merkleset
المستندات القانونية

النسخة: 2026-08-12سارٍ من: 2026-08-12معلوماتي

هذا المستند يُنشر بالإنجليزية فقط. النص الإنجليزي هو المرجع المعتمد: يُسجَّل القبول مقابل قيمة SHA-256 للمصدر الإنجليزي، فلا يمكن أن تكون أي ترجمة هي النص الذي وافقت عليه.

Acceptable Use Policy

Version 2026-08-12. Effective 2026-08-12.

This policy says what you must not do with merkleset — the service and the data. It is part of the Terms of Service. Breaching it is a material breach, and clause 12.2 of the Terms lets us suspend access immediately when we reasonably believe it is happening.

Most of it comes down to two ideas: do not try to turn a non-personal dataset back into personal data, and do not resell what we built.

1. No re-identification

1.1 Do not attempt to identify any individual from data we deliver, alone or by combining it with any other data or model.

1.2 Do not attempt to reverse, undo or reconstruct a redaction. Redacted values are replaced with fixed placeholders such as [redacted:email]; treating those as a puzzle to solve is prohibited.

1.3 Do not use the data to enrich, verify or build a profile about an identified or identifiable individual.

1.4 If you encounter personal data that our screening did not remove, do not use it, do not extract it, and tell us at privacy@merkleset.com. We will remove it from future releases and delete it from our internal evidence store.

2. No decisions about individuals

2.1 Do not use the data to make or support a decision about an individual's eligibility for employment, credit, insurance, housing, or a similar benefit or licence.

2.2 Do not use the data in a consumer report or for any purpose regulated as consumer reporting.

2.3 Do not use the data for background screening, vetting or scoring of people.

3. No redistribution and no competing data product

3.1 Do not sell, licence, publish, post, mirror or otherwise make available the datasets, or any substantial part of them, as data — in our format or any other, for a fee or free.

3.2 Do not use the datasets to build, train or populate a product whose purpose is to supply datasets, corpora or data feeds to third parties.

3.3 Do not use the datasets to build a catalogue, index or search product that competes with merkleset by re-exposing our compilation.

3.4 Clause 4.6 of the Data License Agreement lists what these limits do not restrict — model outputs, aggregate statistics, illustrative individual records, and your own collection of the same public records from their government sources.

4. Credentials and licensed scope

4.1 Your account credentials, tokens and signed download URLs are for the organisation named on your account and the people it authorises. Do not share them beyond that scope.

4.2 Do not publish, post or embed a signed download URL anywhere a third party could use it.

4.3 Do not create multiple accounts to obtain free-tier or demo access at a scale that substitutes for a paid subscription, and do not use demo access to assemble a production corpus.

4.4 Do not resell, rent or share your access, and do not act as a conduit that lets an unlicensed third party obtain releases.

4.5 Tell us promptly at abuse@merkleset.com if you believe your credentials have been compromised.

5. How you may use our endpoints

5.1 Use the published API. Do not scrape, crawl or automate the website or the delivery endpoints beyond what the API and its documented rate limits allow.

5.2 Do not exceed, evade or work around a rate limit — including by rotating addresses, accounts or tokens.

5.3 Do not attempt to bypass authentication, the entitlement check, or the expiry of a signed URL.

5.4 Do not probe, scan or load-test the service without our written permission. If you find a vulnerability, report it under section 7 instead of exploiting it.

5.5 Do not place a disproportionate load on the service. If you need a bulk transfer pattern that the API does not comfortably support, ask us at contact@merkleset.com — a direct answer is cheaper for both of us than an outage.

6. General prohibitions

6.1 Do not use the service for anything unlawful, or to facilitate anything unlawful.

6.2 Do not infringe anyone's intellectual property, privacy or other rights.

6.3 Do not upload or transmit malware, or use the service to distribute it.

6.4 Do not misrepresent your identity, your organisation or your authority to bind it.

6.5 Do not remove, alter or falsify our provenance fields, manifests or hashes and then present them as ours, and do not present altered data as verified by us.

6.6 Do not use the service in breach of export control or sanctions laws that apply to you.

7. Reporting

WhatWhere
Abuse of the service, or a compromised accountabuse@merkleset.com
A security vulnerabilityabuse@merkleset.com — please give us a reasonable period to fix it before disclosing
Personal data present in a releaseprivacy@merkleset.com
A copyright complaint, or a source operator asking us to stop collectingdmca@merkleset.com

We do not currently run a paid bug bounty. We will acknowledge a good-faith report and will not pursue a researcher who tests within section 5.4's request-permission rule and does not access other customers' data.

8. Enforcement

8.1 Where the breach is curable and the risk is contained, we will normally tell you and ask you to fix it before suspending.

8.2 Where continuing would cause harm, breach the law, or put personal data at risk, we will suspend first and explain immediately afterwards.

8.3 Repeated or deliberate breach of sections 1, 2 or 3 is grounds for termination, and — under clause 3.3 of the Data License Agreement — is the only circumstance in which the perpetual licence to data already delivered can be revoked.

8.4 This policy is versioned by effective date. A new version applies from the date we publish it; we will notify account holders of a material change by email.

sha256 234e4a2ee69d…872a7a5d1485