Safe and responsible use

Acceptable Use Policy

This policy defines permitted and prohibited conduct and how violations are handled proportionately and with review.

Published and effective as an operational document, without claiming external legal review

This is a public operational text. It does not replace a project contract, a product-specific privacy notice, or legal review based on the organization and its actual service providers.

Document code
POL-PUB-AUP-001
Version
1.0.0
Effective date
Content review
Next review
Owner
Governance and privacy
Authoritative version
Arabic. If translations differ, the Arabic text prevails, subject to applicable law and contract.
Contact channel
studio@cupcodestudio.com
Scope

Public website, accounts, and connected digital services

Audience

Visitors, users, and clients

Jurisdiction

Kingdom of Saudi Arabia, subject to other mandatory laws where applicable

Operational publication authority

Cup Code operational publication catalog

Document summary

This policy defines permitted and prohibited conduct and how violations are handled proportionately and with review.

Purpose and scope

This policy applies to the website, accounts, Council, portals, support, APIs, and integrations. A contract or test-program rule applies in addition to these terms.

Legitimate use

Use features for genuine communication, business requests, support, participation, and authorized collaboration. Respect technical limits, security instructions, and other people’s rights.

Technical abuse

Do not attempt unauthorized access, bypass isolation or rate limits, scan ports or vulnerabilities outside an authorized program, intercept data, introduce malware, disrupt service, or conceal an attack source.

Automation and data collection

Do not use bots, scrapers, or automated accounts without permission or a documented API. Follow request rate, purpose, and data scope. User profiles, votes, and comments must not be collected to build lists or target individuals.

Harmful content

Threats, exploitation, harassment, hate, fraud, impersonation, unlawful content, personal data exposure, credentials, and infringing material are prohibited.

Spam and manipulation

Repeated messaging, account multiplication, vote buying, covert coordination to manipulate community results, fake reviews, and misleading support to obtain access or compensation are prohibited.

Authorized security research

Stop testing upon accessing data or causing real impact, do not extract data, and test production only under a written scope. Use the security disclosure channel and do not publish exploitable details before remediation.

Proportionate enforcement

We may reduce rate, stop an action, hide content, request verification, or suspend an account. Response depends on severity, recurrence, harm, and intent. A permanent ban requires a documented human decision and is not based on an automated signal alone.

Notice and appeal

Where safe and permitted, we explain the violation, duration, effect, and appeal route. A different reviewer handles the appeal where available, and the decision, evidence, and permission used are recorded.

Versions

Change log

  1. Version 1.0.0

    Published the first operational version with clear scope, responsibilities, rights, and escalation routes.