Draft for legal review. The operating company's details in [square brackets] are not filled in yet, so this page is not final.

Legal

Acceptable Use Policy

Last updated: October 6, 2026

This Acceptable Use Policy (the "Policy") sets out what you may and may not do with Site Monitor (the "Service"), which is operated by [LEGAL ENTITY NAME] ("we", "us", "our"). It forms part of the Terms of Service (the "Terms"). "You" means the customer that holds the account and everyone who uses it, including the team members whose logins you create. You are responsible for their use of the Service.

1. Purpose and scope

The Service sends automated requests to websites and sends messages to people. This Policy keeps that safe and lawful for our customers, for the people who receive alerts and reports, and for the owners of the websites the Service checks. It applies to everything you do with the Service: the websites you monitor, your check settings, alert channels and recipients, reports, public status pages, branding, and your team.

2. Monitor only what you may

  • Only monitor websites, servers and endpoints that you own or operate, or that their owner has authorised you to monitor, for example a client who has asked you to watch their site.
  • Be able to show that authorisation if we ask, for example after a complaint from the site's owner.
  • When the authorisation ends, for example when a client leaves you, remove the website or turn off its monitoring.

3. No abuse of the checks

  • Do not use the Service to attack, overload, flood or disrupt any website, server or network, or to probe it for vulnerabilities, open ports or other weaknesses.
  • Do not choose check settings, or add the same address to several accounts, in order to put load on a target or to harass its owner.
  • Do not point a monitor, webhook or any other address you give us at private or internal network addresses, such as localhost, 127.0.0.1, the ranges 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16, link-local addresses such as 169.254.169.254, or cloud metadata services. Do not use the Service to reach our own infrastructure or our providers' internal systems.
  • Our checks refuse web addresses that point to private or internal networks, such as localhost, the private ranges above, link-local addresses and cloud metadata addresses, and refuse addresses that do not start with http:// or https://. The same protection applies to webhook and Slack addresses and to a mail server you connect for sending email. It has a limit: a hostile DNS server could still change its answer between our lookup and the connection. The rule in the previous point is therefore yours to follow, whatever our checks catch.
  • Do not use the Service to scrape or collect content from websites. The checks exist to tell you whether a site is up.

4. Content and public status pages

  • Names, logos, status page content, report content and any other branding you add must not be illegal, infringing, deceptive, defamatory, hateful, harassing or otherwise abusive.
  • Only use a name or logo that you have the right to use. Do not make a status page or report look as if it comes from a business you do not represent.
  • Do not use a status page, report, logo address or any other content to spread malware or phishing, or to link to it.

5. Messages

  • Alerts, reports, SMS messages and webhooks are for operational information about the websites you monitor. Do not use them for spam, marketing, or any message unrelated to monitoring.
  • Only add recipients, including email addresses, phone numbers, Slack and ClickUp channels and webhook endpoints, whose owners have agreed to receive operational alerts or reports from you. Remove a recipient when they ask.
  • Follow the laws that apply to the messages you cause the Service to send, including anti-spam, electronic marketing and SMS rules.

6. Security and fair use

  • Do not probe, scan or test the security of the Service, except as our Security page allows for responsible disclosure: only against accounts you own, and without harming other people's data.
  • Do not try to get around sign-in, two-factor authentication, rate limits, billing, or the limits of your plan, such as the number of websites, team members or features it includes.
  • Do not resell or sublicense access to the Service itself. You may offer monitoring to your own clients through the white-label features your plan includes, as the Terms allow.
  • Each person needs their own login. Do not share passwords or sign-in sessions; add a login for each team member instead.
  • Do not copy, decompile or reverse engineer the Service, except where the law allows it despite this restriction.
  • Do not send automated requests to the Service at a rate that strains it, and respect the rate limits we apply.
  • Do not use the Service to break any law, or help anyone else break this Policy.

7. Reporting abuse

  • If you believe someone is using the Service to check, load or contact your website without permission, or you are receiving alerts or reports you did not agree to, email support@concepcion.work. Include the address being checked or a copy of the message, and the dates and times. Our checks send ordinary browser request headers, so the address and the times are what let us find the account concerned. We look into every report.
  • Report security vulnerabilities in the Service to security@concepcion.work, as described on our Security page.

8. Enforcement

  • If we reasonably believe this Policy has been broken, we may warn you, remove or turn off the website, channel or content concerned, limit features, or suspend or terminate the account, in line with the Terms.
  • Where it is reasonable, we will tell you first and give you a chance to fix the problem. We may act without notice when that is needed to stop serious harm, to protect others, or to comply with the law.
  • Suspending an account stops its monitoring and signs its users out, but does not delete its data. The Terms explain what happens to your data if an account is terminated.
  • Where the law requires it, we may report illegal activity to the authorities.

9. Changes

We may update this Policy. If a change is material, we will email account owners at least 30 days before it takes effect, as the Terms provide for their own changes. The date at the top of this page shows when the Policy was last updated.

Contact: [LEGAL ENTITY NAME] · support@concepcion.work