Type to search every page. Results are ordered by how well they match, then by where they sit in the contents, and only the letters you typed are highlighted.

Terms of Service

The agreement between you and VGSpartans: what you may do here, what we may do, and what happens if a rule is broken.

AgreementFor everyone

Welcome to the VGSpartans platform (“Platform”), at vgspartans.org and its subdomains. These Terms of Service (“Terms”) govern your access to and use of the Platform. By using the Platform in any way, whether as a registered user or a public visitor, you agree to these Terms. If you do not agree, please do not use the Platform.

These Terms come in four parts:

If you are a registered user, all four parts apply to you. If you are a visitor, Parts I, II, and IV apply.

These Terms cover the agreement between you and the Platform. What we collect and how we handle it is covered by the Privacy Policy, which is part of this agreement by reference. Where a question is about data rather than conduct, the Privacy Policy is the document that answers it.

Part I: General Terms

These terms apply to everyone who uses the Platform, whether as a visitor or a registered user.

1. Definitions

  • “Platform” means the VGSpartans website and everything at vgspartans.org and its subdomains. That includes the console subdomains (sites, admin, advisor, webmaster, treasurer, secretary, developer, and bounty), the subplatform subdomains (wiki, writes, synergy, agora, news, and gallery), and club subdomains such as keyclub.vgspartans.org.
  • “Subplatform” means a distinct space within the Platform with its own purpose and features, such as personal sites, club sites, the wiki, the writing library, the campus feed, the idea board, the newsroom, and the gallery.
  • “Developer” means the Vista Grande student who builds and runs the Platform.
  • “School” means Vista Grande High School, and “District” means the Casa Grande Union High School District. The Platform serves this community but is not operated or endorsed by either.
  • “Visitor” means anyone who views public pages without signing in.
  • “Registered User” or “User” means anyone who has created an account.
  • “Content” means any text, images, files, code, media, or other material uploaded, published, or submitted through the Platform.
  • “Platform Administrators” means the Developer and anyone the Developer authorizes to help manage the Platform.
  • “Community Guidelines” means the Community Guidelines: the rules that apply everywhere on the Platform, plus a separate document for each subplatform. They form part of these Terms by reference.
  • “Bug Bounty Program” means the invitation-based security testing program described in Section 32.
  • “We,” “our,” “us” mean the Platform and its Developer.
  • “You,” “your” mean the person using the Platform.

2. What the Platform Is

VGSpartans is an independent project built and run by a single Vista Grande High School student for the Vista Grande community. It started with club sites and personal sites for students and teachers, and it has grown into a set of subplatforms under one login, including school-friendly spaces for student writing, reference articles, campus discussion, campus ideas, student journalism, and campus photography and art. It is not a commercial service, shows no advertising, and is not an official service of the School or District.

There is no charge to use the Platform, and the Developer funds it. If cost sharing among participating clubs is ever introduced, it will not apply to individual student, teacher, or staff accounts, and we will give notice in the Platform before it takes effect.

A subplatform may add its own rules covering what you can post there and how you use it. Those rules are published as the Community Guidelines, which carry the rules that apply everywhere on the Platform plus a separate document for each subplatform. They apply in addition to these Terms and the Privacy Policy, not in place of them. Where a subplatform’s own rule is stricter, follow the stricter one.

3. Intellectual Property

3.1 Platform Software

The Platform’s software, design, and documentation belong to the Developer and are protected by copyright and other laws. The source code is public in the repository under the GNU Affero General Public License version 3 (AGPL-3.0), and you may use, modify, and share it under that license. All rights not granted by the AGPL-3.0 are reserved by the Developer. The license covers the source code only. It gives you no right to the Platform’s name or branding, to its data, or to the content its users post.

3.2 Name and Branding

The “VGSpartans” name and branding belong to the project. You may not use them in any way that suggests endorsement by or affiliation with the Platform, the School, or the District without prior written permission.

3.3 Content Posted by Others

Content on the Platform is posted by the people who use it. Except for the pages the Developer writes, we do not create, endorse, or vouch for it, and the person who posted it is responsible for it. Content on public pages, such as club sites and personal sites, is shown for information only. Viewing it does not give you a license to copy, distribute, or build on it unless stated otherwise.

3.4 Feedback and Suggestions

If you send us an idea, a suggestion, a bug report, or other feedback about the Platform, we may use it to build and improve the Platform without restriction and without owing you payment or credit. This does not apply to Content you post through the Platform, which is covered by Section 24, and it does not give us rights to anything else you own.

