Legal Information

Our commitment to transparency, privacy, and security.

Acceptable Use Policy

Last updated: June 12, 2026

This Acceptable Use Policy ("AUP") governs use of the DotEnv Service and is incorporated into our Terms of Service. We may update it as the Service and threat landscape evolve.

1. Prohibited Uses

You may not use the Service to:

  • Violate any applicable law or regulation, or facilitate someone else doing so;
  • Store, manage, or distribute credentials, API keys, tokens, or other secrets belonging to third parties without their authorization, including stolen, leaked, or scraped credentials;
  • Store or distribute malware, ransomware, command-and-control configurations, or material that supports unauthorized access to systems or data;
  • Conduct security testing, penetration testing, vulnerability scanning, or load testing of the Service without our prior written authorization (see our Security Policy for responsible disclosure);
  • Probe, interfere with, or disrupt the Service or other customers, including attempting to bypass authentication, access controls, plan limits, or organization isolation;
  • Circumvent rate limits, usage metering, or seat counting, including by automated account creation or token sharing across organizations;
  • Resell, sublicense, or provide the Service to third parties as a competing or white-labelled offering without a written agreement with us;
  • Use the Service's infrastructure for unrelated workloads, such as cryptocurrency mining, proxying, or bulk data scraping;
  • Send spam or communications that violate anti-spam laws (including CASL);
  • Infringe the intellectual property, privacy, or other rights of any person;
  • Misrepresent your identity or affiliation, or impersonate DotEnv staff.

2. API Fair Use

API, CLI, and SDK access is subject to the rate and usage limits of your plan. Automated access must use authenticated API tokens, respect rate-limit responses (HTTP 429), and implement reasonable backoff. We may throttle traffic that degrades the Service for others.

3. Enforcement

We may investigate suspected violations. Depending on severity, we may warn you, remove content, throttle or suspend access, or terminate the account. For serious violations (including security attacks, stolen credentials, or illegal content) we may suspend immediately without notice and may notify law enforcement where appropriate.

4. Reporting Abuse

To report a violation of this AUP, contact [email protected]. For security vulnerabilities, use [email protected] as described in our Security Policy.