1. What we host, and who operates what
We host the curated applications in our catalog. We operate the servers; you operate the app. You control the app's content and its users, and you are the operator of anything the app does on the internet. If your automation tool messages a thousand people, those are your messages.
2. Prohibited content
You must not store or publish through our services: content that is illegal under the law of your region or ours (including any material that exploits or endangers minors); content that infringes others' intellectual property rights; malware; or phishing and brand-impersonation pages.
3. Prohibited conduct
You must not use our services for: unsolicited bulk email or messaging; scanning third-party systems for ports or vulnerabilities; cryptocurrency mining; operating open proxies, relays, VPN exits or Tor exits; credential stuffing or other attack tooling; distributing content you do not have rights to distribute; or scraping that violates target sites' terms or reasonable rate expectations.
4. Email
Outbound port 25 is blocked across the platform. Transactional email through an authenticated third-party SMTP provider (port 465/587) is fine where recipients have consented. Bulk mail and newsletters must go through your own email service provider: your sender reputation, not our IP ranges.
5. Fair use of resources
Your app gets the CPU, RAM and disk you purchased. Sustained usage patterns inconsistent with an app's purpose (a password manager pinned at maximum CPU for days, say) are investigable. Network transfer has no metered charge for normal application use; as a fair-use guide, sustained transfer beyond 1 TB per app per month is where we may start a conversation. We will always contact you before shaping anything, and we will never silently increase your plan or your bill. Changes to your spend require your confirmation.
6. Custom domains
When you attach a domain you warrant that you control it and will not use it to impersonate others. We may suspend routing and certificates for domains flagged by reputable abuse feeds pending review. The route is suspended, not your data.
7. App licences pass through
Some catalog apps carry upstream licence terms, noted on the app's page. We carry the hosting-side licence obligations; you are responsible for complying in how you use the app. Source code offers for copyleft-licensed apps are available on request.
8. Enforcement
Our ladder: notice, 48 hours to remedy, suspension with data preserved, then termination. We skip straight to immediate suspension for illegal content, active phishing or malware, ongoing attack traffic, or a legal order. After termination, data is retained for 14 days and then purged, backups included.
9. Our access to your instances
We access instance contents only to operate the service: backups, updates, diagnostics you request, or abuse investigation with cause. Routine monitoring is metadata (resource usage, connection counts), not your content. No content scanning, no TLS interception, ever.
10. Reporting abuse
Seeing something hosted on our platform that should not be? Email abuse@corehost.io. We act on valid reports within one business day, and faster for the serious categories above.