4. Third-Party Services

The Platform depends on outside services to run:

  • Cloudflare for hosting, network, security, storage, databases, bot checks, email delivery, AI safety checks, and the help assistant on public pages.
  • ZeptoMail (Zoho), Amazon SES, and Resend for email delivery.
  • OpenAI as a backup safety check on content.
  • Have I Been Pwned for screening a password you set against known breached passwords.
  • GitHub for optional archiving of student site content.
  • Bunny.net for streaming and delivery of videos uploaded to the Platform.
  • Instatus for the status page.

Using the Platform means some data is handled by these services under their own terms and privacy policies. Section 3 of the Privacy Policy lists what each one receives and why.

5. Prohibited Conduct: All Users

Whether you are a visitor or a registered user, you may not:

  • Try to gain unauthorized access to any part of the Platform, other accounts, or connected systems or networks.
  • Interfere with or disrupt the Platform, its servers, or connected networks.
  • Use bots, scrapers, or other automated means to access or extract data without prior written permission. Verified search engine crawlers are exempt.
  • Bypass or try to bypass any security measure, rate limit, bot check, device check, or access control.
  • Probe, scan, or test the Platform’s security, except under the Bug Bounty Program and within the scope it sets.
  • Copy, republish, or compile personal information about Platform users from any page, whether by hand or automatically.
  • Use the Platform in any way that breaks the law.

6. Reporting Content, Conduct, and Security Problems

If you see content or behavior on the Platform that breaks these Terms, use the report control on the page it appears on, or the report form at /report. If you have an account, a support ticket reaches us the same way and keeps the conversation in one thread. If a page has no report control, contact the Developer using Section 15. Tell us where the content is and what is wrong with it. We review reports and may remove content, restrict an account, or take no action. We do not tell the person you reported who reported them, and we do not promise a particular outcome. Filing reports you know to be false is itself a breach of these Terms.

Copyright complaints follow Section 25. Security bugs follow Section 32, not this section.

7. Availability, Changes, and Discontinuation

The Platform is a student project, and we do not promise it will be available at any particular time or level. We may add, change, limit, or remove any feature, subplatform, or page at any time, and we may suspend the Platform for maintenance, security, or any other reason. Where a change would remove a feature people rely on, we will give notice in the Platform when we reasonably can. If the Platform is ever discontinued, we will try to give registered users advance notice and a window to retrieve their content, but we cannot guarantee it.

8. Disclaimer of Warranties

THE PLATFORM IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY. THE PLATFORM AND THE DEVELOPER DISCLAIM ALL WARRANTIES, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.

THE PLATFORM DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE, OR THAT ANY CONTENT WILL BE ACCURATE, RELIABLE, OR COMPLETE. YOU USE THE PLATFORM AT YOUR OWN RISK.

Some places do not allow the exclusion of implied warranties, so some or all of the disclaimer above may not apply to you. See Section 31.

9. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE PLATFORM AND THE DEVELOPER WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING LOSS OF DATA, CONTENT, USE, OR PROFITS, ARISING OUT OF OR RELATING TO YOUR USE OF OR INABILITY TO USE THE PLATFORM, UNDER ANY LEGAL THEORY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

THE TOTAL LIABILITY OF THE PLATFORM AND THE DEVELOPER FOR ALL CLAIMS RELATING TO THESE TERMS OR YOUR USE OF THE PLATFORM WILL NOT EXCEED ONE DOLLAR ($1.00 USD).

Some places do not allow the limitation or exclusion of certain damages or liabilities, so parts of this section may not apply to you. See Section 31.

10. Governing Law and Disputes

These Terms are governed by the laws of the State of Arizona, without regard to conflict-of-law rules. Any dispute relating to these Terms or your use of the Platform will be resolved only in the state or federal courts in Pinal County, Arizona, and you agree to the personal jurisdiction of those courts. If you use the Platform as a consumer, this section does not deprive you of the protection of any mandatory rule of the law of the place where you live, including any right to bring or defend a claim in your local courts where that law guarantees it. See Section 31.

Before filing anything, please contact the Developer using Section 15. Most problems with a student project are faster to fix by asking.

11. Time Limit for Claims

Any claim relating to these Terms or your use of the Platform must be brought within one year after the claim arises, or it is permanently barred, unless the law that applies to you sets a period that cannot be shortened by agreement. See Section 31.

