Acceptable Use Policy
Effective 27 August 2026 · Last updated 18 September 2026
PDFeather renders whatever you send it. That is the point of the product, and it is also why this policy exists: a tool that turns instructions into convincing documents can be misused, and we would rather be specific about the line than discover it during an argument.
This policy is part of the Terms of Service. Breaching it is a material breach of that agreement. It applies to everything you do through the Service, including content you render, URLs you ask us to fetch, documents you send for signature, and anything you do with the output afterwards.
We update this policy when a new kind of abuse appears, and those updates take effect when published. A rule against a new attack is worthless if it takes thirty days to come into force. Updates to this policy never change what you pay.
1. Prohibited and restricted businesses
You may not use the Service in connection with any business or activity that appears on the Prohibited and Restricted Businesses list published by Stripe, our payment processor, as that list is updated from time to time.
This is not a formality. Our agreement with Stripe forbids us not only from operating such a business ourselves but from enabling anyone else to operate or benefit from one. If you use PDFeather as part of a prohibited business, you put our ability to take payments at risk, and we will close your account to protect it.
If you are unsure whether your use falls inside a restricted category, ask us at support@pdfeather.com before you build on it. We would much rather answer the question early than terminate the account later.
2. Forged, counterfeit and falsified documents
This is the most important section of this policy and the one we enforce most bluntly.
You may not use the Service to create, complete, alter or send any document that is intended to be passed off as having been issued by a person, company or authority that did not issue it. Without limiting that:
- Identity documents of any kind: passports, national identity cards, driving licences, residence permits, visas, birth and marriage certificates, social security or national insurance documents.
- Academic and professional credentials: diplomas, degree certificates, transcripts, licences to practise, professional certifications, training records.
- Employment and income documents: employment references, letters of employment, payslips, salary certificates, tax documents, benefit statements.
- Financial documents: bank statements, account summaries, proof of funds letters, credit reports, audit reports, financial statements.
- Invoices, receipts, purchase orders, delivery notes and proofs of payment for transactions that did not take place, or that misstate what did take place.
- Insurance certificates, policy documents, claims documentation and proof of cover.
- Government forms, permits, licences, inspection certificates, customs and shipping documentation.
- Court documents, legal notices, affidavits and anything designed to look like an official filing.
- Medical records, prescriptions, test results, vaccination records and fitness-to-work certificates.
The prohibition is on deception, not on document types. Generating your own company's invoices is the product working as intended. Generating an invoice from a company you do not represent, for a sale that never happened, is fraud, and doing it through our API makes it our problem as well as yours.
You may not use PDFeather output, or the PDFeather name, in a way that suggests a document was issued, certified, verified or approved by us. We render documents. We do not attest to anything in them.
Breach of this section results in immediate termination without a cure period, and we report to law enforcement where we are required to or where the conduct warrants it.
3. Deception, fraud and harmful content
You may not use the Service to produce or distribute:
- Phishing pages, credential-harvesting forms, fake login screens, or any document or page designed to trick someone into revealing information or making a payment.
- Material impersonating a brand, institution, public body or individual.
- Deceptive claims about financial products, investment returns, medical treatments, health outcomes or legal rights.
- Content supporting an advance-fee scheme, a pyramid or Ponzi structure, a fake charity appeal, or any other fraudulent solicitation.
- Malware, ransomware, exploit code, or documents crafted to exploit a vulnerability in a reader or viewer.
- Content that sexualises minors, in any form and without exception. We report this to the appropriate authorities.
- Content that harasses, threatens or incites violence against a person or group, or that promotes a terrorist or violent extremist cause.
- Content unlawful in the jurisdiction where it is created, rendered or received.
4. Intellectual property and watermarks
You may not use the Service to reproduce, distribute or create derivatives of material you do not own or have permission to use.
The watermark removal operation removes the PDFeather watermark from a document we rendered on the Free plan. That is its entire scope. You may not use it, or any other part of the Service, to remove, alter or obscure:
- A watermark, copyright notice, attribution or rights-management information applied by anyone other than PDFeather.
- A digital signature, certification, seal or tamper-evidence marking.
- Any technical measure protecting a work, or any information identifying its owner or the terms of its use.
We do not offer, and will not build, a tool for stripping other people's marks from their files. Attempting to use the Service that way is a material breach and, in many jurisdictions, unlawful in its own right.
