Acceptable Use Policy

Acceptable Use Policy

This document is short and direct: what's allowed, what's never allowed under any circumstances, what happens if you break the rules, and where to file a complaint. The policy applies from your very first connection β€” including the free trial β€” and is part of the terms of use.

If a translated version of this document disagrees with the English original, the English version prevails.

Revision 2.0 Effective from August 5, 2026 Complaints: [email protected]

01Scope

TunnelOps sells access to residential, static ISP, and datacenter proxies. Technically, this means the customer's requests reach the internet from addresses that do not belong to the customer, and that in the logs of other systems these requests look like ordinary home or business traffic.

That's the whole point of this document. A tool that hides the origin of a request is just as useful for legitimate work as it is for the kind of thing that gets accounts shut down. Below we set out where the line falls, because it is cheaper for both the customer and us to agree on that before connecting than to argue about it after a complaint.

The policy applies to the account as a whole: to all of its proxy credentials, to all traffic that passed through them, and to the free trial on the same footing as paid access. Responsibility for the actions of contractors, employees, and any third parties given the credentials rests with the account owner. Sharing credentials is not prohibited β€” reselling access under your own name without a separate agreement is prohibited (see also the terms of use).

What we record about connections, on what legal basis, and for how long we keep it is set out in the privacy policy. This document is about behavior, not data.

02Permitted Use

These are the tasks the platform is built for and that its limits are designed around. The list is not exhaustive: if a task is similar in spirit to what's listed and doesn't fall under section 03, it is allowed.

Allowed

  • Collecting public data. Pages accessible without authorization: prices, catalogs, job listings, classified ads, public registries.
  • Availability testing. Checking your own systems: availability, geo-dependent behavior, localization, CDN performance, and how applications behave from different addresses and countries.
  • Price and search-result monitoring. Website availability, content changes, uptime, detection of spoofed search results, and checking partner and affiliate links.
  • Market research. Analyzing competitors' market, product range, and prices from public data, collecting reviews, and studying demand.
  • Ad verification. Ad verification: how your own ads are displayed in different geographies, on which placements, whether they've been swapped out, and whether they appear next to inappropriate content.
  • Testing anti-fraud and security mechanisms β€” your own, or under the written authorization of their owner.

Requires Attention

  • Load on the target resource. Collecting public data is allowed; the volume of requests that brings down someone else's site falls under section 03. Rule of thumb: no more than the site you're pulling data from can handle.
  • robots.txt and the target site's terms. We do not check these on the customer's behalf and do not block based on them, but violating another service's terms is a dispute between the customer and that service, and we are not a party to it.
  • Personal data. Technically public and lawfully processable without restriction are not the same thing. Establishing a legal basis for processing any personal data collected is the customer's responsibility.
  • Automating actions in third-party accounts. Permitted only for accounts the customer is entitled to control.

03Strictly Prohibited

"Strictly" here means literally that: none of the items below can be negotiated, approved for a specific purpose, or discussed with support. Each of them is grounds for immediate disconnection under section 04.