12. Changes to These Terms

We may change these Terms at any time. Meaningful changes will be reflected in the “Last updated” date above, and for registered users we will also flag them in the Platform (for example, a dashboard banner or a notice at sign-in). Continuing to use the Platform after a change means you accept the revised Terms. If you do not agree, stop using the Platform and close your account under Section 22.5.

Because these Terms are a file in the public repository, every change to them is a matter of record: what changed, when, and alongside the change to the Platform it describes. The “Edit this page on GitHub” link at the bottom of this page opens the file itself.

13. Notices and Communications

We send notices to registered users by email to the school address on the account, or by a notice shown in the Platform. A notice is treated as received on the day we send it. Keeping that address working, and reading what arrives there, is your responsibility. You can send us notices at the address in Section 15.

Account and security emails, such as sign-in codes, expiry reminders, and moderation notices, are part of the service and cannot be turned off while you have an account.

14. General Provisions

Severability. If any part of these Terms is found invalid or unenforceable, the rest stay in effect, and the invalid part is narrowed only as much as needed to make it valid.

Entire agreement. These Terms, together with the Privacy Policy and the Community Guidelines, are the entire agreement between you and the Platform about your use of it, and replace any earlier agreements on the subject.

No waiver. If we do not enforce a term right away, we have not given it up, and we can still enforce it later.

Assignment. You may not transfer your account or your rights under these Terms to anyone else. We may transfer ours to a successor who takes over running the Platform, on notice to registered users.

No agency. These Terms do not create an employment, partnership, agency, or joint venture relationship between you and the Developer, the School, or the District.

No third-party beneficiaries. These Terms are between you and the Platform. Nobody else gains a right to enforce them.

Survival. Section 3, Section 8, Section 9, Section 10, Section 11, Section 14, Section 24.2, Section 24.5, Section 27, Section 28, and the confidentiality obligation in Section 32 continue to apply after your account ends or you stop using the Platform.

15. Contact

If you have questions about these Terms, contact the Developer.

Developer: developer@dev.vgspartans.org

If you have an account, a support ticket is the faster route, because it keeps the whole conversation in one place and does not depend on an email getting through.

Part II: Visitor Terms

These terms apply to visitors who browse without an account. If you are a registered user, they also apply when you view public pages.

16. What Visitors Can Access

As a visitor, you can browse public pages: club sites, public student and teacher sites, the main portal, the public subplatform pages, the bug bounty page, the policies, the handbook, and the status page when it is published. You do not need an account for these. Some subplatforms and some pages are open only to signed-in members, and which pages those are can change.

17. Data Collected From Visitors

Visiting a public page means technical data about your visit is collected automatically, without an account and without cookies that identify you. By using the Platform, you agree to that collection. The Privacy Policy is the document that says what is collected, why, and for how long. See Part I and Part II of that policy.

18. Visitor Form Submissions

Some public pages have forms, such as club sign-up, contact, report, and bug bounty forms. By submitting one, you agree to the collection and use of what you provide for the purpose shown on the form, and you agree that what you submit is truthful. Public forms are protected by a bot check, which may also run a short calculation in your browser before the form will send.

19. Embedded and Linked Content

Some pages include content embedded from other services, such as videos, and some link out to other sites. Those services are outside our control. We are not responsible for their content, their availability, or how they handle your data, and a link is not an endorsement. Section 3 of the Privacy Policy explains what an embedded service can see.

20. Visitor Prohibited Conduct

On top of Section 5, visitors may not:

  • Try to reach non-public areas (dashboards, consoles, or API endpoints) without valid credentials.
  • Submit false, misleading, or malicious information through any form.
  • Use information from public pages to harass, stalk, or harm anyone.

Part III: Registered User Terms

These terms apply to people who create and keep an account. Parts I and II also apply to you.

21. Eligibility

21.1 Who May Register

The Platform is open only to people connected to the School, including current students, teachers, staff, club advisors, and designated administrators. Registration needs a valid school email address (@cguhsd.org) or a spot on an access list kept by Platform Administrators. Access follows the address: if you lose access to your school email, you lose access to the Platform.

A person invited into the Bug Bounty Program is the one exception. They hold an account with no school address, limited to the researcher console, for as long as their enrollment lasts.

21.2 Age

The Platform is for people 13 and older. If you are under 13, you may not create an account or use it. If you are under 18, we encourage you to use the Platform with a parent or guardian’s awareness, and by registering you confirm that you are allowed to agree to these Terms or that a parent or guardian has agreed for you. Section 16 of the Privacy Policy covers children’s privacy.

