Legal
Effective date: August 28, 2026 · Version 2026-08-28.1
This Acceptable Use Policy (the "AUP") protects Lemonade Host, customers, website visitors, third parties, and the infrastructure used to provide the Service. It is incorporated into the Terms of Service and applies to every account, Site, custom domain, file, request, deployment, repository connection, API call, CLI command, MCP token, integration, Authorized Agent, managed feature, and other use of the Service.
You are responsible for your own activity and for activity performed through your account by employees, contractors, clients, scripts, integrations, AI assistants, coding agents, and other Authorized Agents. Conduct does not become permitted because an automated tool performed it. This AUP is not an exhaustive list of every harmful use. We may restrict conduct not specifically listed when we reasonably determine that it is unlawful, deceptive, harmful, abusive, insecure, disproportionately burdensome, prohibited by an upstream provider, or inconsistent with the intended use of the Service. We will consider context, purpose, likelihood of harm, applicable law, credible reports, and technical evidence.
The base Service is designed primarily to store and serve static browser-readable assets such as HTML, CSS, client-side JavaScript, images, and fonts. Appropriate uses include portfolios, brochure and informational sites, landing pages, documentation, static blogs, product and event pages, frontend demonstrations, and similar sites that do not require unrestricted customer-supplied server execution. Managed features may provide limited server-side functions for Forms, Bookings, Commerce, integrations, or other purposes. A use prohibited on the base plan is permitted only when a specific Lemonade Host feature expressly authorizes it and the use remains within that feature's documentation, limits, and terms.
Unless a plan, add-on, dashboard, or checkout expressly states different limits, normal operational limits for a Site may include a maximum individual file size of 25 MB, approximately 20,000 files, approximately 100 deployments in a rolling 24-hour period, 1 GB of storage, and 250 GB of bandwidth per monthly measurement period, subject to fair use. "Approximately" describes a normal operational threshold rather than an unconditional entitlement to consume the stated amount in every circumstance. Exact enforcement may vary because of metadata, system overhead, cache behavior, security controls, traffic patterns, infrastructure conditions, and account history.
We may also apply reasonable request, concurrency, deployment-size, deployment-duration, API, CLI, webhook, MCP, certificate, DNS, cache-invalidation, restore, support-assisted-operation, automated-traffic, geographic, network, or source-IP limits needed to maintain security and stability. We may adjust limits to prevent abuse, respond to attacks, comply with provider requirements, protect other customers, or maintain the Service. A material reduction to a core paid allowance will be handled under the Terms and applicable law.
A bandwidth allowance is intended for ordinary website traffic. Fair use requires that a Site function primarily as a website used in a normal manner rather than as a substitute for bulk distribution, media delivery, object storage, a software mirror, a file locker, or another high-volume delivery service. Activity that may violate fair use includes serving assets primarily for unrelated websites; encouraging or failing to address sustained automated scraping or repeated downloads; using a Site as a public file bucket; hosting large archives, disk images, installers, datasets, backups, or media libraries; intentionally bypassing cache or traffic controls; or distributing content at a scale that imposes disproportionate cost, load, or risk.
For a non-urgent issue, we may contact you and offer options such as reducing use, changing configuration, upgrading, or moving the workload. We may throttle, restrict, suspend, or decline renewal if the issue continues. We do not impose an automatic bandwidth-overage charge unless you separately agree to a paid overage or upgrade. We may act without advance notice when traffic threatens infrastructure, security, third parties, or other customers.
Unless a specific managed feature expressly permits the activity, you may not use the Service for customer-supplied server-side execution, including PHP, Node.js, Python, Ruby, Java, Go, .NET, shell scripts, binaries, containers, or similar processes; databases or database servers; cron jobs, daemons, queues, persistent workers, or background processes; virtual machines, remote desktops, or general-purpose compute; open, forward, reverse, residential, anonymizing, or other proxies; VPN, tunneling, relay, Tor exit-node, traffic-broker, or IP-masking services; cryptocurrency mining or proof-of-work computation; botnets, command-and-control systems, credential checking, password cracking, scanning, exploitation, or attack infrastructure; unauthorized packet capture or interception; or another use whose primary purpose is computation, relaying, or automation rather than operating a Site.
