Skip to content
CastPDF
Legal

Acceptable Use Policy

What you may not do with CastPDF, how to report abuse, and how we enforce this policy.

Last updated

Contents

Scope

This policy applies to everyone who uses CastPDF, to every template and piece of data sent to the Service, and to every document it generates. It is part of the Terms of Service. You are responsible for the use of your account and API keys, including use by your own customers through your product.

Content you may not create or process

  • Anything illegal where you or the recipients of the document are, including content that infringes someone else's copyright, trademarks or other rights.
  • Child sexual abuse material, of any kind. We report it to the authorities.
  • Phishing, fraud and impersonation: documents that pretend to come from a person, company or authority that did not issue them, such as fake invoices, bank statements, identity documents, certificates or official letters, or anything meant to trick people into paying or handing over credentials.
  • Malware: documents or templates that carry, link to or deliver malicious code or exploits.
  • Spam: documents generated for unsolicited bulk messages.
  • Content that harasses, threatens or incites violence or hatred against people.

Things you may not do

  • Get around limits: create several accounts, rotate keys or accounts, or use test keys for production work to avoid plan quotas, rate limits, the spending cap, or the test watermark.
  • Probe or attack the renderer: try to make the rendering service reach private, internal or local network addresses, cloud metadata endpoints or our own infrastructure; test or evade its network restrictions; use it to scan networks or ports, or to send traffic to third parties that have not agreed to it.
  • Attack the Service: overload it, try to gain access to other customers' data or to our systems, or run security tests against it without our written permission.
  • Resell raw rendering capacity without a written agreement with us: offering a service whose main purpose is to give others direct access to CastPDF rendering, such as a general PDF-generation API built on your CastPDF account. Generating documents for your own customers as part of your own product is fine.
  • Share access: publish your API keys or let others use your account outside your organisation.
  • Scrape or fetch content you have no right to use through the renderer.

Security research

If you find a vulnerability, please tell us at [email protected] before telling anyone else, and give us reasonable time to fix it. Do not access, change or delete data that is not yours, and stop as soon as you have shown the problem. We will not take action against good-faith research that follows these rules.

Reporting abuse

To report a document or an account that breaks this policy, email [email protected]. Include the document's download link or id if you have it, and why you think it breaks this policy. We look at every report.

Enforcement

When we find or are told about a breach, we may, depending on how serious it is:

  • ask you to stop or to change how you use the Service;
  • remove content, revoke API keys or block specific requests;
  • suspend or close the account, under the Terms of Service;
  • report illegal content or activity to the competent authorities, and preserve the evidence they need.

We usually contact you first and give you a chance to fix the problem. We act at once, without notice, when the breach is serious, when it harms others or the Service, or when the law requires it. Closing an account for a breach of this policy does not by itself entitle you to a refund.

Changes

We may update this policy; the "Last updated" date above shows the latest version.