Acceptable Use Policy

Rules for using ShieldFive accounts and shared links, reporting abuse and enforcing acceptable use.

Last updated – 10 August 2026

This Acceptable Use Policy (“AUP”) governs use of ShieldFive accounts, storage, and share links. It supplements the Terms of Service and is incorporated into them by reference. ShieldFive cannot read user content — encryption keys never leave the user’s device — so this policy is enforced at the account level through reports, abuse signals, and rate-limit telemetry, not by scanning files.

1. Scope

This AUP applies to anyone with a ShieldFive account, anyone receiving a share link issued from a ShieldFive account, and anyone interacting with the ShieldFive service over its API. It applies regardless of plan tier (free, paid, or lifetime).

2. Permitted use

You may use ShieldFive to store and share files that you have the legal right to store and share. Personal archives, professional documents, source code, research data, journalism source material, photos, recordings — anything you would store in a private folder on a hard drive at home, you may store in ShieldFive.

3. Prohibited use

You may not use ShieldFive to store, share, or distribute:

  • Content that is illegal in your jurisdiction. You are responsible for knowing the law that applies to you and your activity. ShieldFive does not provide legal advice and does not vet content for legality.
  • Child sexual abuse material (CSAM) is absolutely prohibited. There are no exceptions. Reports of CSAM should be sent to [email protected]. Confirmed CSAM accounts are terminated immediately and reported to the appropriate authority in the jurisdiction where the report originates — NCMEC for US-sourced reports, INHOPE national hotlines for EU-sourced reports.
  • Malwareor content engineered to damage, disable, or gain unauthorised access to computer systems, networks, or devices — including ransomware payloads, droppers, exploit kits, and command-and-control artifacts staged through a share link.
  • Content intended to harass, threaten, or stalk a specific individual, including non-consensual intimate imagery and doxing materials.
  • Commercial spam delivered through share links — mass-distribution of unsolicited messages, phishing pages, fraud schemes, or scam-bait posing as legitimate content.
  • Content that circumvents ShieldFive’s abuse protections, including automated bulk-account creation, share-password rate-limit evasion, quota-enforcement bypass, or anti-abuse signal manipulation.
  • Resale or unauthorised transfer of ShieldFive accounts or share links for commercial purposes.

4. The zero-knowledge limit

ShieldFive cannot proactively scan content for AUP violations. Files are encrypted on the user’s device with keys ShieldFive never sees; what reaches our servers is ciphertext indistinguishable from random bytes. This is a deliberate architectural property, not an oversight. We will not weaken the cryptography, introduce server-side decryption capability, or deploy client-side content scanning to enforce this AUP.

Enforcement is therefore reactive. It happens when:

  • A user reports an abusive share link or account.
  • Abuse telemetry trips — for example, anomalous account-creation rates, share-password brute-force patterns, or download-spike patterns consistent with malware distribution.
  • A valid legal request from law enforcement compels action on account metadata.

5. Reporting abuse

Email [email protected] with:

  • The share URL or account identifier in question.
  • A description of what makes the use abusive — the AUP category it falls under and why.
  • Supporting context (screenshots, communications, jurisdiction, your role).

We acknowledge reports within 72 hours. CSAM reports are triaged with priority and we aim to act on them within hours, not days.

For security vulnerabilities in the platform itself — not abuse of the platform by another user — please email [email protected] instead. Abuse reports and vulnerability reports are routed and handled separately.

6. Enforcement actions

When an AUP violation is confirmed, ShieldFive may:

  • Suspend the account pending further review.
  • Disable a specific share link.
  • Refund a paid plan at our discretion.
  • Terminate the account permanently.
  • Preserve account metadata (email, IP history, payment data) for legal process.

ShieldFive cannot:

  • Decrypt the user’s stored files. The keys are on the user’s device, not on our servers.
  • Recover account contents after the account is deleted. Encryption keys are destroyed with the account.
  • Override the encryption used by another user to read what was sent to them.

ShieldFive complies with valid legal process in Spain, where the service is operated, and with reasonable cross-border requests served through mutual legal assistance treaties (MLATs) or equivalent. We do not preserve or disclose user data beyond what valid legal process compels. We do not pre-emptively share user data with law enforcement absent a binding order.

We intend to publish an annual transparency report covering the volume and outcome of legal requests received, once a meaningful baseline exists.

8. Changes to this AUP

Material changes to this AUP will be announced at least 30 days before they take effect, by email to account holders and via the public changelog. Non-material changes (typo fixes, clarifications that don’t alter the substance of any rule) may be made at any time and noted in the changelog. Continued use of ShieldFive after the effective date of a change constitutes acceptance of the revised AUP.

9. Contact