Acceptable Use Policy

Last Updated: August 2026

The fortheworld ecosystem exists to help people and organisations build useful digital infrastructure.

That requires a basic level of trust.

This Acceptable Use Policy explains the types of activities that are permitted when using services operated by fortheworld OÜ, including services within the development.city ecosystem.

Our goal isn't to police what people build.

It's to protect people, infrastructure, and the ability of legitimate users to use our services safely.

This policy applies together with our Terms of Service and any service-specific terms or agreements.


1. Use the Infrastructure Responsibly

You may use our services for legitimate personal, professional, commercial, educational, creative, social, environmental, or other lawful purposes, subject to the terms applicable to the service.

You are responsible for making sure that your use of the infrastructure complies with:

  • Applicable laws and regulations

  • These Terms

  • This Acceptable Use Policy

  • Any service-specific conditions

  • The rights of other people and organisations

We encourage experimentation and innovation.

Just don't break the city while you're building in it.


2. Activities We Do Not Permit

You may not use our services to facilitate, support, or carry out unlawful or harmful activities.

This includes, but is not necessarily limited to:

Fraud & Deception

You may not use our infrastructure for:

  • Fraud

  • Phishing

  • Impersonation

  • Identity theft

  • Deceptive schemes

  • Financial scams

  • Fake services or transactions

  • Other intentionally deceptive activity

Unauthorised Access

You may not:

  • Attempt to access systems without authorisation

  • Bypass authentication

  • Circumvent access controls

  • Exploit vulnerabilities without appropriate authorisation

  • Access another user's account

  • Attempt to obtain credentials or authentication tokens

Malware & Malicious Code

You may not use our services to distribute or operate:

  • Malware

  • Ransomware

  • Viruses

  • Trojans

  • Worms

  • Credential-stealing software

  • Destructive code

  • Other malicious software

Attacks & Abuse

You may not use our infrastructure to conduct or facilitate:

  • Denial-of-service attacks

  • Distributed denial-of-service attacks

  • Network attacks

  • Automated abuse

  • Port scanning intended to facilitate unauthorised access

  • Brute-force attacks

  • Infrastructure disruption

  • Deliberate resource exhaustion

Security testing may be permitted where it is properly authorised and conducted within an agreed scope.


3. Spam & Unwanted Communications

Our services must not be used to send or facilitate unlawful or abusive bulk communications.

This includes:

  • Spam

  • Unsolicited commercial messages where prohibited

  • Phishing campaigns

  • Mass deceptive communications

  • Malicious automated messaging

  • Repeated unwanted communications

  • Messages designed to evade anti-spam systems

If you operate a legitimate mailing or notification system, you are responsible for ensuring that you have the appropriate permissions and comply with applicable laws.

Automation doesn't make consent optional.


4. Privacy & Personal Data

You must not use our services to unlawfully collect, expose, process, or distribute personal information.

This includes:

  • Publishing private information without authorisation

  • Collecting personal information without an appropriate legal basis

  • Exposing confidential customer information

  • Misusing authentication information

  • Selling or distributing unlawfully obtained personal data

  • Using our infrastructure to facilitate identity theft

If you process personal information through our services, you are responsible for understanding and meeting the obligations applicable to your role under data-protection law.

Where we process personal data on your behalf, additional contractual data-protection terms may apply.


5. Intellectual Property

You must have the necessary rights or permissions to upload, distribute, publish, or otherwise use content through our services.

You must not knowingly use our infrastructure to distribute content that infringes another person's or organisation's:

  • Copyright

  • Trademark

  • Patent

  • Trade secret

  • Design rights

  • Other intellectual-property rights

If you believe that content hosted or distributed through our services infringes your rights, please contact us with sufficient information for us to investigate.


6. Harmful or Abusive Content

You must not use our services to facilitate serious harm to other people.

This includes using the infrastructure to intentionally facilitate:

  • Credible threats of violence

  • Targeted harassment

  • Extortion

  • Abuse

  • Exploitation

  • Deliberate harm to individuals or organisations

Legitimate discussion, criticism, journalism, research, education, historical material, and other lawful expression are not automatically prohibited simply because the subject matter is controversial or uncomfortable.

Context matters.


7. Child Safety

Our services must not be used to facilitate the sexual exploitation or abuse of children.

This includes creating, storing, distributing, requesting, or facilitating access to child sexual abuse material or other illegal activity involving children.

We may take immediate action where necessary to protect children or comply with legal obligations.


8. Security Research

We support responsible security research.

Security researchers may identify vulnerabilities in systems connected to our services.

If you discover a potential security issue, please report it responsibly rather than exploiting it.

Where possible:

  • Avoid accessing information that does not belong to you

  • Avoid modifying or deleting data

  • Avoid disrupting services

  • Minimise testing activity

  • Provide enough information for us to reproduce the issue

  • Allow reasonable time for investigation and remediation

If you are conducting security testing on behalf of a customer or another organisation, make sure you have appropriate authorisation.

Finding a vulnerability is not the same thing as having permission to exploit it.


9. Automated Access

Automation is an important part of modern digital infrastructure.

We use it ourselves and support legitimate automation.

However, automated access must not:

  • Overload services

  • Circumvent technical limits

  • Evade security controls

  • Harvest information without authorisation

  • Create excessive traffic

  • Interfere with other users

  • Attempt to bypass rate limits

  • Consume disproportionate shared resources

If your legitimate application needs high-volume access, contact us so that we can determine an appropriate technical arrangement.


