Not open yet — signups haven't started. Join the list for the day they do.
Home/Legal/Acceptable use

Legal

Acceptable Use Policy

Effective date: to be set at launch — this policy is not yet in effect. The version shown here is under legal review and subject to change before go-live.

The limits and rules that keep 99¢ hosting possible — including how AI agents and MCP tokens must be used.

The short version: Lemonade Host is for static sites only — HTML, CSS, JavaScript, images and fonts — with real numeric limits on file size, file count, deploys and bandwidth. No server-side code, cron jobs, proxies, crypto mining, phishing, malware, spam or copyright infringement. If you connect an AI assistant or other automated tool through our MCP server, you're responsible for scoping its token to only the sites it needs and for what it publishes. Report abuse to [email protected].

1. Purpose and scope

This Acceptable Use Policy (the "AUP") protects Lemonade Host, its customers, website visitors, third parties, and the infrastructure used to provide the Service. It is incorporated into the Lemonade Host Terms of Service.

The AUP applies to every account, Site, custom domain, file, request, deployment, repository connection, API call, CLI command, MCP token, integration, Authorized Agent, optional feature, and other use of the Service.

You are responsible for your own activity and for activity performed through your account by employees, contractors, clients, scripts, integrations, AI assistants, coding agents, or other Authorized Agents. An action does not become permitted merely because an automated tool or AI agent performed it.

This Policy is not an exhaustive list of every harmful or abusive use. We may restrict conduct that is not specifically listed when we reasonably determine that it is unlawful, deceptive, harmful, abusive, insecure, disproportionately burdensome, or inconsistent with the intended use of the Service.

2. Intended use of the base Service

The base Lemonade Host product is designed primarily to store and serve static website files, including HTML, CSS, client-side JavaScript, images, fonts, and similar browser-readable assets.

The base Service is appropriate for uses such as:

  • portfolios;
  • brochure and informational sites;
  • landing pages;
  • documentation;
  • simple marketing sites;
  • static blogs;
  • product or event pages;
  • frontend demonstrations; and
  • similar sites that do not require customer-supplied server execution.

Optional upgrades may provide additional functions. A use that is prohibited on the base plan is permitted only when a specific Lemonade Host feature expressly authorizes it and the use remains within that feature's documentation, limits, and terms.

3. Normal technical and resource limits

Unless a plan or add-on expressly states different limits, the normal limits for each Site are:

  • Maximum individual file size: 25 MB.
  • Maximum file count: approximately 20,000 files.
  • Deployment frequency: approximately 100 deployments per rolling 24-hour period.
  • Storage: 1 GB.
  • Bandwidth: 250 GB per monthly billing-measurement period, subject to fair use.

"Approximately" means a normal operational threshold, not an entitlement to consume that quantity in every circumstance. Exact enforcement may vary because of file metadata, system overhead, security controls, traffic patterns, infrastructure conditions, account history, or other technical factors.

We may also apply reasonable limits involving:

  • requests per second or minute;
  • concurrent connections;
  • deployment size and duration;
  • API, CLI, webhook, and MCP calls;
  • certificate issuance;
  • DNS changes;
  • cache invalidation;
  • restore frequency;
  • support-assisted operations;
  • automated traffic;
  • source IPs, regions, or networks; and
  • other resources necessary to keep the Service secure and stable.

We may adjust limits when reasonably needed to prevent abuse, respond to attacks, comply with provider requirements, protect other customers, or maintain the Service. A material reduction to a core paid allowance will be handled under the Terms and applicable law.

4. Bandwidth and fair use

The 250 GB monthly bandwidth allowance is intended for ordinary website traffic. Fair use requires that the Site function primarily as a website being visited or used in a normal manner, rather than as a substitute for bulk distribution, media delivery, object storage, a software mirror, or another high-volume delivery service.

Examples of activity that may violate fair use include:

  • a small Site generating sustained or abnormal traffic inconsistent with its content;
  • serving assets primarily for websites hosted elsewhere;
  • automated scraping, bot traffic, or repeated downloads that you encourage or fail to address;
  • using the Site as a public file bucket;
  • hosting large downloadable archives, disk images, installers, datasets, backups, or media libraries;
  • intentionally bypassing cache or traffic controls; or
  • distributing content at a scale that imposes disproportionate cost or risk.

If a non-urgent Site approaches or exceeds an allowance, we may contact you and offer options such as reducing use, changing configuration, upgrading, or moving the workload. We may throttle, restrict, suspend, or decline renewal if the issue continues.

