Legal
Effective date: to be set at launch — this policy is not yet in effect. The version shown here is under legal review and subject to change before go-live.
The limits and rules that keep 99¢ hosting possible — including how AI agents and MCP tokens must be used.
The short version: Lemonade Host is for static sites only — HTML, CSS, JavaScript, images and fonts — with real numeric limits on file size, file count, deploys and bandwidth. No server-side code, cron jobs, proxies, crypto mining, phishing, malware, spam or copyright infringement. If you connect an AI assistant or other automated tool through our MCP server, you're responsible for scoping its token to only the sites it needs and for what it publishes. Report abuse to [email protected].
This Acceptable Use Policy (the "AUP") protects Lemonade Host, its customers, website visitors, third parties, and the infrastructure used to provide the Service. It is incorporated into the Lemonade Host Terms of Service.
The AUP applies to every account, Site, custom domain, file, request, deployment, repository connection, API call, CLI command, MCP token, integration, Authorized Agent, optional feature, and other use of the Service.
You are responsible for your own activity and for activity performed through your account by employees, contractors, clients, scripts, integrations, AI assistants, coding agents, or other Authorized Agents. An action does not become permitted merely because an automated tool or AI agent performed it.
This Policy is not an exhaustive list of every harmful or abusive use. We may restrict conduct that is not specifically listed when we reasonably determine that it is unlawful, deceptive, harmful, abusive, insecure, disproportionately burdensome, or inconsistent with the intended use of the Service.
The base Lemonade Host product is designed primarily to store and serve static website files, including HTML, CSS, client-side JavaScript, images, fonts, and similar browser-readable assets.
The base Service is appropriate for uses such as:
Optional upgrades may provide additional functions. A use that is prohibited on the base plan is permitted only when a specific Lemonade Host feature expressly authorizes it and the use remains within that feature's documentation, limits, and terms.
Unless a plan or add-on expressly states different limits, the normal limits for each Site are:
"Approximately" means a normal operational threshold, not an entitlement to consume that quantity in every circumstance. Exact enforcement may vary because of file metadata, system overhead, security controls, traffic patterns, infrastructure conditions, account history, or other technical factors.
We may also apply reasonable limits involving:
We may adjust limits when reasonably needed to prevent abuse, respond to attacks, comply with provider requirements, protect other customers, or maintain the Service. A material reduction to a core paid allowance will be handled under the Terms and applicable law.
The 250 GB monthly bandwidth allowance is intended for ordinary website traffic. Fair use requires that the Site function primarily as a website being visited or used in a normal manner, rather than as a substitute for bulk distribution, media delivery, object storage, a software mirror, or another high-volume delivery service.
Examples of activity that may violate fair use include:
If a non-urgent Site approaches or exceeds an allowance, we may contact you and offer options such as reducing use, changing configuration, upgrading, or moving the workload. We may throttle, restrict, suspend, or decline renewal if the issue continues.
We do not impose an automatic bandwidth-overage charge unless you separately and affirmatively agree to a paid overage or upgrade. We may act without advance notice when traffic threatens infrastructure, security, other customers, or third parties.
Unless an expressly authorized Lemonade Host feature permits the specific activity, you may not use the Service for:
You may not use the Service primarily as:
Reasonable website downloads, embedded media, and normal asset delivery are allowed when incidental to a legitimate Site and within plan limits.
You may not use the Service to engage in, facilitate, promote, instruct, conceal, or materially support activity that is illegal in an applicable jurisdiction or that violates the rights of others.
Prohibited conduct includes:
We may consider context, purpose, likelihood of harm, applicable law, credible reports, and technical evidence. We do not have to wait for a conviction or court order before acting to prevent apparent harm.
You may not upload, host, serve, link to, deploy, or distribute:
Security research requires prior written authorization from the owner of every affected system and must remain within a lawful, documented scope. Lemonade Host does not grant permission to test customer Sites, other accounts, our infrastructure, or our providers merely because they are publicly reachable.
You may not use the Service to send, facilitate, support, redirect, advertise, or collect leads for spam or unlawful unsolicited communications.
Prohibited activity includes:
A legitimate business Site is not prohibited merely because it contains a contact form, newsletter signup, or lawful marketing content.
You may not use the Service to infringe or misappropriate copyright, trademark, patent, trade-secret, publicity, privacy, database, contractual, confidentiality, or other rights.
You must have the necessary rights to all code, templates, fonts, images, videos, music, text, brands, datasets, and other material used on your Site.
We may remove or disable allegedly infringing material, request evidence of authorization, suspend repeat infringers, or terminate an account. Copyright complaints may be submitted through the abuse-report process in Section 18. We may publish a separate copyright or designated-agent procedure as the Service evolves.
