Acceptable use policy: the five things it has to say to be worth having

An acceptable use policy is a short document that spends most of its life doing nothing and then has to carry an argument. The version that carries the argument names what it covers, what it forbids, what happens when somebody does it anyway, and how a complaint reaches you. The version that does not is a page of adjectives. This is the difference, in five parts.

What it covers, named surface by surface

A policy that says our services means nothing when the question is whether it reaches an API, a public forum, a shared workspace or an email address on your domain. List the surfaces. This is the single most common gap, and it is the one that decides whether the policy applies at all to the thing somebody just did.

What is prohibited, in conduct rather than adjectives

Abusive, inappropriate and unacceptable are unenforceable because two people read them differently. Conduct is enforceable: sending unsolicited bulk email, scraping at a rate that degrades the service, uploading material you have no right to, attempting to access another account. Each line should be something you could point at a log and demonstrate.

What happens, and who decides

Suspension, removal of content, termination, referral. A policy with no stated consequence forces you to invent one under pressure, which is exactly when you will invent an inconsistent one. Say who decides, and say whether notice is given before or after.

How a complaint reaches you

An address that is read. If the policy invites reports and the address bounces, the policy is worse than nothing because it has created an expectation. This is also the line that makes the document useful to the people it protects rather than only to you.

A version and a date

The question later is never what the policy says. It is what the policy said in March, when the account you are about to terminate did the thing. A version number and an issue date cost nothing to add, and they are the whole difference between a document you are asserting and a record you can produce.

Questions people ask about acceptable use policy

Is this the same as terms of service?

No. Terms of service is the whole commercial relationship: payment, liability, termination, governing law. An acceptable use policy is the conduct part, pulled out so it can be changed and enforced on its own. Small products often merge them, which is fine as long as the conduct rules are still findable.

Does it need to be signed?

Usually not, but it has to be presented. A policy nobody could reasonably have seen is hard to enforce, so link it where people sign up and keep the record of which version was live then.

How long should it be?

Short enough to be read. The five parts above fit on one page, and a page that is read is enforceable in a way that six pages of prohibited conduct are not.

Sources

Related answers

Keep the request record: $10 a monthStart the request record