Legal
Acceptable Use Policy
In short
Nodes2Cloud lets you deploy code that sends email, calls APIs and reaches other people’s systems. This policy is therefore an operational constraint, not boilerplate.
In short: no spam, no scraping in breach of a site’s terms, no malware or phishing, no attacks, no abuse of the AI features, and comply with the terms of every service you connect. Breaking these rules can get your account suspended without notice.
This Acceptable Use Policy (“AUP”) forms part of our Terms of Service and applies to everyone who uses Nodes2Cloud — including workflows you deploy into your own Cloudflare account using code we generated.
1. Why this policy matters more here than elsewhere
Most software AUPs govern what you do inside a product. Ours also governs what your workflows do to other people. A Nodes2Cloud workflow can send email through Gmail or SendGrid, message people on WhatsApp, Slack or Telegram, write to databases, call any HTTP endpoint, and run on a schedule without you present.
That reach is the point of the product. It also means a misused workflow can cause real harm to third parties at machine speed, and can get our compiler, our connectors and Cloudflare’s infrastructure implicated in it. Hence the rules below.
2. Illegal and harmful use
You may not use Nodes2Cloud, or anything built with it, to:
- Break any applicable law or regulation, in India or in any jurisdiction you operate in.
- Infringe copyright, trademarks, patents, trade secrets or any other intellectual property right.
- Create, store or distribute child sexual abuse material, content that sexualises minors, or non-consensual intimate imagery. We report such material to the authorities.
- Harass, stalk, threaten, defame or incite violence or hatred against any person or group.
- Facilitate fraud, money laundering, unlawful gambling, pyramid or Ponzi schemes, or the sale of controlled substances, weapons or stolen data.
- Impersonate any person or organisation, or misrepresent your affiliation with one.
- Process personal data in breach of applicable data-protection law, including the DPDP Act and the GDPR.
3. Email, messaging and outbound communication
This section matters because our connectors make bulk sending trivially easy. You may not use a workflow to:
- Send unsolicited bulk email or messages of any kind. You must have a lawful basis and, where required, prior consent from every recipient.
- Send marketing without a clear, working and honoured unsubscribe mechanism.
- Forge, spoof or obscure sender identity, headers or return paths.
- Harvest email addresses or phone numbers, or send to a list you cannot show consent for — including purchased, rented or scraped lists.
- Send phishing messages, or any communication designed to deceive recipients into revealing credentials, payment details or personal data.
- Circumvent a recipient’s opt-out, block, or a platform’s anti-spam controls.
- Breach anti-spam law applicable to you or your recipients, including India’s TRAI commercial communication regulations, the US CAN-SPAM Act, Canada’s CASL and the EU ePrivacy Directive.
Providers such as Google, Twilio and WhatsApp enforce their own strict rules and will suspend your account for violations. We cannot appeal that on your behalf.
4. Scraping and automated collection
- Do not scrape a website or API in breach of its terms of service, its robots directives, or any technical measure it uses to prevent automated access.
- Do not collect personal data from public sources for purposes the individuals would not reasonably expect.
- Do not build datasets of biometric data, or of personal data intended for surveillance or discriminatory profiling.
- Respect rate limits. A scheduled workflow polling aggressively is indistinguishable from an attack to the site receiving it.
5. Security and integrity
You may not:
- Create, host or distribute malware, ransomware, spyware, cryptominers or any malicious code.
- Attempt to gain unauthorised access to any system, account or data — ours, a third party’s, or another customer’s.
- Probe, scan or test the security of systems you are not authorised to test.
- Launch denial-of-service attacks, or use workflows to amplify traffic against any target.
- Interfere with the Nodes2Cloud platform, the compiler, or another customer’s use of it.
- Use credentials you are not authorised to use, or store credentials belonging to someone who has not permitted it.
- Reverse-engineer, decompile or attempt to extract the source of our platform, except where the law expressly permits it.
Good-faith security research is welcome. Test only against your own account, and report findings to security@nodes2cloud.com — see our Security page. Research conducted within those bounds is not a breach of this policy.
6. Resource abuse
- Do not use the editor, compiler or API in a way designed to place a disproportionate load on them, including automated request floods.
- Do not circumvent plan limits, quotas or rate limits by any technical means.
- Do not create multiple accounts to obtain more free allowance than one account provides.
- Do not use our compilation or deployment infrastructure for cryptocurrency mining or similar disproportionate compute.
7. AI features
- Do not use the AI assistant to generate content prohibited elsewhere in this policy.
- Do not attempt to extract, replicate or reverse-engineer the underlying models, or to circumvent their safety measures.
- Do not use the assistant as a general-purpose model proxy unrelated to building workflows.
- Do not submit other people’s personal data, or your own secrets, in prompts.
- Review AI output before deploying it. You are responsible for what you deploy, regardless of what generated it.
8. Third-party services you connect
Every connector is governed by that provider’s own terms as well as this policy. You must:
- Comply with the terms, API policies and rate limits of Google, Microsoft, AWS, Slack, OpenAI, Stripe and every other service you connect.
- Use only credentials you are entitled to use, scoped as narrowly as the task requires.
- Honour any data-handling commitments those providers impose — Google’s Limited Use requirements in particular, which apply to data your workflows obtain from Google APIs. See Google API Limited Use.
Breaching a provider’s terms is a breach of this policy, even where nothing in this document specifically prohibits the act.
9. Commercial restrictions
- Do not resell, sublicense or provide Nodes2Cloud itself as a service to third parties without our written agreement. Building workflows for your clients is fine; reselling access to the editor is not.
- Do not share one account among multiple people — team plans exist for that.
- Do not use the platform to build a directly competing workflow-compiler product.
10. Your responsibility for what you deploy
Once deployed, a workflow runs in your Cloudflare account, under your credentials, without us in the path. We cannot see what it does and we cannot stop it.
You are therefore solely responsible for the behaviour, output and consequences of every workflow you deploy — including workflows the AI assistant helped you write, and including anything that runs on a schedule after you have stopped thinking about it. Test before you deploy, and set sensible limits.
11. How we enforce this policy
Where we become aware of a breach we may, at our discretion and proportionate to the severity:
- ask you to fix it within a stated period;
- disable a specific workflow, credential or feature;
- suspend your account, with or without notice;
- terminate your account under the Terms of Service; or
- report the matter to law enforcement where the law requires or the harm warrants it.
Serious cases — malware, CSAM, active attacks, phishing — get immediate suspension with no prior notice. For less serious matters we will normally contact you first.
We maintain an append-only audit log of significant account actions, which is what we rely on when investigating. You may appeal any enforcement decision by writing to support@nodes2cloud.com; a human will review it.
Suspension for breach does not entitle you to a refund. See the Refund & Cancellation Policy.
Note that we cannot remove or disable workflows already running in your own Cloudflare account. Where a deployed workflow is causing harm, you must stop it — and Cloudflare may act under their own terms.
12. Reporting abuse
If you believe a Nodes2Cloud user is breaching this policy, email support@nodes2cloud.com with as much detail as you can — message headers, timestamps, URLs, and what you observed. We acknowledge abuse reports within 2 business days.
For security vulnerabilities, use security@nodes2cloud.com instead.
We may update this policy as new abuse patterns appear. Material changes are notified to account holders by email.