01Scope and responsibility
These rules apply to every account, profile, post, message, project, site, domain, asset, bot, integration, payment instruction and use of Ident.ink. You are responsible for your own conduct and for people, software and credentials you authorise.
Context matters, but labels such as joke, parody, research, private, encrypted or test do not excuse unlawful or harmful conduct. Attempting, assisting, soliciting or concealing a prohibited act is also prohibited.
02Illegal content and conduct
- Do not commit, promote, facilitate or profit from crime or provide instructions whose purpose is to enable serious wrongdoing.
- Do not sell unlawful goods or services, evade sanctions, launder funds, conceal proceeds, or interfere with an investigation.
- Do not upload or link to material you know is illegal in the place from which you operate or where the service is lawfully required to act.
03Child safety and exploitation
Any child sexual abuse material, grooming, sexual extortion, trafficking, sexualisation of minors, or attempt to obtain sexual content from a minor is forbidden. Apparent or generated depictions are included where prohibited or harmful. We may preserve and report evidence to the appropriate bodies without notice.
04Terrorism and violent extremism
Do not praise, support, recruit for, fund, instruct or distribute propaganda for a proscribed terrorist organisation or violent extremist cause. Documentary, counterspeech, educational and newsworthy material must have clear context and may still be restricted where law or safety requires.
05Violence, threats and self-harm
- No credible threats, targeted incitement, celebration of real-world harm, doxxing that creates danger, or instructions intended to enable an attack.
- No encouragement, coordination or graphic glorification of suicide, self-harm or eating-disorder behaviour. Supportive recovery discussion is allowed.
- Contact emergency services if someone faces immediate danger; a platform report is not an emergency response.
06Hate, harassment and abuse
Do not attack, dehumanise, threaten, exclude or promote hatred against people based on protected characteristics. Persistent unwanted contact, sexual harassment, humiliation campaigns and coordinated abuse are prohibited. Good-faith criticism of ideas, organisations and public conduct is allowed when it does not cross these lines.
07Sexual exploitation and intimate material
No non-consensual intimate imagery, sexual extortion, trafficking, coercion, or sexual content involving a person who cannot lawfully consent. Do not use private information or synthetic media to sexualise, threaten or impersonate someone. Adult material may be restricted or prohibited by feature, audience, processor or law.
08Fraud, impersonation and deception
- No phishing, fake support, credential collection, investment or employment scams, pyramid schemes, fabricated fundraising, chargeback abuse or deceptive checkout flows.
- Do not impersonate a person, business, staff member or verified identity, or falsely claim endorsement, partnership or authority.
- Parody and fan accounts must be unmistakably labelled and may not create a likelihood of harmful confusion.
09Privacy and personal data
Do not expose credentials, private addresses, identity documents, health or financial data, private communications or precise location without a lawful basis and appropriate permission. Do not purchase, scrape, combine or sell personal data through the platform in breach of privacy, marketing or data-broker law.
10Intellectual property
Upload and publish only material you own or are authorised to use. Do not remove rights-management information, sell counterfeit goods, repeatedly infringe rights, or use another party’s branding in a misleading way. Rights holders may report alleged infringement through Support with enough information to identify the work and content.
11Cybersecurity and infrastructure
- No SQL injection, cross-site scripting, server-side request forgery, command or template injection, request smuggling, response splitting, path traversal, unsafe deserialisation, prototype pollution, credential stuffing, password spraying or exploitation of a vulnerability.
- Do not attempt to reach or identify the host filesystem, source repository, environment files, secrets, logs, backups, sockets, processes, service metadata, control plane, private addresses or internal services except through a documented interface expressly intended for that purpose.
- No malware, ransomware, spyware, cryptomining, botnets, denial-of-service activity, traffic amplification, resource exhaustion, unauthorised scanning of infrastructure or interference with another tenant.
- Do not bypass authentication, authorisation, payment gates, quotas, rate limits, bans, moderation, audit trails, tenant boundaries or technical safeguards; do not submit proxy-control headers, local protocols or destinations intended to make the service act on the server itself.
- Good-faith security research must follow security.txt, minimise access, avoid persistence or disruption, and stop immediately if another user’s data is encountered. Report promptly. Prior written authorisation is required for testing that would otherwise breach these rules or law.
12Scraping, automation and artificial activity
Do not scrape or crawl private, authenticated, access-controlled or disallowed content; ignore robots or rate controls; harvest profiles or emails; train a model on platform or user content without rights and permission; or use automation that degrades service.
No account farms, fake engagement, artificial follows, spam networks, coordinated ranking manipulation or automated actions that misrepresent a human. Public search indexing that obeys published controls is allowed.
13AI agents, generated output and tool access
- Do not give an agent credentials, permissions or payment authority broader than the task requires, and do not represent generated output as human-reviewed when it is not.
- Do not use prompts, documents, webpages or connected data to make an Ident.ink agent reveal secrets, cross tenant boundaries, disable safeguards, execute downloaded code or take an unauthorised external action.
- A person with authority must review legal, financial, employment, safety, security, release and destructive actions. You remain responsible for an agent or automation you configure.
- Generated content, code and analysis must be checked for accuracy, rights, security and fitness before publication or operational use.
14Workflow and connected-service safety
- Do not create a workflow that sends unlawful or deceptive communications, initiates unauthorised payments, changes records to conceal activity, or evades a required human approval.
