Motir

Acceptable Use Policy

Version 1.0.0 · not yet in effect

Acceptable Use Policy

This policy applies to the hosted Motir service at app.motir.co, operated by moooon B.V., and forms part of the Terms of Service. It does not apply to a self-hosted installation, whose operator sets its own rules.


Why this policy exists

Most of what you do in Motir is private to your workspace. But Motir also hosts public projects, where a project owner opens a roadmap to the world and anyone signed in can submit a feature request, comment on one, and vote. Those contributions are visible to strangers and attributed to their author.

That changes what is at stake. A private workspace is your business; a public project is a place where people meet, and it needs stated rules — so that a project owner knows what they may remove, a contributor knows what is expected, and anyone affected knows how to report a problem.

This policy is written to be used, not to be comprehensive. It is short on purpose.

Who it binds

Everyone who uses the hosted service: account holders, workspace members, and anyone contributing to a public project. You are responsible for content posted from your account, and a workspace owner is responsible for how their workspace is used.

What you must not do

Content

Do not submit, publish or store content that:

  • Is unlawful, or promotes or facilitates unlawful activity.
  • Infringes someone else's rights — copyright, trademark, trade secrets, privacy, or publicity.
  • Sexualises children, in any form. There is no grey area here and no warning: such content is removed and reported to the authorities.
  • Harasses, threatens, defames or incites violence against a person or group, including on the basis of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability or age.
  • Discloses someone else's personal data without a lawful basis — including doxxing.
  • Is malware, or is designed to damage or gain unauthorised access to any system.
  • Is spam — bulk, repetitive, off-topic or promotional posting on public projects.
  • Impersonates another person or organisation, or misrepresents your affiliation.

Conduct

Do not:

  • Attack the service — probe, scan, overload, or attempt to bypass authentication, rate limits, tenant isolation or entitlement checks.
  • Access data that is not yours, or attempt to.
  • Automate abusively — scraping, bulk account creation, or driving the API or AI features in a way that degrades the service for others. Ordinary API and integration use is fine and encouraged.
  • Resell or provide the hosted service to third parties as if it were your own. (Self-hosting under the GPL-3.0 is a different thing entirely, and is fine.)
  • Use the AI features to generate content that would breach this policy if you had written it yourself. The output is your responsibility.

Security research

We welcome good-faith security research and would rather hear from you than not.

If you find a vulnerability, report it to security@motir.co and give us reasonable time to fix it before disclosing. Stay within your own test accounts and workspaces, do not access other people's data, do not degrade the service, and do not run automated scanning against production without asking first.

Research conducted in good faith and within those limits is not a breach of this policy, and we will not pursue you for it.

Public projects: who moderates what

The project owner moderates their own project first. They may edit, hide or remove submissions, comments and votes, and may restrict who can contribute. They know their community; we do not.

We act where the owner cannot or will not, and where content breaches this policy. We may remove content, restrict a public project, or suspend an account — and we will generally tell the affected party what happened and why, unless telling them would be unlawful or would defeat the purpose.

We are not obliged to monitor public content proactively, and we do not. This policy is enforced when we become aware of a problem.

Reporting illegal content — notice and action

Anyone may report content on Motir they consider illegal, whether or not they have an account. This section is our notice-and-action mechanism under Article 16 of the EU Digital Services Act, and it sits alongside the ordinary policy reporting below.

Send it to security@motir.co. So that we can act on it, please include:

  • a sufficiently substantiated explanation of why you consider the content illegal;
  • the exact URL, and any further information needed to locate it;
  • your name and email address — except where the report concerns an offence under Articles 3–7 of Directive 2011/93/EU, where you may report anonymously;
  • a statement that you believe, in good faith, that the report is accurate and complete.

What we do with it. We confirm receipt to you without undue delay. We decide in a timely, diligent, non-arbitrary and objective manner, and we tell you the decision and the redress available against it. Where we use any automated means in handling or deciding a report, we say so.

