Acceptable Use Policy for SaaS: What It Must Include and Why It Is Not Your ToS

Home  /  SaaS Law  /  Acceptable Use Policy for SaaS: What It Must Include and Why It Is Not Your ToS

Most SaaS founders think about their Terms of Service as the document that governs the relationship with their customers. But there is a category of prohibited behavior that needs its own dedicated document: what users are and are not allowed to do with your platform. A well-drafted Acceptable Use Policy (AUP) handles this, and its absence creates legal exposure that generic Terms of Service language cannot fully address.

When a user sends spam through your email platform, launches a denial-of-service attack using your API, or uses your file-sharing tool to distribute pirated software, your ability to terminate their account and limit your liability depends on whether that conduct was clearly prohibited in writing before it happened. A vague “don’t do anything illegal” clause in your ToS is not a substitute for a specific, enforceable AUP.

This article explains what an Acceptable Use Policy for SaaS companies must include, when it should stand as a separate document from your Terms of Service, and how a specific, well-structured AUP protects your platform against user conduct that damages you, your other customers, and third parties.

1. What an Acceptable Use Policy Actually Does

An Acceptable Use Policy defines the boundary between legitimate use of your platform and conduct that gives you the right to suspend or terminate a user’s account, pursue damages, and limit your own legal exposure for harm caused by that user.

The AUP works in three directions simultaneously. First, it gives you a clear contractual basis for account termination when a user violates its terms. Without specific prohibited conduct language, a user can argue that termination was arbitrary or that they were not on notice their conduct was prohibited. Second, it limits your liability to third parties harmed by your users. If your AUP explicitly prohibits spam, phishing, harassment, and intellectual property infringement, you have a stronger defense when a harmed party claims you were complicit in that conduct. Third, it satisfies regulatory and platform requirements. Many payment processors, app stores, and enterprise procurement teams require SaaS vendors to have an AUP in place as a condition of doing business.

The AUP is not just a legal formality. It is an operational tool your trust and safety team, customer success team, and legal counsel all rely on when a user’s behavior creates a problem.

2. AUP vs. Terms of Service: Why They Are Different Documents

Your Terms of Service governs the commercial relationship between your company and your customers: account access, payment, service availability, intellectual property ownership, liability limitations, and dispute resolution. The AUP governs user behavior while using the platform.

The reason to keep them separate rather than folding AUP content into your ToS is practical. Your Terms of Service is a contract-heavy document your customers review during signup or enterprise procurement. Your AUP is a document your users need to consult when they have a question about what they are allowed to do. Separating them makes each document more usable and more enforceable.

Separation also allows you to update the AUP independently. If you add a new product feature that creates new categories of misuse, or if a new regulatory requirement bans a specific type of content processing on your platform, you can revise the AUP without triggering a full Terms of Service revision. Your ToS should cross-reference the AUP and establish that violations of the AUP are treated as violations of the overall agreement.

For the same reason, your AUP should be incorporated by reference into any SaaS agreement you sign with enterprise customers. An enterprise customer who purchases your platform and deploys it to their employees needs to understand that the AUP applies downstream to those end users.

3. Core Prohibited Conduct Categories Every SaaS AUP Needs

The specific prohibited conduct in your AUP will depend on your platform, but every SaaS AUP should address these categories:

Illegal activity

Explicitly prohibit use of your platform to violate applicable law. This includes federal and state laws in the US, and the laws of any jurisdiction where you have users. Be specific: prohibit use that violates the Computer Fraud and Abuse Act (18 U.S.C. § 1030), the CAN-SPAM Act (15 U.S.C. § 7701 et seq.), the Digital Millennium Copyright Act, export control regulations, and applicable data protection laws. “Don’t do anything illegal” is enforceable but harder to act on than a specific list.

Harmful or abusive content

Prohibit content that is harassing, threatening, defamatory, hateful, or that targets individuals based on protected characteristics. For platforms where user-generated content is a core feature, your AUP must address this category specifically. The scope here should match your platform’s function: a B2B productivity tool has different content risk than a community platform.

Intellectual property infringement

Prohibit users from uploading, transmitting, or processing content that infringes a third party’s copyright, trademark, trade secret, or other intellectual property rights. The Digital Millennium Copyright Act (17 U.S.C. § 512) provides a safe harbor for platforms that respond to takedown notices, but that safe harbor requires you to have a DMCA policy in place. Your AUP prohibition on IP infringement is the foundation of that policy.

Security interference

Prohibit actions that interfere with the security or integrity of the platform, including unauthorized access attempts, vulnerability scanning, denial-of-service attacks, introduction of malware, or circumvention of access controls. If your platform exposes an API, explicitly prohibit using it in ways that disrupt service availability for other users.

Spam and unsolicited communications

For any platform with email or messaging functionality, explicitly prohibit sending unsolicited bulk messages, phishing attempts, or any communication that violates the CAN-SPAM Act or applicable anti-spam laws. This is especially important for email delivery platforms, marketing automation tools, and any SaaS product where users communicate with end recipients at scale.

Data scraping and automated abuse

Prohibit unauthorized scraping of platform data, using bots or scripts to interact with the platform in ways that exceed authorized access, and any use of the platform’s data or outputs for unauthorized commercial purposes. For platforms with AI features or access to third-party data, this category needs careful drafting.

Prohibited content types specific to your platform

Beyond the universal categories above, identify what types of content or use cases your platform was not designed to handle and where you do not want associated liability. Storage platforms, collaboration tools, and AI-powered products each have distinct risk areas. A SaaS AUP drafted for your specific platform is more defensible than a generic one.

4. Enforcement Rights Your AUP Must Establish

The prohibited conduct clauses are only half of an effective AUP. The enforcement provisions are equally important, because they define what you can do when a violation occurs.

