Legal
Acceptable and Fair Use Policy
This policy explains plan fair-use thresholds, prohibited conduct, how we handle abuse without inspecting traffic, and how to report or appeal.
1. Scope
This policy forms part of the Terms of Service and applies to every user on every plan. It governs everything you do through our network, whether or not the traffic is encrypted.
Fair-use rules
Each plan's traffic threshold, device count and concurrency limit are shown on the pricing page and purchase confirmation. Once the traffic threshold is reached, the connection is slowed, not disconnected, and full speed returns automatically in the next billing period. We do not inspect browsing activity, DNS queries or destinations to apply these limits. You must not bypass, tamper with or share an account to evade a threshold.
2. Prohibited conduct
2.1 Network and security abuse
- Sending spam, unsolicited bulk commercial messages, or running the mail infrastructure that supports them.
- Port scanning, vulnerability scanning, fingerprinting or any reconnaissance against targets you are not authorised to test.
- Launching or participating in DoS / DDoS, amplification or reflection attacks.
- Credential stuffing, brute forcing or any automated guessing against third-party accounts.
- Distributing malware, ransomware or spyware, or operating botnet command-and-control (C2) channels.
- Accessing, probing or interfering with any system, network or data without authorisation.
- Forging packet sources, IP spoofing, forging mail headers or otherwise disguising the origin of traffic.
- Circumventing third-party access controls, rate limits or anti-scraping measures; large-scale scraping in breach of a site's terms.
- Interfering with or attempting to bypass our own fair-use thresholds, device limits or metering.
2.2 Unlawful and infringing material
- Transmitting or distributing material that infringes copyright, trademark or other intellectual property.
- Fraud, money laundering, Ponzi and pyramid schemes, identity theft, forged documents or payment instruments.
- Distributing terrorist content, inciting violence or genocide, or organising targeted harassment or threats against people or groups.
- Human trafficking, sexual exploitation, and the creation or distribution of non-consensual intimate imagery (NCII).
- Activity that breaches applicable export control or sanctions law, including providing services to sanctioned parties.
- Anything else that is criminal where you are or where your target is.
2.3 Account and billing abuse
- Reselling, renting out or publicly sharing an account, or using a consumer plan to offer proxy services to others.
- Mass account creation, trial abuse, or fabricating referral attribution to harvest rewards.
- Using stolen payment instruments, or filing a bad-faith chargeback after normal use.
- Impersonating another person or impersonating TP VPN itself — via @handle, avatar or public claims.
3. Child sexual exploitation: zero tolerance
- On confirmation the account is terminated immediately, without refund and without an appeal window.
- We report to the competent authorities and statutory reporting bodies as applicable law requires, and cooperate with investigations under valid legal process.
- We preserve account and metadata records relating to the incident until legal process concludes — the only exception in this policy that overrides our normal deletion timelines.
- If you have a lead, email abuse@tpvpn.com immediately with CSAM in the subject line; we prioritise these.
4. How we detect abuse without looking at your traffic
It is a fair question: if we never log browsing activity, DNS or destinations, how can this policy be enforced at all? The answer is that we rely on exactly three kinds of signal, none of which involves the contents of your traffic:
- Third-party complaints. A victim, rights holder or their agent sends us an evidenced report, normally citing one of our egress IPs and a precise timestamp.
- Upstream abuse reports. Our data centres and network suppliers forward the abuse notices they receive.
- Content-free metadata anomalies. For example an account whose byte totals, concurrent session count, handshake frequency or cross-region switching rate departs sharply from normal use. None of those metrics contains a destination or any content.
5. Reporting abuse
Send reports to abuse@tpvpn.com. To be actionable a report needs at least:
- Our egress IP address (the source of the abuse).
- A precise timestamp with time zone (UTC preferred; minute precision is often not enough — seconds if you can).
- A description and evidence: log excerpts, mail headers, packet capture summaries, screenshots.
- Target details: the affected domain, IP or service.
- Your contact details so we can report back.
We acknowledge receipt and describe what we are doing within 3 business days. For copyright complaints, see Copyright and abuse complaints instead.
6. Enforcement
We take measures proportionate to the severity of the conduct and the strength of attribution, normally escalating in this order:
| Stage | Measure | Trigger |
|---|---|---|
| 1 | Notice and a request to fix | First, minor, plausibly a misconfiguration such as a runaway script |
| 2 | Throttling or concurrency limits | Sustained resource abuse affecting others on the same node |
| 3 | Account suspension | Not fixed in time, or serious conduct still being verified |
| 4 | Termination | Serious or repeated breach, or unlawful activity |
| Immediate | Termination without the stages above and without refund | CSAM, terrorist content, attacks launched through our network, fraud with stolen payment instruments |
Accounts terminated for breaching this policy are not refunded for the remaining period. Every enforcement action is written to our internal audit trail — who did it, when, on what basis, and the before/after state — so that we are accountable internally as well.
7. Appeals
If you think we got it wrong, email support@tpvpn.com within 14 days of the notice with "Appeal" in the subject. Include your @handle, when the action was taken, and why you believe the decision is mistaken, with evidence (for example, that your devices were offline in that window).
- Appeals are reviewed by someone who was not involved in the original decision, and answered within 3 business days.
- If the review finds we were wrong, we restore the account and credit the service time lost to the suspension.
- If the decision stands, we explain the basis for it, so far as that does not expose a reporter or prejudice an investigation.
- This section does not apply to terminations for CSAM.
8. Changes
We update this policy as abuse patterns change. Material changes are announced 30 days in advance; new prohibitions added in response to an emerging attack may take effect immediately, with a notice published at the same time.
Historial de revisiones
- v1.1.0 · 2026-09-02 · Added the fair-use rules and clarified what happens after a threshold is reached
- v1.0.1 · 2026-09-02 · Added the Traditional Chinese (Hong Kong) translation