  • Spam and any form of bulk messaging. Email, messengers, SMS, comments, contact forms, private messages on social networks, calls β€” regardless of content, consent, or the source of the addresses. Mass or automated sending of messages through our addresses is prohibited entirely, not merely "within reasonable volume": an address that a bulk mailing goes out from lands on blocklists and stops working for every other customer.
  • Attacks on infrastructure. DoS and DDoS in any form, flooding, amplification, sending traffic with a spoofed source, scanning the ports and networks of third-party systems, exploiting vulnerabilities, and attempts to bypass security controls.
  • Password and credential guessing. Brute force, credential stuffing, dictionary attacks, checking leaked login and password databases, bypassing two-factor authentication, automated account registration using other people's data, and receiving or reselling SMS verification codes.
  • Fraud. Phishing and hosting phishing pages, theft of payment data, transactions with stolen cards and accounts, inflating ad impressions and clicks, defrauding affiliate programs, and financial schemes built on deception.
  • Torrent and P2P file sharing. BitTorrent and any file-sharing protocols, including clients that run through a proxy. This is a separate item not because of the content of the traffic: persistent outbound connections to thousands of peers generate complaints to the provider whose address is being used, and the address is lost for everyone.
  • Distributing malware. Delivering and downloading viruses, trojans, ransomware, and exploits, operating botnets, hosting command-and-control servers, and using our addresses as a relay for infected machines.
  • Child sexual abuse material. Any access, any transfer, any storage, any distribution. No exceptions, no research exemption, no warning before disconnection. Such reports are forwarded to law enforcement together with all the metadata we hold.
  • Illegal trade. Narcotics, weapons, forged documents, stolen data, and access to compromised systems.
  • Infringement of intellectual property rights. Distributing copyrighted content without the rights to do so.
  • Any activity that violates the law of the exit country or the customer's country. Traffic exits from an address in a specific country, and that country's law applies there β€” even if the same act is legal in the customer's country. The reverse is also true: legality in the exit country does not excuse breaking the law where the customer is located. Both must be observed, including laws on circumventing blocks imposed in the country where the customer is located.

04Consequences of Violation

Violating section 03 means immediate suspension of access with no refund. With no advance warning and no grace period to fix it. The wording is deliberately blunt: an address that a bulk mailing or an attack goes out from lands on blocklists and stops working for every customer sharing that pool β€” so the response here is fast, not proportionate.

Suspension means: proxy credentials are deactivated, active connections are terminated, and any unused account balance is neither refunded nor carried over β€” see also "no refund for violations" in the refund policy. If the violation affected our relationship with the exit-address provider, we reserve the right to seek reimbursement for the costs incurred.

If the Violation Is Not Covered by Section 03

Everything else β€” excessive load on a target resource, behavior that triggered a complaint without a clear-cut violation, exceeding technical limits β€” is discussed first. We write to the account's contact address, describe the problem, and give a reasonable period to fix it; if there's no response, access is suspended until we hear back. Unlike disconnection, suspension is reversible, and the balance is preserved during it.

Right to Suspend Access Immediately

We may suspend access without warning if this is required by an order from an authorized government body, if continued operation poses an immediate threat to our infrastructure or to the infrastructure of third parties, or if the account is clearly compromised. We notify you of the suspension within one business day and explain the reason, unless the law prohibits it.

05Abuse Complaint Process

Complaints are accepted at [email protected]. This is the only address for this kind of report; messages sent to it are read by a person, not an autoresponder. The same address is listed on the contacts page.

What a Report Should Include

  • the IP address in question;
  • the date and time of the incident, with the time zone specified β€” without this it is impossible to match the report to a specific connection, since dozens of users can share one address in a single day;
  • what happened: logs, email headers, request records β€” in any format;
  • a return address for our reply.

Response Times

  • Acknowledgment of receipt β€” within 24 hours. Automatic, with a ticket number.
  • Substantive reply β€” within 3 business days. What we found and what we did about it.
  • Child sexual abuse material, active phishing pages, an ongoing attack β€” response within 4 hours on any day of the week, including weekends. Access is blocked until the investigation is concluded, not after it.
  • Requests from authorized government bodies are handled within the statutory deadlines; the process is described in the privacy policy.

Measures We Take

We match the reported time and address against connection metadata (see the privacy policy), identify the account, and assess whether section 03 has been violated. If a violation is confirmed, we apply the measures from section 04: suspension or immediate disconnection, depending on severity. We inform the reporter that measures have been taken; the customer's personal data is not disclosed to the reporter β€” that requires a legal basis, not a complaint.

We notify the customer of any complaint received and of the decision taken, except when notification is prohibited by law or would directly interfere with the investigation. If a decision seems mistaken, replying to the disconnection notice counts as an appeal; we reconsider the decision when new circumstances come to light.

We do not act on false or bad-faith reports β€” for example, attempts to get a competitor blocked.

Changes to this document made in response to a legal requirement or an order from an authorized government body take effect immediately, unlike the general amendment process described in the terms of use.