You may not use the Service to collect, process, publish, or disclose personal information unlawfully or deceptively.
You are responsible for:
Unless Lemonade Host expressly approves a feature and plan for the specific purpose, do not use the Service to collect or store:
Do not expose private keys, raw API or MCP tokens, repository secrets, environment files, credentials, or confidential configuration in publicly served files.
You may use an AI coding assistant or other Authorized Agent to deploy through the MCP server or another supported method, subject to the Terms and this AUP.
You must:
You may not instruct an AI agent or automation to evade limits, create abusive accounts, probe the Service, access another Site, disguise prohibited activity, or repeatedly redeploy harmful content.
You remain responsible for activity within the scope you authorized. Lemonade Host may revoke a token, block an agent, or suspend automated deployments where activity appears compromised, abusive, unlawful, or operationally harmful.
You may connect only repositories and branches you are authorized to access and deploy. You may not use a connection to exfiltrate repository contents, secrets, personal information, or proprietary code.
Webhooks, commits, deployment packages, and files must not be forged or manipulated to bypass ownership checks, malware controls, limits, or audit records.
Excessive deployment loops, intentionally broken webhooks, repeated failed uploads, automated rollback loops, or other activity that consumes disproportionate resources may be rate-limited or suspended even if the numerical daily deployment threshold has not been reached.
You may host Sites for clients or organizations you are authorized to represent, but you remain responsible for the account, billing, content, and compliance unless we expressly offer a reseller or agency program with different terms.
You may not resell, sublicense, white-label, pool, or redistribute access to the Service as a hosting platform for unrelated third parties without written permission. You may not use one Site as an unauthorized multi-tenant hosting service or create subaccounts that bypass per-Site billing.
You may not:
Good-faith reports, complaints, reviews, and lawful criticism are not prohibited.
We may use automated and manual methods to identify potential violations, including traffic analysis, rate limits, malware scanning, reputation systems, provider notices, content hashes, customer reports, and review of relevant files or logs.
We have no general obligation to monitor every Site or to investigate every report. Failure to detect or act on one violation does not make us responsible for the content or waive our right to act later.
We may preserve, copy, quarantine, or disclose relevant information when reasonably necessary to investigate, protect the Service, comply with law, or establish, exercise, or defend claims.
Depending on severity, urgency, history, and risk, we may:
For active phishing, malware, attacks, child exploitation, credible threats, compromised credentials, legal demands, or immediate infrastructure risk, we may act without advance notice and explain afterward where legally and operationally appropriate.
For a non-urgent, readily curable issue, we may provide notice and a correction period, but we are not obligated to do so.
Suspension or termination for violation does not automatically create a refund, credit, service extension, or damages claim. Billing treatment is governed by the Terms and Refund Policy.
Send an abuse report to [email protected] with the subject line "ABUSE REPORT."
Include, where available:
Do not send malware as an unprotected attachment. Provide a safe link, hash, screenshot, or other non-executing evidence where possible.
Submitting a report does not guarantee removal, disclosure of customer information, or a response. We may request additional information, refer the reporter to a rights holder or authority, or decline to act when a report is incomplete, not credible, outside this Policy, or legally insufficient.
An account holder may appeal a suspension or removal by emailing [email protected] with the subject line "AUP APPEAL."
The appeal should include:
We may require identity, ownership, or authorization verification. We may keep the Site or content disabled during review. We may reject repeated, abusive, incomplete, fraudulent, or substantially unchanged appeals.
We will attempt to review a complete appeal within a reasonable period, but no response or reinstatement time is guaranteed. Reinstatement may be conditioned on removal of content, changed configuration, token revocation, security remediation, an upgrade, or other safeguards.
Repeated violations, attempts to evade enforcement, use of replacement accounts or domains, false statements, compromised accounts that are not secured, or a single sufficiently serious violation may result in account termination and refusal of future service.
We may treat affiliated accounts, common payment methods, shared operators, common repositories, coordinated domains, or other reliable indicators as related when reasonably necessary to prevent evasion.
We may update this AUP as threats, laws, features, providers, and usage patterns change. Material changes affecting ordinary permitted use will be noticed as required by the Terms and applicable law.
Emergency security rules, rate limits, blocks, or controls may be implemented immediately without first updating this public Policy.
Questions, reports, and appeals:
Do not include passwords, full payment-card numbers, private keys, raw MCP tokens, or other secrets in an ordinary email.
Related
What the service includes, how billing and deployments work, and how disputes are resolved.
What we collect, who we share it with, and how to ask us to delete it.
The 30-day guarantee on a new site, and how billing disputes are handled.
Every plan, every interval, on one page.
Join the list and we'll email you just once — that's the only thing we use your address for.