You may not circumvent authentication, access controls, token scopes, rate limits, quotas, billing controls, or security systems; use one Site, token, or account to reach another without authorization; attempt to derive, retrieve, or expose protected keys, credentials, or raw tokens; forge webhooks, commits, manifests, or deployment records; reverse engineer, probe, scrape, or interfere with the Service except where law expressly permits; perform unauthorized penetration, vulnerability, load, or stress testing; or engage in technical activity that creates a material risk of instability, compromise, legal exposure, or disproportionate cost.
You may not use the Service primarily as a video or audio streaming platform, live-streaming origin, hotlink delivery network for content consumed mainly on unrelated sites or apps, file-sharing repository, download mirror, package repository, software-update server, public object store, unrelated backup destination, image-hosting service for unrelated third parties, deceptive domain-parking or doorway-page network, traffic-arbitrage system, spam landing-page network, click-fraud or ad-fraud system, automated scraping service, or another service whose principal function is bulk storage, distribution, relaying, or computation. Reasonable downloads, embedded media, and ordinary asset delivery are allowed when incidental to a legitimate Site and within plan limits.
You may not use the Service to engage in, facilitate, promote, instruct, conceal, or materially support activity that is illegal in an applicable jurisdiction or violates the rights of others. Prohibited conduct includes fraud, scams, impersonation, and material misrepresentation; phishing, credential theft, account takeover, identity theft, or collection under false pretenses; counterfeit or stolen goods; money laundering or sanctions evasion; unlawful gambling, illegal financial activity, or unlicensed regulated activity; evasion of court orders, export controls, or legal restrictions; trafficking, exploitation, extortion, blackmail, or coercion; child sexual abuse material, grooming, or exploitation of minors; credible threats, unlawful harassment, stalking, doxxing, or incitement of imminent violence; terrorism or prohibited material support; unlawful publication of confidential, personal, financial, authentication, or medical information; unauthorized sale or disclosure of personal data; false government, financial, healthcare, employer, brand, or service-provider pages designed to deceive; and tools or instructions whose principal purpose is committing or evading detection of unlawful acts.
We do not need to wait for a criminal conviction or final court order before taking reasonable action to prevent apparent harm. A good-faith educational, journalistic, security, or advocacy use will be evaluated in context, but labels or disclaimers do not excuse conduct that materially facilitates abuse.
You may not upload, host, serve, link to, deploy, or distribute viruses, worms, trojans, ransomware, spyware, keyloggers, rootkits, malicious extensions, exploit kits, droppers, loaders, or similar code; code intended to obtain unauthorized access, persist on a device, steal information, evade detection, or impair systems; malicious redirects, drive-by downloads, cryptojacking scripts, or deceptive update prompts; stolen credentials, private keys, access tokens, session cookies, or authentication databases; exploit code used without authorization and safeguards; content designed to trigger harmful commands in AI agents or automated tools; or files and instructions intended to damage, disrupt, overload, disable, or compromise a person, device, network, provider, or service.
Security research requires prior written authorization from the owner of every affected system and must remain within a lawful, documented scope. Public reachability does not grant permission to test customer Sites, other accounts, Lemonade Host infrastructure, or our providers. A customer wishing to test its own Site must obtain any required authorization from Lemonade Host and affected providers before generating traffic or activity that could resemble an attack.
You may not use the Service to send, facilitate, support, redirect, advertise, or collect leads for spam or unlawful unsolicited communications. Prohibited conduct includes bulk email or messaging that violates consent, sender-identification, opt-out, or other legal requirements; Sites primarily supporting spam campaigns; harvesting email addresses, telephone numbers, credentials, or personal information without authorization; deceptive unsubscribe pages; malicious tracking links or redirectors; snowshoe spam, spamvertising, or rotating Sites and domains to evade enforcement; and distribution of unlawfully obtained contact lists. A legitimate Site is not prohibited merely because it contains a contact form, newsletter signup, or lawful marketing material.
