Ownware Cloud: Acceptable Use Policy
Part of the Ownware Cloud Terms of Service · version 1.0 · published 27 September 2026 · in force from that date
This policy is part of the Ownware Cloud Terms of Service. It covers you, and everyone you give access to your Instance — your staff, and your own customers where the app gives them a login or a public page.
It exists for one reason: every Instance shares infrastructure with other customers' Instances, and what one Instance does can affect the rest. We keep it short and apply it in proportion.
1. What you agree not to do
You agree not to use the Cloud, or let anyone use your Instance, to:
1.1 Break the law — store, publish or send anything that is unlawful where you or the people concerned are, or use an app for a purpose that is unlawful.
1.2 Infringe other people's rights — including copyright, trade marks, privacy and data protection rights.
1.3 Process personal data without a lawful basis — put personal data into your Instance that you have no right to hold, or use it in ways you have not told the people concerned about where the law requires you to tell them.
1.4 Send spam or deceptive messages — use an app's email, reminder, review-request or messaging features to send unsolicited bulk messages, or messages that pretend to come from someone else, including phishing.
1.5 Harm other people — harass, threaten or defraud anyone, or publish content that incites violence or hatred.
1.6 Spread malicious code — upload or distribute malware, or use your Instance to host files meant to harm other systems.
1.7 Attack or probe the service — try to reach other customers' Instances or data, get round the separation between Instances, scan, probe or load-test the Cloud, or interfere with its operation. Security research is welcome only with our written permission in advance; see section 3.
1.8 Get round limits or controls — bypass authentication, billing or technical limits, or share an Account in a way meant to avoid paying for a Plan.
1.9 Resell the service — offer your Instance, or access to it, to other people as a hosted or multi-tenant service they sign up for, unless we have agreed in writing. (Your own customers using the parts of the app built for them — a booking page, a tenant portal, a verification page — is normal use, not reselling.)
1.10 Use disproportionate resources — run workloads unrelated to the app, such as cryptocurrency mining, or use storage or bandwidth far beyond what the app is designed for. Plans have no user or record limits. As a guide, an Instance is sized for up to 1 GB of stored files. If yours grows past that, or its traffic starts to slow other customers' Instances, we contact you first and agree a way forward before we act.
2. Your integrations
2.1 You can connect your own AI assistant through your Instance's MCP endpoint, add your own AI provider key, or set up webhooks and other integrations. You choose those services and they act under your own agreements with their providers.
2.2 This policy still applies to what you do through them: an automated agent acting with your API key is treated as acting for you.
3. Reporting a problem
3.1 To report abuse of the Cloud, or content in an Instance that you believe breaks this policy, email support@ownware.io with enough detail for us to find it.
3.2 To report a security vulnerability, use the contact in https://ownware.io/.well-known/security.txt. Please give us 90 days to fix an issue before publishing it.
3.3 We are the host, not the controller, of the data in your Instance. Where a report concerns personal data in your Instance, we pass it to you to deal with, unless the law requires us to act directly.
4. What we do if this policy is broken
4.1 We act in proportion to the harm. In most cases we will first email you, explain what we have found and give you 7 days to fix it.
4.2 If there is an immediate risk to other customers, to the service or to anyone's safety, or if the law requires it, we may restrict the affected part of your Instance straight away and tell you as soon as we can.
4.3 Serious or repeated breaches can lead to suspension or termination under the Terms of Service. Suspension does not delete your data; what happens to it is set out in "Your data when a Plan ends".
4.4 We may report unlawful activity to the relevant authorities where the law requires or allows it.
5. Changes
5.1 We will email you any change to this policy at least 30 days before it takes effect, unless it is needed sooner to deal with a new security threat or a legal requirement.
---
Version: draft 0.1, 25 September 2026. Not published.