When we restrict something, we tell you why

If we remove or disable content, restrict a public project's visibility, or suspend or terminate an account, the affected user gets a statement of reasons — this is our Article 17 commitment, and it is a specific explanation rather than a form letter.

It states:

  • what we did and how far it reaches — which content, whether the restriction is removal, hiding, or a limit on visibility, and whether it is temporary or permanent;
  • the facts and circumstances we relied on, including whether the decision followed a report from someone else;
  • whether automated means were used in detecting or deciding;
  • the ground — the specific clause of this policy relied on, or the legal basis where we acted on illegality, with an explanation of why the content is incompatible with it;
  • how to contest it, per the section below.

We do not send a statement of reasons where the law forbids it — for instance where doing so would prejudice an ongoing criminal investigation.

Contesting a decision

Reply to the statement of reasons and tell us why you think we got it wrong. We review it, and we reinstate the content or the account if we did. A person makes that decision; we do not decide a contested case by automated means alone.

Our internal review is not the only route open to you. You may also bring the dispute to a certified out-of-court dispute settlement body, and your right to go to court is unaffected — using ours first is not a precondition for either.

Reporting a policy problem

For content that breaches this policy without being illegal — spam, harassment, an off-topic flood on a public project — the same address works: security@motir.co. If you are reporting something about your own personal data, privacy@motir.co reaches the same place and routes it correctly.

We aim to acknowledge reports promptly and act proportionately. Content that sexualises children, or that presents an immediate threat to someone's safety, is handled immediately and reported to the authorities.

That last part is also an obligation, not only a policy. Where we become aware of information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person has taken place, is taking place or is likely to — Article 18 of the Digital Services Act — we promptly inform the law enforcement or judicial authorities of the Member State concerned, or Europol where no Member State is identified, and give them everything we hold that is relevant.

Where we sit under the Digital Services Act

Motir is an online platform. It is a hosting service that stores information you provide and disseminates it to the public — the public projects, where anyone can read a roadmap and any signed-in visitor can post to it. That is what puts us in scope, and we would rather state it than leave you to work it out.

Articles 16, 17 and 18 apply to us, and the sections above implement them: the notice and action mechanism, the statement of reasons for every restriction, and the duty to inform the authorities about a suspected offence threatening someone's life or safety.

Articles 20 to 28 — the additional duties on online platforms — do not currently apply to us. Article 19 exempts providers that are micro or small enterprises within the meaning of Recommendation 2003/361/EC, and moooon B.V. is one.

We implement the two that matter most to you anyway, as a voluntary commitment. The internal complaint route and the out-of-court dispute settlement option described under Contesting a decision are Article 20 and Article 21 in shape, and we are offering them because a restriction you cannot argue with is a bad experience whatever the law requires. Treat them as binding on us: we do not intend to withdraw them, and we would rather not change how we treat you on the day an exemption lapses.

The exemption is conditional, and we will not rely on it quietly. It ends if moooon B.V. ceases to be a micro or small enterprise — which turns on headcount and turnover, counted with any linked or partner enterprises — and Article 19(2) then allows twelve months before Articles 20 to 28 attach. When that happens the obligations that arrive are transparency reporting, trusted-flagger priority, the misuse-suspension policy, and the protection-of-minors measures, and this page changes with them.

What we may do

Proportionate to the breach and the risk:

  • Remove or hide specific content.
  • Restrict a public project's visibility or its ability to accept contributions.
  • Suspend an account temporarily.
  • Terminate an account for serious or repeated breaches.
  • Report to law enforcement where the law requires it or where someone is at risk.

Where the breach is not serious we will tell you first and give you a chance to fix it. Where it is — illegal content, an active attack, a safety risk — we act first and explain after.

Changes

We update this policy as the product and its risks change. Each version carries a version label and an effective date, and material changes are notified under the Terms of Service.


Report abuse or a vulnerability: security@motir.co