Acceptable Use Policy
Last updated:
What is not permitted on shared hosting and why: content, spam, excessive resource use, file counts, and how breaches are enforced.
Shared hosting means your account sits on a server with other accounts. This policy protects everyone from the one account that disrupts the rest. It forms part of the Terms of Service and binds every subscriber.
The general rule, before the detail: your account is free to do anything that neither harms others nor breaks the law.
Prohibited content
Accounts may not host or distribute:
- Child sexual abuse material, in any form and under any description. This clause alone requires immediate deletion and reporting, with no notice and no refund.
- Malware, viruses, intrusion tooling and exploit kits.
- Phishing pages impersonating a bank, a platform or a government body, and any page built to extract login or payment details from a deceived user.
- Copyrighted material without licence, including libraries of pirated films, books and software, and republished "nulled" WordPress themes.
- Content inciting violence or hatred against a group, and content publishing a person's private data in order to harm them.
- Drugs and weapons, forged documents, stolen data, and any marketplace for them.
- Financial fraud, including pyramid schemes, fake investment sites and counterfeit currency platforms.
Legal adult pornography is not prohibited in itself, but it is not permitted on shared hosting, for two operational reasons: the bandwidth it consumes, and its effect on the reputation of IP addresses shared between accounts.
Spam and bulk mail
- Sending to any list whose members did not subscribe themselves is prohibited. A purchased, scraped or inherited list is spam however polite its contents.
- Running a bulk newsletter service from shared hosting is prohibited. The server's sending limits are tuned for transactional and day-to-day business mail, not campaigns. Use a dedicated bulk email provider — that serves your interests before ours, since your delivery rate through one is far higher.
- Forging sender headers, or sending as a domain you do not own, is prohibited.
- Your account is responsible for the mail leaving it, even mail you did not send. An open contact form or a compromised plugin blasting thousands of messages is treated as deliberate sending, because the effect on the server's reputation is identical.
A single serious complaint, or a spike in bounce rate, is sufficient grounds to stop sending from the account while we investigate.
Excessive resource use
Every account has a share of CPU and memory of its own: a full CPU core and 1–2 GB of burstable memory on the Start and Business plans, and two cores and 3–4 GB on the Premium plan. Disk and bandwidth are shared between the accounts on the server, which is where this policy comes from.
Prohibited:
- Cryptocurrency mining, or any sustained heavy computation unrelated to serving a website to its visitors.
- Running a proxy, VPN, Tor node or any gateway relaying other people's traffic.
- Permanent background processes consuming CPU continuously beyond what ordinary web applications need.
- Storing files your site does not use: personal device backups, media libraries, download repositories. Hosting is not a storage drive.
- Crawlers and scrapers operating from your account at a rate that loads the server.
- Unindexed database queries against large tables that keep the CPU chronically busy.
Temporary heavy use is fine and expected: a traffic spike, a data import, a build. What is not acceptable is a sustained pattern where your account uses its share and then begins slowing the server for everyone else. When that happens we contact you first, with the figures we are seeing, and propose a fix or an upgrade.
File count limits
We publish no numeric limit on the number of files (inodes) an account may hold, and we impose none today. That is a genuine advantage, and we intend to keep it for as long as it is not abused.
But file count is not free on the server. Backups, file scanning and maintenance jobs walk every file individually, so an account holding millions of small files slows those operations for every account on the server, even where its size in gigabytes is modest.
For that reason — and because this is by far the most common way one subscriber comes to affect another:
- We monitor file counts at the server level, not to penalise them, but to find the account that has begun to affect others.
- If your account is shown to be slowing maintenance or backup operations on the server, we will contact you with the figures and give you a reasonable period to clean it up.
- The usual causes are well known and fixable: a cache that is never cleared, logs that are never rotated, a bloated session directory, thousands of backups generated by a plugin, and a
node_modulesfolder left on the server. - If it is not addressed within that period, we may suspend the account to protect the rest of the server. This clause specifically is our basis for suspending an account that harms others.
The same logic applies to databases: any number of tables and concurrent connections is acceptable so long as it does not disrupt the server.
Unlawful activity
Using your account for any activity contrary to applicable law is prohibited, and in particular:
- Intruding into other people's systems, scanning them, or attempting unauthorised access, from or through your account.
- Denial-of-service attacks in every form, participation in a botnet, and operating a command-and-control node for one.
- Impersonating an organisation or an individual, forgery, and money laundering.
- Selling personal data without a basis, or publishing leaked data.
- Breaching sanctions or export restrictions applying to the infrastructure we operate on.
We cooperate with lawful requests from a competent authority, and notify the subscriber of them unless the law prevents us from doing so.
Enforcement
We escalate according to the severity of the breach and its effect on others:
- Notice. The usual case. We write to you with what we have observed and set a period to fix it, proportionate to the problem. Most breaches at this stage were never deliberate — a compromised plugin, or a misconfiguration.
- Temporary restriction. Sending stopped, a resource limit lowered, or a particular process halted, with the site left running.
- Suspension where it is not addressed within the period, or where the harm to the server is ongoing.
- Immediate suspension without prior notice, limited to: child sexual abuse material, live phishing pages, intrusion or denial-of-service activity, and anything placing the server at direct risk. We notify you of the reason as soon as it is applied.
- Termination for a serious or repeated breach. No amount is refunded in that case, and the data retention window set out in the Terms of Service still runs, so you can extract your data.
You may challenge any of these by writing to us, and we will review it. If it turns out we were wrong, we reactivate at no fee and compensate the downtime in service days.
To report a breach taking place on one of our sites: info@qasioun.cloud