Acceptable Use Policy
What you may not do with HourlyVPS servers and network, and how we enforce the rules.
Last updated
In plain English
- Do not use HourlyVPS for anything illegal, for spam, for attacks or unauthorized scanning, for malware or phishing, or for cryptocurrency mining.
- Outbound port 25 is closed on new servers. If you run a legitimate mail server, ask us to open it.
- You are responsible for everything on your servers, including what your users and customers do, and for keeping your systems secure.
- We act on credible reports. Usually we warn first and give you time to fix the problem; serious or ongoing harm can lead to immediate suspension.
- Report abuse coming from our network to [email protected].
This summary is here to help you read the document. If it differs from the numbered sections, the numbered sections apply.
1. Scope
This Acceptable Use Policy (the “AUP”) is part of our Terms of Service. Terms defined there have the same meaning here.
The AUP applies to every Service and to everyone who uses one: you, your staff, and your own users and customers. If they break the AUP, we treat it as a breach by you.
The examples below are not a complete list. When something is not listed, we judge it by the harm it causes or risks causing.
2. Illegal activity and content
You may not use the Services to store, transmit, publish or facilitate anything that is illegal under US law, the law of the State of Wyoming, or the law of the country where your server is located. This includes:
- child sexual abuse material or any content that sexualizes minors. We do not tolerate it: we terminate the Service immediately, preserve data as the law requires and report it to the US National Center for Missing & Exploited Children (NCMEC) and other competent authorities;
- content that infringes copyright, trademarks or other intellectual-property rights;
- fraud and scams, including fake shops, investment fraud, money laundering and the sale of counterfeit goods;
- terrorist content, incitement to violence, credible threats, harassment and stalking;
- intimate images shared without the consent of the people shown;
- unlawfully obtained personal data, such as stolen credentials, payment-card data or leaked databases;
- anything that breaches sanctions or export-control law.
3. Email and messaging
- Do not send unsolicited bulk or commercial messages (spam), wherever the addresses came from.
- Send bulk email only to recipients who opted in. Every message must identify the sender truthfully and contain a working unsubscribe link, and you must follow the anti-spam laws that apply to you, such as the US CAN-SPAM Act and, where relevant, the EU and UK rules on electronic marketing.
- Do not use purchased, rented, harvested or scraped address lists.
- Do not advertise a site hosted with us through spam sent from anywhere else.
- Do not forge headers, use misleading subject lines or relay mail through third-party systems without permission.
- The same rules apply to other channels, such as SMS gateways, messaging apps, social networks, forums and comment sections.
Outbound port 25
Outbound SMTP on TCP port 25 is blocked on new servers. To have it opened, open a ticket in the Portal and describe what you will send, for example mail for your own domains. We may ask for account history or verification first, and we may decline. If we receive spam complaints or the server’s IP address appears on blocklists, we may close the port again.
4. Attacks, scanning and unauthorized access
You may not:
- launch denial-of-service attacks, run “stresser” or “booter” services, or flood any network or system with traffic;
- scan ports, scan for vulnerabilities or map networks that you do not own and have no written permission to test;
- run brute-force or credential-stuffing attacks;
- access, use or interfere with any system, account or data without authorization, including by exploiting vulnerabilities;
- spoof IP addresses, forge packet headers, use IP addresses that are not assigned to you or announce routes we have not authorized;
- intercept or monitor other people’s traffic;
- run botnet or command-and-control infrastructure.
Security testing. Penetration tests and security research are allowed when you have the written permission of the owner of the target systems, stay within the agreed scope and can show us the permission if we ask. Load tests against systems outside our network need the same permission and must not affect our network. Internet-wide scanning for research needs our approval in advance and must honor opt-out requests.
5. Open services that others can abuse
Do not run the following, whether on purpose or through misconfiguration:
- open mail relays;
- open proxies that let unauthenticated third parties route traffic through your server. Authenticated VPN or proxy services for your own users are allowed if those users must follow rules at least as strict as this AUP;
- open recursive DNS resolvers, or other internet-facing UDP services that can be used for reflection or amplification attacks, such as unrestricted NTP, Memcached or SSDP.
