#1. Purpose and scope
CryptGPU rents dedicated GPU servers with root access, so you decide what runs on them. This policy sets the limits that protect other people, other customers and our network.
It applies to you, to anyone you allow to use your servers, and to any use of the website and the public pricing API. It is part of our Terms of Service: breaking it is a breach of those terms.
The examples below are not exhaustive. Anything illegal is prohibited, even if it is not listed. If you are unsure whether a use is allowed, ask us first through the contact form.
This policy takes effect on 23 September 2026.
#2. Prohibited content
You may not use the service to store, generate, process, publish or distribute:
- Child sexual abuse material (CSAM): any material that depicts or promotes the sexual abuse or exploitation of minors, whether real, drawn or generated by AI.
- Non-consensual intimate imagery: intimate or sexual images or videos of a real person made or shared without their consent, including sexual deepfakes.
- Content that infringes intellectual property: for example pirated software, films, music, books or datasets, or model weights you have no right to use or share.
- Malware: viruses, ransomware, spyware, exploit kits or botnet software intended to harm others, and servers used to distribute or control them.
- Other illegal content: for example material inciting terrorism or violence, or any content that is illegal under the laws that apply to you or to us.
We have zero tolerance for child sexual abuse material. When we become aware of it, we suspend the server at once, end the service, preserve evidence as the law requires and report it to the competent authorities.
#3. Prohibited activities
You may not use the service to:
- Gain unauthorized access to any system, account or data, for example by brute-forcing passwords, credential stuffing or exploiting vulnerabilities.
- Scan or attack networks: port or vulnerability scans, penetration tests or exploits against systems you do not own and are not authorized to test. Security testing of our own infrastructure requires our written permission.
- Launch denial-of-service attacks (DoS or DDoS), take part in them, or run “booter” or “stresser” services.
- Send spam or phishing: unsolicited bulk messages, phishing pages or kits, or messages with forged sender information.
- Run open services that are used for abuse, such as open proxies, open mail relays or open DNS resolvers exploited by others.
- Commit fraud: scams, fake shops, carding, impersonation, money laundering or any other deception for gain.
- Disrupt the service or other customers, for example by using IP addresses not assigned to you, forging network traffic, or interfering with our network or systems.
- Circumvent limits: get around technical or usage limits, restrictions or suspensions that we apply, including by opening a new account after a termination.
- Resell access without our agreement: reselling, renting out or sub-letting access to your servers or their GPUs, for example on a GPU marketplace, is allowed only with our written agreement. Running your own application or API on your servers for your customers is not reselling.
- Violate privacy: collect, process or publish personal data unlawfully, or track, stalk or harass people.
#4. Cryptocurrency mining
Cryptocurrency mining is not permitted unless we have agreed to it in writing. This includes proof-of-work mining of any coin or token, alone or through a pool, and similar workloads such as proof-of-space plotting.
This rule is about mining on our servers. It does not affect paying for the service in cryptocurrency.
To request an agreement, contact us through the contact form before you start.
#5. AI workloads
Training, fine-tuning and running AI models are core uses of the service. The following rules apply to them:
- No illegal output. Do not train, fine-tune or run models to generate illegal content, or to help commit a crime.
- No child sexual abuse material. Do not generate it, and do not train or adapt models to produce it. The zero-tolerance rule in section 2 applies.
- No non-consensual deepfakes. Do not create sexual or intimate images of real people without their consent, or realistic fake images, audio or video of real people intended to deceive, defraud, harass or defame.
- Respect model licenses. Follow the license and use restrictions of every model, dataset and piece of software you use, including non-commercial or acceptable-use terms set by their publishers.
- Use data lawfully. Make sure you have the right to use the data you train on, and respect privacy and data-protection law when it contains personal data.
- Follow the AI rules that apply to you, including any obligation to label or disclose AI-generated content.
We do not look at your models, data or outputs. We act on reports and on evidence of abuse, as described in section 9.
#6. Export controls and sanctions
Advanced GPUs are subject to export controls, and the service is subject to economic sanctions. Depending on the situation, the rules that apply may include the US Export Administration Regulations (EAR), the EU dual-use export rules, and sanctions adopted by the United Nations, the European Union, the United Kingdom and the United States, including those administered by the US Office of Foreign Assets Control (OFAC).
You must comply with every export-control and sanctions law that applies to you and to your use of the service. In particular, you may not use the service:
- if you are, or act for, a person or organization targeted by sanctions, or an organization owned or controlled by one;
- from, or for the benefit of anyone located in, a country or region subject to comprehensive sanctions or embargoes;
- for the development, production or use of nuclear, chemical or biological weapons, or of missiles or other systems designed to deliver them;
- for military, military-intelligence or other end uses or end users that export-control law prohibits, or for which it requires a license that has not been obtained;
- to give access to someone who could not use the service directly under these rules.
Do not use VPNs, proxies, intermediaries or false information to hide where you are, or on whose behalf you act, in order to evade these rules.
Export-control rules on remote access to advanced GPUs are evolving. We may refuse orders, restrict access or suspend the service where this is needed to comply with these laws, and we may update this section as they change. You are responsible for checking which rules apply to your own activities; if in doubt, take legal advice.
#7. Your security responsibilities
You have root access, so the security of your server is in your hands. At a minimum:
- keep the operating system, drivers and software up to date;
- use SSH keys or strong, unique passwords, and remove access that is no longer needed;
- expose only the services you need, behind a firewall;
- protect notebooks, inference APIs, dashboards and similar tools with authentication: tools like these are frequent targets when left open to the internet;
- act promptly on the security or abuse notices we send you.
If your server is compromised and used for abuse, you remain responsible for it. We may restrict or suspend it to stop the harm (see section 9), and you must secure it before we lift the restriction.
#8. Reporting abuse
To report abuse coming from a CryptGPU server or involving our website, use the contact form and choose the topic “Abuse”. To help us act quickly, include:
- what happened, and why you believe it is illegal or breaches this policy;
- the IP address or URL involved;
- the date, time and time zone;
- evidence such as log extracts or message headers.
Never send us child sexual abuse material, even as evidence. Tell us where it is, for example the URL or IP address, and report it to your national hotline or the police as well.
We use your email address to follow up on your report. We may pass the substance of your report to the customer concerned so that they can fix the problem, but we do not share your name or email address with them unless you agree or the law requires it.
Reports must be accurate and made in good faith.
#9. Enforcement
We investigate reports and signs of abuse. Depending on how serious the problem is, we may:
- ask you to fix it within a set time;
- restrict the server, for example by blocking some network traffic or ports;
- suspend the server;
- end the service and refuse future orders.
Where reasonably possible, we contact you before acting. We may act immediately, without notice, when the situation is urgent (for example, an ongoing attack, child sexual abuse material or a serious risk to people or systems) or when the law does not allow us to tell you.
When we restrict or end a service, we tell you what we did and why, unless the law or an ongoing investigation prevents it. If you think we made a mistake, reply through the contact form and we will review the decision.
We cooperate with law-enforcement and other competent authorities where the law requires it, and we preserve data related to an investigation when the law requires us to.
A restriction, suspension or termination under this policy does not entitle you to a refund, except where the law requires otherwise (see sections 5 and 8 of the Terms of Service).
#10. Changes to this policy
We may update this policy, for example to address new forms of abuse or changes in the law. We publish each new version on this page with its date. Changes take effect as described in section 14 of the Terms of Service; a change that the law requires may apply straight away.
