Toskr Acceptable Use Policy

Last updated: August 23, 2026

This Acceptable Use Policy (“AUP”) forms part of the Toskr Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.

Toskr hosts infrastructure for customer-operated Matrix communities. This policy is intended to protect End Users, other Matrix homeservers, Toskr’s infrastructure, and third parties without pretending that Toskr can inspect the plaintext of end-to-end encrypted communications.

1. Scope and Customer responsibility

This AUP applies to the Customer’s use of the Service and to use by the Customer’s End Users. Use of the Service requires meeting the eligibility requirements in the Terms, including the minimum-age requirement (18+).

Customer must establish and reasonably enforce community rules that are consistent with this AUP. Customer must take reasonable action when Toskr provides sufficiently specific information showing that use of the Customer’s Server violates this AUP.

Toskr may enforce this AUP directly against accounts, users, rooms, media, or Servers using Toskr-operated infrastructure where Toskr has an appropriate technical control and sufficient information to identify the issue.

2. Prohibited content

You may not knowingly use, permit, or facilitate use of the Service to host, transmit, distribute, solicit, or make available:

  1. Child sexual exploitation material. Child sexual abuse material, sexual exploitation material involving minors, grooming or solicitation of minors for sexual activity, or other material whose possession, creation, solicitation, or distribution is prohibited by applicable child-protection law.
  2. Unlawful content. Material whose hosting, possession, transmission, or distribution through the Service is unlawful under law applicable to Toskr or the Customer’s use of the Service.
  3. Non-consensual intimate material. Intimate images, recordings, or synthetic intimate depictions distributed without the legally required consent of the depicted person.
  4. Copyright-infringing material. Material that infringes copyright or other intellectual-property rights, subject to applicable defenses, limitations, licenses, and the DMCA process described in Section 7.
  5. Threats and unlawful violent activity. Credible threats of violence, unlawful incitement, or content used to facilitate violent criminal activity.
  6. Unlawful terrorist or extremist activity. Material or activity that constitutes prohibited material support, solicitation, recruitment, instruction, or other conduct barred by applicable law.

Toskr may prohibit additional categories by contract even where legality varies by jurisdiction, but material policy expansions will be handled under Section 8 rather than silently treated as existing law.

3. Prohibited conduct

You may not use the Service to:

Good-faith security research is not automatically abusive merely because it involves testing. However, research must not access other customers’ data, materially disrupt the Service, or exceed authorization. Toskr may publish a separate vulnerability-disclosure or security-research policy governing permitted testing.

4. Federation

Federation is not a way to shift abusive conduct to systems Toskr does not operate.

You may not use Federation to direct spam, harassment, malware, attacks, policy evasion, or other prohibited conduct toward remote Matrix homeservers.

Toskr accepts actionable abuse reports from remote homeservers and may evaluate them in the same manner as reports from local Customers or End Users.

Local enforcement by Toskr does not guarantee deletion or restriction on remote federated homeservers. Information already sent through Federation may remain available on systems Toskr does not control.

5. Reporting abuse and urgent issues

Report suspected violations of this AUP to:

Email: abuse@toskr.io

A useful report should include, where available:

For copyright claims, use the dedicated process at https://toskr.io/dmca and dmca@toskr.io rather than the general abuse address.

For legal process or governmental requests, use legal@toskr.io and Toskr’s published legal-request instructions.

If there is an immediate danger to life or physical safety, contact the appropriate emergency service or law-enforcement agency first. A report to Toskr is not a substitute for emergency assistance.

6. How Toskr investigates and enforces this AUP

6.1 No representation of proactive E2EE scanning

Toskr does not proactively inspect the plaintext of end-to-end encrypted messages and does not represent that it scans encrypted message content for policy violations.

That limitation does not mean Toskr can never act. A Customer, End User, remote homeserver, complainant, vendor, or government agency may provide plaintext, event identifiers, account information, screenshots, server logs, or other evidence that gives Toskr enough information to investigate or identify an account, room, media object, or Server.

6.2 Sources of reports and signals

Toskr may act based on information including:

6.3 Available actions

Toskr selects an action based on the information available, severity, recurrence, legal requirements, safety concerns, technical feasibility, and the risk to other users or systems.

Available actions may include:

Toskr does not promise that enforcement will occur at message granularity. In some circumstances, especially where Toskr cannot reliably isolate the offending material or where abuse is systemic, Server-level suspension or termination may be the only reasonable action.

Local action does not recall copies already delivered to remote federated homeservers and does not guarantee that remote systems will delete or restrict their copies.

6.4 Child sexual exploitation reports

Toskr follows applicable reporting and preservation requirements when it obtains the facts or knowledge that trigger those duties.

Toskr does not interpret those duties as a general obligation to proactively monitor users, monitor the content of communications, or affirmatively search, screen, or scan encrypted communications merely because Toskr operates the Service.

When reporting or preservation duties apply, Toskr may preserve affected material beyond ordinary deletion periods and restrict access to that material in accordance with the applicable legal requirement.

7. Copyright and DMCA

7.1 Designated agent

Toskr has registered a designated agent with the U.S. Copyright Office. Current designated-agent contact information and the full notice/counter-notice procedure are published at:

https://toskr.io/dmca

Copyright notices should be sent to dmca@toskr.io and should include the information required by applicable law.

7.2 Action on copyright notices

When Toskr receives a substantially compliant notice identifying material residing on or controlled through Toskr systems, Toskr may remove or disable access to the material, notify the affected Customer or subscriber, request additional information, or take another action appropriate to the technical and legal circumstances.

Where material has already propagated to independently operated federated homeservers, Toskr’s local action does not remove remote copies.

Toskr may reject or request clarification of notices that do not identify the allegedly infringing material or location with enough specificity to permit Toskr to act.

7.3 Counter-notices and restoration

An affected subscriber may submit a counter-notice through the process described at https://toskr.io/dmca if the subscriber believes material was removed or disabled because of mistake or misidentification.

Toskr will process substantially compliant counter-notices in accordance with applicable law, including forwarding them to the original claimant and restoring eligible material after the statutory waiting period unless Toskr receives notice of a qualifying legal proceeding that prevents restoration or another lawful basis independently requires the material to remain disabled.

7.4 Repeat-infringer policy

Toskr maintains a policy of terminating, in appropriate circumstances, Customers or End Users who are repeat copyright infringers.

Toskr evaluates repeat infringement in good faith based on reliable notices, counter-notices, court or Copyright Claims Board outcomes where known, the Customer’s response, evidence of abuse of the notice process, and the technical context. Toskr does not treat every allegation as conclusive merely because it was submitted as a DMCA notice.

Toskr may suspend or terminate a Customer that repeatedly fails to address substantiated infringement on its Server or that uses the Service as a persistent vehicle for infringement.

8. Changes to this AUP

Toskr may update this AUP separately from the Terms because abuse and security patterns change more quickly than commercial terms.

Each version will carry a version or effective date. Toskr will provide reasonable notice of material changes that substantially expand prohibited uses or Customer obligations, except where a faster change is reasonably necessary to address law, security, abuse, or an urgent threat to the Service.

Where applicable law or the Terms require renewed acceptance for a material change, Toskr will provide a re-acceptance mechanism.

Acceptable Use Policy — Toskr — Toskr