We do not impose an automatic bandwidth-overage charge unless you separately and affirmatively agree to a paid overage or upgrade. We may act without advance notice when traffic threatens infrastructure, security, other customers, or third parties.

5. Prohibited technical uses

Unless an expressly authorized Lemonade Host feature permits the specific activity, you may not use the Service for:

  • server-side code execution, including customer-supplied PHP, Node.js, Python, Ruby, Java, Go, .NET, shell scripts, binaries, containers, or similar processes;
  • databases or database servers;
  • cron jobs, scheduled processes, daemons, workers, queues, or persistent background tasks;
  • virtual machines, containers, remote desktops, or general-purpose compute;
  • open, forward, reverse, residential, anonymizing, or other proxy services;
  • VPN, tunneling, relay, Tor exit-node, traffic-broker, or IP-masking services;
  • cryptocurrency mining, staking infrastructure, proof-of-work computation, or similar resource-intensive blockchain activity;
  • botnets, command-and-control systems, credential checking, password cracking, scanning, exploitation, or attack infrastructure;
  • packet capture or interception not expressly authorized;
  • unauthorized penetration testing, vulnerability scanning, load testing, or stress testing;
  • circumventing authentication, access controls, scopes, rate limits, quotas, billing controls, or security systems;
  • using one Site, token, or account to reach another Site or account without authorization;
  • attempting to derive, retrieve, or expose secret keys, raw MCP tokens, encrypted credentials, or other protected information;
  • modifying, probing, reverse engineering, or interfering with the Service except where applicable law expressly permits it; or
  • any technical use that creates a material risk of instability, compromise, legal exposure, or disproportionate cost.

6. Prohibited hosting and delivery patterns

You may not use the Service primarily as:

  • a video or audio streaming platform;
  • a live-streaming origin;
  • a hotlink content-delivery network for content consumed mainly on other websites or apps;
  • a file locker, file-sharing repository, download mirror, package repository, software-update server, or public object store;
  • a backup destination or archival repository unrelated to operating the Site;
  • an image-hosting or media-hosting service for unrelated third parties;
  • a domain parking, redirect, doorway-page, or traffic-arbitrage network designed to deceive users or search engines;
  • a spam landing-page network;
  • a click-fraud, ad-fraud, impression-fraud, or affiliate-fraud system;
  • an automated scraping or crawling service; or
  • another service whose primary purpose is bulk storage, distribution, relaying, computation, or automation rather than operating a website.

Reasonable website downloads, embedded media, and normal asset delivery are allowed when incidental to a legitimate Site and within plan limits.

7. Illegal, fraudulent, and deceptive activity

You may not use the Service to engage in, facilitate, promote, instruct, conceal, or materially support activity that is illegal in an applicable jurisdiction or that violates the rights of others.

Prohibited conduct includes:

  • fraud, attempted fraud, scams, deceptive schemes, impersonation, or material misrepresentation;
  • phishing, credential theft, account takeover, identity theft, or collection of information under false pretenses;
  • counterfeit goods, stolen property, unlawful marketplaces, money laundering, or sanctions evasion;
  • unlawful gambling, illegal financial activity, or unlicensed regulated activity;
  • evasion of court orders, law-enforcement action, export controls, sanctions, or other legal restrictions;
  • trafficking, exploitation, extortion, blackmail, or coercion;
  • child sexual abuse material, sexual exploitation of minors, grooming, or any content or conduct that exploits or endangers children;
  • credible threats, unlawful harassment, stalking, doxxing, or incitement of imminent violence;
  • terrorism or material support for prohibited terrorist activity;
  • publication of unlawfully obtained confidential, personal, financial, authentication, or medical information;
  • unauthorized sale, transfer, or disclosure of personal data;
  • false government, financial institution, healthcare, brand, employer, or service-provider pages designed to deceive; and
  • instructions, tools, or services whose principal purpose is committing or evading detection of unlawful acts.

We may consider context, purpose, likelihood of harm, applicable law, credible reports, and technical evidence. We do not have to wait for a conviction or court order before acting to prevent apparent harm.

8. Malware, attacks, and security abuse

You may not upload, host, serve, link to, deploy, or distribute:

  • viruses, worms, trojans, ransomware, spyware, keyloggers, rootkits, malicious browser extensions, exploit kits, droppers, loaders, or similar code;
  • code intended to gain unauthorized access, persist on a device, steal information, evade detection, or impair systems;
  • malicious redirects, drive-by downloads, cryptojacking scripts, or deceptive update prompts;
  • stolen credentials, private keys, access tokens, session cookies, or authentication databases;
  • exploit code used without authorization or safeguards;
  • content that intentionally triggers harmful commands in AI agents or automated tools; or
  • files or instructions designed to damage, disrupt, overload, disable, or compromise a person, device, network, provider, or service.

