1.What this policy covers
The policy applies to everything you obtain from us: domains registered and renewed through the service, VPS you rent and any services you run on them, as well as your account dashboard and your support requests.
It covers both what you host and what you do from our resources toward other networks and other users.
Alongside this policy, you must comply with the law of the operator's country of registration and, for domains, with the rules of ICANN and of the registry for the relevant zone.
This policy sits alongside the Terms of Service at /terms. How we handle your data is described in the Privacy Policy at /privacy.
2.Spam and bulk messaging
You may not send email or messages to people who never signed up for them. The recipient's consent must be genuine and verifiable, not assumed.
You may not use our servers and domains as a mailing tool: forging the sender address, hiding the origin of a message, relaying through other people's vulnerable mail services, or using purchased address lists.
Bulk messaging in messengers, comment sections, contact forms, and on third-party websites is likewise prohibited when it is done automatically and without the platform's consent.
3.Phishing and brand impersonation
You may not create pages that pose as someone else's website, a bank, a payment service, a government agency, or any other organization in order to obtain other people's passwords, verification codes, card details, or documents.
You may not use another company's logos, names, or visual design in a way that leads visitors to believe they are dealing with that company.
We treat phishing as a severe violation: such material is taken offline without prior warning.
4.Malware and botnets
You may not host or distribute malicious software: viruses, ransomware, trojans, hidden miners, password stealers, or programs used to monitor people without their knowledge.
You may not use our servers as a command-and-control center for infected devices, as a botnet node, as a collection point for stolen data, or as a relay for transmitting it.
It makes no difference whether you wrote the program yourself or are merely storing it with us: hosting it and distributing it are prohibited either way.
5.Attacks, scanning, and intrusion
Denial-of-service attacks are prohibited, whether launched directly, routed through intermediaries, or amplified through other people's vulnerable services. Ordering such attacks from third parties using our resources is also prohibited.
You may not scan other networks and ports, brute-force passwords, probe for vulnerabilities, or otherwise attempt to gain access to systems that do not belong to you and that you have no owner's permission to test.
You may not circumvent other parties' access controls, intercept their traffic, or tamper with routing.
6.Copyright and prohibited goods
You may not host or distribute films, music, books, software, courses, or other material to which you do not hold the rights and for which you have no permission from the rights holder.
You may not use our resources to trade in goods and services whose circulation is prohibited: drugs, weapons, forged documents, stolen databases, other people's accounts, or payment credentials.
We handle complaints from rights holders through the same process described below.
7.Child exploitation material
Child sexual exploitation material is absolutely prohibited. There are no exceptions, no qualifications, no warnings, and no opportunity to remedy.
If such material is discovered, access is terminated immediately, services are stopped, no funds are refunded, and information is disclosed where the law of the operator's country of registration requires it.
8.Fraud and deception of users
Schemes built on deception are prohibited: fake stores with no goods, sham giveaways and payouts, pyramid schemes, extortion, and the sale of services that do not exist.
You may not mislead visitors by technical means: hidden redirects, page content substitution, intrusive windows that make it hard to leave a page, or false warnings that a device is infected.
You may not deceive the service itself: creating accounts to get around restrictions, concealing the true purpose for which a service is used, or using someone else's payment instruments to top up an account balance.
9.Special rules for domains
You may not register domains in order to hijack someone else's brand: to resell a domain to the trademark owner, to divert their traffic, or to pass your site off as theirs. Disputes of this kind are decided under the UDRP and URS procedures. Any decision is carried out by our partner registrar, and we cannot override or work around it.
Registrant contact details must be genuine and current: they are passed to the registrar and to the zone registry. Knowingly false WHOIS data is a violation of ICANN and registry rules in its own right. The registrant's email address must be confirmed through the link we send; the link is valid for a limited time, and without confirmation the domain may be suspended under the rules of the zone.
A domain may not be used as cover for deception: disguising it as someone else's address, pointing it at phishing pages, sending spam in its name, or listing it as a contact in a fraudulent scheme.
Keep in mind that a domain registration is non-refundable once our partner registrar has processed it. Blocking a domain for a violation does not refund what you paid.
10.Fair use of resources
You rent VPS resources on the infrastructure provider's equipment, which other customers use as well. A load that interferes with other customers or with the provider's network is not acceptable.
Do not use your server as a source of constant outbound traffic to other networks without genuine need: mass connections, brute-force attempts, or continuous requests to third-party sites and services.
If the load from your server creates a problem for the network, we may throttle or shut down the server to protect our other customers, and we will tell you at the email address on your account.
There are no backups by default, and safeguarding your own data is your responsibility. If we terminate a service for a violation, the server is deleted along with everything on it.
11.Keeping your credentials safe
Your dashboard password and your server's root password are your responsibility. We store server credentials in encrypted form and show them to you in the dashboard, and we also send them to the email address on your account; from there, keeping them safe is up to you.