10. Shared Infrastructure

Some services operate on shared infrastructure.

That means one user's behaviour can potentially affect other users.

You must not intentionally consume disproportionate resources or interfere with the availability or performance of services used by others.

This can include:

  • Excessive resource consumption

  • Deliberate traffic flooding

  • Runaway automation

  • Uncontrolled background processes

  • Storage abuse

  • Deliberate attempts to degrade performance

Where a service has defined resource limits, those limits apply.


11. Circumventing Restrictions

You must not attempt to circumvent:

  • Account restrictions

  • Authentication requirements

  • Rate limits

  • Usage limits

  • Security controls

  • Service restrictions

  • Suspension measures

  • Geographic or technical restrictions where they are lawfully imposed

If you believe a restriction has been applied incorrectly, contact us.

Trying to defeat the lock isn't the same as asking us to open the door.


12. Reverse Engineering

Some forms of reverse engineering may be permitted by applicable law.

However, you may not use reverse engineering or similar techniques to:

  • Bypass security controls

  • Obtain unauthorised access

  • Extract confidential information

  • Circumvent licensing restrictions

  • Attack infrastructure

  • Interfere with services

Nothing in this policy is intended to remove rights that cannot legally be excluded.


13. Financial & Payment Abuse

You may not use our services to facilitate:

  • Payment fraud

  • Stolen payment methods

  • Money laundering

  • Fraudulent transactions

  • Fake invoices

  • Deceptive payment schemes

  • Other unlawful financial activity

Where payments are processed through third-party providers, their own rules and restrictions may also apply.


14. Illegal Goods & Services

You may not use our infrastructure to facilitate transactions or activities involving goods or services that are unlawful under applicable law.

This includes using our systems to facilitate illegal markets or transactions.

Certain regulated activities may also be restricted by the terms of individual service providers even where they are lawful in a particular jurisdiction.

Where there is uncertainty, contact us before building the activity into the infrastructure.


15. Misuse of Third-Party Services

Our ecosystem may connect to external platforms and providers.

You are responsible for complying with the applicable rules of those services when you use them through our infrastructure.

You must not use our integration capabilities to bypass another provider's:

  • Terms of service

  • Security controls

  • Usage limits

  • Licensing restrictions

  • Access restrictions

  • Anti-abuse mechanisms

Connecting two systems doesn't magically make the rules of either system disappear.


16. Content You Are Responsible For

You remain responsible for content and information that you provide through services where you control that content.

You should ensure that the content you upload or distribute:

  • Is lawful

  • Does not knowingly infringe third-party rights

  • Does not contain malicious code

  • Does not expose confidential information improperly

  • Complies with applicable service terms

We do not necessarily monitor every piece of user-provided content.

However, we may investigate reported or detected violations where reasonably necessary.


17. Reporting Abuse

If you believe our infrastructure is being used in violation of this policy, please report it to us.

Useful information can include:

  • The affected service

  • Relevant URL or identifier

  • Description of the suspected abuse

  • Approximate date and time

  • Evidence where available

  • Any immediate risk to people or infrastructure

Please do not attempt to investigate or confront the suspected user yourself.

Report it. Let us investigate it.


18. What Happens If the Policy Is Violated?

If we reasonably believe that a service is being used in violation of this policy, we may take appropriate action.

Depending on the situation, this may include:

  • Requesting additional information

  • Asking the user to stop the activity

  • Limiting specific functionality

  • Temporarily restricting access

  • Suspending an account or service

  • Removing or disabling access to unlawful content where required

  • Terminating the relevant service

  • Reporting activity to appropriate authorities where legally required or permitted

We will consider the nature and severity of the situation when determining the appropriate response.


19. Immediate Action

Some situations may require immediate action.

For example, we may need to act quickly where there is a credible risk involving:

  • Serious security threats

  • Active attacks

  • Malware

  • Fraud

  • Child safety

  • Significant infrastructure abuse

  • Illegal activity

  • Serious harm to another person

In such cases, we may restrict access before completing a full investigation.

Where appropriate and legally possible, we will provide information about what happened and what options are available.


20. Appeals & Review

If you believe that action has been taken against your account or service incorrectly, contact us.

Explain:

  • What happened

  • Why you believe the decision was incorrect

  • Any relevant context

  • What you would like us to review

We will review the situation based on the information available and the applicable terms.

Where appropriate, we may restore access or modify the action taken.


21. Changes to This Policy

The technology and services we provide may change.

We may therefore update this Acceptable Use Policy from time to time.

When we make changes, we will update the Last Updated date.

If a change materially affects an existing contractual relationship, the applicable agreement and mandatory legal requirements will determine how the change is handled.


The Short Version

Use the infrastructure to build, connect, automate, communicate, and create useful things.

Don't use it to:

Steal.

Scam.

Attack.

Abuse.

Harass.

Spy.

Spread malware.

Break into systems.

Exploit people.

Break the law.

And if you're unsure whether something is acceptable:

Ask before you build it.

We'd rather have a conversation about an unusual idea than discover it after something has gone spectacularly sideways.

Build better. Connect smarter. Scale sustainably.

#ForPeopleForPlanet


Was this article helpful?