Acceptable Use Policy (AUP)
Last updated: 2026-05-21 Version: 1.0
This Acceptable Use Policy ("AUP") tells you what you may and may not do on the Swaps service. It complements the Terms of Service §10 by giving concrete examples and the enforcement framework. If you breach this AUP, we may suspend or terminate your access without notice (see Limits & Enforcement).
1. The short version
- Use the Service for its intended purpose. Compare crypto-buying options, redirect to a Provider, manage your Account.
- Stay within the rate limits. Don't try to scrape, bombard, or extract.
- Be one person with one Account. No multi-accounting, no proxy-farming, no referral fraud.
- Don't help criminals. No money laundering, no sanctions evasion, no fraud, no tax evasion.
- Don't attack the Service. No DDoS, no exploits, no malware, no impersonation.
If you are a security researcher, see Section 8 — we welcome responsible disclosure.
2. Prohibited transactional uses
You must not use the Service to:
- Launder money or finance terrorism — including by structuring transactions to evade reporting thresholds, by funnelling proceeds of crime, or by routing funds to or from sanctioned parties.
- Evade sanctions — including by transacting from a sanctioned jurisdiction, on behalf of a sanctioned person, or with assets known to derive from sanctions evasion. See the Sanctions policy.
- Commit fraud or assist fraud — including phishing, romance scams, pig-butchering, fake-investment scams, business-email compromise, and any other scheme intended to deceive a third party.
- Evade tax obligations — including by deliberately obscuring transaction trails to avoid tax in your jurisdiction.
- Buy crypto with funds obtained illegally — including stolen card numbers, stolen bank credentials, or fraudulent chargeback flows.
- Facilitate market manipulation — including wash trading, spoofing, layering, and pump-and-dump schemes.
- Buy or sell crypto-assets you are not legally allowed to in your jurisdiction.
- Use the Service while under 18 years of age — see the Terms of Service §3.1.
3. Prohibited technical uses
You must not:
- Bypass or attempt to bypass rate limits, geo-blocks, sanctions screening, KYC redirects, or any other access control.
- Scrape the Service beyond published rate limits. Reasonable, attributed scraping for research consistent with the rate limits is permitted; aggressive scraping is not.
- Use automated tools to create Accounts, complete checkouts, or click through redirects, except via the documented developer surfaces (agent.swaps.app, MCP package) within their own rate limits — see the Developer / API / MCP Terms.
- Operate multiple Accounts to circumvent referral, Search-credit, or rate-limit controls. One natural person = one Account.
- Reverse-engineer, decompile, disassemble, or attempt to extract the source code of any Service component beyond what is necessary for interoperability and permitted by mandatory law.
- Interfere with the operation of the Service — DDoS, request flooding, exploit attempts, fuzz testing without prior authorisation, malware injection.
- Probe or test vulnerabilities in the Service except as part of the responsible-disclosure programme (Section 8).
- Impersonate Swaps, any Provider, any other user, or any other natural or legal person.
- Use a VPN or proxy to make the Service believe you are in a different jurisdiction than your real jurisdiction. (You may use a VPN for privacy reasons consistent with your lawful jurisdiction.)
4. Prohibited content and communications
You must not submit, transmit, or upload to the Service:
- Content that is unlawful in your jurisdiction or in Estonia.
- Content infringing intellectual-property rights.
- Content that defames, harasses, threatens, or harms others.
- Content that contains malware, viruses, or destructive code.
- Personally identifiable information of third parties without their consent (other than wallet addresses, which are necessary for the Service).
- Content depicting or encouraging self-harm, child sexual exploitation, terrorism, or other content prohibited by Estonian or applicable law.
5. Specific subproduct rules
5.1 Search Address Report
- One Account = one set of free reports (3 by default, then paid).
- Multi-accounting to obtain more free reports is prohibited and may result in revocation of all Reports on associated Accounts.
- Reports are for your own informational use. You may not republish a Report as if it were certified or as a substitute for professional investigation. Quoting individual data points with attribution to "Swaps Address Report" is permitted.
- Mass-querying addresses (more than 50 unique addresses per hour from a single Account, IP, or device) is treated as scraping and rate-limited or blocked.
- See the Search Address Report Terms for full Search-specific terms.
5.2 Friend Rate Referral
- Self-referral (referring yourself via a second Account, alternate email, or alternate device) is prohibited. Both Accounts will lose Credits and may be terminated.
- Referring fake users (bot Accounts, dummy emails) is prohibited.
- Paid-traffic referral farming — operating ad campaigns that funnel users to your referral link with the primary aim of harvesting Friend Rate Credits — is prohibited.