- Do not connect an API or webhook you do not control or have authority to use. Connected services may receive bounded data events only and must never be used to request executable code, local files, secrets, internal addresses or infrastructure control.
- Review high-impact actions before activation and promptly pause a workflow that behaves unexpectedly. Repeated triggering intended to exhaust email, payment, database, queue or third-party capacity is prohibited.
15Spam and unsolicited communications
Do not send bulk or repetitive messages without valid consent, use purchased lists, conceal the sender, evade opt-outs, or create doorway pages and low-value content solely to manipulate traffic or advertising. Commercial communications must be truthful, properly identified and provide every legally required unsubscribe route.
16Sites, domains and bots
Hosted sites and bots must not steal credentials, distribute malware, operate abusive proxies, manipulate other platforms, raid communities, evade platform rules, infringe rights or conceal unlawful services. You must secure secrets, comply with Discord and other connected-platform rules, and keep bot permissions no broader than needed.
Do not point a domain you do not control, abuse certificates, generate deceptive subdomains or use Ident.ink infrastructure as disposable storage, a redirect farm or a command-and-control service.
17Profiles and Business Chat
Public profiles and Business Chat activity must be authentic and relevant. Do not use hiring, partnership or payroll tools for discriminatory, exploitative or fraudulent offers. Recipients may block and report contact.
End-to-end encryption and User Key features protect message content from ordinary access; they do not create immunity. Reported metadata, participant-provided content, abuse signals and activity outside an encrypted session may still be reviewed and acted on.
18Payments, referrals and payroll
- Do not use Connect, payroll or referrals for money laundering, sanctions evasion, self-referral, sham work, tax evasion, unlawful gambling, stolen instruments or circular transactions.
- Do not misclassify workers, conceal legally required information, generate fake recipients or manipulate schedules to evade review.
- Only submit a payment instruction you are authorised and funded to make. Test environments must use provider-approved test credentials, never real payment data.
19Ident Market participation
- Do not submit unlawful, unsafe, deceptive or rights-infringing software proposals, conceal the intended use, or split one prohibited project into apparently harmless submissions.
- Do not falsify Stripe Identity or Connect information, complete verification for another person, share a connected account, evade re-verification, or submit identity documents through public fields, ordinary email or chat.
- Do not collude, place sham bids, manipulate ranking or timing, abuse payment authorisations, interfere with auction closing, misrepresent delivery ability, or bid without authority and a genuine intention to perform the proposal.
- Do not treat assessment, approval, a generated specification, auction selection or release review as legal, security, investment or commercial assurance. Report a material change that makes an approved project unsafe or unlawful.
20Stores, products and fulfilment
- Do not operate a store under a false legal identity, omit a company registration when selling as a company, impersonate a trader, or use another organisation’s Stripe or fulfilment account without authority.
- Complete and maintain the seller’s own Stripe Connect verification when requested. Do not bypass, falsify or complete verification for a different person or organisation. Unverified stores cannot publish or accept checkout and may have commerce access restricted after notice.
- Do not list illegal, unsafe, counterfeit, recalled, age-restricted or deceptively described products, fabricate stock or delivery claims, hide mandatory charges, or obstruct lawful cancellation, returns, refunds or consumer remedies.
- Connected fulfilment data must be reviewed before publication. You remain responsible for product safety, intellectual-property rights, tax, consumer disclosures, customer service and the acts of providers you select.
21Fair use and free-resource abuse
Do not squat on accounts, projects, storage, domains or bots; intentionally exhaust resources; evade metering; resell shared access; or use free features for bulk archival, automation or traffic. Dormant free content may be archived or removed after appropriate notice where required.
22Reporting and cooperation
Use Support to report illegal content, safety issues, impersonation, infringement, spam or other violations. Identify the exact URL, account or message, explain the concern and include lawful evidence. Do not file knowingly false or retaliatory reports.
Preserve relevant records and cooperate with proportionate requests during an investigation. Never obtain evidence by hacking, harassment or publishing private information.
23Evidence preservation and investigation integrity
Do not delete, falsify, backdate, conceal or manipulate records after you know of a credible report, payment dispute, security incident, legal hold or regulatory enquiry. Do not threaten reporters, witnesses, reviewers or staff, and do not coordinate misleading evidence.
Ident.ink may preserve relevant account, content, transaction and technical records, restrict an affected feature and share proportionate information with providers, advisers or competent authorities where there is a lawful basis. Preservation is not a finding of guilt and remains subject to privacy, privilege and appeal safeguards.
24Enforcement
Depending on severity, intent, harm, history and risk, we may warn, reduce distribution, label or remove content, freeze a payment instruction, restrict features, revoke sessions, rate-limit, suspend, apply known-network controls, terminate, preserve evidence or notify a provider or authority.
We may act without advance notice for urgent safety, legal, fraud or security reasons. Account-level action is not proof of criminal conduct. We may correct an action when new evidence changes the assessment.
25Complaints and appeals
Eligible users may challenge a moderation decision through the Reports, Moderation and Appeals Policy. Provide the case reference and explain the error or new evidence. A reviewer not responsible for the original decision should conduct the review where practicable.
Repeated, abusive or identical appeals may be closed. Legal rights and any mandatory complaint route remain available regardless of an internal decision.
These rules are applied proportionately and alongside the Reports, Moderation and Appeals Policy.