Acceptable Use Policy

Last updated 25 July 2026

This policy sets out what you agree not to do with Vault. It forms part of the Terms of Service.

You agree not to

  • Store, transmit or share material that is unlawful where you are or in India.
  • Infringe the intellectual property or privacy rights of others.
  • Store or share credentials you are not authorised to hold, or facilitate unauthorised access to any system.
  • Share credentials in violation of a third party's terms of service or an employer's policy.
  • Distribute malware, or use Vault as a channel for command-and-control or data exfiltration.
  • Attack, overload, probe, or attempt to circumvent the rate limits or access controls of the notification relay or the sharing directory.
  • Circumvent, patch or redistribute the licensing mechanism, or misrepresent Vault as your own.
  • Use Vault in violation of export control or sanctions law, or for any prohibited end use.

What we can and cannot enforce

We cannot see your vault contents and therefore do not and cannot monitor them. This policy states your obligations; it does not describe a capability we possess. Where enforcement is possible at all, it is limited to the optional components we operate — the realtime relay and the sharing directory — which we may rate-limit, suspend or terminate for abuse.

Reporting abuse

Report abuse of the relay or the sharing directory to founder@dfacto.ai. Include what you observed and when. We cannot act on a report that requires us to read someone's vault, because we cannot.

Consequences

Material breach may result in suspension of the optional services or termination of your licence under the Terms. Termination does not delete your data, which remains on your device and in your own Drive.