Acceptable Use Policy

Version 1.0 · Effective: 27 April 2026

This Acceptable Use Policy ("AUP") describes what you may publish on display.dev ("Service") and how violations are handled. By using the Service you agree to this AUP, which forms part of the Terms of Service.


1. Accepted File Formats

The Service accepts .html and .md files only. The platform maximum file size is 50 MB per artifact (some plans cap individual files lower; see Pricing for current per-tier limits). Uploads in other formats are rejected at the publish boundary.


2. Prohibited Content

The following content categories are prohibited regardless of plan or configuration:

CategoryWhy
Phishing and credential harvestingFraudulent pages that impersonate other services or solicit login credentials.
Child sexual abuse material (CSAM)Illegal under US and EU law; we are required to report to NCMEC and preserve evidence.
Malware and drive-by downloadsContent designed to compromise visitors' systems.
Sexually explicit or NSFW contentProhibited to preserve access for our B2B customer base through corporate proxies and filters.
Copyright-infringing contentContent that violates third-party intellectual property rights. We comply with the DMCA.

3. Prohibited Data Categories

Regardless of content category, the following types of personal data may not be uploaded:

  • Protected Health Information (PHI) — display.dev does not offer a Business Associate Agreement; any PHI use is unauthorised.
  • Payment card data (PCI) — card numbers, magstripe tracks, CVV codes.
  • GDPR Article 9 special categories — health, biometric, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, trade union membership, or criminal record data.
  • Children's data — data relating to individuals under 16 (EU/GDPR) or under 13 (US/COPPA).
  • Non-public financial records (GLBA) — prohibited without a separate written agreement.

4. Prohibited Use Patterns

Behavioural restrictions that apply regardless of what is published:

  • Using artifact URLs as a general-purpose content delivery network unrelated to display.dev's gated publishing use case.
  • Serving scraped third-party content without substantive transformation.
  • Automated account creation or account farming to circumvent per-organization tier limits.
  • Scripted scraping of the Service via API or viewer endpoints.
  • Any activity that materially degrades the Service for other customers.

5. Rate Limits

Rate limits are uniform across all plans. They protect service availability for all customers.

SurfaceLimit
Publish or update an artifact30 per minute per API key
Anonymous (claimable) publish10 per hour per IP address
User API key requests (all endpoints)120 per minute per key
Org / CI API key requests (all endpoints)600 per minute per key
Guest viewer OTP — send5 per minute per email address
Guest viewer OTP — verify10 per minute per IP address
Account email OTP (sign-in / sign-up)30 per minute per IP address — combined limit covers both sending and verifying the code
Authenticated session requests (web dashboard)100 per minute per session

The platform maximum file size is 50 MB per upload (see §1 for per-tier caps).

When a limit is reached, requests will be temporarily blocked and resume automatically once the window resets.

If your legitimate workflow requires sustained throughput above the per-key limit, provision additional API keys (each key has its own independent bucket).


6. Enforcement

Rate-limit violations are handled automatically: the server returns 429 and the bucket resets when the window elapses. No human review is required.

Content and behavioural violations follow a human-review path:

Violation typePath
Reported abuse (phishing, NSFW, misuse)Email [email protected] — internal review and admin takedown
DMCA takedown noticeEmail [email protected] — registered DMCA agent, takedown, and counter-notice procedure
CSAMCloudflare automated detection + NCMEC CyberTipline report + evidence preservation + legal counsel
Repeat or severe AUP violationsAccount suspension or termination

Takedowns are per-artifact by default. Account suspension is reserved for repeated violations or single severe ones (phishing, CSAM, clear AUP breach).


7. Reporting and Contact

To report a violation or submit a DMCA takedown notice: [email protected]

For general questions about this policy: [email protected]

Displaydev OÜ · Harju maakond, Tallinn, Estonia