Effective 15 March 2026 · Version 1.1
This Acceptable Use Policy ("AUP") forms part of the Terms of Service. It applies to everyone who sends traffic through the FleetProxy network, including your employees, contractors, customers, and anyone using credentials issued to your account.
The network exists to make legitimate work possible: market research, price monitoring, ad verification, brand protection, SERP tracking, security testing you are authorised to perform, and access to information that is restricted by geography rather than by law. The prohibitions below exist to keep that work possible for everyone else.
1. Prohibited activities
You must not use the Service, or permit it to be used, to:
1.1. Gain or attempt to gain unauthorised access. Accessing any system, account, network, application, or data without the authorisation of the person entitled to grant it. This includes exploiting a vulnerability, bypassing a paywall or access control, using a session token or API key you were not issued, port scanning or vulnerability scanning a host you do not own or have not been engaged in writing to test, and any activity that would constitute an offence under the Computer Misuse Act 1990, the Computer Fraud and Abuse Act, or their equivalents.
1.2. Perform credential stuffing, password spraying, or brute-force authentication. Submitting credential lists — however obtained — against any login endpoint. Automating authentication attempts against accounts that are not yours. Trafficking in stolen credentials, session tokens, or cookies. This is the single most common cause of account termination on this network and it results in immediate, permanent termination without refund.
1.3. Participate in denial-of-service activity. Originating, relaying, amplifying, or coordinating any DoS or DDoS attack. Operating or contributing to a botnet, stresser, or booter service. Generating traffic whose purpose or foreseeable effect is to exhaust a third party's bandwidth, connections, compute, or rate limits. Load-testing infrastructure you do not own without the operator's written authorisation.
1.4. Send or facilitate spam and unsolicited messaging. Bulk unsolicited email, SMS, or platform messages. Harvesting email addresses or phone numbers for unsolicited contact. Creating accounts in bulk for the purpose of messaging. Evading a platform's anti-spam controls, a sender blocklist, or an unsubscribe request. Sending mail that forges its origin or misrepresents its sender.
1.5. Access, produce, or distribute child sexual abuse material. Any involvement whatsoever with CSAM, or with the sexual exploitation of a minor in any form. This results in immediate permanent termination, preservation of all associated records, and a report to the National Center for Missing & Exploited Children, the Internet Watch Foundation, and the appropriate law-enforcement authority. There is no warning, no appeal, and no refund.
1.6. Commit or facilitate fraud. Carding, testing stolen payment instruments, account takeover, fake-review generation, click fraud or impression fraud, ticket-bot activity that breaches applicable law, phishing site operation, romance or investment scams, identity theft, and money laundering. Creating accounts on any platform using another person's identity documents or details.
1.7. Distribute malware or command infrastructure. Hosting, delivering, or relaying viruses, ransomware, spyware, stalkerware, keyloggers, cryptominers installed without consent, or exploit kits. Operating command-and-control channels, malware droppers, or exfiltration endpoints. Obfuscating the origin of any of the foregoing.
1.8. Scrape or collect data in violation of applicable law. Automated collection is not prohibited in itself and much of it is entirely lawful. It becomes a breach of this AUP where it: requires circumventing an authentication or access control; continues after the operator has served you with a specific and legitimate demand to stop; collects personal data without a lawful basis under the data-protection law that applies to you; collects material in breach of copyright or database right; or breaches a court order or regulatory direction binding on you. You are responsible for making this assessment before you start, not after you receive a complaint.
1.9. Harass, threaten, dox, or stalk. Targeting an individual with abuse, surveillance, or the publication of private information. Evading a block, ban, or restraining order imposed to protect a person.
1.10. Breach sanctions or export controls. Using the Service from, or on behalf of any person or entity in, a jurisdiction subject to comprehensive sanctions, or where you or a beneficial owner appear on a sanctions list applicable to us.
1.11. Degrade the network. Exceeding published concurrency limits, sharing or reselling credentials without a written reseller agreement, attempting to enumerate or map the peer pool, targeting our own infrastructure or that of our peers, or any conduct that materially degrades service for other customers.
2. Special categories
2.1. Security testing. Permitted only against systems you own or where you hold written authorisation from the owner. We may ask to see it. Bug-bounty scope documents are acceptable evidence.
2.2. Multiple-account operation. Operating several accounts on a third-party platform is not prohibited by us. It may breach that platform's terms, which is a matter between you and them, and it becomes a breach of this AUP where it involves false identity documents, stolen identities, or fraud.
2.3. Adult content. Lawful adult material is permitted. Anything involving minors, non-consensual material, or content unlawful in the jurisdictions involved is not.
3. Reporting abuse
Send reports to [email protected] with the exit IP address, the destination, timestamps including a timezone, and evidence such as log excerpts or headers. We acknowledge within one business day. Reports concerning CSAM or an active attack are handled immediately, out of hours included.
4. Enforcement process
We aim to be proportionate. Except for the categories listed in clause 4.5, enforcement follows this sequence:
4.1. Investigation. We correlate the report against gateway authentication and metering records. We do not have traffic content and will not fabricate it; our evidence is connection metadata plus what the reporter supplies.
4.2. Notice. The account holder receives a description of the activity, the evidence we can share, and a deadline — normally 48 hours — to respond and remediate.
4.3. Restriction. Where the activity is continuing, we may restrict the affected credentials, targeting options, or destinations while the investigation runs, leaving the rest of the account operational.
4.4. Decision. We close the report, apply conditions to continued use, suspend the account, or terminate it. The account holder is told which and why.
4.5. Immediate action without notice. CSAM, active denial-of-service, credential stuffing in progress, malware command-and-control, and any activity presenting an imminent risk of serious harm are suspended on detection, before notice. Notice follows within 24 hours where lawful.
4.6. Appeals. Any decision other than one under clause 1.5 may be appealed to [email protected] within 14 days. Appeals are reviewed by someone who was not involved in the original decision. Provide evidence; assertions alone rarely change an outcome.
5. Consequences
Depending on severity and history: a warning; mandatory remediation with conditions on continued use; suspension of affected credentials; suspension of the account; permanent termination; forfeiture of unused balance and bandwidth where termination follows a clause 1 breach; and referral to law enforcement where required or warranted.
We reserve the right to suspend or terminate access under this policy at our discretion, and to refuse service to any person. We will not exercise that discretion arbitrarily, but we will exercise it quickly when the alternative is ongoing harm to a third party.
6. Preservation and disclosure
On a credible report or valid legal process we preserve relevant account records, authentication logs, and metering data. Disclosure to law enforcement requires valid legal process except where there is an imminent risk to life, or where the material concerns CSAM and the law requires proactive reporting. Every request and disclosure is logged.
What this means
Use the network for legitimate work and you will never hear from us. Do not break into things, do not test stolen passwords, do not take part in attacks, do not send spam, do not touch anything involving children, do not commit fraud, do not move malware, and do not collect data the law where you are says you cannot collect. If someone reports you, we will tell you what was reported and give you a chance to explain and fix it — except for the small number of categories where waiting would let real harm continue, and there we switch you off first and explain afterwards. We cannot see your traffic, so we cannot police it proactively; we act on evidence, and we act quickly.