1. General rule
Use yellowhost only for lawful applications that do not harm other users, third parties, Discord, our providers or our infrastructure. You are responsible for your workload, including activity performed by dependencies or code you upload.
2. Discord platform abuse
You may not use yellowhost for Discord self-bots or automated normal-user accounts; unsolicited mass messaging; mass mentions; token theft; credential collection; account farming; raid tooling; ban or moderation evasion; fake engagement; scraping that violates applicable platform rules; or any other activity that violates Discord's applicable terms or developer policies.
3. Malware, credentials and exploitation
You may not host, distribute or operate malware, ransomware, spyware, credential stealers, phishing pages or infrastructure, botnets, cryptominers, exploit kits intended for unauthorized compromise, password/credential stuffing, or code intended to gain unauthorized access to systems or accounts.
Good-faith security tooling must not target systems you do not own or have explicit permission to test.
4. Network and infrastructure abuse
You may not use yellowhost for denial-of-service attacks; traffic amplification; port or vulnerability scanning of third-party networks without authorization; open proxies, VPN exit nodes or traffic relays; spam delivery; attempts to access the Docker socket, worker management API, host system, metadata endpoints, private infrastructure or other users' workloads; or attempts to evade network restrictions.
5. Illegal, infringing or harmful activity
You may not use the service to facilitate activity that is illegal where it is hosted or where you operate it, including fraud, theft, threats, unlawful harassment, sexual exploitation or abuse material, trafficking, or unlawful sale/distribution of regulated goods. You may not knowingly host content that infringes intellectual-property rights when you do not have a lawful basis to use it.
6. Resource and service abuse
You may not bypass CPU, memory, storage, process, build, upload or bot-slot limits; create multiple accounts to evade limits or enforcement; deliberately create crash/restart loops at scale; consume resources primarily to degrade service for others; or use free beta capacity for unrelated general-purpose compute when the workload is not reasonably connected to a supported bot/application use case.
7. Secrets and sensitive data
Do not intentionally collect or store passwords, authentication tokens, payment credentials or other highly sensitive data unless your application has a legitimate need, appropriate user notice and suitable security controls. Never log bot tokens or user credentials. Rotate exposed secrets immediately.
8. Enforcement
We may stop, suspend, isolate or remove a workload or account that violates this AUP or presents a material security, legal or stability risk. Urgent threats may be handled immediately without prior notice. We may preserve relevant logs or records when reasonably necessary to investigate abuse, prevent repeat abuse or comply with law.
Where appropriate, we may ask you to correct a problem before restoring service. Repeated or deliberate abuse may result in permanent loss of access.
9. Reporting abuse
Report suspected abuse to support@yellowhost.cc. Include the yellowhost bot/account identifier and enough detail for us to investigate, but do not send passwords or secret tokens.
10. Relationship to the Terms
This AUP is part of the yellowhost Terms of Service. If this AUP and the Terms address the same issue, both apply to the extent they are compatible.