5. URL fetching and third-party systems
When you give us a URL, we make a request to it from our infrastructure, in your name. You are pointing our servers at someone else's systems, so the rules here are strict.
You may not ask us to fetch:
- Private, internal, link-local, loopback or otherwise non-public address space, including 127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16 and their IPv6 equivalents.
- Cloud instance metadata endpoints, including 169.254.169.254 and any provider equivalent.
- Any host you are not authorised to access, or any resource behind an access control you are not entitled to pass.
- Any endpoint whose purpose in the request is to probe, enumerate, fingerprint or map infrastructure.
You may not use the Service to circumvent a paywall, a rate limit, a robots exclusion rule, a geographic restriction or a bot-detection measure. You may not use it to scrape at a volume or frequency that burdens the target, and you may not use it to direct traffic at a third party for the purpose of disrupting them.
We block address ranges and destinations at our discretion, without notice and without explanation. If a legitimate fetch is blocked, tell us and we will look at it.
If the operator of a system you directed us to complains, we will act on it. Repeated complaints end the account, and section 25 of the Terms means the resulting claim is yours to answer.
6. Platform integrity and fair use
You may not:
- Exceed documented rate limits, concurrency limits, file size limits, page count limits or timeouts, or design around them by distributing load across accounts or keys.
- Create multiple accounts to multiply Free plan allowances, to evade a suspension, or to obtain promotional credit more than once.
- Share, sell, sublicense or rent API keys, or resell the Service as your own without a written agreement with us.
- Reverse engineer, decompile or attempt to derive the source of the Service, except where the law expressly permits it despite a contractual prohibition.
- Probe, scan or test the security of the Service other than under an agreed disclosure arrangement, or attempt to access another customer's account, keys, data or jobs.
- Interfere with the Service, introduce malicious code into it, or place a load on it intended to degrade it for others.
- Use the Service to build a competing product by systematically extracting its behaviour.
Security researchers are welcome. Write to support@pdfeather.com before testing and we will agree a scope. We will not pursue good-faith research conducted within an agreed scope.
7. Data you send us
You must have a lawful basis for every piece of personal data you send us to render, convert, recognise or sign, and you must have told the people concerned whatever your own law requires you to tell them.
Take particular care with special categories of data, including health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life and sexual orientation, and with children's data. We do not prohibit them outright, because a clinic rendering its own patient letters is a legitimate use, but you carry the responsibility and you should be confident of your position before you send them.
Do not send us payment card numbers for rendering. We are not a cardholder data environment and we will not become one.
8. Electronic signatures
You may not use the signature feature to obtain a signature by deception, to sign on behalf of someone without authority, or for any document category excluded from electronic signature legislation. Section 17 of the Terms lists those categories.
You may not present a PDFeather audit trail as certification by us that a signature is valid, that the signer is who they claim to be, or that the document is enforceable. We record what happened. We do not vouch for it.
9. How we enforce this policy
We do not monitor Customer Content, and we are not obliged to. We act on what we find, what our abuse detection surfaces, and what people report to us.
Our response is proportionate to what happened:
- A warning, where the breach looks like a misunderstanding and no harm was done.
- Blocking a specific capability, destination or content pattern, leaving the rest of the account working.
- Rate limiting, where the problem is volume rather than intent.
- Suspension of an API key or the whole account, immediately and without notice where there is a security risk, a fraud indicator, a legal demand or a live attack in progress.
- Termination, immediately for forgery, sexual content involving minors, attacks on third parties, or unlawful use, and after notice and a chance to fix it for other material breaches.
- Reporting to law enforcement, to affected third parties, and to our payment processor, where the conduct warrants it or the law requires it.
We will tell you what we have done and why, unless the law prevents us or telling you would defeat an investigation. If you think we got it wrong, reply and say so. We read those replies and we do reverse decisions.
Section 27 of the Terms sets out what happens to your balance in each case. In short: we do not treat your prepaid balance as a fine. Promotional credit lapses, and the cash portion comes back to you unless we are setting it off against losses we can actually document.
10. Reporting abuse
If you have received a document produced through PDFeather that you believe is fraudulent, infringing or otherwise abusive, write to support@pdfeather.com. Include the document if you can, and anything identifying where it came from.
If our infrastructure has made requests to a system you operate and you want them stopped, write to the same address with the timestamps and the address range you saw. We will identify the account and act.
We acknowledge abuse reports within one business day.