22. Accounts and Signing In

22.1 How Signing In Works

Signing in starts with a one-time code sent to your school email, which is also how an account is created. Codes are short-lived. Your school email is the key to your account, so whoever controls that mailbox can start a sign-in.

22.2 Second Factors and Step-Up Verification

You can add a second factor to your account: an authenticator app, a passkey or security key, or a password used only as a second step after the emailed code. A password on its own never signs you in. Some roles are required to hold a second factor, and some sensitive actions ask you to confirm again even during an active session. Choosing a weak or reused password is a breach of this section, and we screen new passwords against known breached passwords and refuse them. When you add your first second factor we also give you a short list of single-use recovery codes, shown once, so that losing a device does not lock you out. Section 6 of the Privacy Policy says what each kind of second factor stores.

22.3 Keeping Your Account Safe

You are responsible for keeping your sign-in codes, recovery codes, second factors, and school email account private. Do not share a code, hand over a passkey or security key, or sign anyone else in on your behalf. Activity under your account is your responsibility unless you report the account as compromised under Section 27.4.

22.4 One Account Per Role

Each eligible person may hold one account per role. Creating extra accounts, impersonating someone, or using another person’s credentials is not allowed.

22.5 Closing Your Account

You can ask us to close your account at any time by contacting the Developer. Closing it disables your access and archives your content under Section 24.5. Some records stay, including audit entries and moderation records, as Part VI of the Privacy Policy explains. Closing your account does not refund anything, because nothing is charged, and it does not release either of us from anything that happened before.

Closing and erasing are different things and you can ask for either. Closing archives your content and destroys it on the 30-day clock in the deletion schedule. If you would rather it were erased, say so and Section 13.5 of the Privacy Policy is the path, which runs in 7 days instead.

23. Acceptable Use

23.1 General Use

Use the Platform only for lawful purposes in keeping with the School’s educational mission. You may create, host, and manage content within the features available to your role.

23.2 Prohibited Conduct

On top of Section 5, registered users may not:

  • Upload, publish, or submit content that is unlawful, threatening, abusive, harassing, defamatory, obscene, or otherwise objectionable.
  • Upload content that infringes anyone’s patent, trademark, copyright, trade secret, or other rights.
  • Upload or spread malware or any code meant to disrupt, damage, or limit software, hardware, or networks.
  • Use the Platform to send spam or unsolicited messages.
  • Bully, harass, intimidate, or discriminate against anyone.
  • Post someone else’s personal information without their consent.
  • Impersonate another person, a club, the School, or the District, including by choosing a handle or display name that does so.
  • Try to get around storage, resource, or rate limits set for your role.
  • Use the Platform in a way that breaks the School’s or District’s acceptable use policies.

The Community Guidelines are the day-to-day version of this section, space by space. Where they are stricter, they are what you follow.

23.3 Resource Limits

Your use of storage, bandwidth, uploads, and other resources is subject to the limits set for your role. Administrators may adjust these limits at any time.

24. Your Content

24.1 Ownership

You keep ownership of the original content you create and upload, subject to the license below. The Platform does not claim ownership of your content.

24.2 License to the Platform

By uploading content, you grant the Platform a non-exclusive, royalty-free, worldwide license to host, store, display, copy, adapt (for formatting and technical purposes), cache, archive, and serve your content solely to run, maintain, improve, and secure the Platform. This license lasts while your content is on the Platform and for a reasonable time after, to meet archiving needs. You confirm that you have the rights to grant this license for everything you upload.

24.3 Content Standards and Moderation

Content you upload, publish, or submit must follow these Terms, the Community Guidelines, the law, and the School’s and District’s acceptable use policies. Content is checked by automated tools and by people. We may flag, hold, restrict, or remove content, with or without notice, when it breaks these Terms, the law, or School policy. No account is suspended or disciplined by an automated check alone. Where practical, we will tell you when we act on your content. Section 7.1 of the Privacy Policy describes how the automated checks work and what is kept.

24.4 Appeals

If your content is held or removed, or your account is restricted, you can ask us to look again by opening a support ticket, or by contacting the Developer using Section 15, and saying what was affected and why you think the decision was wrong. A person reviews the appeal, not an automated system, and can restore the content or lift the restriction. We aim to answer within a reasonable time.

You have 30 days to appeal, counted from the day we tell you about the decision. The deadline exists so that the window matches what we keep: what was removed is preserved for a year under Section 12.5 of the Privacy Policy, and that preserved copy is what a person reviewing your appeal actually reads. Ask after the 30 days and we may still look, but we do not promise to. Our decision on an appeal is final.

