1. Who this policy applies to
This Acceptable Use Policy ("Policy") applies to everyone who accesses or uses OneVault ID, our websites, our sign-in and consent services, our account site, our developer area and any related services (the "Services"), including account holders, developers, connected apps and automated clients. It forms part of our Terms of Service and, for developers, our Developer Terms. The examples below are not exhaustive; we may treat any conduct that is similar in purpose or effect as a violation.
2. Your account and identity
You must not:
- provide false, inaccurate or misleading registration information, including your name, date of birth or country;
- impersonate any person, business, government body or OneVault, or misrepresent your affiliation with anyone;
- create more than one account unless we have expressly permitted it, or create an account for anyone else;
- create accounts using scripts, bots, disposable or throwaway email addresses, or other automated or bulk means;
- sell, buy, rent, lend, trade, transfer, give away or otherwise commercialize accounts or usernames, including "aged" or "verified" accounts;
- share your password, passkeys, recovery codes or verification codes, or let another person use your account;
- use another person's account, credentials or verification contact points without authorization;
- register or use an account to evade a warning, restriction, suspension, termination or ban; or
- use your account on behalf of a sanctioned person or from a comprehensively sanctioned country or region.
3. Security and system integrity
You must not:
- access, or attempt to access, any account, system, data or network without authorization;
- probe, scan, test or exploit vulnerabilities in the Services, except through an authorized OneVault security disclosure program and within its rules;
- bypass, disable or interfere with authentication, consent screens, rate limits, bot protection (including Cloudflare Turnstile), security monitoring or any other protective measure;
- phish or attempt to obtain credentials, one-time codes, recovery codes or session tokens from anyone, or create pages or apps that imitate OneVault sign-in;
- intercept, replay, forge or tamper with tokens, authorization codes, cookies or protocol messages;
- upload or transmit viruses, malware, ransomware, spyware or any other harmful code;
- conduct denial-of-service attacks or otherwise overload, flood or disrupt the Services; or
- reverse engineer, decompile, disassemble or attempt to derive the source code of the Services, except to the extent that this restriction is prohibited by applicable law.
4. Automation, scraping and capacity
You must not:
- scrape, crawl, spider, harvest or collect information from the Services by automated means, except through documented public interfaces and in compliance with robots.txt instructions;
- use automated means to enumerate usernames, test email addresses, check availability at volume or guess credentials;
- use the Services in a way that places an unreasonable or disproportionate load on our infrastructure; or
- resell, sublicense, frame or provide the Services to others as a service, except as permitted by the Developer Terms.
5. Illegal and harmful activity
You must not use the Services, or any connected app accessed with OneVault, to engage in, promote, facilitate or conceal:
- child sexual abuse or exploitation, including creating, possessing, storing or distributing child sexual abuse material, grooming, or sexualizing minors;
- terrorism or violent extremism, including recruitment, financing, propaganda or support for terrorist organizations;
- fraud and scams, including identity theft, account takeover, investment or romance scams, fake giveaways, phishing and deceptive solicitation;
- money laundering, terrorist financing or sanctions evasion;
- harassment, threats, stalking, bullying, doxxing or incitement to violence or hatred against any person or group;
- human trafficking, sexual exploitation or non-consensual intimate imagery;
- the sale of illegal goods or services, including illegal drugs, weapons, stolen data or counterfeit goods;
- the storage, transmission or distribution of any illegal material; or
- any other activity that violates applicable law or the rights of others.
6. Misuse of connected apps and personal data
You must not:
- use information obtained through OneVault about another person for stalking, profiling, discrimination, unsolicited marketing or any unlawful purpose;
- trick, pressure or mislead anyone into signing in to an app or approving the sharing of their information;
- attempt to link or re-identify a person across apps by combining identifiers or other data that OneVault provides separately to different apps;
- use OneVault sign-in or information obtained through it to make decisions about a person's eligibility for credit, employment, housing, insurance or similar purposes; or
- if you are a developer, request more information than your app needs, sell or rent OneVault-derived data, or otherwise breach the Developer Terms.
7. Intellectual property
You must not infringe or misappropriate the copyright, trademark, trade secret, patent, privacy or publicity rights of anyone, including OneVault, or use the OneVault name, logo or marks without our written permission, or in a way that suggests endorsement or affiliation.
8. Enforcement
If we reasonably believe that you have violated this Policy, or that your use of the Services creates a risk for OneVault, other users, connected apps or third parties, we may, at our discretion and with or without notice, take one or more of the following actions:
- give you a warning;
- require additional verification, a password change or other security steps;
- end your sessions, revoke connected-app access or remove Content;
- restrict features or place a temporary hold on your account;
- suspend your account temporarily or indefinitely;
- permanently terminate your account and prohibit you from creating new accounts; and
- for developers, suspend, restrict or revoke apps and credentials.
We consider the severity and impact of the conduct, whether it was intentional or repeated, and our legal obligations. We may act immediately where we believe it is necessary to protect people or the Services. Illegal activity described in Section 5 will result in account termination and the steps described in Section 9. We are not obliged to monitor the Services, but we may do so, and our decision not to act in one case does not waive our right to act in another.
9. Investigations, preservation and reporting
Where we suspect illegal activity or a serious violation of this Policy, we may, to the extent permitted by law:
- investigate the conduct, including by reviewing relevant account, sign-in and security records;
- preserve relevant records, including records that would otherwise be deleted, for as long as needed for the investigation and any resulting proceedings;
- cooperate with law enforcement and other competent authorities, and respond to valid legal process;
- report the matter to the appropriate authorities where we are legally required or permitted to do so, including reporting apparent child sexual exploitation to the National Center for Missing & Exploited Children (NCMEC) as required by United States law; and
- notify affected connected apps or other service operators where reasonably necessary to stop harm.
We may be prohibited by law from notifying you of an investigation or a request from authorities.
10. Reporting abuse
If you believe someone is violating this Policy, or that a connected app is misusing OneVault, please report it through our contact form, choosing "Other question" and the subject "Abuse report". Include the account username or app involved, the date and time, what you observed, and any supporting evidence. Never send passwords, one-time codes or private keys. If anyone is in immediate danger, contact your local emergency services first. Do not send us child sexual abuse material; report it directly to NCMEC (report.cybertip.org) or your national hotline.
11. Reviews and appeals
Where appropriate and lawful, we will tell you why we took action and how to ask for a review. You may request a review through the contact form within 30 days of our decision, explaining why you believe it was wrong. We will review the request and tell you the outcome. We are not required to reinstate an account, and we may decline reviews for conduct involving illegal activity, repeated violations, or where disclosure would compromise an investigation or security. This does not limit any right you have under mandatory law.
12. Changes to this policy
We may update this Policy from time to time to address new risks or legal requirements. We will post the updated Policy with a new version number and effective date, and give notice of material changes as described in our Terms of Service.