HolyCode Cloud — Acceptable Use Policy
Effective date: July 14, 2026 Provider: TigerPoint Technologies LLC ("TigerPoint," "we," "us"), a New York limited liability company based in Brooklyn, NY, United States. Service: HolyCode Cloud, a hosted, persistent, always-available Linux coding workstation that wakes from idle in about one second ("the Service" or "your workstation").
1. What this policy is
HolyCode Cloud gives you a full Linux machine in the cloud that you control. Because you can run almost any software on it, we need a short, clear set of rules about what you may and may not do. This Acceptable Use Policy ("AUP") is part of your agreement with us, and you accept it when you accept the Terms of Service at checkout. If you break it, we may act under Section 10.
This policy applies to everyone who uses a HolyCode Cloud workstation, and to everything you run, store, transmit, or generate on it.
Your Terms of Service govern the overall relationship. If anything here conflicts with the Terms of Service, the Terms of Service control. The order of precedence across our documents is: the Terms of Service, then this AUP, then the Refund Policy (which controls refunds), then the Privacy Note (which controls data handling).
2. Eligibility and export compliance
During the beta, HolyCode Cloud is offered to customers in the United States only; Stripe Checkout restricts purchases to US billing details. By using the Service you represent that you are not located in, or a national of, a country subject to US embargo or comprehensive sanctions, and that you are not on any US government denied-parties or sanctions list (such as the OFAC Specially Designated Nationals list). You agree to comply with all applicable US export-control and sanctions laws and not to use, export, or re-export the Service in violation of them. Full eligibility and account terms are in your Terms of Service.
3. You are responsible for your workstation
Your workstation is yours to operate, and you are responsible for what happens on it. That includes:
- Everything you run or store, including code, data, AI agents, and automated processes, whether you started them by hand or an agent started them for you.
- Your credentials. Keep your login and workspace password private. You are responsible for activity under your account.
- Your own API keys (BYOK). You bring your own Anthropic, OpenAI, Google, or other provider keys or subscriptions. Those keys live on your workstation's disk. We do not upload or centrally store your keys, we do not access them in the normal course of operating the service, and we do not resell AI tokens. You are responsible for keeping your keys secure and for following the terms and usage limits of whatever AI provider you use, including any restrictions that provider places on automated or agentic use. You accept that the AI provider — not us — may throttle or revoke your key. HolyCode Cloud is not an AI model provider.
- Anything anyone you allow onto your workstation does. Their actions count as yours.
4. Normal use is welcome and unlimited within your plan
We built this for serious, heavy coding. Within the CPU, RAM, and storage of your plan, your normal development use is unlimited and unmetered — only outbound bandwidth (egress) carries a fair-use allowance (Section 5). That expressly includes:
- Running one or more AI coding agents (Claude Code, Codex, OpenCode, Gemini, or others), including long-running, unattended, or overnight agent loops.
- Compiling, building, and running large test suites and workloads.
- Legitimate browser automation and headless-browser tasks for your own development, testing, and workflows.
- Keeping your workstation busy for long stretches, day after day.
You never need to ask permission for ordinary heavy development work. Your plan's hardware is your ceiling, and hitting that ceiling is fine.
5. Resource limits and fair-use bandwidth
- CPU, RAM, and disk are physically fixed by your plan. You cannot exceed them, and using them fully is allowed. Compute is unlimited within your box.
- Outbound network bandwidth (egress) is the one resource not capped by the box, so it carries a monthly fair-use allowance that scales with your plan. The allowance exists only to stop abuse (Section 6), not to limit real development. Ordinary coding, package downloads, deployments, and agent traffic will not come close to it.
The current per-plan monthly egress fair-use schedule is:
| Plan | Monthly outbound (egress) fair-use allowance |
|---|---|
| Lite | 250 GB |
| Plus | 500 GB |
| Pro | 1 TB |
| Ultra | 2 TB |
| Max | 4 TB |
This schedule is the authoritative statement of the egress fair-use allowance. Where the Terms of Service refer to a fair-use bandwidth limit, they refer here.
- If your egress approaches or exceeds your plan's allowance, we will normally contact you first and, where it makes sense, suggest a larger plan, before taking any stronger step. A legitimate spike is treated differently from deliberate abuse.
6. Prohibited uses
You may not use HolyCode Cloud, or allow it to be used, for any of the following.
Resource and network abuse
- Cryptocurrency mining or any equivalent proof-of-work / token-minting workload.
- Denial-of-service attacks, traffic flooding, or deliberately overloading any system, network, or third party.
- Unauthorized scraping or crawling, including scraping that violates a target site's terms of service, robots restrictions, or applicable law. (Legitimate automation against systems you own or are authorized to access is fine.)
- Egress abuse beyond the fair-use schedule (Section 5), including running the workstation as a seedbox, media/torrent distribution node, file-sharing relay, CDN, VPN/proxy exit for others, or similar bandwidth-shifting service.
Distribution and messaging abuse
- Distributing pirated or unlicensed software, media, or "warez," or circumventing technical protection measures.
- Spam or unsolicited bulk/mass email or messaging, sending mail in violation of anti-spam laws (such as CAN-SPAM), or operating open mail relays or bulk-sending infrastructure.
