1. Core rule
Use Noria only for systems, accounts, communities, recipients, and data you are authorized to automate. A technical ability to send a request or select a target is not proof of authorization. You must use safeguards proportionate to the possible impact.
2. Unauthorized access and security abuse
You may not use Noria to:
- access, scan, test, control, or interfere with a system or account without authorization;
- steal, solicit, expose, validate, or reuse passwords, tokens, cookies, keys, or credentials;
- deliver malware, ransomware, malicious code, exploit payloads, phishing, or deceptive login pages;
- bypass authentication, authorization, quotas, rate limits, captchas, moderation, or safety controls;
- probe private, local, link-local, cloud-metadata, or otherwise non-public network resources;
- conceal the origin or purpose of an attack or coordinate abusive traffic.
3. Harmful and deceptive automation
You may not automate:
- unsolicited bulk messages, spam, fake engagement, or platform manipulation;
- harassment, stalking, threats, doxxing, discrimination, or targeted abuse;
- fraud, scams, impersonation, phishing, misleading claims, or deceptive transactions;
- mass bans, deletions, permission changes, destructive actions, or raids without clear authorization;
- the exploitation, sexual abuse, or endangerment of children;
- credible threats to life or safety, terrorism, or instructions intended to facilitate violent wrongdoing.
4. Data, surveillance, and intellectual property
You may not:
- collect or process personal data without a lawful basis, transparency, and appropriate security;
- conduct unlawful monitoring, profiling, facial recognition, or surveillance;
- expose private messages, identifiers, credentials, or sensitive data in logs or public templates;
- infringe copyright, trademark, privacy, publicity, database, or other third-party rights;
- upload regulated or high-risk data that the beta is not designed to protect.
5. Platform and infrastructure abuse
You may not:
- violate the applicable rules of Discord, Twitch, Google, or another connected provider;
- scrape, overload, disrupt, benchmark abusively, or degrade Noria or another service;
- create accounts or workflows to evade a restriction, suspension, quota, or enforcement action;
- resell or provide unauthorized access to the beta;
- publish a template with hidden behavior, obfuscated malicious logic, secrets, or unsafe defaults.
6. Security research
Good-faith research is welcome only when it stays within accounts and resources you own or have explicit permission to test. Do not access other users' data, disrupt service, use social engineering, run denial-of-service tests, or publicly disclose a vulnerability before we have had a reasonable opportunity to investigate. Report vulnerabilities privately through the reporting form or by email.
7. Enforcement
Depending on severity, intent, history, and urgency, Noria may warn the user, throttle or stop executions, quarantine a workflow, remove a template, revoke access to an integration, suspend an account, preserve relevant evidence, or notify a competent authority or affected provider where permitted or required. Immediate protective action may be taken before contacting the user.
Decisions may be contested by contacting [email protected] with the decision or report reference and the reasons for reconsideration.
8. Reporting abuse
Submit a precise notice through Report abuse. Include the exact workflow, execution, public template, account, or integration identifier, the facts, the reason it may be unlawful or unsafe, and evidence you may lawfully share. Do not include secrets or unnecessary personal data.