Acceptable Use Policy

Last updated: August 5, 2026

Scope and Incorporation

This Acceptable Use Policy (the "AUP") governs your use of ClusterCode and forms part of our Terms of Service. Capitalized terms have the meanings given in the Terms, and violating this AUP is a breach of them. It applies to everyone who uses the Service on any plan, including free trials, and to all compute you direct through it — whether that runs on your own hardware as a self-hosted worker or on ClusterCode-managed infrastructure as a Cloud Worker. We may update this AUP as new forms of misuse emerge, and will post changes here with a new "Last updated" date. Because this AUP forms part of the Terms, a material change to it is a material change to the Terms, and we will give you notice before it takes effect in the way the Terms describe.

Permitted Use of Compute

ClusterCode exists to run software development workloads that you direct: builds, tests, AI coding agent runs, and the development tooling that supports them. Cloud Worker compute is metered infrastructure that we pay for before it is billed to you. It is provided for that development purpose only. Any other use of ClusterCode-managed compute requires our prior written permission. If you are unsure whether a workload is permitted, ask us at legal@clustercode.io before running it.

Prohibited Workloads

You may not run, or permit anyone else to run, any of the following on ClusterCode-managed compute: • Cryptocurrency mining, staking, or blockchain validation of any kind, and password or hash cracking • Distributed computing projects unrelated to your development work (for example BOINC or protein folding) • General-purpose hosting: game servers, media transcoding or streaming farms, torrent or seedbox activity, file hosting, backup targets, or content-delivery endpoints • VPN services, proxy or relay services, Tor nodes, or any other traffic-anonymizing egress • Holding DevBoxes open without active work in order to reserve capacity • Operating Windows DevBoxes as a general remote-desktop or virtual-desktop service • Large-scale automated scraping or crawling unrelated to your development work These are examples, not an exhaustive list. The governing principle is that ClusterCode-managed compute is for development work — not for workloads whose value is the computation itself. If a workload would be equally valuable running on any anonymous machine anywhere, it does not belong here.

Prohibited Conduct

You may not use ClusterCode, or any network access it provides, to: • Scan, probe, penetration-test, or attack any system or network you do not own or have written authorization to test • Participate in denial-of-service attacks, credential stuffing, or brute-force attempts against any third party • Send unsolicited bulk email, or operate a relay for it • Host or distribute phishing pages, malware, ransomware, or command-and-control infrastructure • Attempt to escape DevBox isolation, reach another customer's data or workloads, or attack ClusterCode's own systems • Store or distribute material that infringes intellectual property rights, or that is illegal to possess or transmit • Create accounts by automated means, or attempt credential stuffing or brute-force login against ClusterCode • Reverse engineer the Service, or access it in order to build a competing product or to benchmark it for one, except to the extent that restriction is prohibited by law or permitted by an applicable open-source license • Scrape, crawl, or systematically extract data from the ClusterCode website or application itself, or access it by automated means other than the APIs and integrations we provide for that purpose • Use ClusterCode's integrations — including GitHub — to send unsolicited pull requests, issues, or other automated traffic to repositories you do not control

AI and Model Use

ClusterCode's AI capabilities are provided through third-party model providers. When you use them, you must also comply with those providers' usage policies, including Anthropic's Usage Policy. Their restrictions apply to you as though set out here, and violating them violates this AUP. You may not: • Use ClusterCode's agents to generate malware, exploits intended for unauthorized use, phishing content, or bulk spam • Use the Service primarily as a general-purpose inference proxy, or resell, sublicense, or redistribute access to the models behind it • Attempt to bypass the safety controls or system instructions of Nucleus, Nova, or any other agent — including by prompt injection — or to extract those underlying instructions

Account, Trial and Billing Integrity

Trials. Free trials are limited to one per person, one per organization, and one per payment instrument. Creating additional accounts, using disposable email addresses, or using different payment instruments to obtain more than one trial is prohibited. We may end or refuse a trial at any time if we suspect abuse. Payment. You must use a payment instrument you are authorized to use. Funding a wallet with a stolen or unauthorized instrument is fraud, and will result in immediate termination and, where appropriate, referral to law enforcement. Chargebacks. Reversing a charge for compute you have already consumed, rather than raising the problem with us first, is also grounds for suspension. If you think you have been billed in error, contact support@clustercode.io and we will look into it — that route is open to you before and after any suspension. Seats and resale. Each seat is for one named individual. You may not share account credentials, and you may not resell, sublicense, rent, or whitelabel ClusterCode or its compute to any third party without a written agreement with us. Your hardware. When you connect a self-hosted worker, you represent and warrant that you own that machine or are authorized by its owner to use it for this purpose. You may not connect hardware you are using without authorization — including compromised machines, botnet nodes, employer or academic equipment used contrary to that organization's policy, or infrastructure funded by stolen cloud credentials.

Enforcement and Consequences

We enforce this AUP to protect our infrastructure, our costs, and our other customers. If we believe in good faith that you have violated this AUP, we may, at our sole discretion and without prior notice: • Suspend or terminate your account, subscription, trial, workers, or DevBoxes, in whole or in part • Stop a DevBox that is currently running, including one with work in progress • Delete the workloads and artifacts held in the account — including DevBoxes, schedules, loops, prototypes, container images, and stored volumes — immediately, and without the retention periods that apply when an account is closed in the ordinary course • Reclaim any unused trial credit • Decline to issue a refund, consistent with the Terms • Decline to provide the Service to you again, including through new or additional accounts Where an account has more than one member, a violation by any member is a violation by the account. We may suspend the account as a whole, and delete resources belonging to it, even where only one member was responsible — under the Terms, the people who create and administer a team are responsible for the members they invite. We may also set, change, and enforce limits at any time — including rate limits, concurrency caps, quotas, and fair-use throttling on how much compute a single account may hold at once — with or without notice, so that capacity stays available to every customer. We may investigate suspected violations, retain the relevant logs and resource-usage telemetry for as long as needed to do so, and report unlawful activity to law enforcement or to affected third parties. Where we suspend or terminate an account, we keep a record of what we did and why — including what was deleted — for as long as we need it to handle disputes and prevent repeat abuse. Where we take action against your account, we will normally tell you what we did and the reason for it, unless the law prevents us or telling you would compromise an investigation or the security of the Service. Acting without prior notice does not mean acting without explanation. Enforcement may be carried out by automated means, in whole or in part. If you believe we have acted in error, contact legal@clustercode.io and a person will review the decision. Nothing in this AUP obliges us to monitor for violations, and choosing not to enforce it in one case does not waive our right to enforce it in another.

Reporting Abuse

If you believe someone is using ClusterCode in violation of this AUP — including abuse that appears to originate from a ClusterCode IP address — report it to security@clustercode.io. Please include timestamps, IP addresses, and any relevant logs so we can act quickly.