WP Cloud host partners must not use the platform, or allow their end users to use it, for the prohibited content and activity in their governing agreement and applicable Automattic policies. The partner is responsible for reflecting these restrictions in its own terms, acceptable-use policy, onboarding, and abuse process.
This page is a plain-language summary. The governing agreement and current policy control if they differ from this summary.
The categories below describe policy boundaries, not an exhaustive list of every prohibited value, product, or example.
Prohibited content and activity
Sites on WP Cloud must not:
- keep or share another person’s private or sensitive information without the required permission and safeguards;
- send spam or mass messages to people who did not request them;
- disrupt, attack, or attempt unauthorized access to services, networks, or accounts;
- create, distribute, or host malware, viruses, phishing, or identity-theft material;
- reverse-engineer or bypass protected technology except where an applicable open-source license or law permits it;
- rent, sell, or transfer access to WP Cloud outside the permissions in the partner agreement;
- facilitate prostitution or sex trafficking;
- sexualize, exploit, endanger, or otherwise harm children; or
- promote terrorism or targeted violence.
Some otherwise lawful categories can require additional review before WP Cloud accepts the workload. Examples can include adult content, gambling, financial services, regulated or restricted products, health products making medical claims, and services directed at children. A partner should resolve that question before onboarding the end user rather than treating absence from the short list as approval.
Personal and sensitive information
Sensitive information includes government identifiers, payment-card details, home addresses, phone numbers, private email addresses, medical records, and other data that can identify or harm a person if exposed. A site can collect information that a customer knowingly provides for a legitimate business purpose only when the partner and site owner have the required consent, security, retention, and privacy practices.
WP Cloud is not offered as a HIPAA-compliant service. See Compliance before accepting a regulated health-information workload.
Spam and service interference
Spam includes unsolicited bulk messages, automated marketing without consent, and continued contact after a recipient opts out. WP Cloud’s transactional email service is not a bulk-marketing service; see Transactional email for its limits and provider guidance.
Service interference includes excessive or abusive requests, attempts to crash systems, accessing accounts without authorization, and disrupting service for other users. Legitimate load testing, security research, and automation still need to follow the partner agreement and avoid affecting the shared platform.
Enforcement and changes
WP Cloud can use automated detection, reports, and human review to investigate violations. The host partner should maintain a process to contact the end user, preserve relevant evidence, remove prohibited material, suspend access when necessary, and respond to WP Cloud notices within the stated deadline.
Policies can change. Keep the partner’s legal and abuse contacts current and update customer-facing terms when the governing requirements change.