Skip to content
Heroku

Acceptable Use Policy

This Acceptable Use Policy defines the boundaries for using heroku.tech and, in contracted form, the boundaries Heroku data services enforce for their users and for ourselves. It forms part of the Terms of Service.

1. Site Usage

Do not submit content through site forms that is unlawful, harassing, infringing, or that contains personal data of others. Do not attempt to access non-public parts of the application, overload it with automated traffic, or use it to distribute malware. Standard, moderate use — reading, commenting, evaluating the platform — is exactly what it's for.

2. Data Program Boundaries

The same boundaries govern collection programs run by, or delivered through, Heroku services:

  • Public data only. No collection from behind authentication, paywalls or technical access controls.
  • Respectful collection. Rate-limited, identifiable collection that honors robots.txt directives where applicable and avoids degrading source services.
  • No personal data harvesting. Programs exclude private individuals' personal information and focus on commercial, public and aggregate signals.
  • Documented purpose. Every collection program has a documented, lawful purpose and retention limit.
  • No deception. No misrepresentation of identity or purpose when interacting with public services.

3. API Usage

Where APIs are concerned, rate limits are part of the product, not an obstacle: stay within documented limits, keep credentials secure, don't resell raw delivered data outside your licensed use, and design integrations to degrade gracefully when a 429 arrives. Abuse of shared infrastructure harms every user of it.

4. Enforcement

Violations of this policy may result in content removal, rate throttling, key suspension and, where necessary, account termination and legal escalation. We will contact you where practical before enforcement, except where the violation causes ongoing harm or involves illegal activity.

5. Reporting

To report a violation of this policy — by a user, a client program or a Heroku collection operation itself — contact tech@heroku.tech with the details and, where possible, evidence. Reports are reviewed by humans, and good-faith reports are always welcome.