Acceptable Use Policy
Last updated 28 September 2026
In short: Use Stuga ID and remote access for your own work and for the people you invite. Don’t use them to break the law, harm people, attack computers, or carry anything other than your Stuga node. Report abuse to abuse@mystuga.com. We usually ask a node’s owner to fix a problem first, but in serious cases we block new connections to its Stuga address as soon as we can.
What this covers
This policy covers our online services: Stuga ID, remote access, billing, and our websites stuga.dev and id.stuga.dev. It’s part of our Terms, so breaking it breaks the Terms.
It doesn’t cover the Stuga software, including Stuga for Claude. You run them under their open-source licenses, and nothing here limits those licenses.
Words we use
- We and us mean PillarXYZ, Inc., the company that makes Stuga.
- You means anyone who uses our services, including anyone who reaches a node through its Stuga address.
- Stuga is our open-source software.
- Stuga ID is your free account at id.stuga.dev. You need it for remote access and to sign in to nodes that accept it.
- Your node is a computer running Stuga that you or your team control, such as your own Mac.
- Remote access is our subscription that lets you and the people you invite reach your node from anywhere.
- Your Stuga address is your node’s web address for remote access, such as
https://abc123.mystuga.com. - The relay is our server that passes connections between visitors and your node. The connection is encrypted between the visitor’s device and your node, and the relay has no key to read it.
People you let in
If you own a node, you’re responsible for how the people you let in use it through your Stuga address. Make sure they know these rules. If one of them breaks the rules, we may act against your Stuga address.
The owner of a node decides what happens on it. If you have a problem with someone on another person’s node, talk to that node’s owner. If a node is being used for anything on this page, tell us.
What’s not allowed
Don’t use our services for any of the following, and don’t let anyone use them that way through your node.
Illegal or harmful content
- Child sexual abuse material, or anything that sexualizes, exploits or endangers children.
- Intimate images of anyone shared without their consent, including fakes.
- Pornography, or other obscene material. This rule comes from our host: Akamai, which hosts the relay, doesn’t allow it on its network, and all remote access traffic passes through that network.
- Anything illegal where you are, or where the people you deal with are.
- Copying or sharing films, music, software, books or other work you don’t have the right to share, or otherwise infringing intellectual property rights.
- False statements that damage a real person’s or organization’s reputation.
- Threats, harassment, stalking, or publishing someone’s private details to hurt them.
- Promoting terrorism or violence, or helping anyone cause death or serious injury.
- Selling illegal goods or services, or running illegal gambling.
Deceiving people
- Phishing: pages or messages that trick people into giving up passwords, card numbers or other personal details.
- Pretending to be another person or organization, or us, including in a Stuga ID name or on a Stuga address.
- Fraud and scams.
- Spam: unsolicited mass email, messages or advertising.
Attacking computers and networks
- Sending or hosting malware: viruses, worms, ransomware, spyware, trojans, or files made to deceive.
- Getting into, or trying to get into, any account, computer or network without permission.
- Taking over, or trying to take over, someone else’s Stuga address.
- Scanning, probing or testing systems you don’t own and don’t have permission to test.
- Flooding a system with traffic, or controlling networks of hijacked computers.
- Mining cryptocurrency with our services.
- Disrupting or overloading our services or other people’s nodes.
Misusing remote access
Remote access is for reaching your node. It’s for you, the people you invite, and the apps and AI agents you connect, such as Claude. So don’t:
- Carry anything through your Stuga address other than your Stuga node. No other apps, servers or devices.
- Run an open proxy, a VPN exit, a Tor exit, or any other service that passes on traffic for others.
- Serve the public. That means no public websites, no file distribution and no streaming to an audience.
- Sell, rent or lend out remote access, your Stuga address or the relay’s capacity, or put other people’s nodes behind your address. Charging clients for your own work that they reach on your node is fine.
- Get around limits we set to keep the relay fair, such as a limit on your node’s speed.
- Run heavy scans, load tests or floods through your Stuga address. Everyone shares the relay.
Misusing accounts and offers
- Sharing a Stuga ID. Each one is for one person. Don’t use anyone else’s.
- Creating accounts in bulk or with automated tools.
- Opening a new account, or getting a new Stuga address, to get around a suspension.
