Legal
Acceptable Use & Sanctions Policy
Last updated July 27, 2026
Part of the Terms of Service. It covers what our infrastructure may not be used for, how sanctions compliance works in a self-custodial system, and what enforcement can — and cannot — do.
1. Scope
This policy is part of the Terms of Service and applies to everything Aphanite Labs operates: the relay, the handle directory and transparency log, claim-link coordination, encrypted backup storage, the developer API, and the websites. It exists to keep the Service usable and lawful while preserving what makes it valuable — end-to-end encryption and self-custody.
Honest framing up front: because messages are end-to-end encrypted and funds never pass through us, we cannot see content and cannot seize or freeze on-chain assets. What we can govern is access to the infrastructure we run. This policy describes how we do that.
2. Prohibited uses
You may not use the Service to break the law or to harm others. Prohibited uses include, without limitation:
— Any illegal activity, including money laundering, financing of terrorism, trafficking, or the sale of illegal goods and services.
— Fraud and deception: scams, phishing, payment-for-nothing schemes, impersonating a person, brand, or Aphanite itself (including through handles, avatars, or verified-look styling), or creating claim links designed to mislead recipients.
— Child sexual abuse material or any sexual content involving minors. We treat this with zero tolerance and report to the relevant authorities where the law requires.
— Harassment, credible threats of violence, or incitement to violence against any person or group.
— Spam and abuse of reach: bulk unsolicited messages, circumventing consent or rate limits, harvesting the directory, or automated account creation for abuse.
— Distributing malware or content designed to compromise other users' devices or keys.
— Infringing others' intellectual property or privacy, including doxxing.
— Attacking the Service itself: probing, disrupting, or overloading the relay or APIs, attempting to break other users' encryption, or abusing the transparency log or claim channels.
3. Sanctions compliance
You may not use the Service if you are, or are acting for the benefit of, a person or entity subject to sanctions administered by the United States (including OFAC's SDN list), the European Union, the United Kingdom, or the United Nations, and you may not use it from a comprehensively embargoed country or region. By using the Service you represent that none of these apply to you.
Aphanite Labs complies with the sanctions obligations that apply to it. In practice, for a non-custodial system, that means we may decline or withdraw the services we operate — relay delivery, directory listing, paid features, API access — where we are required to, and we do not process, custody, or convert funds for anyone. Self-custodied assets on public blockchains are outside our control in every case.
4. Handles and the public directory
Handles are identifiers, not endorsements. We may revoke or reassign a handle that impersonates a person or organization, was registered to deceive, or exists to squat on someone else's name — and we may remove directory listings and verified badges on the same grounds. The transparency log is append-only by design: revocation appears as a new, visible entry, never a silent rewrite.
5. Enforcement — what we can and cannot do
What we can do: refuse or rate-limit relay delivery for abusive senders; remove handles, badges, and directory listings; revoke API keys and paid-feature entitlements without refund where they were used to violate this policy; cancel unclaimed claim channels we coordinate; and block addresses or infrastructure from the services we operate. Where the law requires, we report and cooperate with authorities — and our Privacy Policy describes exactly how little we hold to produce.
What we cannot do, by construction: read end-to-end encrypted content, recover or reset keys, reverse on-chain transactions, or seize self-custodied funds. Enforcement is always about access to our infrastructure, never about taking control of yours.
Users also have direct tools: consent-gated first contact keeps strangers out of your inbox, and you can block any address at any time.
6. Reporting abuse
To report abuse, impersonation, sanctioned activity, or a security concern, contact us through the wallet-verified form on our homepage. For security vulnerabilities, please report privately and give us a reasonable opportunity to fix the issue before disclosure.
7. Changes
We may update this policy as the product and the law evolve; material changes will be reflected here with an updated date. Continued use of the Service after changes take effect constitutes acceptance.