Do not hand credentials to outsiders or publish them in public repositories and chats, change the root password on your server, and revoke access from anyone who no longer needs it.
A service used to commit a violation counts as yours, whoever actually used it. A weak or leaked password is not a mitigating circumstance but a cause to eliminate.
12.How to report abuse
Send abuse complaints to [email protected]. We accept reports from anyone, not only from customers of the service.
So that a complaint can be verified, include: the exact URL, domain, or IP address the complaint concerns; a description of the violation; evidence — screenshots, email headers, log excerpts; the date and time of the event with the time zone; and your contact details for follow-up.
The more specific the report, the faster we can act on it. A complaint with no resource address and no supporting evidence cannot be verified.
We may decline to respond to repeat reports about a case we have already decided, and to knowingly false or mass reports sent to disrupt another customer or our support team.
13.How we handle complaints
We review the substance of a report and, if the violation is not clear-cut, we ask the customer to explain and allow a reasonable period to fix it — usually a few business days, depending on what needs fixing.
If a violation is obvious and ongoing — phishing, malware, or an active attack, for example — we may restrict the service immediately and investigate afterwards.
We aim to review reports within a reasonable time, usually a few business days; urgent cases are handled faster.
We tell the customer our decision at the email address on their account. We may confirm to the reporting party that the report has been reviewed, but we do not disclose customer data on our own initiative.
14.Measures we may take
Depending on the severity of the violation, we may: request an explanation, require the violation to be fixed within a deadline, temporarily suspend the service, block the domain, shut down or delete the server, or terminate service entirely.
For a severe violation — such as child exploitation material, phishing, malware, a botnet, or an attack on other networks — service is terminated with no refund.
We pass information about a violation, and data connected with it, to third parties only where the law of the operator's country of registration requires it, and to our partners — the registrar and the infrastructure provider — to the extent they need it to enforce their own rules. Data sharing in the ordinary course of running the service (payments, analytics, email delivery, DNS) is described in the Privacy Policy at /privacy.
We try to keep the measure proportionate: if a violation can be fixed, we will give you the chance to fix it.
15.What happens to the service and your money during a restriction
A restriction or suspension for a violation does not pause the life cycle of the service. The paid period keeps running while we look into the case.
For a VPS the sequence is this: when the paid period ends, the service tries to renew it automatically by charging your balance. If the balance is short, a grace period of about twenty-four hours begins and the server keeps running. After that the server is shut down, and about six days after the shutdown it is deleted together with its data, which cannot be recovered.
Automatic renewal can be switched off in the dashboard. If it is on and there is money on your balance, charges continue during a suspension as well. There are no backups by default, so do not count on your data waiting until a dispute ends — take copies in advance.
If we terminate service for a severe violation, money paid for the current period is not refunded, and a domain registration is non-refundable in any case. Billing, renewals, and refunds are described in the Terms of Service at /terms.
16.Responsibility for your own users
You are responsible for everything that happens under your account and on your services, whether you did it yourself or someone else did.
If you give other people access to your server, host other people's websites, sublease resources, or run a service with users of your own, this policy applies to them as well — and you are the one answerable to us.
If your services are used without your knowledge — for example, your server is compromised or your credentials leak — tell us as soon as possible and eliminate the cause. That does not relieve you of responsibility, but it helps stop the harm quickly.
17.The role of our partners
Domains are registered through an accredited partner registrar, and servers run on an infrastructure provider's equipment. We stand between you and them.
Those partners have rules of their own, and they can suspend a domain or a server on their own initiative, regardless of what we decide. We cannot always reverse such a decision, but we will try to explain the reason and help you address it.
Following our rules alone is therefore not enough: domains are also governed by ICANN and zone registry rules, and servers by the infrastructure provider's rules.
18.How to appeal a decision
If you believe a suspension or block was a mistake, write to [email protected]. Describe which service is affected and how things looked from your side, and attach supporting evidence.
We will review your appeal, usually within a few business days, and if there was no violation or it has been fixed, we will restore the service where that is technically possible. A deleted server and the data on it cannot be restored.
There is no appeal for absolute prohibitions: decisions concerning child sexual exploitation material are not reconsidered.
19.Changes to this policy
We may change this policy: new forms of abuse appear, and the requirements of the registrar, the zone registries, and the infrastructure provider change over time.
The current version is always published on this page. By continuing to use the services after a change, you accept the new version.
Questions about this policy go to [email protected]; abuse reports go to [email protected].
20.Language and version of this document
The Russian version of this document is the original and the English one is a translation. If the two differ, the Russian version governs the meaning.
This page carries the current version of the policy, and the date it was last updated is shown here as well. The Terms of Service are published at /terms and the Privacy Policy at /privacy.