anti-abuse-policy

Last updated Aug 16, 2026

Governing language: The Simplified Chinese version is authoritative. This translation is provided for convenience.

Anti-Abuse Policy

Effective date: August 5, 2026

This Anti-Abuse Policy is adopted to protect the security and availability of users, partners, and 摇月 Swaymoon Account and related services (this “Service”). This policy supplements the Terms of Use; if the two conflict, the stricter constraint on abusive conduct prevails.

1. Scope

This policy applies to all individuals and organizations that use this Service, including without limitation: registration and sign-in, authorizing third-party applications, Hide My Email (privacy email), developer integration capabilities, and access to the documentation site, APIs, and infrastructure.

2. Prohibited Abuse

Without written permission from 摇月 Swaymoon, you must not engage in or assist others in engaging in the following:

2.1 Account and identity abuse

  • Bulk, automated, or fake account registration; buying, selling, renting, or lending accounts
  • Forging or impersonating another person’s identity information, or circumventing real-name, verification, and security checks
  • Credential stuffing, credential filling, brute-forcing passwords or verification codes, or distributing stolen accounts
  • Circumventing two-factor authentication, passkeys, step-up verification, or other security controls

2.2 Technical and API abuse

  • Scanning, penetrating, stress-testing, or conducting denial-of-service attacks against the Service, APIs, email relay, or infrastructure (except security testing with our written authorization)
  • Scraping, bulk-exporting, or reselling data without authorization
  • Interfering with or tampering with requests/responses, spoofing clients, or exploiting rate-limit vulnerabilities
  • Distributing malware or phishing pages, or inducing users to visit a counterfeit “Swaymoon Account” sign-in page

2.3 Hide My Email and communications abuse

  • Using Hide My Email to send or receive spam, scams, extortion, or harassment
  • Creating aliases at scale to evade bans, inflate volume, engage in underground activity, or conduct illegal transactions
  • Using the relay to forge identity, mislead recipients, or otherwise harm the email ecosystem

2.4 Authorization and application abuse

  • Tricking users into authorizing permissions unrelated to the business, or using authorized data beyond the agreed scope
  • Using Swaymoon Account sign-in capabilities for illegal applications or content distribution
  • Abusing OAuth / OIDC flows to carry out phishing, session hijacking, or account takeover

2.5 Other illegal or harmful conduct

  • Endangering national security or public safety, or infringing the rights and interests of minors
  • Infringing others’ intellectual property, privacy, reputation, or other lawful rights and interests
  • Money laundering, gambling, trading in prohibited goods, or other illegal activities, or facilitating such activities
  • Any conduct we reasonably believe poses a material risk to users, the Service, or third parties

3. Detection and Investigation

We may identify abuse using risk controls, rate limiting, log audits, user reports, third-party intelligence, and similar means. A burst of new app grants or a large number of enabled Hide My Email aliases may place the account on a system hold for review (sign-in itself stays available; you can Request Access). Too many failed sign-ins lock password sign-in until you unlock with a code or passkey and reset the password. To investigate suspicious activity, we may, to the extent permitted by law, restrict related features, require additional verification, or temporarily suspend the Service.

You agree to cooperate with reasonable investigations. If you refuse to cooperate and a material risk exists, we may proceed directly to the measures in Section 4.

4. Enforcement Measures

Once abuse is confirmed or we have reasonable grounds to believe it exists, we may, depending on the circumstances, take one or more of the following measures:

  • Warn, require removal of violating content, or require that the relevant conduct stop
  • Restrict sign-in, restrict verification-code/email sending, or disable Hide My Email aliases
  • Revoke third-party application authorizations, or restrict or take down developer clients
  • Freeze or terminate the account, and delete violating data
  • Report to competent authorities, or preserve and disclose necessary information in accordance with law
  • Pursue civil, administrative, or criminal liability

In emergencies (such as an ongoing attack or fraud), we may take temporary restrictive measures before prior notice, and inform you within a reasonable time thereafter (except where law provides otherwise or notice would hinder handling).

5. Request Access

If you believe a measure was taken in error, submit Request Access through Report a Problem within a reasonable period after receiving notice, stating the account identifier, relevant times and reasons, and providing verifiable materials. If that portal is unavailable, email hello@swaymoon.com. We will review as soon as possible. Where abuse is severe or violations are repeated, we may not restore the Service.

6. Policy Updates

We may update this policy and will publish it on the documentation site. Continued use of this Service constitutes awareness of and acceptance of the updated rules (except where law requires consent to be obtained again).

7. Contact Us

To report abuse or a security vulnerability: hello@swaymoon.com. To Request Access, use Report a Problem; email only if that portal is unavailable.

For security issues, please provide reproduction steps and impact scope where possible. Do not conduct destructive testing against the production environment without prior arrangement. For more contact options, see Contact Swaymoon.