VeloOpen workspace

Legal

TermsPrivacyAcceptable useCopyrightSubprocessors
Version
1
Effective
Aug 25, 2026
Publisher
Meridian Studios

Current policy

Acceptable Use Policy

The authorization and conduct boundaries that keep captures, reviews, and integrations safe.

1. Purpose

This Policy protects reviewers, creators, website operators, service providers, and Velo's infrastructure. It applies to every account, capture, upload, review link, comment, integration, export, and automated request. It is incorporated into the Velo Terms of Service. Questions or abuse reports may be sent to legal@meridianproject.studio.

2. Capture authorization

You may upload, capture, publish, or invite review of material only when you own it or have permission or another lawful basis to do so. Before requesting a website capture, confirm that the target is the public HTTPS page you intended, that you are authorized to review it, and that the capture will not expose secrets or personal information beyond what the review requires.

Do not use Velo to enter a private account, bypass authentication, defeat a paywall or technical access control, probe an internal environment, or capture material obtained through stolen or shared credentials. Authenticated and private-site capture is not part of the current web service. A page being technically reachable does not by itself establish permission to capture, republish, or invite others to review it.

3. Prohibited technical activity

You may not use Velo to:

  • reach localhost, private, carrier-grade NAT, link-local, multicast, reserved, or cloud-metadata addresses;
  • exploit DNS rebinding, open redirects, alternate address encodings, proxy chains, or redirect loops to evade capture controls;
  • deliver malware, malicious documents, credential prompts, tracking payloads, decompression bombs, or intentionally oversized responses;
  • scan ports, enumerate services, test vulnerabilities without authorization, interfere with availability, or impose unreasonable load;
  • obtain or expose passwords, API keys, session tokens, private keys, payment data, government identifiers, or other secrets;
  • bypass rate limits, invitation controls, review-link expiration, tenant boundaries, blocking, or database authorization; or
  • reverse engineer Velo except to the extent applicable law expressly permits and cannot be waived.

Security research must be authorized in writing and limited to the approved scope. If you encounter another person's data, stop, preserve confidentiality, and report it to legal@meridianproject.studio.

4. Prohibited content and conduct

You may not use Velo for unlawful activity; intellectual-property infringement; fraud or impersonation; threats, harassment, stalking, or hateful abuse; sexual exploitation; non-consensual intimate material; promotion of violence; unlawful surveillance; doxxing; discriminatory exclusion; deceptive evidence; or material intended to facilitate serious harm. Do not submit content that violates another person's privacy, publicity, confidentiality, contractual, or data-protection rights.

Feedback may be direct and critical, but it must remain connected to legitimate review. Do not use comments, tasks, invitations, or contact sharing to spam, intimidate, repeatedly contact someone who has closed or blocked a conversation, or pressure a person to reveal private contact details.

5. Review boundaries and evidence integrity

Do not attempt to discover another reviewer's private session, infer hidden feedback, reuse a review receipt for another identity, or redistribute private feedback outside its intended audience without permission. Community participants may quote or export shared feedback only in a way consistent with the creator's instructions, applicable law, and the rights of other participants.

Do not falsify the source route, release, author, timestamp, target, screenshot, device context, or task state of review evidence. If you edit or excerpt exported evidence, make the alteration clear. Never represent a recreated screenshot or modified packet as an unaltered Velo record.

6. Integrations and credentials

Connect only accounts and endpoints you are authorized to use. Review the displayed destination, operation, scopes, and redacted payload before approving an external action. Do not configure free-form endpoints to reach private networks, substitute an unreviewed URL, pass another provider's token through an MCP server, or send project data beyond the approved payload.

Credentials belong in Velo's designated encrypted connection flow, not in project names, comments, Brand Books, source URLs, support messages, or screenshots. Disconnect and rotate a credential immediately if exposure is suspected. Optional providers remain subject to their own acceptable-use rules.

7. Enforcement

We may block a capture or endpoint, rate-limit requests, revoke a link, quarantine or remove content, restrict an integration, preserve evidence, warn a user, suspend access, or terminate an account when we reasonably believe this Policy was violated or action is necessary to protect users, providers, the public, or Velo. We consider severity, intent, repetition, impact, remediation, and legal obligations. Immediate action may occur without advance notice when delay would create risk.

We may cooperate with valid legal process and report credible threats or unlawful conduct where permitted or required. Enforcement decisions do not create an obligation to monitor all content. If you believe an action was mistaken, email legal@meridianproject.studio with the account, project or review reference and relevant context. We will review a good-faith appeal, but emergency protective restrictions may remain during review.

8. Contact

Abuse, security, and policy reports: legal@meridianproject.studio

Product and account support: support@meridianproject.studio