Legal
Acceptable Use Policy
Effective Last updated
This policy is part of the Terms of Service and applies to every surface of Myna — the dashboard, API, CLI, SDK, MCP server, previews, webhooks, and public content delivery — whether used by a person or by an agent acting on your behalf.
Prohibited content
You may not store, publish, or distribute through Myna content that:
- Is illegal under applicable law, or facilitates illegal activity.
- Sexually exploits or endangers minors in any way. We report child sexual abuse material to the relevant authorities.
- Infringes copyright, trademark, or other proprietary rights.
- Contains malware, or is used for phishing, credential harvesting, or deceptive impersonation.
- Discloses personal data you have no right to process, or is used to dox or harass individuals.
- Incites violence or promotes terrorism or violent extremism.
- Is unsolicited bulk content (spam) or supports spam operations.
Prohibited conduct
- Accessing or attempting to access other tenants’ data, or probing, scanning, or testing the security of the Service without prior written authorization (see responsible disclosure for the sanctioned path).
- Circumventing or attempting to circumvent authentication, authorization, rate limits, usage metering, or plan limits.
- Interfering with the Service’s operation, including denial-of-service attacks or workloads intended to degrade it.
- Sharing, selling, or publishing account credentials or API keys, or using another tenant’s credentials.
- Using Myna webhooks to attack third-party systems, or pointing webhooks at endpoints you do not control.
- Reselling the Service as your own without our written agreement.
Agents and automation
Myna is agent-native: scripts, CI systems, and AI agents are welcome, first-class users. Automation still has rules:
- Everything an agent does with your keys is your responsibility under the Terms of Service.
- Give each agent or integration its own key, scoped to the minimum permissions and projects it needs, and revoke keys you no longer use.
- Automation must respect rate limits and back off on errors rather than hammering the API.
- Do not use automation to circumvent metering, inflate usage, or generate prohibited content at scale.
Collecting feedback
An ingest key is publishable, so it is meant to sit in your browser bundle where anyone can read it. What keeps it safe is that it can only submit, only to one board, and only from an origin you registered — so do not treat those controls as optional, and do not use an ingest key as a general write path into a project.
- Do not use report submission as a message queue, a file transfer, or any pipeline unrelated to feedback about your application.
- Do not assert an identity you cannot vouch for. Signed identity exists for that; the signing secret must stay on your server.
- Tell your reporters what you collect and who receives it. They are your users, not ours.
- Moderate the boards you make public. Publishing a report that exposes someone else’s personal data is your responsibility, and it is not undone by taking it down.
Assets and delivery
Asset storage and delivery exist to serve the content of your projects, not as a general-purpose file host or download mirror. Uploads are validated, and executable files and SVG images are blocked for safety. Do not use asset delivery primarily to distribute files unrelated to content managed in Myna.
How we enforce this
Enforcement is proportionate. Depending on severity we may warn you, throttle traffic, remove or disable specific content, suspend keys, members, projects, or organizations, or terminate accounts — and where required we cooperate with law enforcement. For anything short of legal necessity or acute harm, we act narrowly and avoid taking a customer’s published site offline as a first resort.
If we take action against your account and you believe we got it wrong, contact [email protected] and we will review it.
Reporting abuse
To report content or behavior that violates this policy, email [email protected] with links to the material and enough context for us to investigate. To report a security vulnerability, use the process on the Security page instead.
