Acceptable Use Policy
Last updated: 28 August 2026
This policy sets out what you may and may not do with Token Curb. It forms part of our Terms of Service and applies to everyone who uses the service.
1. Authorization
You may only connect provider accounts and credentials that you own or are authorized by their owner to connect. You may only invite people to a workspace who are entitled to see that organization's spending data.
2. Prohibited activities
You must not:
- Access, or attempt to access, another customer's workspace, data, or credentials
- Probe, scan, or test the vulnerability of the service, or breach or circumvent any authentication, authorization, or rate-limiting measure, except under a security testing arrangement agreed with us in writing
- Use the service to store or transmit malware, or to conduct phishing, fraud, or other unlawful activity
- Interfere with or disrupt the integrity or performance of the service, including by overwhelming it with automated requests
- Reverse engineer, decompile, or attempt to derive the source code of the service, except to the extent this restriction is prohibited by law
- Resell, sublicense, or provide the service to third parties as a service bureau, unless expressly permitted in a written agreement with us
- Remove, obscure, or alter proprietary notices, or misrepresent your affiliation with Token Curb
- Use the service in violation of applicable law, export controls, or sanctions, or in breach of your agreement with an AI provider
3. Security expectations for customers
You are expected to:
- Supply reporting-scope credentials only — never a credential with broader permissions than the service requires
- Remove workspace members promptly when they leave your organization or change roles
- Rotate provider credentials in line with your own security policy, and revoke them immediately if you suspect compromise
- Report any suspected vulnerability or security incident affecting Token Curb to hello@tokencurb.com without unreasonable delay
4. Responsible disclosure
If you believe you have found a security vulnerability in Token Curb, please report it to hello@tokencurb.com with enough detail for us to reproduce it. Please give us a reasonable opportunity to investigate and remediate before disclosing publicly. We will not pursue action against researchers who act in good faith, avoid privacy violations and service disruption, and do not access or modify data beyond what is necessary to demonstrate the issue.
5. Enforcement
If we believe this policy has been breached, we may investigate and take action proportionate to the circumstances, including warning you, restricting features, suspending access, or terminating the account. Where a breach threatens the security of the service or other customers, we may act immediately and notify you afterwards. We will cooperate with law enforcement where legally required.
6. Reporting misuse
To report suspected misuse of Token Curb, contact hello@tokencurb.com.
7. Changes
We may update this policy as the service evolves. The date at the top reflects the current version.