Acceptable Use Policy
Last updated: August 18, 2026
This Acceptable Use Policy applies to everyone who accesses or uses services provided by Rivet Gaming, Inc. (“Rivet”, “we”). It applies to you, to your end users, and to any software — including AI agents and other automated workloads — that acts through your account. You are responsible for everything that runs under your account.
This policy is part of the Terms of Service, and capitalized terms used here have the meanings given there. See also our Privacy Policy for how we handle personal information.
The examples below are illustrative, not exhaustive. Rivet may take action on conduct that harms the services or others even if it is not listed here, and we may update this policy from time to time by posting a revised version on this page.
Illegal and Harmful Content
You may not use the services to do any of the following:
- Violate any applicable law, or store, publish, or share material that is fraudulent, defamatory, or misleading.
- Store, publish, or share content that is unlawfully pornographic or indecent, promotes unlawful gambling, or depicts or incites extreme violence or terrorism, including terror propaganda.
- Create, store, or distribute child sexual abuse material (CSAM) or non-consensual intimate imagery (NCII) in any form, whether human- or AI-generated.
- Advocate bigotry or hatred against any person or group based on race, religion, ethnicity, sex, gender identity, sexual orientation, disability, or impairment.
- Violate the privacy or infringe the intellectual property or other rights of others. Copyright complaints follow the DMCA process described in the Terms of Service.
- Harass or abuse Rivet personnel, representatives, or agents acting on Rivet’s behalf.
Security Violations
You may not:
- Probe, scan, or test the vulnerability of any system or network without authorization.
- Breach or circumvent security or authentication measures.
- Access, tamper with, or use non-public areas of the services, or shared areas of the services you have not been invited to.
If you believe you have found a security vulnerability in Rivet itself, report it in good faith to legal@rivet.dev rather than exploiting it.
Network Abuse
You may not:
- Interfere with or disrupt any user, host, or network, including through denial-of-service attacks, flooding, overloading, mail-bombing, or distributing viruses or other malicious code.
- Operate open proxies, open mail relays, open recursive DNS resolvers, Tor exit nodes, or similar network services.
- Operate infrastructure for transmitting spam or bulk unsolicited mail.
Resource Abuse and Platform Integrity
You may not:
- Mine cryptocurrencies or tokens, or run similar proof-of-work or proof-of-space computation, particularly on free or trial plans.
- Make excessive use of shared system resources in ways that degrade the service for others.
- Circumvent service limits, quotas, or usage-based billing.
- Reserve excessive numbers of environment, project, or namespace names.
- Access the services or create accounts other than through Rivet’s supported interfaces, including scraping or creating accounts in bulk.
AI Agents and Automated Workloads
You are responsible for the behavior of AI agents and automated workloads you run on Rivet, for the code those agents generate and execute, and for Dynamic Apps or other backends you deploy on behalf of your own users. Conduct prohibited by this policy remains prohibited when an agent performs it autonomously on your behalf. You may not:
- Use agents or agent-generated code to create, deploy, or distribute malware, or to control compromised systems.
- Use agents to conduct penetration testing, vulnerability scanning, or exploitation of third-party systems without the system owner’s authorization.
- Use agents to scrape or harvest data from third-party services in violation of those services’ terms or applicable law.
- Use agents to generate child sexual abuse material or non-consensual intimate imagery (see Illegal and Harmful Content above).
- Use preview URLs — public, time-limited URLs that proxy traffic into your workloads — to host phishing pages, distribute malware, serve other deceptive or harmful content, or evade any other rule in this policy.
- Dispatch workloads from Rivet to third-party sandbox providers (for example Docker hosts, E2B, Daytona, or Modal) in violation of this policy or of those providers’ own terms.
Scope network egress and permissions appropriately when running untrusted or agent-generated code.
Deceptive Practices and Communications
You may not:
- Send unsolicited communications, promotions, advertisements, or spam.
- Send altered, deceptive, or false source-identifying information, including spoofing and phishing.
- Impersonate Rivet, Rivet personnel, or any other person or entity.
- Promote or advertise products or services other than your own without appropriate authorization.
Restrictions on Resale and Accounts
You may not:
- Sell, share, or transfer accounts.
- Resell or sublicense the services without a written agreement with Rivet.
- Use the services to facilitate direct currency transactions between users.
Enforcement
Rivet may investigate suspected violations of this policy and, as reasonably necessary, review workloads, network activity, and content, consistent with our Privacy Policy. Remedies scale with the severity of the violation and may include: issuing a warning; throttling workloads; quarantining or suspending specific workloads, deployments, or preview URLs; removing content; and suspending or terminating accounts.
We will give notice before taking action where practicable. We may act immediately and without notice where harm is ongoing, the violation is severe, or the law requires it. Rivet may report unlawful activity to law enforcement and cooperate with valid legal process.
Failure to enforce this policy in one case is not a waiver of our right to enforce it in another.
Reporting Abuse
Report suspected violations of this policy to legal@rivet.dev. Include the URL or preview URL involved, the project or environment if known, and relevant timestamps or logs. Copyright complaints follow the DMCA process described in the Terms of Service.