Acceptable Use Policy
What Photon Now may not be used for. Part of the Terms of Service.
Version 2026-09-03 · effective
1Why this policy exists
Photon Now gives you remote control of the devices you enrol: it runs commands on them, opens sessions into them and can publish services on them to the internet. This policy says what that may not be used for. It is part of the Terms of Service, and changes to it are made the way section 13 of the Terms describes.
It applies to you, and you are responsible for compliance by everyone in your organisation and by anyone you let use your account or your devices.
2The rule everything else follows from
You must own every device you enrol, or otherwise be entitled to exercise administrative control over it. You warrant that this is true for each device, and that you have every consent, notice and legal basis needed for what you do to it through Photon Now. Enrolling a device you are not entitled to control is the most serious breach of this policy there is.
If people use the devices you manage — your staff, your household, or members of the public at a kiosk or a shared terminal — you are responsible for telling them what you monitor and what you can do remotely. We have no relationship with them and cannot tell them on your behalf.
3What you must not do
You must not use Photon Now, or let anyone use it, to:
- Reach a system you are not entitled to control — gaining or attempting to gain unauthorised access to any device, network, account or data, including through a tunnel, an automated flow or a terminal session.
- Distribute or operate malicious software — malware, ransomware, rootkits, cryptominers installed without the device owner’s knowledge, or anything designed to damage or take control of a system.
- Run command-and-control infrastructure for a botnet or for compromised machines.
- Conduct covert surveillance — stalkerware, spyware, or monitoring of a person’s device without the notice and consent the law where they live requires. Monitoring a partner, an ex-partner, a family member or a child in secret is never acceptable use, whatever the device’s ownership.
- Intercept communications unlawfully — or capture credentials, keystrokes or private messages you are not entitled to.
- Abuse the tunnel gateway — using it to relay traffic to systems you do not control, to proxy or anonymise unrelated traffic, to bypass a network control that someone else lawfully imposed, or to publish content that breaks the rest of this policy.
- Attack or overload anything — denial-of-service traffic, port scanning or vulnerability testing against systems that are not yours, spam, or deliberately exhausting our infrastructure or another organisation’s share of it.
- Undermine the platform itself — circumventing authentication, the separation between customers, permission checks, rate limits or billing; probing another organisation’s data; or reverse engineering the service except where the law expressly permits it. Reporting a flaw responsibly is not a breach — see section 6.
- Break the law or a sanctions regime — Norway applies EU and UN sanctions. You must not use Photon Now in, or for the benefit of, a sanctioned jurisdiction or a sanctioned party, or to store or distribute content that is unlawful — child sexual abuse material above all, which we report to the authorities.
- Infringe someone else’s rights — distributing software or content you have no licence to distribute, including through the Files feature.
4Your own security obligations
Device tokens and your sign-in credentials are keys to real machines. Keep them secret, do not commit them to public repositories, and revoke them when someone leaves or a device is retired — deleting a device revokes its token immediately.
A tunnel endpoint is reachable by anyone who finds it unless you gate it: keep the address allow-list or the sign-in credentials on the rule current, and do not choose “public” for a service that has no authentication of its own. Remove a device from Photon Now as soon as you stop being entitled to control it, and close tunnels you no longer need.
5What we do about breaches
We do not inspect the content of your commands, your logs or your tunnel traffic as a matter of course. Command output and step results are stored for the periods in the Privacy Policy, HTTP tunnel traffic is decrypted at our gateway in order to route it, and our staff look at any of this only in the cases section 4 of the Terms allows. We act on what we are told, on what our own security logs show us, and on what a lawful request requires.
Where abuse is live, we may suspend an account, a device or a tunnel immediately and without prior notice — and, where we cannot isolate the device or tunnel concerned, the whole account. We will tell you what we suspended and why as soon as we reasonably can.
If you think we got it wrong, write to hello@photonnow.com and say so; we will answer within five working days. Where a suspension turns out to be unjustified we will restore access and credit or refund the part of any paid period you lost.
Depending on what we find we may also remove content, report the matter to the authorities, and terminate the agreement.
6Reporting abuse, and reporting flaws
To report abuse of Photon Now — including a device you believe is enrolled without its owner’s authority — write to hello@photonnow.com with enough detail for us to find it. We take reports about non-consensual monitoring seriously and we act on them quickly.
To report a security vulnerability in Photon Now itself, follow our Vulnerability Disclosure Policy. Testing within that policy is authorised and is not a breach of this one.