Security research requires prior written authorization from the owner of every affected system and must remain within a lawful, documented scope. Lemonade Host does not grant permission to test customer Sites, other accounts, our infrastructure, or our providers merely because they are publicly reachable.

9. Spam and abusive communications

You may not use the Service to send, facilitate, support, redirect, advertise, or collect leads for spam or unlawful unsolicited communications.

Prohibited activity includes:

  • bulk email or messaging that violates consent, identification, opt-out, or other legal requirements;
  • Sites whose primary purpose is to support spam campaigns;
  • harvesting email addresses, phone numbers, credentials, or personal information without authorization;
  • deceptive unsubscribe pages;
  • malicious tracking links or redirectors;
  • snowshoe spam, spamvertising, or rotating Sites or domains to evade enforcement; and
  • distributing contact lists obtained unlawfully.

A legitimate business Site is not prohibited merely because it contains a contact form, newsletter signup, or lawful marketing content.

10. Intellectual property and rights of others

You may not use the Service to infringe or misappropriate copyright, trademark, patent, trade-secret, publicity, privacy, database, contractual, confidentiality, or other rights.

You must have the necessary rights to all code, templates, fonts, images, videos, music, text, brands, datasets, and other material used on your Site.

We may remove or disable allegedly infringing material, request evidence of authorization, suspend repeat infringers, or terminate an account. Copyright complaints may be submitted through the abuse-report process in Section 18. We may publish a separate copyright or designated-agent procedure as the Service evolves.

11. Privacy, forms, and sensitive data

You may not use the Service to collect, process, publish, or disclose personal information unlawfully or deceptively.

You are responsible for:

  • an accurate privacy notice;
  • required cookie and tracking disclosures;
  • lawful consent and other legal bases;
  • appropriate security;
  • data minimization and retention;
  • honoring applicable privacy rights; and
  • contracts with third-party tools and processors.

Unless Lemonade Host expressly approves a feature and plan for the specific purpose, do not use the Service to collect or store:

  • full payment-card numbers or card security codes;
  • Social Security numbers or similar government identifiers;
  • financial account passwords or authentication secrets;
  • protected health information subject to HIPAA;
  • biometric identifiers used for identification;
  • precise geolocation intended to track an individual;
  • children's personal information requiring parental consent;
  • highly sensitive employment, education, insurance, or credit information; or
  • other regulated data requiring specialized contractual, audit, residency, or security controls.

Do not expose private keys, raw API or MCP tokens, repository secrets, environment files, credentials, or confidential configuration in publicly served files.

12. AI, automation, MCP, and Authorized Agents

You may use an AI coding assistant or other Authorized Agent to deploy through the MCP server or another supported method, subject to the Terms and this AUP.

You must:

  • scope each token to only the Sites reasonably needed;
  • protect the raw token;
  • revoke unused or suspected-compromised tokens;
  • review generated code and files before or promptly after deployment;
  • ensure the agent does not publish secrets, unlawful content, malware, or third-party material without permission;
  • monitor deployments and account activity; and
  • comply with the external tool provider's terms and applicable law.

You may not instruct an AI agent or automation to evade limits, create abusive accounts, probe the Service, access another Site, disguise prohibited activity, or repeatedly redeploy harmful content.

You remain responsible for activity within the scope you authorized. Lemonade Host may revoke a token, block an agent, or suspend automated deployments where activity appears compromised, abusive, unlawful, or operationally harmful.

13. Repository and deployment integrity

You may connect only repositories and branches you are authorized to access and deploy. You may not use a connection to exfiltrate repository contents, secrets, personal information, or proprietary code.

Webhooks, commits, deployment packages, and files must not be forged or manipulated to bypass ownership checks, malware controls, limits, or audit records.

Excessive deployment loops, intentionally broken webhooks, repeated failed uploads, automated rollback loops, or other activity that consumes disproportionate resources may be rate-limited or suspended even if the numerical daily deployment threshold has not been reached.

14. Resale and multi-tenant use

You may host Sites for clients or organizations you are authorized to represent, but you remain responsible for the account, billing, content, and compliance unless we expressly offer a reseller or agency program with different terms.

You may not resell, sublicense, white-label, pool, or redistribute access to the Service as a hosting platform for unrelated third parties without written permission. You may not use one Site as an unauthorized multi-tenant hosting service or create subaccounts that bypass per-Site billing.