You may not use the Service to infringe or misappropriate copyright, trademark, patent, trade-secret, publicity, privacy, database, contractual, confidentiality, or other rights. You must possess the necessary rights to code, templates, fonts, images, video, music, text, brands, datasets, and other material used on a Site. We may request evidence of authorization, remove or disable material, suspend a Site, or terminate repeat or serious infringers.
A copyright complaint should be sent to [email protected] with the subject "DMCA NOTICE" and should include a physical or electronic signature of the authorized complaining party; identification of the copyrighted work or a representative list; identification and location of the material claimed to infringe; contact information; a statement of good-faith belief that the use is not authorized by the owner, agent, or law; and a statement under penalty of perjury that the information is accurate and the sender is authorized to act. We may forward the notice to the customer and take action we consider appropriate. An affected customer may submit a counter-notice containing the information required by applicable law. Submission of a notice or counter-notice does not guarantee a particular outcome.
We maintain a policy of terminating, in appropriate circumstances, customers or accounts that repeatedly infringe. Any separate public designated-agent details control for formal notices. A complainant should use the designated agent listed on the Copyright Complaints page, which also sets out what a notice and a counter-notice must contain.
You may not collect, process, publish, or disclose personal information unlawfully, deceptively, or without adequate security. You are responsible for an accurate privacy notice; required cookie and tracking disclosures; lawful consent or another legal basis; data minimization; appropriate retention; honoring privacy rights; contracts with third-party tools and processors; and compliance with marketing, communications, consumer, and industry laws.
Unless Lemonade Host expressly approves a feature and plan for the specific purpose in a signed writing, do not use the Service to collect or store full payment-card numbers or card security codes; Social Security numbers or similar government identifiers; financial-account passwords or authentication secrets; protected health information subject to HIPAA; biometric identifiers used for identification; precise geolocation intended to track a person; children's personal information requiring parental consent; highly sensitive employment, education, insurance, credit, or background information; or other regulated data requiring specialized contracts, audits, residency, or security controls. Do not expose private keys, raw API or MCP tokens, repository secrets, environment files, credentials, or confidential configuration in publicly served files.
General-purpose form and booking note fields must not be configured to solicit symptoms, diagnoses, treatment details, insurance information, or other medical information. A Site may describe healthcare or wellness services, but the managed data features are not represented as a medical-record system or HIPAA-compliant intake platform.
You may use an AI coding assistant or other Authorized Agent through a supported method, subject to the Terms and this AUP. You must scope credentials to only the Sites and functions reasonably needed; protect raw credentials; revoke unused or suspected-compromised credentials; review generated code and files before or promptly after deployment; ensure the agent does not publish secrets, unlawful material, malware, or third-party content without permission; monitor deployments and account activity; and comply with the external provider's terms and applicable law.
You may not instruct or permit an agent to evade limits, create abusive accounts, probe the Service, access another Site, conceal prohibited conduct, generate deceptive or illegal Sites at scale, or repeatedly redeploy harmful material. You remain responsible for activity within the scope you authorized. We may revoke a credential, block an agent, or suspend automation when activity appears compromised, abusive, unlawful, or operationally harmful.
You may connect only repositories and branches you are authorized to access and deploy. You may not use a connection to exfiltrate repository contents, secrets, personal information, or proprietary code. Webhooks, commits, deployment packages, manifests, and files must not be forged or manipulated to bypass ownership checks, malware controls, limits, or audit records. Excessive deployment loops, intentionally broken webhooks, repeated failed uploads, automated rollback loops, or other disproportionate activity may be rate-limited or suspended even if a stated numerical threshold has not been reached.
You may host Sites for clients or organizations you are authorized to represent, but you remain responsible for the account, billing, content, instructions, and compliance unless we expressly offer a reseller or agency program with different terms. You may not resell, sublicense, white-label, pool, or redistribute access to the Service as a hosting platform for unrelated third parties without written permission. You may not use one Site as an unauthorized multi-tenant hosting service, create subaccounts that bypass per-Site billing, or represent that you can bind Lemonade Host to obligations not stated in our policies.