- Inflating referral counts via Account-creation incentives that violate any other AUP rule is prohibited.
- See the Friend Rate Programme Terms for full referral terms.
5.3 Developer / API / MCP
- Free-tier rate limit: 60 requests per minute per IP, with burst tolerance and 429 responses including
Retry-After. Sustained breaches result in IP-level blocks. - API keys must not be embedded in client-side code shipping to end users.
- You may not resell or sublicense API access without our prior written consent.
- See the Developer / API / MCP Terms for full developer terms.
5.4 Cosmic Graph / address visualisation
- Same data-source acknowledgement as Search reports.
- No automated re-rendering at high frequency from many addresses without prior arrangement.
5.5 Payment Links
In addition to the transactional and technical prohibitions in Sections 2 and 3, you must not use Payment Links:
- to invoice or collect payment for unlawful goods or services;
- to facilitate fraud, money laundering, or terrorist financing;
- to misrepresent who is requesting payment, or for what — including impersonating another business or person on the public
/paypage, or falsely self-declaring as a business or individual to obtain a rail or limit you are not entitled to.
See the Payment Link Terms. We may deactivate any link and suspend any Merchant for breach, and the Provider may independently decline, reverse, or block any transfer under its own controls.
5.6 Payroll
In addition to the transactional and technical prohibitions in Sections 2 and 3, the Employer must not use Payroll:
- to evade tax, conceal income, or disguise the nature, source, or ownership of funds;
- to pay any sanctioned or otherwise prohibited person or entity (see the Sanctions policy);
- to misrepresent the nature of a payment or the identity of a Recipient, or to make payments the Employer is not lawfully entitled to make.
See the Payroll Terms. Prohibited use may result in suspension or termination of Payroll access.
5.7 Wallet Service
- You must not abuse the non-custodial Wallet Service — including by using it to launder funds, to receive or move proceeds of crime, or to interact with sanctioned addresses or protocols (see Section 2 and the Sanctions policy).
- You must not attempt to extract, phish, or solicit another person's passkey, seed phrase, session signing key, or any signing material, or impersonate Swaps support to do so. Swaps never asks for this material.
- See the Wallet Service Terms.
6. Rate limits (anonymous users)
| Endpoint | Limit | Throttle behaviour |
|---|---|---|
/best-quote (anonymous) | 30 req / min / IP | 429 with Retry-After |
/api/search (free reports) | 10 req / min / IP | 429 |
| Static page loads | Cloudflare default | Bot management |
| AI Concierge | 20 messages / hour / Account or IP | 429 + UI message |
agent.swaps.app/llm/* | 60 req / min / IP | 429 |
We reserve the right to tighten limits in response to abuse.
7. Enforcement
Breaches of this AUP can result in:
| Severity | Action |
|---|---|
| Minor (e.g., rate-limit overrun) | Throttle (429) until limit window resets |
| Moderate (e.g., scraping, multi-accounting attempt) | Temporary IP block, Account warning |
| Major (e.g., sanctions evasion, fraud, AML breach) | Permanent Account ban, IP block, data retention for law-enforcement cooperation |
| Critical (e.g., attack on the Service, child sexual exploitation, terrorist financing) | Immediate permanent ban, lawful disclosure to authorities, possible legal action |
We may suspend or terminate access without notice. We do not refund Credit balances if termination follows a major or critical AUP breach. For minor or moderate breaches, residual Credit balances are refunded on request.
See Limits & Enforcement for the full enforcement procedure, appeals path, and DSR interaction.
8. Responsible disclosure
If you discover a security vulnerability in the Service, please report it to security@swaps.app. We commit to:
- Acknowledge receipt within 3 business days.
- Triage and respond with status within 14 days.
- Not pursue legal action against good-faith researchers who:
- Test only on accounts they own or have explicit permission to test on;
- Do not access, modify, or destroy other users' data;
- Do not perform DoS attacks or attacks that degrade availability;
- Give us reasonable time (90 days default) to remediate before public disclosure;
- Do not extort, threaten, or demand payment as a condition of disclosure.
We do not currently run a paid bug-bounty programme but recognise meaningful disclosures publicly with consent.
9. Reporting abuse
If another user abuses you through the Service or you suspect abuse of the Service generally:
- Fraud or scams: legal@swaps.app
- Security: security@swaps.app
- Sanctions / AML concerns: legal@swaps.app
- General complaint: legal@swaps.app
We aim to acknowledge reports within 3 business days.
Contact: legal@swaps.app