24.5 Content Archival

Your content may be archived and kept in line with our retention practices, which are set out in Part VI of the Privacy Policy. Archived content may live on third-party infrastructure (such as GitHub or cloud storage) for backup and safekeeping. Deleting your account does not necessarily delete every archived copy right away.

How long an archived copy lasts is not open-ended, and the deletion schedule is where the periods are named: 30 days once you delete something, 7 days if you ask us to erase your data instead, and up to a year for content we removed for breaking these Terms.

24.6 Club Content

Content on club sites is managed by authorized club webmasters and advisors and belongs to the club and its members. If you contribute to a club site as a webmaster or authorized contributor, you understand it is subject to the club advisor’s and Platform Administrators’ editorial control. The VGClubs guidelines cover what that means in practice.

If you believe content on the Platform infringes your copyright, send a written notice to the Developer at the address in Section 15 that includes:

  • Your signature (an electronic one is fine) as the owner or an authorized agent.
  • Identification of the work you say is infringed.
  • The URL of the content you want removed, specific enough for us to find it.
  • Your name, address, telephone number, and email address.
  • A statement that you believe in good faith that the use is not authorized by the owner, its agent, or the law.
  • A statement, under penalty of perjury, that the information in your notice is accurate and that you are the owner or authorized to act for the owner.

We will review a complete notice, and where it appears well founded we will remove or disable the content and tell the person who posted it. If your content was removed and you believe that was a mistake or a misidentification, you can send us a counter-notice containing:

  • Your signature (an electronic one is fine).
  • Identification of the content that was removed and the location it appeared at before removal.
  • A statement, under penalty of perjury, that you believe in good faith it was removed as a result of mistake or misidentification.
  • Your name, address, and telephone number.
  • Your consent to the jurisdiction of the United States District Court for the judicial district your address is in, or, if your address is outside the United States, of the District of Arizona, and your agreement to accept service of process from the person who sent the original notice.

We may restore the content after a reasonable period unless the complainant tells us they have filed a court action.

The elements above are the ones 17 U.S.C. § 512 sets out, and we use them because they are a fair, tested description of what a copyright complaint needs to contain. To be straight with you about what that does and does not mean: the Platform has not designated an agent with the United States Copyright Office, which section 512(c)(2) requires of a service provider relying on the statutory safe harbour, so we do not claim that safe harbour. Nothing in this section limits any right or defense either of us has under copyright law. We do terminate the accounts of repeat infringers, which is the practice section 512(i) describes.

Sending a notice or counter-notice that misrepresents the facts can carry legal liability.

26. Account Lifecycle

26.1 Student Accounts

A student account is held for as long as you are a student here. It becomes due to expire when you graduate or otherwise leave the School, and an Administrator disables it at or after that point: the account is disabled, the site is archived, and content is handled per our retention practices. Expiry is an act by an Administrator rather than an automatic clock, so an account can outlive the date it became due, and the fact that it still works does not mean it is still authorized.

26.2 Teacher and Staff Accounts

Teacher and staff accounts run for a fixed term and can be renewed through a confirmation process involving both the account holder and an Administrator. An account that is not renewed becomes due to expire and is disabled and handled per our retention practices, on the same basis as Section 26.1.

26.3 Leaving Mid-Year

If you leave the School mid-year, an Administrator may disable your account at any time.

26.4 Suspension and Termination

We may suspend or end your account at any time, with or without notice, for breaking these Terms, the law, or School policy. Where the reason is not urgent, we will normally tell you first and give you a chance to respond. On termination, your access ends. We are not obligated to give you a copy of your content, though archived copies may remain per our retention practices. You can appeal under Section 24.4, within 30 days, and what we removed is kept for a year so that the appeal has something to look at.

27. Security and Monitoring

27.1 Monitoring by Platform Administrators

Your use of the Platform is subject to monitoring, logging, and review by Platform Administrators. You should not expect privacy from these parties for content or activity on the Platform. Activity including sign-ins, uploads, deletions, edits, page visits, and settings changes is logged and may be reviewed for security, safety, or investigation. Section 8 of the Privacy Policy lists what each entry records.

27.2 Security Controls

The Platform applies security controls to protect itself and its users, including device recognition, connection checks, rate limits, bot checks, and step-up verification. You agree to those controls, and you agree not to defeat or evade them. A control may challenge, slow, or block a request, including one of yours. Part III of the Privacy Policy says what these controls collect and why.

