Acceptable Use Policy
Last updated: 21 September 2026Effective: 21 September 2026Version 1.0
In plain language
Short version: use TracePath to observe systems you are responsible for, do not break the law, do not aim it at other people’s infrastructure, and do not try to get around quotas or security controls.
Two things deserve particular care because they reach outside our platform: synthetic monitors, which send real requests to endpoints you configure, and on-call notifications, which send messages to real people and phones.
We would rather email you than suspend you. Immediate action is reserved for cases where waiting would cause harm.
This summary is for orientation only. The numbered sections below are the binding text.
1.Scope
This Acceptable Use Policy applies to everyone using TracePath and forms part of the Terms of Service. Capitalised terms have the meanings given there. It covers the application and API at app.tracepath.dev, the telemetry endpoint at ingest.tracepath.dev, our SDKs and command-line tools, and any status page or public artefact you publish through the Service.
You are responsible for ensuring that everyone you give access to — employees, contractors, automated agents — follows it.
2.Prohibited uses
You must not use the Service to:
- break any applicable law or regulation, or infringe anyone’s intellectual property, privacy, publicity or other rights;
- store, process or distribute malware, ransomware, exploit kits, credential-stuffing lists, stolen data, or material obtained through unauthorised access to a system;
- host or distribute child sexual abuse material, content that incites violence or terrorism, or content that harasses, threatens or defames a person;
- monitor, instrument or collect data from systems, applications or networks you do not own and are not authorised to monitor;
- surveil individuals — the Service is for observing systems, not people. Do not use session replay, logs or traces to build covert behavioural profiles of employees or end users beyond what your lawful basis and your own privacy notice permit;
- send unsolicited bulk messages, or use the notification system to deliver marketing or any content unrelated to operational alerting;
- resell, white-label or provide the Service to third parties as if it were your own product, without a written agreement with us;
- misrepresent your identity or affiliation, or impersonate another person or organisation in an account, a status page or a notification;
- use the Service in a safety-critical or life-critical context as the sole safeguard — it is a monitoring aid and is not certified for such use.
3.What you must not send us
You control what your applications transmit. Unless we have separately agreed it in writing, including any additional safeguards, do not send as telemetry:
- special categories of personal data under Article 9 GDPR — health data, biometric or genetic data, data about racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation;
- personal data relating to criminal convictions and offences (Article 10 GDPR);
- payment card numbers, CVV codes or full magnetic stripe data. The Service is not a cardholder data environment and is not assessed against PCI DSS;
- government identifiers such as national identity, passport, social security or tax numbers;
- authentication secrets — passwords, private keys, API tokens, session cookies;
- data about children where you have no lawful basis for processing it;
- content subject to export control or sanctions restrictions that would make our processing of it unlawful.
Use the tools we give you
Protected health information in particular. TracePath does not offer a Business Associate Agreement, on any plan, and makes no HIPAA offering. Do not transmit protected health information to the Service. If your workload involves it, talk to [email protected] before you send anything — we would rather tell you no than find it in our storage.
4.Protecting the platform
You must not:
- probe, scan or test the vulnerability of the Service, or breach or circumvent its authentication, authorisation, rate limiting or quota controls, except as permitted under section 6;
- attempt to access another customer’s data, account or organisation, or any part of the Service you have not been granted access to;
- create multiple accounts, or split an organisation across accounts, in order to evade a plan limit, a suspension or a payment obligation;
- place a disproportionate load on the Service — for example sustained ingest or query volume far beyond what your plan contemplates, or automated traffic designed to test capacity;
- interfere with other customers’ use of the Service, or with the infrastructure it depends on;
- reverse engineer, decompile or disassemble the Service, or attempt to derive its source code, except to the extent mandatory law expressly permits despite this restriction;
- use automated means to scrape our websites or documentation at a rate that burdens them, or to replicate the Service’s functionality.
We apply rate limiting and admission control to protect the platform. Deliberately engineering around those controls is a breach of this policy.
5.Monitors, notifications and status pages
Synthetic monitors and notifications leave our platform and land on other people’s systems and phones. Treat them accordingly.
- Only monitor what you are authorised to monitor. Configure checks against endpoints you own or have explicit permission to probe. Repeated automated requests to a third party who has not agreed to them can constitute abuse, and the responsibility is yours.
- Do not use monitors as a load or attack tool. Check frequency must be proportionate to the endpoint’s capacity. Do not use the monitoring system to generate traffic against a target for any purpose other than genuinely observing its availability.
- No internal or reserved address ranges. In the hosted service, monitors cannot target private, loopback or link-local addresses. Do not attempt to circumvent that restriction through redirects, DNS entries pointing at internal ranges, or any other means.
- Notification recipients must have agreed. Only configure phone numbers, email addresses and webhooks belonging to people and systems that expect to receive operational alerts from you. Do not use alerting as a channel for marketing or for contacting anyone who has not consented.
- Status pages are public. Anything you publish on a status page, including incident updates and post-mortems, may be read by anyone. Do not publish third-party confidential information or personal data there.
6.Security research
We welcome good-faith security research and we will not pursue legal action against researchers who follow the rules on our security page. In summary: test only against your own account and your own data, do not access or modify other customers’ data, do not degrade the Service, do not run automated scanners at volume, do not use social engineering or physical attacks, and report what you find to [email protected] before disclosing it publicly.
Testing that stays inside those bounds is not a breach of this policy. Testing outside them is.
7.Your responsibility for your users
Everything done under your account is your responsibility, including by your employees, contractors, automated pipelines and any AI agents you connect. Set roles to the minimum each person needs, revoke access when people leave, rotate ingest keys and personal access tokens when they may have been exposed, and require multi-factor authentication for administrative accounts.
8.How we enforce this policy
- Our normal first step is an email explaining the problem and what needs to change, with a reasonable period to fix it.
- If the problem persists, or if it is serious, we may rate-limit the account, disable the specific feature involved, or suspend the account under section 9 of the Terms.
- We may act immediately and notify you straight afterwards where delay would cause harm — an active attack, illegal content, a threat to the Service or to another customer, or a binding legal order.
- Repeated or deliberate breaches can lead to termination of the agreement. Fees already paid are not refunded on termination for breach.
- Where the law requires it, we report illegal content or conduct to the competent authorities and preserve the relevant records.
- If you think an enforcement decision was wrong, use the complaints procedure in section 16 of the Terms. We will review it and explain the outcome.
9.Reporting abuse
To report misuse of TracePath — abusive monitoring, unwanted notifications, illegal content on a status page, or anything else covered by this policy — write to [email protected] with as much detail as you can give: URLs, timestamps, headers and the nature of the problem. Suspected vulnerabilities go to [email protected] instead.
We acknowledge abuse reports within 3 business days and tell the reporter the outcome.
10.Changes
We update this policy as the Service and the threat landscape change. Material changes are notified to account holders by email at least 30 days before they take effect, in line with section 17 of the Terms.
More legal documents: Legal & trust centre.