Legal summary
Acceptable Use Policy
The behaviour Capell does not allow, the boundaries for security research, and the action we may take to protect people and services.
| Abuse prevention | Covered in this document |
|---|---|
| Package safety | Covered in this document |
| Marketplace trust | Covered in this document |
Sections
Plain-language summary: Use Capell without harming people, systems, or marketplace trust. Report security issues safely. We may restrict access or remove material when protection or the law requires it.
Do not harm systems or people
Do not use Capell to attack, disrupt, scrape, overload, reverse engineer private systems, bypass access controls, distribute malware, hide malicious code, exfiltrate data, or interfere with another user, website, package, or service.
The same rule applies across Capell accounts, marketplace listings, install flows, package downloads, support routes, and public forms. Do not use any of them to test another person's site without permission or to conceal abusive traffic.
Describe marketplace work honestly
Do not submit misleading package names, false compatibility claims, fake reviews, manipulated download signals, hidden tracking, undisclosed paid placement, copied listings, or packages that appear to do one thing while doing another.
Marketplace authors should describe meaningful capabilities, dependencies, support expectations, data access, pricing, licences, and compatibility honestly. A site owner should be able to understand the package risk before installing it.
Publish only lawful material
Do not upload, submit, link to, or promote content that is unlawful, infringing, defamatory, abusive, discriminatory, sexually exploitative, deceptive, or designed to evade legal or platform controls.
You must have the right to publish any content, package, screenshot, documentation, name, logo, or dataset you submit. Do not expose another person's confidential information.
Keep security research within safe limits
Good-faith reports are welcome. During testing, avoid data access, service disruption, persistence, social engineering, destructive testing, and public disclosure before Capell has had a fair opportunity to investigate.
Once you can show a suspected issue, stop probing production systems. Send the affected route, package or account workflow, reproduction steps, and impact through the security contact path.
How we may enforce this policy
Capell may throttle, restrict, suspend, remove, delist, or block accounts, packages, domains, install workflows, API requests, or content where we believe this policy has been breached or urgent action is needed to protect users, site owners, authors, infrastructure, or Capell.
We may also refuse marketplace submissions, withhold package access, reverse abusive signals, preserve evidence, notify affected users, or cooperate with lawful requests where required.