Acceptable Use Policy
Effective date: June 18, 2026.
Governed by: the Terms of Service § 6 (Acceptable Use). This Policy is the human-readable version of that section.
Brume provides rate-limiting infrastructure. Like any network-connected service, the Service can be misused. This page describes the categories of activity that are not permitted. It is not exhaustive; we may suspend or terminate your account for behaviour that is harmful to the Service, to other customers, or to sub-processors, even if that behaviour is not listed here.
1. Illegal activity
You may not use the Service for any activity that violates applicable law. This includes, depending on your jurisdiction:
- Violations of computer-misuse laws in any jurisdiction (Germany's Strafgesetzbuch §§ 202a–c, the Computer Fraud and Abuse Act in the US, the Computer Misuse Act in the UK, equivalent laws elsewhere).
- Distribution of content that is illegal in the jurisdiction of the recipient (child sexual abuse material, content that incites violence, defamation where it is a crime).
- Infringement of intellectual property rights, including copyright, trademark, and trade-secret violations.
- Money laundering, sanctions evasion, or financing of prohibited activity.
- Fraud, phishing, or impersonation.
2. Harm to people
You may not use the Service to:
- Harass, threaten, stalk, or intimidate any person.
- Distribute content that encourages self-harm, suicide, or eating disorders.
- Distribute child sexual abuse material (CSAM). We report CSAM to the relevant authorities (the German BKA in our hosting jurisdiction; NCMEC in the US; the IWF in the UK) and terminate the account immediately on confirmed CSAM activity.
- Distribute content that depicts graphic violence or cruelty.
3. Spam and unsolicited communications
You may not use the Service to facilitate unsolicited bulk messages. Rate limiting is a defense against abuse; it is not a tool for making abuse look legitimate. Configuring Brume to pace a spam campaign, a credential-stuffing attack, or any other unsolicited bulk activity so that it stays under your targets' thresholds is a violation, and we treat it as a serious one.
4. Malicious code
You may not use the Service to distribute:
- Malware, ransomware, spyware, or any code designed to disrupt, damage, surveil, or gain unauthorized access to any system.
- Phishing payloads or credential-harvesting infrastructure.
- Code designed to perform denial-of-service attacks.
- Cryptocurrency miners or other unauthorized resource consumers that are loaded onto someone else's device.
5. Attacks on the Service itself
You may not attempt to:
- Bypass rate limits, payload size limits, or any other technical safeguard we operate.
- Bypass plan restrictions (for example, by creating multiple free accounts to exceed the free tier's daily check budget on a single project).
- Probe, scan, or test the vulnerability of the Service, our infrastructure, or our sub-processors without our written permission.
- Reverse engineer the gateway binary (
crates/core) or attempt to extract cryptographic keys.
- Interfere with another customer's use of the Service, including by exhausting shared resources (Redis quota, Postgres metadata slots, public-internet bandwidth at the edge).
6. Resale and redistribution
You may not resell the Service as a standalone rate-limiting platform. You may use the Service as part of an application you ship to your own end users (for example, protecting your SaaS product's API). If you want to offer Brume as a managed rate-limiting service to your own customers, contact legal@brume.run first; we do not currently support this and will redirect you to a partner channel if it exists.
7. Training machine learning models
You may not use the Service to train machine learning models on data that flows through it. Identifiers, evaluation outcomes, and analytics are not a permitted training corpus.
8. Regulated data
You may not use the Service to process data that is regulated in a way that requires a contractual data processing agreement we do not currently offer, including:
- Health data regulated by HIPAA (US) or equivalent laws.
- Financial data subject to PCI-DSS.
- Government identifiers (social security numbers, Aadhaar numbers, PAN numbers).
- Children's data (under 18) for any purpose.
If you need to process any of these categories, contact legal@brume.run first. We do not currently offer enterprise-grade data processing agreements and may decline.
9. Reporting violations
If you believe a customer is violating this Policy, email abuse@brume.run with:
- The project id and namespace (if known).
- The timestamps and a description of the activity.
- Your contact details.
We investigate reports within 7 days. We do not commit to a particular enforcement outcome but will not retaliate against a good-faith report.
10. Enforcement
We may suspend or terminate your account for violation of this Policy. We may give you notice before suspension, or we may act immediately if the violation is causing harm. Refunds for unused billing periods are at our discretion; in cases of repeated or malicious violations, no refund is given.
If we suspend or terminate your account, you may appeal by emailing legal@brume.run within 30 days of the action. Appeals are reviewed within 14 days.
11. Acceptance
By using the Service, you agree to this Acceptable Use Policy in addition to the Terms of Service.