Acceptable Use Policy
Version 1.7 · Effective date: 12 September 2026 · Governing law: Scotland
Purpose
This Acceptable Use Policy ("AUP") protects customers, testers, third parties and the Service. It forms part of the AppGantry Terms of Service.
1 Scope and responsibility
This AUP applies to every Account, Customer Content, Build, recipient, API request and use of mobile service offerings. Customer must ensure its users, contractors and anyone using its credentials comply. Defined terms have the meanings in the Terms of Service.
2 Prohibited content and conduct
You must not use the Service to:
- upload, distribute or facilitate malware, spyware, ransomware, destructive code, credential theft, covert surveillance or code intended to damage or unlawfully control systems;
- create, store or distribute content or Builds that are illegal, fraudulent, deceptive, defamatory, infringing, or that violate intellectual property, confidentiality, privacy or data-protection rights;
- distribute a Build to a person without appropriate authority, notice or consent, or misuse device identifiers and provisioning data;
- distribute a Build to the general public, or publish, post, index or otherwise make a distribution or install link openly available on a website, social network, forum, link aggregator, search engine or other publicly accessible location, instead of sharing it with an identified and limited group of testers chosen by Customer;
- use the Service in breach of an applicable developer, device or application-platform programme, including the Apple Developer Program License Agreement, the Apple Developer Enterprise Program terms and the Google Play Developer terms, or use a distribution method for general release where the platform reserves general release to its own store or beta channels;
- abuse, threaten, harass, exploit or discriminate against a person, or facilitate sexual exploitation or content that unlawfully endangers children;
- gain or attempt unauthorised access to an account, tenant, device, network, API, administrative surface or data;
- probe, scan, test or circumvent security controls except in accordance with the Responsible security research section below, AppGantry's prior written authorisation or another vulnerability-disclosure policy we publish;
- share, sell, expose or misuse passwords, session cookies, recovery codes, API keys, tokens or other credentials;
- send spam, unsolicited bulk messages, phishing, deceptive invitations or distribution notices, or falsify origin or identity;
- disrupt, overload, degrade or interfere with the Service or another system, including denial-of-service activity;
- evade metering, fees, quotas, rate limits, storage limits, access controls, suspension or other technical restrictions;
- scrape, crawl, copy, benchmark, reverse engineer or derive source or underlying ideas except to the limited extent applicable law does not permit that restriction;
- breach sanctions, trade controls, export controls or laws applying to the user, Customer, recipient, Build or destination; or
- use the Service as a control, warning or failure-critical component in medical, transport, nuclear, emergency, weapons or other high-risk systems where failure could cause death, injury or major property or environmental harm.
3 Responsible security research
This section is AppGantry's published vulnerability-disclosure policy and authorises good-faith security research that follows these rules. Researchers must also follow any additional scope or method requirements in written authorisation from AppGantry. Researchers must avoid privacy violations, disruption, persistence, data destruction, social engineering and access beyond what is necessary to demonstrate a finding.
Researchers must report findings confidentially and coordinate disclosure with us. A finding may be disclosed when it is resolved or on the applicable disclosure date. The default disclosure date is 90 days after the initial report is sent to security@appgantry.com. The researcher and AppGantry may agree a different date. If they discuss a different date but do not reach agreement, the date selected by AppGantry applies. AppGantry may subsequently change the disclosure date as required for any reason and will inform the reporter of the change.
4 Fair use of resources
Use must remain within the Plan, Order, documented limits and ordinary purpose of distributing mobile application Builds. You must not split organisations, automate account creation or use other methods to avoid limits or charges. If use threatens reliability or creates materially unusual load, we may require reasonable mitigation, apply documented limits, restrict the affected function or propose an appropriate Plan.
5 Reporting
Report suspected abuse, compromised credentials or security issues promptly to security@appgantry.com. Include enough information for us to identify the relevant organisation, Build or event. Do not include unnecessary sensitive data.
6 Enforcement and emergency action
We may investigate suspected breaches and preserve relevant records. We may remove or restrict content, rate-limit activity, revoke credentials, quarantine a Build, suspend access or terminate service as reasonably necessary. We will consider context, severity, recurrence, intent, risk and the possibility of remedy.
Where practical, we will notify Customer and allow a reasonable opportunity to correct a breach. We may act immediately where needed to address malware, unlawful activity, active compromise, danger to a person or system, legal requirements, or material risk to the Service or others. We may cooperate with lawful requests from authorities and notify affected parties where permitted.
7 Changes and contact
We may update this AUP prospectively. Material changes will be identified by version and effective date and notified by email or in the Service on reasonable notice. Questions and general enquiries should be sent to contact@appgantry.com. Security and abuse reports should be sent to security@appgantry.com.
Questions about this document? support@appgantry.com.