Acceptable Use Policy
Effective date: March 2, 2026
This Acceptable Use Policy ("AUP") defines the types of services, websites, and applications for which PrivaScan may and may not be used. This AUP is incorporated into our Terms of Service. Violations may result in immediate account suspension or termination without refund.
1. Prohibited Industries
PrivaScan may not be used to generate privacy policies, terms of service, cookie policies, or consent banners for services, websites, or applications that primarily operate in any of the following categories:
2. How We Enforce This Policy
PrivaScan employs a three-layer automated detection system:
- Layer 1 — Domain blocklist: Known domains associated with prohibited industries are blocked before scanning begins.
- Layer 2 — Content analysis: URL patterns, page content, metadata, and keyword matching are analyzed both before and after scanning to detect prohibited content.
- Layer 3 — App store category detection: For mobile apps, we check the app's store category against prohibited classifications.
Low-confidence detections are flagged for manual review. High-confidence detections result in an immediate block with an explanation and the option to request manual review.
3. Consequences of Violation
- First violation: Scan or generation request is blocked with an explanation. No account action is taken.
- Repeated attempts: Account may be suspended pending review.
- Circumvention attempts: Attempting to circumvent our guardrails (e.g., by obfuscating URLs, providing false questionnaire answers, or using proxied domains) will result in immediate account termination without refund.
- Published policy removal: If a prohibited service is discovered to have published policies through our platform, those hosted pages will be taken down and the associated account terminated.
4. Additional Prohibited Uses
Beyond prohibited industries, you may not use PrivaScan to:
- Generate fraudulent or intentionally misleading privacy policies that misrepresent your actual data practices
- Scan websites or apps you do not own or have authorization to scan
- Resell generated policies as a competing service without an Agency plan
- Use the API or scanner to perform unauthorized security testing, vulnerability scanning, or penetration testing on third-party websites
- Overload our systems with automated requests beyond documented rate limits
- Use the consent banner to collect user data beyond what is disclosed in the associated privacy policy
- Generate policies for services that primarily target or exploit minors
- Use the Service in connection with any activity that violates applicable laws or regulations
5. Gray Areas and Manual Review
We recognize that some legitimate businesses may overlap with prohibited categories. For example:
- A restaurant that serves alcohol (allowed — alcohol is not the primary business)
- A fintech app with loan comparison features (allowed — it is not itself a lender)
- A health app that tracks medication (allowed — it does not sell controlled substances)
- A news site that reports on gambling (allowed — it does not facilitate gambling)
If your service is blocked and you believe it should be allowed, email support@privascan.net with your URL and a brief explanation. We aim to respond to manual review requests within 2 business days.
6. Rationale
This policy exists to:
- Maintain the integrity and reputation of the PrivaScan platform
- Ensure our AI-generated content is not used to provide cover for harmful or illegal activities
- Comply with the terms of our own service providers (Anthropic, Stripe, Vercel)
- Reduce legal liability for the company and its users
- Align with industry best practices for responsible AI use
7. Updates
We may update the list of prohibited industries and additional restrictions as needed. Material changes will be communicated with at least 14 days' notice. The prohibited industries list may be expanded but never reduced without explicit notice.
8. Contact
For questions about this policy or to request a manual review:
Email: support@privascan.net
Response time: 2 business days