing programmes, registries, registrars and payment providers
  • Monitor infrastructure telemetry such as traffic volume, bandwidth, storage, resource consumption, error rates and deployment activity
  • Investigate any account, site, deployment or stored file where we receive a notice, or where we have reason to believe this Policy, the law, or the security of the Service is being breached
  • Access customer content to the extent strictly necessary for that investigation, to comply with a legal obligation, or to respond to a lawful request from a competent authority
  • Retain evidence, including logs, deployment history and copies of the content concerned, for the purposes of the investigation, legal claims and reporting obligations

We exercise these rights proportionately and in line with our Privacy Policy.

8.2 Enforcement actions

Where we determine that this Policy has been breached, or that a breach is reasonably suspected, we may take one or more of the following actions, chosen according to the seriousness, recurrence and impact of the breach:

  • Issue a warning and require you to remedy the breach within a stated period
  • Restrict, disable, unpublish or delete the specific content, file, page or site concerned
  • Disable a custom domain, a form relay, an API key or another individual feature
  • Apply rate limiting, throttling or a resource cap
  • Suspend the account, in whole or in part, with or without prior notice
  • Terminate the account and the contract for cause, and delete the associated data after the retention period in the Terms of Service
  • Withhold refunds of prepaid fees where termination is for cause, and charge the reasonable costs of investigating and remediating serious abuse
  • Refuse to provide the Service to you, or to any related account, in the future
  • Report the matter to law enforcement, a regulator, a registry, a registrar or our payment provider, and share the information necessary for that report

We act immediately and without prior notice where content is manifestly illegal, where there is a risk to the safety of persons, where a site is actively serving malware or phishing, where the security or integrity of the Service is threatened, or where the law or a competent authority requires it. In all other cases we aim to give you notice and a reasonable opportunity to remedy the breach first.

8.3 Notice and appeal

When we take an enforcement action against your account or content, we inform you of the decision and its reasons, unless a legal obligation prevents it. You may contest a decision by writing to legal@vibedeploy.be within 30 days. We review appeals under human supervision, not by automated means alone, and answer within a reasonable period. Your statutory rights, including any right to complain to a competent authority or to seek out-of-court dispute settlement under the Digital Services Act, are unaffected.

8.4 No waiver

Not enforcing a provision of this Policy in one instance does not waive our right to enforce it later. Our enforcement rights are in addition to, and not instead of, the suspension and termination rights in the Terms of Service.

9. Reporting a violation

To report content or behaviour that breaches this Policy, use the form at vibedeploy.be/abuse or email abuse@vibedeploy.be. Please include the exact URL, a description of the problem, and, for intellectual property claims, evidence of your rights. Reports of child sexual abuse material are treated with the highest priority and are forwarded to the competent authorities.

If someone is in immediate danger, contact your local emergency services first.

10. Changes to this Policy

We may update this Policy to reflect changes in law, in the risks we see on the platform, or in the Service. Material changes are announced by email or in the dashboard at least 30 days before they take effect, except where a change must take effect immediately to comply with the law or to address a security or abuse risk. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy. If you do not accept it, you may terminate your subscription as described in the Terms of Service.

11. Contact

Tnet Comm.V, trading as VibeDeploy, company number and VAT BE0770401120, Belgium. We aim to respond to all enquiries within 5 business days, and faster for abuse reports.