Your AUP should explicitly state your right to suspend or terminate an account upon any violation, without advance notice and without refund, at your sole discretion. The “sole discretion” language matters because it eliminates the argument that you were required to follow a specific process before terminating access.

Include the right to preserve and disclose user data to law enforcement when legally required or when you have a good-faith belief that doing so is necessary to comply with legal process or prevent harm. This is not optional language: the Stored Communications Act (18 U.S.C. § 2701 et seq.) governs your ability and obligations when law enforcement requests user data, and your AUP should reflect that you will cooperate when legally required.

Establish that a violation by a user in an enterprise account creates liability for the enterprise customer, not just the individual user. This is critical for B2B SaaS where the account holder is a company that deploys your platform to multiple employees or clients. Your AUP enforcement rights should flow through to the account contract.

5. What Happens If You Don’t Have an AUP

Platforms without an AUP, or with only generic prohibited conduct language buried in their ToS, face three practical problems:

Termination disputes. When you terminate an account for misuse, a user with no clear AUP notice can claim they had no warning their conduct was prohibited and that termination was wrongful. If the conduct was not clearly listed in a prohibition, you may be in a weaker position to defend the decision. This is particularly problematic in jurisdictions where courts scrutinize platform termination decisions or where the user has a business-critical dependency on your platform.

Third-party liability exposure. When a user of your platform harms a third party, whether by sending phishing emails, infringing a copyright, or harassing someone, you can face claims that you facilitated or enabled that conduct. An AUP that clearly prohibits the conduct and gives you enforcement rights is evidence that the violation was contrary to your platform’s rules, not condoned by them. Without an AUP, your complicity argument is weaker.

Enterprise deal risk. Large enterprise customers and regulated-industry buyers routinely request your AUP during procurement as part of their vendor risk assessment. Not having one signals that your legal infrastructure is incomplete, which can delay or block deals.

6. AUP Drafting Considerations for AI-Powered SaaS

If your SaaS platform includes AI features, including AI-generated content, AI-assisted analysis, or any model that processes user inputs to produce outputs, your AUP needs additional categories that standard templates do not address.

Prohibit using AI features to generate content that is intentionally deceptive, including deepfakes, fraudulent impersonation, or automated misinformation at scale. Prohibit using AI outputs to reverse-engineer the model, extract training data, or attempt to access functionality outside the scope of the licensed service. Prohibit inputting third-party confidential information or personal data into AI features without authorization from the data subjects or data controllers whose information is being processed.

These are not hypothetical edge cases. As regulatory scrutiny of AI systems increases, including under the EU AI Act and proposed US AI legislation, having documented prohibited use cases for your AI features is both a compliance requirement and a liability management tool. A technology lawyer who works with AI-powered SaaS companies can review whether your AUP’s AI provisions align with current regulatory requirements and your actual model behavior.

7. How a Technology Lawyer Approaches AUP Drafting

A generic AUP template from the internet will address the obvious categories but it will not be tailored to your platform’s risk profile, your specific regulatory environment, or the enforcement rights you actually need when something goes wrong.

A technology lawyer who works with SaaS companies will review your product, identify the specific misuse scenarios that your platform is most exposed to, and draft prohibited conduct language that is specific enough to be enforceable but not so narrow that it leaves gaps. They will also align your AUP with your Terms of Service and any enterprise agreement templates you use, so your enforcement rights are consistent across all your contracts.

The privacy and data law practice at TOS Lawyer works with SaaS founders on AUP drafting, Terms of Service alignment, and trust and safety legal frameworks. If your platform is growing and you are encountering user conduct problems you are not sure you can act on, your AUP is the right place to start.


Frequently Asked Questions

Is an Acceptable Use Policy legally required for SaaS companies?

No federal law requires SaaS companies to publish an AUP by that name, but several legal frameworks effectively require you to have the equivalent: the DMCA safe harbor requires a policy for handling copyright infringement, the CAN-SPAM Act requires email senders to follow specific rules you should reflect in your AUP, and data protection regulations require documented policies on authorized data processing. Beyond legal requirements, payment processors, enterprise customers, and app store operators typically require an AUP as a condition of doing business.

Can I just include AUP provisions in my Terms of Service?

You can, but a standalone AUP is generally more effective for three reasons: it is easier for users to locate and review, it can be updated independently when your platform changes, and it signals to enterprise buyers that your legal framework distinguishes between commercial terms (ToS) and use restrictions (AUP). Your ToS should cross-reference the AUP to make violations of the AUP a breach of the overall contract.

Does my AUP apply to API users?

Yes, your AUP should explicitly state that it applies to all methods of accessing the platform, including the web interface, mobile apps, and API. If your API is accessed by developers who then deploy applications to end users, consider whether those end users are subject to your AUP through the developer agreement, or whether you need a separate downstream use restriction.

How often should I update my AUP?

Review your AUP whenever you add a significant new feature, change your target market, encounter a new category of misuse that your current prohibitions do not clearly address, or when a relevant law or regulation changes. For AI-powered products in particular, the regulatory environment is moving quickly enough that an annual review is a minimum.

What if a user violates the AUP but I didn’t enforce it immediately?

Your AUP should include a non-waiver clause stating that failure to enforce a provision on one occasion does not waive your right to enforce it later. Without this, a pattern of non-enforcement can create an argument that you implicitly accepted the conduct. The non-waiver language and the “sole discretion” enforcement right work together to preserve your flexibility.

If your SaaS platform is growing and you do not have an AUP that specifically addresses your risk profile, the next user conduct problem you face will cost more to resolve than it would have to draft the document. Contact TOS Lawyer to have your Acceptable Use Policy drafted or reviewed by a technology lawyer who understands SaaS platforms.


Comments are closed.