Acceptable Use Policy
What Intracia may and may not be used for, and what happens when someone crosses the line.
Last updated 18 August 2026
This policy sets out what you may not publish, store or do with Intracia. It sits alongside our Privacy Policy, Terms of Service and Data Processing Agreement.
It applies to everything in a site and everything in an account: published pages, drafts, media, metadata, version history, and the way the service itself is used. Something doesn't become acceptable by being unpublished — a draft nobody has seen is still stored on our systems and still counts.
Parts of this are stricter than the law requires. We run entirely on other people's infrastructure — Cloudflare above all — and their acceptable-use terms bind us as their customer. A single site breaking those terms puts the hosting underneath every customer at risk, not only the account responsible. So on the things that threaten the platform, we enforce at least as strictly as they do, and sometimes sooner.
1. Content that's never allowed
You may not put any of the following anywhere in a site or an account, whatever the context and whatever the intent behind it:
- Child sexual abuse material, or any sexual exploitation of minors. There's no threshold, no warning and no appeal before action. See section 8.
- Grooming, and material that teaches it — content meant to build trust with a child or a vulnerable adult in order to exploit them, and guidance on how to go about it.
- Pornographic or sexually explicit material.
- Graphic real-world violence — gore, mutilation, and depictions of death intended to shock.
- Hateful content — material that attacks, demeans or incites hatred against people on the basis of race, religion, ethnicity, nationality, gender, sexual orientation, disability or any comparable characteristic.
- Content promoting suicide, self-harm or disordered eating — encouragement, instructions, methods, and challenges that invite someone to take part.
- Coercion and psychological manipulation aimed at people — coercive control, cult-style recruitment, and techniques taught for exploiting someone's trust, fear or isolation.
- Content promoting, glorifying or recruiting for terrorism or violent extremism.
- Harassment, threats, or the publication of someone's private information to expose or endanger them.
- Fraud and scams, including deceptive schemes dressed up as something else.
- Illegal goods and trafficking — controlled drugs, counterfeits, weapons parts, people.
- Material that infringes someone else's rights — pirated work, or anything else you don't have the right to distribute.
- Spam and bulk unsolicited content.
- Health or election misinformation where the likely result is real-world harm.
- Unlicensed gambling or financial services, and regulated goods sold without the compliance they require — alcohol, tobacco, pharmaceuticals and the like.
- Anything else whose likely result is serious harm to a person. This list can't name every way that happens, so we act on the harm rather than on whether we thought to list it.
Each of these turns on what the content does, not what it's about. A support service, a newsroom or a researcher writing about suicide, abuse or extremism is doing the opposite of promoting it. If you're unsure which side of the line your site sits on, ask before you build.
2. Sites we won't host
Some subjects are perfectly fine to write about but not to build a site around. The distinction is the site's primary purpose, not whether a topic appears at all:
- Weapons — sales, marketplaces, and dedicated enthusiast or advocacy sites. A photograph of a firearm in an article about something else isn't a violation.
- Partisan political campaigning — sites whose purpose is electoral advocacy. A company stating its position on a policy question that affects it isn't a violation.
If you're unsure which side of this line you're on, ask before you build. We'll give you a straight answer, and it's an easier conversation now than after the site is up.
3. How the service may not be used
This section is about conduct, not subject matter. It restricts what you may do with the service and to other people's systems. It places no limit on what you may write about. Technical writing is ordinary publishing, and this is a publishing tool — including writing about how something is built, how it fails, and how it was taken apart.
With that distinction in mind, we prohibit the following regardless of what content is involved, or whether any content is involved at all:
- Using the service to distribute malware, or to host a payload staged for an attack.
- Phishing, or obtaining anyone's credentials by deception.
- Accessing, probing, scanning or interfering with systems, accounts or data you don't own and do not control — including other tenants of this service, and including our own infrastructure.
- Circumventing rate limits, quotas or access controls on services that aren't yours, or automating against this one at a volume that degrades it for anyone else.
- Bulk scraping of the service beyond ordinary use of your own content.
The common thread is consent and ownership. Do what you like to your own equipment; leave everyone else's alone unless they have asked you to look.
Sites published through Intracia run on Cloudflare's network and must also satisfy Cloudflare's own terms. A breach of this section can see hosting restricted or withdrawn upstream, independently of anything we decide about your account — see section 4.
4. The services you connect, and their rules
Connecting a Git provider, a storage bucket or a deployment target hands us access to something of yours. You're responsible for making sure you're entitled to connect it: that the repository is yours or your client's, that whoever owns it agreed, and that you were permitted to use the credential you supplied.
Use the narrowest credential that works. If you give us a token with more reach than the integration needs, that scope is what is exposed if anything goes wrong — on your side or ours.
Their policies apply too
Intracia doesn't store your content in a vacuum. It sits in a repository, a bucket, or a hosting account belonging to you and provided by someone else — and that provider's acceptable-use terms apply to it just as ours do. We can't waive them on your behalf, and content perfectly acceptable under this policy can still be removed by the company whose disk it's on.
The ones our customers meet most often:
- Cloudflare — hosting, and R2 storage
- GitHub — repositories, and the Intracia GitHub App
- Amazon Web Services — S3
- Microsoft Azure — Azure storage and hosting
- Other providers — S3-compatible storage such as MinIO, Backblaze B2, DigitalOcean Spaces or Wasabi, each under its own terms
That list is illustrative rather than complete: whatever you connect, its terms come with it. Read them before you build something that depends on a provider tolerating it. A breach upstream takes your site down on their timetable rather than ours, and there's little we can do about it from here.
