Acceptable Use Policy

Effective August 6, 2026 · Last updated August 6, 2026

Assistance gives you tools that run inside other people's communities: automations that post on their behalf, packages that other servers install, transcripts that capture conversations, and verification that decides who gets in. This policy sets out what those tools may not be used for. It is part of our Terms of Service, and breaking it is breaking them.

The rules below are specific on purpose. We would rather tell you exactly what gets a package removed than reserve a vague right to remove anything.

1. Scope

This policy applies to everyone who uses Assistance — server operators, staff, members who interact with the bot, and anyone using the API or package registry. It covers the content you publish, the automations you configure, and the way you interact with our systems.

It does not govern your Discord server's own rules. Your community sets those. It governs what you may do with our Service.

2. Content you may not publish

This applies to packages, library files, templates, custom command responses, automation output, ticket content, package names and descriptions, and anything else you put into the Service.

Absolutely prohibited

  • Child sexual abuse material, or any sexualization of minors. Zero tolerance. We remove it, terminate the account immediately and permanently, preserve evidence, and report it to the National Center for Missing & Exploited Children and to law enforcement. There is no appeal.
  • Content that facilitates terrorism, mass violence, or violent extremism, or that promotes an organization engaged in it.
  • Content that solicits, arranges, or facilitates illegal transactions — controlled substances, weapons, stolen credentials or accounts, fraudulent documents, or stolen data.
  • Content that promotes suicide or self-harm, or that provides instructions for either.

Also prohibited

  • Infringement. Content you do not have the rights to publish, including copied packages, licensed assets used outside their license, and trademarks used without permission. Copyright complaints follow our DMCA Policy.
  • Harassment and threats. Content that targets a person for abuse, threatens violence, or is designed to intimidate. This includes automations built to mass-mention or pile onto an individual.
  • Hateful content. Content that attacks or dehumanizes people based on race, ethnicity, national origin, religion, caste, sexual orientation, sex, gender identity, disability, or serious disease.
  • Doxxing.Publishing another person's private information — home address, phone number, workplace, government ID, financial details, or an unpublished legal name — without their consent. Building an automation that collects or exposes it is the same violation.
  • Sexual content. Pornographic or sexually explicit content in public packages, package listings, or anywhere it can be seen without a deliberate choice to see it.
  • Impersonation.Packages, commands, or bot messages that pretend to be Assistance staff, Discord staff, another service, or another person, including packages named or described to be mistaken for someone else's.
  • Deception.Packages whose described purpose differs from what they actually do — a "welcome message" package that quietly grants roles, exfiltrates data, or messages members off-topic.
  • Malicious payloads. Content that links to malware, phishing pages, token grabbers, or crypto drainers, or that instructs a member to run code or install software that does.
  • Spam. Bulk unsolicited messaging, advertising unrelated to the server, or automations built to promote something into communities that did not ask for it.

3. Conduct we do not allow

  • Accessing accounts, servers, or data you are not authorized to access, including using an API token for a server you no longer administer.
  • Evading rate limits, running the API through rotating credentials or addresses, or scraping the dashboard, docs, or registry rather than using the API.
  • Registering accounts in bulk, or using alternate accounts to evade a suspension.
  • Reverse engineering, decompiling, or probing the Service except as section 6 permits.
  • Reselling access to Assistance, or sublicensing Plus slots you did not buy.
  • Inflating install counts, ratings, or other public metrics through automation or coordinated accounts.
  • Using ticket transcripts to publish a private conversation for harassment, or publishing a transcript link to expose a member.
  • Interfering with the Service's operation — denial of service, deliberately malformed requests, or exploiting a bug rather than reporting it.

4. Resource abuse

Assistance is a support and moderation tool. Do not use it as general infrastructure:

  • No cryptomining, distributed computation, or workloads unrelated to running your community.
  • No using library file storage as a general file host, backup target, or content delivery network.
  • No automations that loop, retry, or fan out in ways designed to consume capacity rather than accomplish something.
  • No bulk direct messaging through the notification system. Member notifications exist to tell someone about their own ticket, not to reach an audience.

5. Verification and risk data

Verification and member risk profiles exist so moderators can keep raids and alt accounts out. They are aids to a human decision, not a verdict, and they carry their own rules:

  • Do not use risk scores or verification data to harass, expose, or retaliate against a member.
  • Do not export risk data, or combine it with data from elsewhere, to build a profile of someone across communities. The signals are deliberately hashed and scoped to one server so this is not possible with what we provide; do not try to defeat that.
  • Do not represent an Assistance risk score to your members as proof that someone is a bad actor. It is a probability, and it is sometimes wrong.
  • Do not attempt to circumvent verification on a server you are joining, including by sharing verified accounts or automating the flow.

6. Security research

We want vulnerability reports and will not pursue you for finding one in good faith. You may test against your own account and your own server if you:

  • Do not access, modify, or retain data belonging to anyone else, and stop as soon as you confirm a vulnerability exists.
  • Do not degrade the Service for other users — no denial-of-service or high-volume automated scanning.
  • Report what you find to TODO_EMAIL_SECURITY before disclosing it anywhere else, and give us a reasonable time to fix it.
  • Do not extort us, and do not sell the finding to anyone else.

Stay inside those lines and we will treat your testing as authorized under this policy and under the Computer Fraud and Abuse Act. We do not currently pay bounties.

7. Reporting a violation

Report a package through the report abuse form, which routes to our moderation queue. For anything else, email TODO_EMAIL_LEGAL.

Include, where you can:

  • A link to the package, server, or content.
  • Which rule above you believe was broken.
  • What you saw, and when.
  • Screenshots or message links.

Copyright complaints go through our DMCA Policy instead, because that process has statutory requirements this one does not.

Reports made in bad faith — to remove a competitor, or to harass a publisher — are themselves a violation of this policy.

8. Enforcement

Depending on what happened, how severe it was, and whether it has happened before, we may:

  • Warn you and ask you to fix it.
  • Remove or unlist a package, or revert content.
  • Restrict a feature — publishing, the API, notifications.
  • Suspend an account or a server's access temporarily.
  • Terminate an account permanently.
  • Preserve evidence and report to law enforcement, where the law requires it or the harm is serious.

We aim for the least disruptive action that solves the problem. The prohibitions in section 2 under "absolutely prohibited" skip that ladder entirely.

When we remove content or restrict an account, we tell the person affected what was removed and which rule it broke, unless telling them would interfere with a legal investigation or put someone at risk.

9. Appeals

If you think we got it wrong, reply to the enforcement notice or email TODO_EMAIL_LEGAL within 30 days. Tell us what you believe we misread. A person who was not involved in the original decision will review it, and we will respond within 14 days. If we were wrong, we restore what we removed.

Content removed under the child safety rule in section 2 cannot be appealed.

10. Changes

We update this policy as new kinds of abuse appear. Material changes are announced in our support server before they take effect, and the dates at the top of this page always reflect the current version.