Acceptable Use Policy
PageWard hosts arbitrary HTML and JavaScript written by other people and runs it in visitors' browsers. This policy is what stands between that capability and its obvious misuses. It forms part of the Terms of Service.
Last updated: 4 August 2026 · Version 0.1 (draft)
A working draft for legal review, not a document to rely on. It has not been reviewed by anyone legally qualified. Items marked TO FILL or DECIDE are open.
1. Who this applies to
Everyone who uploads to PageWard, and everyone who opens a page hosted on it. If you invite someone to view a page, you are responsible for what you have given them access to.
2. Content you must not upload
Do not upload, host or link to anything that:
- is unlawful under Austrian or EU law, or under the law of any country where the page is likely to be viewed;
- depicts child sexual abuse, or constitutes terrorist content, incitement to violence, or unlawful hate speech;
- infringes copyright, trade marks, trade secrets or any other intellectual property right you do not hold or have permission to use;
- breaches a duty of confidence you owe to an employer, client or anyone else;
- is defamatory, or discloses another person's private information without a lawful basis;
- contains malware, exploit code, cryptocurrency miners, or any script whose purpose is to harm, mislead or take resources from the visitor;
- impersonates a person or organisation, or is designed to deceive a visitor about who published it — including pages built to mimic a login screen, a bank, a government service or PageWard itself;
- harvests credentials, payment details or other sensitive information under false pretences.
2.1 Data PageWard is not built for
This is a binding restriction, not advice. Do not upload:
- Special categories of personal data under Art. 9 GDPR — health, genetic or biometric data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation;
- personal data relating to criminal convictions and offences (Art. 10 GDPR);
- payment card data within the scope of PCI DSS;
- classified or export-controlled material.
PageWard has not been designed, assessed or audited for these categories, and hosting them here would expose both of us to obligations neither of us has prepared for.
3. Conduct that is not allowed
- Do not attack the isolation model. Uploaded pages run sandboxed with an opaque origin. Do not attempt to escape that sandbox, reach PageWard's session cookies, read another customer's page, or probe the storage layer directly. Legitimate security research is welcome — see §6.
- Do not use PageWard as attack infrastructure — no command-and-control, no phishing landing pages, no redirect chains, no hosting payloads for delivery elsewhere.
- Do not use it as a general file host or CDN. PageWard exists to share a working page with named colleagues, not to distribute bulk content to the internet.
- Do not place disproportionate load on the service — automated upload loops, deliberate traffic amplification, or scripts designed to consume server resources.
- Do not circumvent access controls, including sharing sign-in links, pooling one account across many people to avoid seat charges, or re-publishing a page you were invited to view.
- Do not resell or white-label PageWard without a written agreement.
4. Reporting illegal content — notice and action
PageWard is a hosting service under Art. 3(g)(iii) of Regulation (EU) 2022/2065 (Digital Services Act). Art. 16 of that Regulation applies to us regardless of our size, and this section is our notice-and-action mechanism.
Report to abuse@pageward.dev. Anyone may submit a notice — you do not need an account.
To let us act, a notice should contain:
- a sufficiently substantiated explanation of why you believe the content is illegal;
- the exact URL, and any further information needed to locate the content;
- your name and email address — except where the notice concerns offences under Arts. 3–7 of Directive 2011/93/EU, where it may be submitted without them;
- a statement of your good-faith belief that the information in the notice is accurate and complete.
We will confirm receipt without undue delay, decide in a timely, diligent, non-arbitrary and objective manner, and tell you the outcome and the means of redress available. Where a notice allows us to identify the illegality without a detailed legal examination, we treat it as giving us actual knowledge for liability purposes.
DECIDE — the target response time to commit to publicly. With a single operator, promising 24 hours is a promise that will eventually be broken; state something achievable.
4.1 Other kinds of complaint
| Concern | Where to send it |
|---|---|
| Illegal content, abuse, impersonation, phishing | abuse@pageward.dev |
| Security vulnerability in PageWard itself | security@pageward.dev |
| Personal data — access, erasure, objection | privacy@pageward.dev |
| Anything else | hello@pageward.dev |
If the content concerns you personally but is not unlawful, consider contacting the page owner directly — they control the allowlist and can remove the page themselves in seconds.
5. What we do about breaches
Depending on severity, and proportionate to it, we may:
- pause a page, so its link stops serving while we look at it;
- remove the content and the underlying file;
- suspend or terminate the account;
- report the matter to law enforcement where we are required or where there is a risk to life or safety.
We aim to notify the customer before acting, unless doing so would be unlawful, would defeat the purpose, or the content is manifestly illegal. Whenever we restrict content, we provide a statement of reasons under Art. 17 DSA — what we did, why, the legal or contractual ground, and how to contest it.
5.1 Contesting a decision
Write to abuse@pageward.dev within 30 days. We will review the decision, and reverse it where the complaint is well-founded. Decisions are reviewed by a person, not automatically. Your rights to go to court, or to the competent Digital Services Coordinator — KommAustria in Austria — are unaffected.
5.2 Misuse of the reporting mechanism
Notices submitted in bad faith, or repeatedly and manifestly unfounded, may be deprioritised or refused after warning.
6. Security research
We welcome good-faith reports and will not pursue researchers who follow these rules:
- Test only against your own account and your own pages. Do not access, modify or exfiltrate anyone else's data.
- No denial of service, no spam, no social engineering of us or our customers.
- Report to security@pageward.dev and give us a reasonable period to fix the issue before disclosing it.
There is no bug bounty. We will credit you if you would like us to.
7. Changes
We may update this policy as the product and the threat picture change. Material changes are notified to registered customers by email. The "last updated" date above always reflects the current version.