Acceptable Use Policy (AUP)
This Acceptable Use Policy establishes the mandatory operating rules governing all deployments of PrivacyScrubber across our Web Workspace, Chrome Extension (MV3), PII MCP Server, and Developer SDK.
Enterprise privacy defense
Zero tolerance for fraud
Anti-scraping restrictions
Enforced on abuse
Permitted & Legitimate Uses
Authorized workflows across all commercial and community tiers.
PrivacyScrubber is built specifically to protect data privacy and enable safe AI adoption. You are expressly authorized to use the software for:
- Pre-LLM Prompt Sanitization: Stripping PII, PHI, financial numbers, API secrets, and customer names before dispatching text to ChatGPT, Claude, Gemini, Copilot, or open-weight models.
- Engineering & Code Protection: Sanitizing hardcoded credentials, JWT tokens, AWS keys, database URIs, and internal endpoint hosts from code reviews and logs.
- HR & Recruitment Anonymization: Generating blind candidate resumes and performance scorecards to prevent algorithmic bias during automated hiring evaluations.
- Commercial Underwriting & Invoicing: Redacting personal tax IDs, SSNs, and employee names from W-2s, paystubs, and AP accounting vouchers while preserving 100% of mathematical figures.
Strictly Prohibited Malicious Activities
Absolute prohibitions and zero-tolerance violations.
You agree not to use PrivacyScrubber to engage in, facilitate, or further any of the following:
- Criminal Obfuscation & Subpoena Evasion: Obfuscating digital evidence, concealing financial fraud, money laundering, cyber extortion, or evading lawful law enforcement subpoenas or court orders.
- CSAM & Child Endangerment: Processing, obfuscating, or transmitting any Child Sexual Abuse Material (CSAM) or any content exploiting or harming minors.
- Malware & Exploit Payloads: Crafting malicious regular expression payloads designed to induce catastrophic backtracking (ReDoS) against client browsers, MCP runtime hosts, or worker threads.
- Engine Reverse-Engineering & Rule Scraping: Systematically decompiling, extracting, or scraping the proprietary 25-profile Named Entity Recognition regex dictionary to build competing commercial services.
- Cryptographic Lock Tampering: Attempting to tamper with, modify, or circumvent the client-side Ed25519 token verifiers, Argon2id key derivation mechanics, or XChaCha20-Poly1305 session vaults.
Zero-Server Enforcement & License Termination
Operational mechanics of policy enforcement.
Due to our strict Zero-Trust Data Sanitization (ZTDS) architecture, PrivacyScrubber does not monitor, inspect, or log customer prompt contents. However, if we identify material breaches through payment fraud, chargeback abuse, unauthorized redistribution of extension CRX packages, or malicious security exploits reported under our VDP:
We reserve the right to immediately terminate the associated commercial license (PRO or TEAMS), invalidate issued cryptographic offline activation tokens, and restrict further distribution without liability or refund.