27.3 Extra Requirements for Elevated Roles

Accounts with administrative or developer access carry stricter conditions. These can include holding a second factor, passing an additional browser and device check before any console loads, using a specific supported browser, and re-confirming your identity more often. These requirements can change without notice, and failing one blocks access to the console until it is resolved. They do not apply to ordinary student, teacher, or staff accounts. Section 8.5 of the Privacy Policy says what that check reads.

27.4 Reporting a Compromised Account

If you think your account is compromised, report it right away through the compromised-account process or by contacting an Administrator. We will take reasonable steps to secure your account and look into it. Report it promptly: activity before you report stays your responsibility under Section 22.3.

28. Indemnification

You agree to indemnify and hold harmless the Platform and the Developer from any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising out of or relating to: (a) your use of the Platform; (b) your breach of these Terms; (c) your breach of any law; (d) any content you upload, publish, or submit; or (e) your violation of anyone else’s rights. This section applies only to the extent the law that applies to you allows it. See Section 31.

Part IV: International Users and Regional Terms

This part applies to everyone. It adds terms for people who use the Platform from outside Arizona, whether from other US states or other countries, such as people who take part in the Bug Bounty Program or testing.

29. International Access

The Platform is operated and hosted from the United States, in the State of Arizona, for a community based there. We make no claim that it is appropriate or available for use in any other place. If you use it from somewhere else, you do so on your own initiative and are responsible for following the laws that apply where you are. You may not use the Platform from anywhere its content or your use of it would be unlawful.

30. Export Controls and Sanctions

By using the Platform, you confirm that you are not located in, and are not a national or resident of, any country or region under a comprehensive United States embargo, and that you are not on any United States government list of restricted or denied parties, such as the Treasury Department’s Specially Designated Nationals and Blocked Persons List. You agree not to use the Platform in breach of any export-control or sanctions law that applies to you. This matters most for people taking part in the Bug Bounty Program or testing from outside the United States.

31. Mandatory Local Rights

If you use the Platform as a consumer from outside Arizona, nothing in these Terms takes away rights that the law where you live gives you and does not let you waive by agreement. Where such a mandatory rule conflicts with the disclaimers in Section 8, the limits in Section 9, the governing-law and venue terms in Section 10, the claim period in Section 11, or the indemnity in Section 28, that mandatory rule prevails, but only as far as needed and only for you. Nothing in these Terms limits or excludes any liability that cannot be limited or excluded under the law that applies to you, such as liability for death or personal injury caused by negligence, or for fraud.

32. Bug Bounty Program

The Bug Bounty Program is how, and the only way, security testing of the Platform is authorized. Taking part is by invitation: you sign up on the bug bounty page and we confirm you. Nothing about scope is published, so we share it with you privately once you are in, and the scope and rules we give you are confidential. That confidentiality obligation outlives the enrollment.

Every enrollment is time-boxed. A grant runs for a set window of at most 62 days, we email you before it runs out, and when it lapses your access to the researcher console closes on its own, without anyone having to remember to close it. A grant can be renewed, suspended, or revoked at any time.

If you are in the program, you agree to:

  • Stay inside the scope you were given, and stop and ask before anything outside it.
  • Test only against your own accounts and data, never against another person’s.
  • Stop as soon as you reach personal data, keep only what you need to show the finding, and delete the rest.
  • Avoid anything destructive or disruptive, including denial of service, spam, social engineering, and physical attacks.
  • Report what you find to the Developer promptly and keep it private until it is fixed and we agree it can be shared.

We do not pay monetary rewards.

Safe harbour. If you follow the rules above and the scope we gave you, we consider your testing authorized, and we will not bring or support a claim against you for it. That includes a claim under the Computer Fraud and Abuse Act, 18 U.S.C. § 1030, under Arizona’s computer tampering statute, A.R.S. § 13-2316, or under the anti-circumvention provisions of 17 U.S.C. § 1201, and it means we will say so if a third party asks. Both of those statutes turn on whether access was authorized, which is exactly what this paragraph settles. Authorization does not extend to a third party’s systems, so nothing here authorizes anything against Cloudflare or another provider named in Section 4, and it does not bind them. This safe harbour follows the disclose.io model of authorization, good-faith acceptance, no retaliation, and reciprocity.

Testing outside the program or outside its scope is not authorized and is prohibited under Section 5, wherever in the world you are.

For how we handle personal data, including the extra rights available to California residents, to people in the European Economic Area, the United Kingdom, and Switzerland, and to residents of other US states, see Part IX of the Privacy Policy.