If we find such a service, we will ask you to fix it and may block the affected port in the meantime.
6. Malware, phishing and deception
- Do not host or distribute malware, including ransomware, spyware, exploit kits and droppers.
- Do not host phishing pages, fake login pages or credential-harvesting forms, or impersonate banks, brands, public bodies or other people.
- Do not run mining scripts in visitors’ browsers or on other people’s devices without their informed consent.
- Malware samples kept for legitimate research are allowed if they are not publicly reachable and are never run against systems you do not own.
7. Cryptocurrency mining
Mining or plotting any cryptocurrency or token is prohibited on every plan and in every location. This includes proof-of-work mining, proof-of-space or proof-of-capacity plotting and farming, and mining-pool proxies. Running a blockchain node that does not mine is allowed within the fair-use rules in section 8.
If we detect mining, we may stop the server immediately and may terminate the account.
8. Fair use of shared resources
- Quartz plans use shared vCPU. Running shared vCPU at full load for long periods can slow down other customers on the same host. If a server does this, we may contact you and may limit its CPU allocation. Chrono plans have dedicated vCPU and are designed for sustained CPU work.
- Unmetered transfer is subject to the fair-use rule in section 10 of the Terms.
- Do not try to get around resource limits, the billing meter or the isolation of the virtualization layer.
- Do not open several accounts to avoid limits, verification or enforcement.
9. IP addresses and reputation
- Use only the IP addresses assigned to you, follow the policies of the regional internet registry that allocated them and keep reverse-DNS records accurate.
- If your activity gets our IP addresses listed on a blocklist, stop that activity immediately. We may charge you the reasonable, documented cost of getting the listing removed, and we may withdraw or replace the affected address.
10. Keeping your server secure
- Keep your operating system and software up to date, use strong authentication (we recommend SSH keys), change default passwords and close services you do not use.
- If your server is compromised and used for attacks, spam or malware, it is a breach of the AUP even if you did not intend it. We will isolate the server to stop the harm and help you regain control, for example by keeping console access open while its network access is restricted.
11. Reporting a violation
Send reports of abuse coming from our network to [email protected]. Our Report abuse page explains what to include and what happens next. To report a security vulnerability in our own website or Portal, see our Security page.
12. How we enforce this policy
We do not monitor the content of our customers’ servers. We act on abuse reports, on signals from our own network, such as attack traffic or blocklist alerts, and on legal orders. Our response is proportionate to the harm and usually follows these steps:
- Notice. We forward the report or describe the problem, and ask you to fix it within a deadline that fits the harm, usually 24 hours for active harm and longer for less urgent issues.
- Restriction. If the problem is not fixed or the harm continues, we may block ports, null-route an IP address, limit bandwidth or restrict network access, while keeping console access open where we can.
- Suspension of the affected servers or of the account.
- Termination of the affected Services or of the account, for serious or repeated violations.
We may act immediately and without prior notice when that is needed to stop serious, ongoing harm or to comply with the law, for example for child sexual abuse material, active attacks, phishing or malware distribution, a compromise that threatens our network, or a court order. We then tell you what we did as soon as we can.
Statement of reasons. When we restrict, suspend or terminate a Service under this AUP, we tell you what we did, the facts we relied on, the rule concerned, the scope and duration of the measure and how to contest it, unless the law forbids it or telling you would compromise an investigation or put someone at risk.
Contesting a decision. Reply to the ticket or write to [email protected], with any information that shows the decision was wrong. A member of our team will review it and tell you the outcome. If the measure was not justified, we reverse it.
Billing during enforcement. Restricting or suspending a server under this AUP does not pause its billing, because its resources stay reserved. You can delete the server to stop charges. If we terminate your account for a serious violation, we do not pay out your remaining account credit unless the law requires it, and we may use it to cover documented costs your violation caused us.
We may cooperate with law enforcement, computer emergency response teams, other network operators and blocklist operators to stop abuse.
13. Changes to this policy
We may update this AUP. If a change is material and works against you, we will email you at least 30 days before it takes effect, except for changes needed to comply with the law or to address new forms of abuse, which may take effect when we publish them. The version number and effective date are at the top of this page.