Effective date: 1 August 2026
1. Scope
This Acceptable Use Policy ("Policy") applies to everyone who uses Nibit's applications, desktop builds, websites, storage, sync, AI features, collaboration, sharing, and chat features (the "Services"). It forms part of the Terms of Service and is referenced there at section 9.
Nibit is a private notebook. Most of what you write is seen only by you, and this Policy is not an invitation for us to read it - we do not scan private content looking for violations. This Policy matters most where content leaves your account: sharing links, collaboration, groups, chat, and AI requests. It also sets the boundaries on how you may treat the infrastructure itself.
Breaching this Policy can lead to content removal, feature restriction, suspension, or termination under section 6, and you can appeal under section 7.
2. Prohibited content and conduct
You may not use the Services to create, store, share, transmit, or generate:
Illegal material
- child sexual abuse material, or any sexualised depiction of a minor, real or generated - we report this to the relevant authorities and preserve records as law requires;
- content that facilitates human trafficking, exploitation, or the sexual abuse of any person;
- material that is otherwise unlawful in a jurisdiction where you or your recipients are located.
Harm to people
- credible threats of violence, incitement to violence, or glorification of violence against people or groups;
- harassment, stalking, bullying, or targeted abuse;
- hate speech attacking people on the basis of race, ethnicity, national origin, caste, religion, disability, disease, age, sex, gender, gender identity, or sexual orientation;
- doxxing - publishing another person's private information without a lawful basis;
- non-consensual intimate imagery, or sexual content involving anyone who has not consented to its distribution;
- content that encourages self-harm, suicide, or eating disorders, other than recovery-oriented or educational material.
Deception and rights violations
- material that infringes copyright, trade marks, patents, trade secrets, database rights, or moral rights - see the Copyright and DMCA Policy;
- impersonation of a person, organisation, or Nibit itself, including misleading profile identities;
- phishing, fraud, scams, forged documents, counterfeit goods, or fake credentials, transcripts, or identity documents;
- coordinated inauthentic behaviour, spam, or bulk unsolicited messaging through chat, sharing, or invitations.
Dangerous technical content
- malware, ransomware, exploits, or malicious code, except where held for legitimate defensive research and not distributed through the Services;
- instructions that provide meaningful operational uplift toward weapons capable of mass casualties - chemical, biological, radiological, nuclear, or high-yield explosive;
- material intended to compromise other people's accounts, devices, or networks.
Other people's data
- personal information you have no lawful basis to hold or share;
- regulated records the Services are not designed to hold, as described in Terms section 5.3 - payment-card data, authentication secrets for other systems, government identity documents, or protected health information held on behalf of a covered entity, unless we have agreed otherwise in writing.
3. Security research and vulnerability disclosure
We want to hear about security problems, and we will not pursue researchers who follow this section.
Safe harbour. If you make a good-faith effort to comply with this section, we will treat your research as authorised, will not initiate or support legal action against you for it, and will not report you to law enforcement for it. If a third party brings action against you for research conducted within these rules, we will make that authorisation clear. We cannot waive the rights of third parties whose systems you touch, so stay inside ours.
In scope
nibit.aiand its subdomains,app.nibit.ai, and Nibit's own API endpoints;- the Nibit desktop and mobile builds, including local storage and update mechanisms.
Out of scope
- infrastructure operated by our providers rather than by us. Report issues in their systems to them;
- findings that require physical access to another person's unlocked device;
- volumetric denial-of-service testing, automated scanning that degrades the Services for others, or load testing of any kind;
- social engineering of Nibit staff, users, or providers;
- reports generated solely by an automated scanner with no demonstrated impact.
Rules of engagement
- use only your own accounts and test data;
- stop as soon as you have confirmed a vulnerability - do not pivot, escalate, persist, or enumerate;
- if you encounter another person's data, stop immediately, do not save or share it, and tell us what you saw so we can assess exposure;
- do not modify, delete, or exfiltrate data that is not yours;
- do not publicly disclose before we have had a reasonable period to remediate, and coordinate timing with us;
- do not demand payment in exchange for withholding a report.
How to report. Send details to security@nibit.ai. Include the affected component, reproduction steps, impact, and anything else needed to verify it. If you want to encrypt the report, ask us for a key first and we will send you one.
What to expect.
- We acknowledge a report within 3 business days.
- We tell you our assessment - whether we can reproduce it, how we rate the severity, and roughly when we expect to fix it - within 10 business days.
- We ask you to hold public disclosure for 90 days from your report, or until a fix is released, whichever comes first. If we need longer, we will explain why and agree a date with you rather than let the clock run out silently.
- We do not currently pay bounties. We do credit researchers who want to be credited, and we will say plainly in the acknowledgement that no payment is coming, so nobody spends time on a false expectation.
- The safe harbour above is a commitment made on Nibit's behalf, not an aspiration.