You may not claim to be Lemonade Host, the Operator, or an authorized representative without permission; use our marks or interface to deceive users; impersonate an account owner or fabricate authorization; submit knowingly false abuse, copyright, privacy, or legal reports; conceal material facts in an appeal or investigation; harass support personnel; abuse refund or chargeback processes; or use legal or security procedures to interfere with a competitor or lawful speaker. Good-faith reports, complaints, reviews, and lawful criticism are not prohibited.
We may use automated and manual methods to identify potential violations, including traffic analysis, rate limits, malware scanning, reputation systems, provider notices, content hashes, customer reports, and review of relevant files or logs. We have no general obligation to monitor every Site or investigate every report. Failure to detect or act on one violation does not make us responsible for the content or waive our right to act later.
We may preserve, copy, quarantine, or disclose relevant information when reasonably necessary to investigate, protect the Service, comply with law, respond to a provider, or establish, exercise, or defend claims. Investigation access will be limited to personnel and systems reasonably involved in the purpose.
Depending on severity, urgency, history, and risk, we may warn or request correction; block a file, path, domain, request, deployment, repository, credential, IP address, region, or feature; throttle traffic or deployments; disable public access while preserving files; revoke credentials or integrations; quarantine or remove content; suspend a Site or account; require an upgrade, security remediation, or migration; refuse renewal or future service; preserve evidence; notify affected third parties or providers; or refer a matter to an authority where appropriate or required.
For active phishing, malware, attacks, child exploitation, credible threats, compromised credentials, legal demands, or immediate infrastructure risk, we may act without advance notice and explain afterward where legally and operationally appropriate. For a non-urgent and readily curable issue, we may provide notice and a correction period, but are not obligated to do so. Suspension or termination for a violation does not automatically create a refund, credit, service extension, or damages claim.
Send an abuse report to [email protected] with the subject "ABUSE REPORT." Include, where available, the full Site URL or Lemonade Host subdomain; the specific file, path, page, or content at issue; a clear description of the alleged violation; screenshots, message headers, logs, or other evidence; the reporting person's name and contact information; and any urgency or immediate safety concern. Do not send malware as an unprotected attachment. Provide a safe link, hash, screenshot, or non-executing evidence where possible.
Submitting a report does not guarantee removal, disclosure of customer information, or a response. We may request additional information, refer the reporter to a rights holder or authority, or decline to act when a report is incomplete, not credible, outside this AUP, or legally insufficient.
An account holder may appeal a suspension or removal by emailing [email protected] with the subject "AUP APPEAL." The appeal should identify the account, affected Site, enforcement notice if available, reason the decision is believed incorrect, relevant evidence, and corrective action taken or proposed. We may require identity, ownership, or authority verification. We may keep the Site or content disabled during review and may reject repeated, abusive, incomplete, fraudulent, or substantially unchanged appeals.
We will attempt to review a complete appeal within a reasonable period, but no response or reinstatement time is guaranteed. Reinstatement may be conditioned on removal of content, changed configuration, credential revocation, security remediation, an upgrade, or another safeguard.
Repeated violations, attempts to evade enforcement, replacement accounts or domains, false statements, failure to secure a compromised account, or one sufficiently serious violation may result in termination and refusal of future service. We may treat accounts, payment methods, operators, repositories, domains, or other reliable indicators as related when reasonably necessary to prevent evasion. We may maintain records needed to enforce a ban and protect the Service.
We may update this AUP as threats, laws, features, providers, and usage patterns change. Material changes affecting ordinary permitted use will be noticed as required by the Terms and applicable law. Emergency security rules, rate limits, blocks, and controls may be implemented immediately without first updating the public policy.
Questions, reports, and appeals may be sent to [email protected]. Do not include passwords, full payment-card numbers, private keys, raw API or MCP tokens, or other secrets in ordinary email.
Related
Billing, renewal, deployments, and what happens if something goes wrong.
What we collect, who we share it with, and how to ask us to delete it.
The 30-day guarantee on a new site, and how billing disputes are handled.
How we handle the visitor data your site collects through Forms, Bookings and Commerce.
Where to send a DMCA notice, what it must contain, and how counter-notices work.
Every plan, every interval, on one page.
Join the list and we'll email you just once — that's the only thing we use your address for.