Illegal or harmful content and activity
- Hosting, generating, storing, or transmitting content that is illegal, or using the Service to plan or carry out illegal activity.
- Child sexual abuse material (CSAM) is absolutely prohibited. We report it to the appropriate authorities and terminate immediately and without notice.
- Content or activity that infringes others' intellectual property (see Section 7), or that is used to harass, defraud, or harm others.
- Distributing malware, ransomware, botnet command-and-control, phishing kits, or credential-harvesting tools intended to harm others.
Platform and security abuse
- Attempting to break tenant isolation or escape your workstation's boundary to reach the underlying host, our infrastructure, or another customer's workstation or data.
- Attacking, probing, or interfering with the HolyCode Cloud platform, our providers, or other users, including unauthorized penetration testing of our systems, exploiting vulnerabilities, or evading our security controls. (You may run security tooling against systems you own or are explicitly authorized to test; you may not point it at us, our infrastructure, or anyone else without permission. To report a vulnerability responsibly, see Section 11.)
Account and seat abuse
- Sharing a single workstation or login among multiple people to avoid paying for seats. Using your own workstation yourself across your own devices is fine. Team use by multiple people is available only under a separate, signed team agreement (team plans are concierge-only and not yet live); the terms of that agreement, not self-checkout, govern multi-person use and are how the seat-sharing prohibition is enforced against team buyers.
- Reselling, sublicensing, or providing your workstation as a service to third parties without our written permission.
We may add clarifying examples over time, but the underlying rules above are what govern.
7. Copyright and DMCA
We respect intellectual property rights and expect you to do the same. Hosting, storing, or distributing content that infringes someone else's copyright is prohibited under Section 6.
If you believe content on a HolyCode Cloud workstation infringes your copyright, send a notice to our designated agent at support@holycode.cloud (subject line "DMCA"). Your notice should include: (1) your physical or electronic signature; (2) identification of the copyrighted work you claim is infringed; (3) identification of the material you claim is infringing and enough information for us to locate it; (4) your contact information; (5) a statement that you have a good-faith belief the use is not authorized by the copyright owner, its agent, or the law; and (6) a statement, under penalty of perjury, that the information in your notice is accurate and that you are the copyright owner or authorized to act on the owner's behalf.
If we remove or disable material in response to a notice, we will make reasonable efforts to notify the affected customer, who may submit a counter-notice containing the corresponding elements required by law (identification of the removed material and its prior location, a statement under penalty of perjury of a good-faith belief that it was removed by mistake or misidentification, and the customer's contact information and consent to jurisdiction). We may restore the material as permitted by law after receiving a valid counter-notice.
We will terminate, in appropriate circumstances, the accounts of customers who are repeat infringers.
8. Your data and backups
We store your email and your workstation data (your code and files) on persistent storage. Backups are best-effort and retained per your plan's tier (roughly 7 to 90 days). We do not guarantee that any particular backup can be recovered.
Storage and backups do not change your obligations under this policy: the fact that something is stored or backed up does not make prohibited use acceptable.
If you cancel, you have a 7-day window to export your workstation data. After that window, we initiate deletion and force-purge your backups early, overriding the normal retention window. Residual copies may persist in our providers' systems and purge on their normal rolling cycle, up to 30 days. We do not claim instant, irreversible deletion of every copy everywhere. This is described consistently in your Terms of Service, Refund Policy, and Privacy Note.
Data-breach notification. If we become aware that your data has been materially compromised, we will notify affected customers without undue delay.
9. Early-access / no availability guarantee
HolyCode Cloud is offered as an early-access beta. The Service runs on third-party infrastructure that can have outages, and we do not promise any specific uptime, availability, or service-level guarantee during the beta. This does not excuse prohibited use, and it does not entitle you to use the Service in violation of this policy.
10. How we enforce this policy
When we believe you have violated this policy, our usual approach is to act in proportion to the problem, escalating as needed:
- Warning — we notify you and give you a chance to fix it.
- Throttle — we temporarily limit bandwidth or resources (for example, on egress overages).
- Suspend — we pause your workstation while we investigate or wait for you to resolve the issue.
- Terminate — we close the workstation and, where appropriate, the account.
We may skip steps. For severe cases, including illegal content, security attacks, attempts to break isolation, active harm to others, or clearly deliberate abuse, we may suspend or terminate immediately and without prior notice, and we may preserve or disclose information where required by law or to protect people and systems.
Where practical and safe, we will tell you why we acted and give you a chance to respond. Termination for cause, and its effect on any fees or refunds (including the 7-day money-back guarantee), is governed by your Terms of Service. We are not liable for losses resulting from enforcement action taken in good faith under this policy.
11. Reporting abuse or vulnerabilities
If you see abuse of HolyCode Cloud, or you believe you have found a security vulnerability, please contact us at support@holycode.cloud. Do not exploit a vulnerability beyond what is minimally necessary to demonstrate it, and do not access, alter, or exfiltrate other users' data.
12. Changes to this policy
We may update this policy as the Service grows and as new kinds of abuse appear. If we make material changes, we will take reasonable steps to notify active customers (for example, by email or a notice on https://holycode.cloud). Continued use after a change means you accept the updated policy. This policy is governed by the laws of New York.
Questions about this policy: support@holycode.cloud.