Acceptable Use Policy
Effective Date: June 14, 2026
Last Updated: June 14, 2026
Hypastack is a file sharing and CDN hosting platform. Files uploaded through the website are protected by a zero-knowledge architecture; CDN assets and developer API uploads are not encrypted and are readable by me. However, privacy does not equate to lawlessness.
This Acceptable Use Policy defines strictly what is not allowed on my infrastructure. If you violate this policy, your account, associated access keys, and all uploaded ciphertext will be terminated and permanently purged without warning. By utilizing my network, you explicitly agree to adhere to these constraints.
1. Zero-Tolerance Content (Strict Prohibition)
You must under no circumstances upload, distribute, or facilitate access to the following categories of content. Violation of this section will result in immediate network bans and cooperation with relevant global law enforcement agencies:
- Child Sexual Abuse Material (CSAM): Any material depicting or promoting the abuse or sexual exploitation of minors. All instances are reported immediately to the National Center for Missing & Exploited Children (NCMEC) and relevant authorities.
- Terrorism and Violent Extremism: Content that promotes, encourages, or provides instructional material for terrorist acts or mass violence.
- Non-Consensual Intimate Imagery (NCII): Often referred to as "revenge porn", distributing intimate media without the explicit consent of the subjects involved is strictly forbidden.
- Malicious Payloads: Malware, ransomware, trojans, worms, or any code expressly designed to disrupt, damage, or gain unauthorized access to computer systems.
- Phishing and Fraud: Hosting phishing pages, credential-harvesting kits, or materials designed to defraud individuals or organizations.
2. Network Abuse and Operational Constraints
The Hypastack CDN is designed for the rapid delivery of legitimate assets. To maintain high availability for all users, you must not engage in activities that degrade the network:
- Evasion of Quotas: Attempting to bypass rate limits, storage quotas, bandwidth caps, or file-size restrictions through automated scripts or rapid account rotation.
- Infrastructure Probing: Scanning, testing, or probing the vulnerability of any Hypastack edge node, API endpoint, or database without prior explicit, written authorization.
- Primary Hosting Abuse: Utilizing the CDN endpoints to host an entire website's primary HTML structure (the platform is strictly for distributing static assets and media, not operating as a web server replacement).
- Distributed Denial of Service (DDoS): Leveraging the platform to artificially inflate traffic or attack third-party networks.
3. Enforcement Under Zero-Knowledge
Because Hypastack employs client-side AES-GCM encryption for website uploads, I am mathematically incapable of proactively scanning the contents of those files. I cannot implement traditional hash-matching or keyword-scanning algorithms on ciphertext. This constraint applies to that pipeline alone: CDN assets and developer API uploads are stored unencrypted, and I am technically able to inspect them when I have cause to.
Consequently, my enforcement mechanisms rely on:
- User Reports: I actively process abuse reports sent via https://t.me/t_usekiko. A valid report should include the URL of the file. Please do not include the decryption key fragment.
- Traffic Analysis: I monitor anomalous traffic patterns, bandwidth spikes, and request origins to detect automated abuse or malware distribution networks.
- Metadata Heuristics: I utilize unencrypted metadata (file size ratios, upload patterns) to identify coordinated abuse campaigns.
When a valid violation is confirmed, the offending ciphertext is permanently deleted from the R2 edge storage, and the associated uploader's session or account may be terminated.
CDN Assets are different. Files uploaded through the Permanent CDN Hosting pipeline are not encrypted, and they are publicly accessible by design. This means CDN assets are not subject to the zero-knowledge constraint above. I plan to introduce client-side scanning for CDN uploads in a future update, which will flag prohibited content before it is ever transmitted to my servers. Until that is in place, CDN asset uploads remain subject to the same user-report and traffic-analysis mechanisms above, and prohibited content will be removed upon discovery.
4. Reporting Abuse
If you encounter content hosted on Hypastack that violates this policy, send a report to https://t.me/t_usekiko with the file link and a brief description of the violation.
Do not include the decryption key fragment. I will not ask for it, and you should not send it. Receiving the key would require me to actively decrypt and view potentially illegal content, including CSAM, which creates direct legal liability for me under laws governing possession and viewing of such material. I am not equipped or willing to act as a human review queue for illegal content.
Instead, include:
- The URL of the file (without the
#...fragment) - A screenshot, description, or any other contextual proof that does not require me to decrypt the content
- The nature of the violation (e.g. CSAM, malware, phishing)
For CSAM specifically: do not screenshot or preserve the content. Report the URL directly to the NCMEC CyberTipline and send me the file URL so I can remove it immediately. That is all I need.