5. The AI features
We offer a few AI-assistive features inside the product — help generating a schema for a template, and alt text for image accessibility. They are triggered on demand by the person using them and are entirely optional: nothing reaches a model unless you ask it to. What each feature sends, and to whom, is set out in the privacy policy.
That leaves 2 rules:
- Don't submit anything you don't have the right to send. Other people's confidential material, personal data that has no business being there, credentials, or content you're contractually barred from disclosing to a third party.
- Don't use them to generate content prohibited by this policy, and don't attempt to manipulate the models into producing it.
Suggestions from a model are a starting point, not a fact. What you publish is yours, and you're responsible for it whether you wrote it or accepted it.
6. The people you invite
An invitation is a grant of access to a site, its content and its history. Inviting someone makes you responsible for what they do with it, and for removing them when they no longer need it.
Be particularly deliberate with organisations. As the privacy policy explains, organisation membership reaches every site in that organisation, and an organisation administrator holds administrator rights across all of them. That's the feature working as designed, but it means an invitation can grant far more than the person issuing it intended.
7. Draft preview links
A preview link contains a token, and anyone holding that link can see the draft — no account, no sign-in, no membership required. That's what makes previews useful for showing work to a client who doesn't use the CMS, and it's also the whole of their security.
Treat a preview link as you would a password. Send it to the people who need it, keep it off anywhere public or indexable, and assume anyone you forward it to can forward it again.
8. What we do about a violation
Proportionately, and in most cases with a conversation first.
- Ordinarily, we tell you what we have found, and give you a reasonable period to fix it. Most violations are misunderstandings, an inherited site, or something a colleague did, and someone deleting a page settles them.
- Where content or conduct is actively causing harm — phishing, malware, an attack on the service, or anything that puts the hosting underneath other customers at risk — we remove or suspend first and discuss afterwards. We'll still tell you what we did and why.
- Child sexual abuse material — we remove it immediately, report it to the relevant authorities, and terminate the account, without warning.
- Repeated violations, or a refusal to put something right — we terminate the account.
We'll explain our reasoning in every case except child sexual abuse material. If you think we have made a mistake, reply and say so — a human reads it, and we have been wrong before. Where we suspend rather than terminate, your content stays put while the matter is resolved.
9. Reporting a violation
If you have found something on a site published through Intracia that breaks this policy, tell us at abuse@intracia.com.
Include the URL and enough detail for us to find what you're describing. You don't need an account to report something, and you don't need to be the injured party. We'll acknowledge your report and look into it with an urgency that matches what you have described.
If you're reporting a security vulnerability rather than content, we want to hear about it. Report it to the same address. Test only against your own sites and accounts, don't access or alter anyone else's data, give us a reasonable chance to fix the problem before publishing, and we won't pursue you for having looked. Testing that damages the service or exposes other people's data isn't research, and this paragraph doesn't cover it.
10. Copyright and takedown
If material published through Intracia infringes your copyright, tell us and we'll act on it. This is one process rather than 3: it's built to satisfy what the United States, the EU and the UK each expect, so you don't have to work out which applies to us.
Sending a notice
Email abuse@intracia.com with:
- the work you say has been infringed, and where it can be seen;
- the location of the material you want removed, precisely enough for us to find it;
- your name, postal address and email address;
- a statement that you believe in good faith the use isn't authorised by the rights holder, its agent, or the law;
- a statement that the information in your notice is accurate and — made under penalty of perjury — that you're the rights holder or authorised to act on their behalf.
The last 2 are what United States law requires of a valid notice. We ask everyone for them because one process is easier to run honestly than 3, and because a notice missing them may leave us unable to act as quickly as you would like.
What we do with it
We remove or disable access to the material, and we tell the account holder what went, why, and who said so, with a copy of your notice. We don't decide who owns what — that's a question for the parties and, if it comes to it, a court. We act on properly made notices; we don't adjudicate the claim behind them.
If you think we got it wrong
An account holder whose material has been removed can send us a counter-notice, at the same address. It should identify what was removed and where it was, give their name, address and email, and state under penalty of perjury that the removal was a mistake or a misidentification.
We'll pass it to whoever complained. Unless they tell us within 10 business days that they have begun legal proceedings, we restore the material. Mistaken and bad-faith takedown notices are common enough that a route back matters as much as the route in.
Repeat infringement
We terminate accounts that repeatedly infringe other people's copyright. That's a standing policy, not a discretion we exercise case by case.
What we can't do
This is unusual, and it matters to a complainant: removing something from Intracia doesn't always remove it from the internet. In the usual arrangement the Markdown lives in the account holder's own Git repository and the published site runs on their own hosting. We can delete our copy, revoke preview links, and suspend or terminate the account — and we'll — but that repository and that live site are theirs, held with providers who aren't us.
If you need content gone everywhere, send your notice to the Git provider and the host as well. Their addresses are in section 4.
There's an exception: for customers whose sites we built and whose infrastructure we run, the repository and the storage may sit in our accounts. Where that's so, a notice to us does reach them, and we act on it directly.
11. Changes to this policy
We'll revise this policy as the product and its obligations change, and update the date at the top. The privacy policy's approach to changes applies here too: if we hold an email address for you we'll tell you about anything material, and if we don't, the date above is how you check.