Legal

Acceptable Use Policy

Effective Date: July 21, 2026 Last Updated: July 28, 2026

This policy covers what you may build, host, publish, and distribute using Peko. It applies to every part of the platform, including hosted servers, app-store distribution, the packages registry, the build runners, and the CLI.

1. Scope

This policy applies to you, to anyone you allow to use your account, and to the applications and packages you deploy or publish. It forms part of the Terms of Service. Where this policy and the Terms differ, the stricter rule applies.

You are responsible for content your application serves to its own users, even when that content is generated by those users rather than by you.

2. Content You May Not Host or Distribute

You may not use Peko to build, host, publish, or distribute:

  • Child sexual abuse material, or any content that sexualises minors. We report this to the relevant authorities and terminate the account immediately, without notice.
  • Malware, spyware, ransomware, keyloggers, credential harvesters, or applications whose purpose is to gain unauthorised access to a device or account.
  • Phishing pages, fraudulent storefronts, fake login screens, or anything designed to impersonate another person, company, or service.
  • Content that infringes copyright, trademark, patent, or trade secret rights you do not hold.
  • Content that is unlawful where it is distributed, or that you are not permitted to distribute under the rules of the app store you are targeting.
  • Material that promotes violence against, or harassment of, a person or group.

3. Platform and Resource Abuse

The hosting layer, the device farm, and the build runners exist to build and run your own applications. You may not:

  • Run cryptocurrency mining, distributed computing for hire, or any workload whose primary purpose is to consume compute rather than serve your application.
  • Use hosted servers as an open proxy, VPN exit, anonymiser, or general-purpose file host for content unrelated to your application.
  • Resell, sublicense, or share Peko compute, storage, egress, or credits with third parties as a service of your own.
  • Deliberately exhaust credits, storage, or egress, or attempt to obtain compute without the corresponding credit charge.
  • Submit build or screenshot jobs for software you do not have the right to build and run.
  • Attempt to persist data, processes, or credentials on a build runner or device-farm machine beyond the life of your own job.

4. Security

You may not attempt to access another tenant's data, applications, build artifacts, signing material, or credentials. You may not probe, scan, or attempt to breach the platform's authentication, authorisation, isolation, or billing controls, except as permitted in the paragraph below.

We welcome good-faith security research. If you find a vulnerability, report it to [email protected] before disclosing it publicly, and give us a reasonable opportunity to fix it. Do not test against accounts, applications, or data that are not yours, and do not exfiltrate more data than is needed to demonstrate the issue. Research conducted on those terms will not be treated as a violation of this policy.

5. Packages Registry

Packages published to the registry are public. In addition to the rules above, you may not publish packages that impersonate another package or author, that squat a name you have no connection to, that deliberately mislead about what the package does, or that execute unrelated code at install or build time.

Every version is reviewed before it becomes public. Review is not a security audit, and passing review does not mean a package is safe or endorsed.

6. Signing Material and Store Credentials

When you use remote builds, signing material you supply is encrypted to the build runner's public key and can only be decrypted on that machine. You may only supply signing material and store credentials that belong to you or that you are authorised to use, and you remain bound by the developer program rules of Apple, Google, and Microsoft when distributing through their stores.

7. Enforcement

Where we believe this policy has been broken, we may remove or disable the offending content, suspend or pause an application, suspend or terminate the account, or refuse future service. We will give notice and an opportunity to correct the problem where it is safe and lawful to do so. We may act without notice where there is an immediate risk of harm, legal exposure, or damage to the platform.

Credits consumed before a suspension are not refunded. Credits remaining on an account terminated for a violation of this policy are forfeit.

8. Reporting a Violation

Report abuse, infringing packages, or anything else covered by this policy to [email protected]. Include the application, package name, or URL, and enough detail for us to find the problem.

9. Changes

We may update this policy as the platform changes. When we make a material change we will ask you to accept the updated agreements the next time you sign in. Continuing to use Peko after that point means you accept the current version.