This Acceptable Use Policy (“AUP”) explains what is not allowed on html.contact. It applies to all accounts, forms, submissions, API use, and related activity.
Prohibited Sensitive Data
Do not use html.contact to collect, process, store, transmit, or route:
- Health information or PHI.
- Payment card numbers or PCI-regulated data.
- Social Security numbers, tax IDs, government IDs, or identity documents.
- Passwords, passphrases, private keys, API keys, secrets, seed phrases, or credentials.
- Children’s data.
- GLBA, FERPA, HIPAA, PCI, or similar regulated workloads.
- Highly sensitive personal data.
- Data that you are not legally allowed to collect or process.
Prohibited Conduct
You may not use html.contact to:
- Send, facilitate, or collect spam.
- Run phishing, credential-harvesting, impersonation, or deceptive forms.
- Distribute malware, malicious links, or harmful files.
- Harass, threaten, abuse, dox, or exploit people.
- Collect data through misleading, fraudulent, or unlawful forms.
- Violate privacy, data-protection, consumer-protection, export-control, sanctions, or anti-spam laws.
- Sell illegal goods or services.
- Promote or facilitate sexual exploitation, especially involving minors.
- Interfere with html.contact, other users, or third-party services.
- Bypass, weaken, or evade rate limits, domain allowlists, source checks, recipient verification, spam screening, usage limits, or security controls.
- Probe, scan, test, or attack the service except as permitted by the vulnerability disclosure rules on the Security page.
Email And Recipient Rules
Public submissions never control To, CC, BCC, or From routing. Visitor-submitted fields such as _to, _cc, _bcc, or _from may be stored as submitted fields, but they do not route email.
Customers must verify recipient emails and use html.contact only for legitimate form notifications and operational messages.
Attachments
Attachments are user-submitted and untrusted. You may not use attachments to send malware, illegal content, credential-harvesting material, or other harmful files.
html.contact does not provide malware scanning at launch. Customers should scan unexpected downloads before opening them.
Enforcement
We may investigate suspected violations and may block, quarantine, rate-limit, suspend, disable, delete, or preserve forms, submissions, attachments, API keys, or accounts when we believe it is necessary to protect html.contact, customers, end users, third parties, or the public.
We may also report unlawful activity to appropriate providers, platforms, or authorities.
Report Abuse
Report abuse, phishing, spam, malicious forms, or AUP violations to trust@html.contact.