- Signing up again and again for free trials, or selling or trading invite and discount codes.
- Threatening or abusing the people who answer your emails.
Breaking our providers’ rules or trade law
- Anything that breaks the acceptable use rules of Akamai, which hosts the relay, or of Cloudflare, which hosts our websites and Stuga ID and runs our DNS. Their rules cover the traffic on their networks, including yours.
- Using our services from a country under a US trade embargo, while you are named on a US government list of sanctioned or restricted parties, or in a way that breaks export control laws.
Testing security
- Test your node on your own computer or network, not through your Stuga address, because that traffic passes through the relay. A quick check of your own address, such as with an online certificate checker, is fine.
- Don’t scan or test the relay, Stuga ID, billing or our websites without our written permission. To test the relay, you also need written permission from our host, Akamai.
- If you find a security problem in our online services, email hello@stuga.dev with “Security” in the subject. For the Stuga software, use GitHub’s private reporting, as our security policy describes.
- We won’t treat a good-faith security report as an attack.
Reporting abuse
Email abuse@mystuga.com. If that address doesn’t work, use hello@stuga.dev. Please include:
- the Stuga address involved, such as
abc123.mystuga.com - the date and time you saw it, with your time zone
- what happened
- your evidence: links, screenshots, or the full headers of a spam or phishing email
- how to reach you
Never send us images of child sexual abuse. Send us the address and the time instead. Report the images to NCMEC’s CyberTipline in the US, to Cybertip.ca in Canada, or to the hotline where you live. If someone is in immediate danger, call your local emergency services first.
Copyright complaints go to the same address. Name the work, say where it appears, and confirm that you own the rights or act for the owner.
We use your report to look into the problem, and we may tell the node’s owner what was reported. We don’t give them your name or email address unless you agree or the law requires it. Copyright complaints are the exception: we forward them to the node’s owner in full, so the owner can respond.
What we do
The relay can’t read the traffic it passes on, and we don’t have what’s on your node. So we act on three things:
- reports;
- what anyone can see by visiting a Stuga address;
- our connection records: addresses, times and amounts of data.
A person makes every enforcement decision.
- Most problems. We email the owner, say what was reported, and ask them to fix it, usually within 3 days. If it isn’t fixed, we block new connections to the Stuga address or suspend the Stuga ID.
- Serious harm. This covers child sexual abuse material, active phishing or malware, and attacks under way. We block new connections to the Stuga address as soon as we can, and we may suspend the owner’s Stuga ID. Then we tell the owner. We also act without warning when a court, an authority or our host requires it.
- Repeats. If someone keeps breaking these rules, or breaks one badly, we end their remote access and close their Stuga ID. That includes people who repeatedly infringe copyright.
We act fast because every node shares the relay. One person’s abuse can get the relay blocked for everyone, by our host or by other networks.
If we act against your Stuga address or Stuga ID, we tell you what we did and why, unless the law forbids it or telling you would put someone at risk of harm. We never give a Stuga address to anyone else. What happens to your payments is in our Refund and Cancellation Policy.
Authorities
We report apparent child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC), as US law requires. We keep what we reported for as long as the law requires.
Otherwise, we give information to police, courts or other authorities in only two cases:
- when valid legal process requires it, such as a subpoena, court order or warrant;
- when someone faces a risk of death or serious physical injury.
We give only what is needed. We can hand over account, billing and connection records. We don’t have what’s on your node. If an authority lawfully asks us to preserve records, we keep them. We tell you before we answer a request about you, unless the law forbids it or telling you would put someone at risk of harm.
Appeals
If we blocked your Stuga address or suspended your Stuga ID and you think we got it wrong, email hello@stuga.dev within 30 days. Tell us what happened and anything we missed. A person looks at it again and replies within 14 days. If we got it wrong, we restore your access.
If you reported something and think we got it wrong, you can write to us too.
Changes
The date at the top of this page shows when we last changed it. If a change limits what you may do, we email Stuga ID holders 30 days before it takes effect. If you don’t agree, you can cancel within 30 days of our email, or of the change if that is later. We then refund the unused part of your paid period. A change the law requires can take effect sooner if the law says so.
Questions about this policy go to hello@stuga.dev.