4. Automated access, rate limits, and fair use
You may not:
- access the Services with scrapers, crawlers, bots, or automated clients except through an interface we document for that purpose;
- circumvent, disable, or interfere with rate limits, quotas, authentication, authorisation, entitlement checks, or licence enforcement;
- share, resell, sublicense, or proxy your access, including reselling AI capacity or acting as an intermediary for other users' requests;
- create accounts in bulk, or create new accounts to evade a suspension, quota, or trial limit;
- deliberately overload, stress, flood, or degrade the Services, or interfere with other users' access;
- probe, scan, or test the vulnerability of the Services except under section 3;
- use the Services to build or train a competing product or model, or to benchmark them for publication without our written consent.
Storage, upload, request, and AI usage limits apply and may change. Sustained use far outside normal individual patterns may be limited even where no specific numeric cap was published.
5. AI features
When you use AI features, you may not:
- attempt to extract system prompts, model weights, provider credentials, or other users' data;
- attempt to bypass safety controls, whether in Nibit or in the underlying provider, including through jailbreaks, injected instructions, or obfuscated requests;
- generate any material prohibited by section 2;
- generate content that impersonates a real person in a deceptive way, or synthetic media presented as authentic;
- use AI features to produce work you will submit as your own where the rules that apply to you forbid it - academic-integrity obligations are yours to meet, and we cannot resolve them for you;
- rely on output for consequential decisions about another person's employment, education, credit, insurance, healthcare, or housing.
Requests are subject to the AI provider's own usage policies, which apply in addition to this Policy. Where a provider blocks or flags a request, we may act on that signal.
6. Enforcement
We may take action proportionate to the violation:
- removing, restricting, or disabling access to specific content;
- disabling a sharing link, group, or chat;
- restricting or throttling a feature, including AI features;
- suspending an account temporarily;
- terminating an account permanently; and
- reporting to law enforcement where we are required to, or where there is a credible risk of serious harm.
What we consider: the severity and duration of the violation, whether it was deliberate, whether it harmed identifiable people, whether the content left your private account, and your history. We aim to use the narrowest measure that addresses the problem, and to reach for termination only for severe or repeated violations.
Where practicable and lawful, we will tell you what was actioned, which part of this Policy applied, and how to appeal. We may act without prior notice where the risk is serious or the law requires it.
Detection. We act on reports, on signals from our providers, and on automated abuse and security detection at the infrastructure level. We do not routinely inspect the content of private notes. Where an automated system triggers a decision that significantly affects you, you can ask for human review under section 7.
7. Appeals
If we remove your content, restrict a feature, or suspend or terminate your account and you believe the decision was wrong, you can appeal.
- Submit the appeal to legal@nibit.ai, with "Appeal" in the subject line, within 6 months of the decision.
- Include your account email, what was actioned, and why you believe it was mistaken.
- A person reviews the appeal. Decisions are not made solely by automated means at the appeal stage, and the reviewer is not the person who made the original decision where we can avoid it.
- We aim to give you an outcome within 30 days, and we will tell you if a case is going to take longer than that.
- We tell you the outcome and the reason for it. If we got it wrong, we reinstate - the content, the feature, or the account.
- We keep a record of each appeal and its outcome for 24 months, so that a pattern of bad decisions is visible to us rather than invisible.
Terms section 10 makes the same commitment; if the two ever read differently, this section is the operative one.
This appeal route does not remove any right you have to complain to a regulator or to seek a remedy in court.
8. Reporting a violation
Policy violations. Report content or conduct that breaches this Policy to legal@nibit.ai, with "Report" in the subject line. Tell us what you saw, where - a share link, group, or username - and why it breaches this Policy. If you can, include the URL. We acknowledge reports and act on those we can verify. Do not send us copies of illegal material; describe it and give us the location.
Copyright. Use the process in the Copyright and DMCA Policy, which has its own notice requirements.
Security vulnerabilities. Use section 3.
Emergencies. If someone is in immediate danger, contact your local emergency services first. Then tell us at security@nibit.ai with "URGENT" in the subject line - it is the inbox we watch most closely - so we can preserve evidence and act.
Where the Services are offered. Nibit offers the Services in the European Union, the United States, and India. Reports from anywhere are read and acted on, and section 7 gives everyone the same appeal, so nothing in this Policy turns on where you are.
Illegal content in the EU. Nibit is established in the Netherlands, so anyone may report content they consider illegal under the Digital Services Act notice-and-action mechanism, whether or not it also breaches this Policy. Copyright and DMCA section 7.1 sets out how, what a notice should contain, and what we do with it.
9. Changes
We may update this Policy as the Services, the law, or the abuse landscape change. We will update the effective date and give notice of material changes as described in Terms section 18.
Each published version has a permanent, dated URL - for example, /legal/acceptable-use/2026-08-01.