You may not:

  • claim to be Lemonade Host, the Operator, or an authorized representative without permission;
  • use our trademarks or interface to deceive users;
  • submit knowingly false abuse, copyright, privacy, or legal reports;
  • impersonate an account owner or fabricate authorization;
  • harass support personnel;
  • conceal material facts in an appeal or investigation;
  • abuse refund or chargeback processes; or
  • use legal or security processes to interfere with a competitor or lawful speaker.

Good-faith reports, complaints, reviews, and lawful criticism are not prohibited.

16. Detection and investigation

We may use automated and manual methods to identify potential violations, including traffic analysis, rate limits, malware scanning, reputation systems, provider notices, content hashes, customer reports, and review of relevant files or logs.

We have no general obligation to monitor every Site or to investigate every report. Failure to detect or act on one violation does not make us responsible for the content or waive our right to act later.

We may preserve, copy, quarantine, or disclose relevant information when reasonably necessary to investigate, protect the Service, comply with law, or establish, exercise, or defend claims.

17. Enforcement options

Depending on severity, urgency, history, and risk, we may:

  • warn or request correction;
  • block a file, path, domain, request, deployment, repository, token, IP address, region, or feature;
  • throttle traffic or deployments;
  • disable public access while preserving files;
  • revoke credentials or integrations;
  • quarantine or remove content;
  • suspend a Site;
  • suspend or terminate an account;
  • require an upgrade or migration;
  • refuse renewal or future service;
  • preserve evidence;
  • notify affected third parties or providers; or
  • refer a matter to law enforcement or another authority where appropriate or required.

For active phishing, malware, attacks, child exploitation, credible threats, compromised credentials, legal demands, or immediate infrastructure risk, we may act without advance notice and explain afterward where legally and operationally appropriate.

For a non-urgent, readily curable issue, we may provide notice and a correction period, but we are not obligated to do so.

Suspension or termination for violation does not automatically create a refund, credit, service extension, or damages claim. Billing treatment is governed by the Terms and Refund Policy.

18. Abuse reports

Send an abuse report to [email protected] with the subject line "ABUSE REPORT."

Include, where available:

  • the full Site URL or Lemonade Host subdomain;
  • the specific file, path, page, or content at issue;
  • a clear description of the alleged violation;
  • screenshots, message headers, logs, or other evidence;
  • the reporting person's name and contact information; and
  • any urgency or immediate safety concern.

Do not send malware as an unprotected attachment. Provide a safe link, hash, screenshot, or other non-executing evidence where possible.

Submitting a report does not guarantee removal, disclosure of customer information, or a response. We may request additional information, refer the reporter to a rights holder or authority, or decline to act when a report is incomplete, not credible, outside this Policy, or legally insufficient.

19. Appeals

An account holder may appeal a suspension or removal by emailing [email protected] with the subject line "AUP APPEAL."

The appeal should include:

  • the account email;
  • the affected Site;
  • the enforcement notice, if available;
  • why the decision is believed to be incorrect;
  • relevant evidence; and
  • the corrective action already taken or proposed.

We may require identity, ownership, or authorization verification. We may keep the Site or content disabled during review. We may reject repeated, abusive, incomplete, fraudulent, or substantially unchanged appeals.

We will attempt to review a complete appeal within a reasonable period, but no response or reinstatement time is guaranteed. Reinstatement may be conditioned on removal of content, changed configuration, token revocation, security remediation, an upgrade, or other safeguards.

20. Repeat and serious violations

Repeated violations, attempts to evade enforcement, use of replacement accounts or domains, false statements, compromised accounts that are not secured, or a single sufficiently serious violation may result in account termination and refusal of future service.

We may treat affiliated accounts, common payment methods, shared operators, common repositories, coordinated domains, or other reliable indicators as related when reasonably necessary to prevent evasion.

21. Changes to this Policy

We may update this AUP as threats, laws, features, providers, and usage patterns change. Material changes affecting ordinary permitted use will be noticed as required by the Terms and applicable law.

Emergency security rules, rate limits, blocks, or controls may be implemented immediately without first updating this public Policy.

22. Contact

Questions, reports, and appeals:

[email protected]

Do not include passwords, full payment-card numbers, private keys, raw MCP tokens, or other secrets in an ordinary email.

Related

The rest of the legal pages

Terms of service

What the service includes, how billing and deployments work, and how disputes are resolved.

Privacy policy

What we collect, who we share it with, and how to ask us to delete it.

Refund policy

The 30-day guarantee on a new site, and how billing disputes are handled.

Pricing

Every plan, every interval, on one page.

Get on the list

Join the list and we'll email you just once — that's the only thing we use your address for.

Join the list