1. Scope
This Acceptable Use Policy (“AUP”) applies to everyone who uses the services and tools that Offline Protocol, Inc. (“Offline Protocol”, “we”, “us”) operates: the website at www.offlineprotocol.com, the developer portal at dev.offlineprotocol.com, the documentation, the Offline Protocol CLI, the hosted MCP server at mcp.offlineprotocol.com, and the hosted services behind api.offlineprotocol.com, including OfflineID, the relay, telemetry ingestion, and Proof of Location (together, the “Services”).
The AUP is part of the Developer Terms of Service and the Website Terms of Use. Capitalized terms not defined here have the meaning given in the Developer Terms. If you are a Customer, you are responsible for making sure your team members, your Customer Applications, and your End Users follow this AUP.
The Offline Protocol mesh SDK is licensed separately under AGPL-3.0-only or a commercial license, and the OfflineID and Proof of Location client packages under MIT or ISC. This AUP does not add restrictions to those licenses for code you run entirely on your own devices and infrastructure. It applies whenever you use the Services, including when a Customer Application connects to them.
2. Prohibited uses
You may not use the Services, or allow anyone to use them, to:
- Break any applicable law or regulation, or help anyone else do so, including export control, sanctions, consumer protection, privacy, and telecommunications laws.
- Infringe, misappropriate, or violate the intellectual property, privacy, or publicity rights of others.
- Collect, track, or disclose the location, identity, or communications of any person without the notice and consent the law requires, or to stalk, harass, surveil, or intimidate anyone.
- Create, distribute, or store child sexual abuse material, or content that exploits or endangers minors. We report such material to the relevant authorities.
- Send spam, unsolicited bulk messages, or messages that a recipient has not agreed to receive, including through the relay or through sign-in codes.
- Distribute malware, ransomware, or any code intended to damage, disrupt, or gain unauthorized access to a device, system, or network.
- Engage in fraud, phishing, impersonation, or misrepresentation, including creating OfflineID accounts in someone else’s name or submitting location claims you know to be false.
- Promote or carry out violence, terrorism, or credible threats against people or property.
- Operate a Customer Application in a way that could cause death, serious injury, or severe physical or environmental damage if the Services fail, unless we have agreed to that use in a signed agreement. The Services are not designed or certified as the sole means of life-safety, emergency, or critical control communications.
3. Security and integrity of the Services
You may not:
- Access or attempt to access any account, organization, application, key, or data that is not yours, or bypass any authentication, authorization, domain restriction, or origin check.
- Probe, scan, or test the vulnerability of the Services, except as described in our responsible disclosure policy.
- Interfere with or disrupt the Services, including by denial-of-service attacks, flooding, or sending malformed requests at volume.
- Circumvent rate limits, quotas, spend caps, usage pauses, or billing, including by creating multiple accounts or organizations to obtain additional free usage.
- Share, publish, sell, or embed secret API keys where others can read them, or use another customer’s credentials.
- Submit fabricated, replayed, or manipulated data to Proof of Location, or attempt to corrupt witness attestations, commitments, or on-chain records.
- Reverse engineer, decompile, or disassemble any hosted, closed-source part of the Services, except where the law allows it despite this restriction. This does not limit your rights under the open-source license of any component we publish.
- Use the Services to build a directly competing hosted service by copying our non-public interfaces, or to benchmark the Services and publish the results in a misleading way.
4. Automated access and AI agents
Coding agents and AI assistants may use the CLI and the hosted MCP server. When you connect an agent, you are responsible for what it does with your credentials, as if you had taken the action yourself. Do not give an agent broader keys than it needs, and do not let an agent send End User personal data to the hosted MCP server. The hosted MCP server provides integration guidance and public reference material; it is not a place to store or process End User data.
Crawling the website or documentation is allowed when it respects our robots directives and does not burden our infrastructure.
5. End users and content
Customers are responsible for their Customer Applications and for the content their End Users send through the Services. Most traffic between End User devices never reaches Offline Protocol, and message content that the SDK encrypts end to end cannot be read by Offline Protocol even when it passes through the hosted relay. That means we rely on Customers to set and enforce their own content rules, to give End Users a way to report abuse, and to respond to reports.
Customers must publish their own privacy notice and terms for End Users, and must obtain any consent the law requires before collecting location, identity, or telemetry data through the Services.
6. Enforcement
If we reasonably believe that you, a Customer Application, or an End User has violated this AUP, we may take proportionate action. This can include asking you to fix the problem, revoking or rotating an API key, suspending an application, suspending an organization or account, removing content we host, or reporting the activity to law enforcement. Where it is practical and lawful, we will notify you first and give you a reasonable chance to fix the issue. We may act without notice when that is needed to protect the Services, other customers, End Users, or the public, or to comply with the law.
Suspension under this AUP does not relieve you of fees already incurred. Repeated or serious violations are grounds for termination under the Developer Terms.
7. Reporting abuse
To report abuse of the Services, email legal@offlineprotocol.com with as much detail as you can, such as the application, organization, or account involved and when it happened. Report security vulnerabilities to security@offlineprotocol.com under our responsible disclosure policy.
8. Changes
We may update this AUP as the Services change or as new risks emerge. We will post the updated version on this page and update the date above. Material changes take effect as described in the Developer Terms.
Questions about this document, privacy requests, and anything else policy related: email legal@offlineprotocol.com. Security vulnerabilities: security@offlineprotocol.com. All of our legal documents are listed on the legal page.