This Acceptable Use Policy ("Policy") describes activities that are not permitted when you use PopMCP, including our website, application, hosted MCP endpoints, provider connections, and tokens (the "Service"). It is part of, and incorporated into, our Terms and Conditions.
Because PopMCP connects to provider accounts using credentials you control, and because the tools exposed by an MCP endpoint can perform real and sometimes destructive operations, responsible use is essential. You are responsible for your own conduct and for the conduct of your team, your invited users, and the AI clients and agents you connect.
We may investigate suspected violations and may suspend, restrict, or terminate access to protect the Service, providers, other users, and the public.
1. General Principles
You must use the Service lawfully, honestly, and only with accounts, data, and credentials you are authorized to use. You must respect the rights of others, the terms of the providers you connect, and the integrity and security of the Service.
2. Prohibited Uses
You may not use the Service to:
- violate any law or regulation, or facilitate any illegal activity;
- infringe intellectual property, privacy, publicity, or other rights of others;
- connect credentials, accounts, or data that you are not authorized to access or use;
- engage in fraud, deception, phishing, or impersonation, or misrepresent PopMCP as the owner or operator of a connected provider;
- distribute malware, spam, or harmful, harassing, or unlawful content through connected provider operations.
3. Security and Abuse
You may not attempt to compromise the security or integrity of the Service or any connected provider. Prohibited activities include:
- attempting to gain unauthorized access to accounts, tenants, endpoints, tokens, data, systems, or networks;
- probing, scanning, or testing the vulnerability of the Service without our prior written authorization;
- interfering with, overloading, or disrupting the Service, its infrastructure, or other users;
- circumventing authentication, tenant isolation, access modes, rate limits, or other technical controls.
4. Respecting Provider Terms and Limits
Each provider you connect has its own terms, acceptable use rules, and API and rate limits. You are responsible for knowing and complying with them when you use the Service against that provider.
- do not use the Service to bypass, evade, or exceed a provider's published limits or restrictions;
- do not use the Service in a way that a provider prohibits, or that would breach your agreement with the provider;
- do not generate automated traffic intended to degrade, abuse, or unfairly burden a provider's systems.
5. Responsibility for AI Agent Actions
AI clients and agents you connect may invoke tools automatically, including tools that write, update, or permanently delete data. You are responsible for the actions your AI clients and agents take through the Service.
- supervise autonomous agents and constrain the tools and access modes available to them;
- use read-only mode where write access is not required, and leave the full catalog disabled unless you need it;
- do not deploy agents in a manner that you know or should know will cause harm, data loss, or abuse of a provider.
6. Credential and Token Hygiene
MCP URLs, tokens, and provider credentials are sensitive. You are responsible for protecting them and for any activity performed with them.
- do not publish tokens or MCP URLs, embed them in client-side or public code, or share them with people who should not have access;
- scope tokens narrowly, rotate them when exposure is suspected, and revoke tokens and disconnect credentials you no longer need;
- do not connect credentials with broader provider permissions than your use actually requires.
7. Enforcement
We may take any action we consider appropriate to enforce this Policy, including investigating suspected violations, removing or disabling access, suspending or revoking connections, endpoints, or tokens, and suspending or terminating accounts.
We may report activity to providers, law enforcement, or other authorities where we believe it is unlawful or harmful. Enforcement decisions are at our reasonable discretion and do not limit any other remedy available to us.
8. Reporting and Contact
To report misuse, abuse, or a suspected violation of this Policy, contact support@popmcp.com. To report a security concern, see our Security Overview or email security@popmcp.com.
PopMCP