Acceptable Use Policy
Version 1.0 · Effective: 27 April 2026
This Acceptable Use Policy ("AUP") describes what you may publish on display.dev ("Service") and how violations are handled. By using the Service you agree to this AUP, which forms part of the Terms of Service.
1. Accepted File Formats
The Service accepts .html and .md files only. The platform maximum file size is 50 MB per artifact (some plans cap individual files lower; see Pricing for current per-tier limits). Uploads in other formats are rejected at the publish boundary.
2. Prohibited Content
The following content categories are prohibited regardless of plan or configuration:
| Category | Why |
|---|---|
| Phishing and credential harvesting | Fraudulent pages that impersonate other services or solicit login credentials. |
| Child sexual abuse material (CSAM) | Illegal under US and EU law; we are required to report to NCMEC and preserve evidence. |
| Malware and drive-by downloads | Content designed to compromise visitors' systems. |
| Sexually explicit or NSFW content | Prohibited to preserve access for our B2B customer base through corporate proxies and filters. |
| Copyright-infringing content | Content that violates third-party intellectual property rights. We comply with the DMCA. |
3. Prohibited Data Categories
Regardless of content category, the following types of personal data may not be uploaded:
- Protected Health Information (PHI) — display.dev does not offer a Business Associate Agreement; any PHI use is unauthorised.
- Payment card data (PCI) — card numbers, magstripe tracks, CVV codes.
- GDPR Article 9 special categories — health, biometric, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, trade union membership, or criminal record data.
- Children's data — data relating to individuals under 16 (EU/GDPR) or under 13 (US/COPPA).
- Non-public financial records (GLBA) — prohibited without a separate written agreement.
4. Prohibited Use Patterns
Behavioural restrictions that apply regardless of what is published:
- Using artifact URLs as a general-purpose content delivery network unrelated to display.dev's gated publishing use case.
- Serving scraped third-party content without substantive transformation.
- Automated account creation or account farming to circumvent per-organization tier limits.
- Scripted scraping of the Service via API or viewer endpoints.
- Any activity that materially degrades the Service for other customers.
5. Rate Limits
Rate limits are uniform across all plans. They protect service availability for all customers.
| Surface | Limit |
|---|---|
| Publish or update an artifact | 30 per minute per API key |
| Anonymous (claimable) publish | 10 per hour per IP address |
| User API key requests (all endpoints) | 120 per minute per key |
| Org / CI API key requests (all endpoints) | 600 per minute per key |
| Guest viewer OTP — send | 5 per minute per email address |
| Guest viewer OTP — verify | 10 per minute per IP address |
| Account email OTP (sign-in / sign-up) | 30 per minute per IP address — combined limit covers both sending and verifying the code |
| Authenticated session requests (web dashboard) | 100 per minute per session |
The platform maximum file size is 50 MB per upload (see §1 for per-tier caps).
When a limit is reached, requests will be temporarily blocked and resume automatically once the window resets.
If your legitimate workflow requires sustained throughput above the per-key limit, provision additional API keys (each key has its own independent bucket).
6. Enforcement
Rate-limit violations are handled automatically: the server returns 429 and the bucket resets when the window elapses. No human review is required.
Content and behavioural violations follow a human-review path:
| Violation type | Path |
|---|---|
| Reported abuse (phishing, NSFW, misuse) | Email [email protected] — internal review and admin takedown |
| DMCA takedown notice | Email [email protected] — registered DMCA agent, takedown, and counter-notice procedure |
| CSAM | Cloudflare automated detection + NCMEC CyberTipline report + evidence preservation + legal counsel |
| Repeat or severe AUP violations | Account suspension or termination |
Takedowns are per-artifact by default. Account suspension is reserved for repeated violations or single severe ones (phishing, CSAM, clear AUP breach).
7. Reporting and Contact
To report a violation or submit a DMCA takedown notice: [email protected]
For general questions about this policy: [email protected]
Displaydev OÜ · Harju maakond, Tallinn, Estonia