You may use Pubto for legitimate development, testing, demonstrations, temporary file delivery, remote collaboration, and authorized service access. This policy applies to every account, device, endpoint, file, domain, Relay connection, and person using your workspace.
Prohibited activity
Do not use Pubto to break the law, violate another person's rights, evade security controls, or create material risk for users or infrastructure providers.
- Phishing, credential theft, impersonation, or deceptive login pages
- Malware, ransomware, spyware, botnets, exploit delivery, or command-and-control traffic
- Unauthorized scanning, probing, intrusion, persistence, or access to systems and accounts
- Distribution of stolen data, private credentials, payment-card data, or unlawful content
- Child sexual abuse material, sexual exploitation, non-consensual intimate content, or content that facilitates harm to children
- Content or services that facilitate illegal weapons, regulated-drug sales, gambling, fraud, or evasion of law-enforcement or provider controls
- Harassment, credible threats, hateful or violent abuse, spam, or deceptive commercial activity
- Copyright, trademark, privacy, or other rights infringement without a lawful basis
Network and resource abuse
Do not use Pubto to run denial-of-service activity, open proxies, VPN services, traffic relays for unrelated third parties, cryptocurrency mining, bulk scraping, unsolicited messaging, or workloads that intentionally evade quotas, rate limits, abuse controls, or provider restrictions.
Databases, TCP, and administrative services
Publish MySQL, PostgreSQL, Redis, SSH, MQTT, admin panels, and other sensitive services only when you own or are explicitly authorized to access them. Use strong service authentication, encryption where supported, short expiry, limited recipients, and immediate revocation when the task is complete.
Files and public pages
You must have the right to share every file, folder, website, and collection you publish. Do not disguise executable or harmful content as a document, bypass file-safety controls, or use Pubto as permanent network storage, mass-distribution infrastructure, a public download mirror, or durable public hosting.
Security research
Good-faith security testing is allowed only against systems you own or have written authorization to test. Do not test Pubto infrastructure or another user's endpoint outside a published vulnerability-disclosure or bug-bounty scope.
How controls work
Pubto checks selected publication metadata and normalized source hostnames against operator-managed terms and protected-domain rules before authorization. It also enforces plan-specific request, traffic, visitor, duration, file-size, and connection limits. These automated controls do not inspect every byte or replace account-holder responsibility.
High or unusual traffic, repeated creation attempts, reports, protected targets, security signals, or attempts to evade controls may result in additional automated restriction or human review. Pubto may request proof of authorization or other information before restoring access.
Enforcement
Pubto may investigate suspected violations and may rate-limit, block, stop, rotate, quarantine, or delete an endpoint; restrict a target or protocol; suspend a device, workspace, or account; preserve evidence; or report activity to infrastructure providers, payment providers, rights holders, or authorities when appropriate.
Fees for a service period lost because of your material or repeated violation are not refundable, except where required by law or where Pubto determines the restriction was imposed in error. This does not limit rights that cannot legally be waived. Billing errors and ordinary cancellation remain governed by the Billing and Refund Policy.
Reports and review requests
Report a suspicious Pubto address to [email protected] with the URL, observed behavior, time, and supporting evidence. Do not include passwords, access tokens, or unrelated personal information. Urgent security issues can be sent to [email protected].
To request review of a restriction, email [email protected] from the account address and include the affected endpoint or workspace, intended use, authorization evidence if relevant, and why you believe the decision was incorrect. We may keep a restriction in place while reviewing credible risk.
