Technology & Policy

Acceptable Use Policy: build a starting draft free, or have me draft the one you can actually enforce

The generator below produces a clean starting draft with live preview. It cannot know what your product is actually abused for, what your subscription agreement says about termination, or whether you get to keep the money when you cut someone off. That part is my day job.

Sergei Tokmakov, California attorney, CA Bar #279869. Writing platform policies since 2011.

Sergei Tokmakov, Esq., California attorney, CA Bar #279869
Sergei Tokmakov, Esq.
California Bar #279869

The most common way an acceptable use policy reaches my desk

You already have a ChatGPT or Claude draft of an acceptable use policy

The prohibited-conduct list is probably fine, and it is also the easy half. The risk is the six things the model had no way to know, because none of them are in its training data or in your prompt.

1. What your product is actually abused forEvery platform has two or three real abuse patterns. A generic list of twenty prohibitions covers neither of yours precisely.
2. What your subscription agreement says about terminationThe policy names the conduct. The agreement carries the termination right. If they disagree, the agreement wins.
3. Whether you keep prepaid feesTerminating for cause and refunding a year in advance are different outcomes, and only one of them is written down somewhere.
4. Whether you enforce what you publishedA policy is a representation about how your service runs. Selective enforcement is what a terminated customer builds their argument on.
5. Which carve-outs reach your contentIntellectual property and the trafficking carve-out sit outside Section 230, and need their own mechanisms.
6. What your appeals language promisedA friendly appeals paragraph can create a process you now owe every account you suspend.

$750 flat: one policy drafted or redlined, written comments, up to three rounds of email revisions. Scope confirmed in writing after a conflict check; nothing here creates an attorney-client relationship.

Short answer

Section 230 protects the moderation decision and says nothing about your contract. Under 47 U.S.C. 230(c)(2)(A), no provider of an interactive computer service is liable “on account of… any action voluntarily taken in good faith to restrict access to or availability of material that the provider or user considers to be obscene, lewd, lascivious, filthy, excessively violent, harassing, or otherwise objectionable, whether or not such material is constitutionally protected.” But a suspended paying customer almost never sues over the material. They sue for breach of the agreement they paid under, and that claim turns on a question Section 230 does not answer: did your acceptable use policy give you the right to cut them off on these facts, immediately or only after notice and a chance to cure, and did anything let you keep the prepaid fees. The policy is where you buy that right, and the price of not buying it is one bad account times a cure window. The generator below writes a sound prohibited-conduct list; the enforcement rights are the part that decides money.

What does one abusive account cost, and what does a cure period add?

Every number here is your own. I supply no industry averages for abuse cost, because yours depends on your infrastructure, your payment processor, and your deliverability. The calculator prices the clause you are about to accept or delete.

Enter 0 if the policy lets you suspend immediately for this category of conduct.
Chargebacks, complaint handling, infrastructure, deliverability damage, support load. Your estimate.
Handling cost
Cost of the cure window
Prepaid fees at risk
Annualized, across these accounts

Arithmetic on your own inputs, not a prediction or legal advice. It does not price the litigation risk of a wrongful suspension, which runs the other direction and is why the categories for immediate action have to be defined rather than open-ended.

Where acceptable use policies actually bleed

Five consequences, not definitions. Each one is a place I have watched real money change hands. Tap to open.

Section 230 protects the takedown, not the contractTwo different provisions doing two different jobs

People treat Section 230 as a single shield. It is two provisions with different subjects. 47 U.S.C. 230(c)(1) says that “no provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider,” which is about leaving content up. 47 U.S.C. 230(c)(2)(A) says no provider or user “shall be held liable on account of… any action voluntarily taken in good faith to restrict access to or availability of material that the provider or user considers to be obscene, lewd, lascivious, filthy, excessively violent, harassing, or otherwise objectionable, whether or not such material is constitutionally protected,” which is about taking content down. Neither one is about your subscription agreement.

The claim that actually arrives. Not a defamation suit from a third party. A breach-of-contract letter from the customer whose annual plan you killed in month four, arguing that the conduct was not within your policy, that you never gave the notice your own policy promised, and that you owe the unused balance back. Section 230 is silent on all three points. Your policy is not, or should not be.

Verified against 47 U.S.C. 230 at uscode.house.gov and law.cornell.edu on 2 August 2026.

The cure period is the abuse windowThe one clause with an arithmetic answer

Generated policies copy the notice-and-cure structure out of commercial contracts, where it belongs, and apply it to abuse, where it does not. If your policy says you will give thirty days’ written notice and an opportunity to cure before terminating, then for thirty days the spam keeps sending, the fraudulent listings keep converting, the scraper keeps running, and your infrastructure and your reputation keep paying. That is not a hypothetical risk, it is a multiplication: cure days times your cost per day, times the number of accounts like it per year, which is exactly what the calculator above computes.

The structure that works. Split the policy in two. Immediate suspension without notice for a closed, defined list: illegal content, security attacks, spam and unsolicited messaging, payment fraud, and conduct that exposes you to third-party liability. Notice with a real opportunity to cure for everything else, which is most things. Then say what happens to prepaid fees in each case, and say it in the agreement, not only in the policy.
Publishing a policy you do not runA posted policy is a representation about how the service works

The temptation with a generated policy is to accept a long, impressive prohibited-conduct list that nobody at the company has ever checked against. That creates two problems at once. The regulatory one: 15 U.S.C. 45(a)(1) declares unlawful “unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce,” and a published policy is a representation to your users about how your service operates. The contractual one is nearer term and more likely: a terminated customer whose lawyer finds three accounts doing the same thing that you left running has the beginning of a selective-enforcement argument, which is not a winning claim in itself but is enough to turn a clean termination into a negotiation.

What I write instead. A shorter list that matches your real abuse patterns, an express statement that enforcement is discretionary and that failure to act in one case is not a waiver, and no promise of a review process you are not staffed to run. Discretion, stated plainly, is more defensible than a promise you break.

Verified against 15 U.S.C. 45(a)(1) at uscode.house.gov on 2 August 2026. Quoted here as the operative statutory sentence; whether any particular enforcement practice is unfair or deceptive is a fact question I am not answering on a public page.

What Section 230 expressly does not reachIntellectual property, and the trafficking carve-out

Two carve-outs in the statute change what your policy has to do. 47 U.S.C. 230(e)(2) provides that “nothing in this section shall be construed to limit or expand any law pertaining to intellectual property,” which is why a copyright complaint runs on its own track and why a DMCA notice-and-takedown process is a separate mechanism from an acceptable use policy rather than a paragraph inside one. And 230(e)(5), added by FOSTA in April 2018, removes the protection, other than the good-faith filtering protection in 230(c)(2)(A), for civil claims under 18 U.S.C. 1595 predicated on section 1591 conduct and for state criminal charges predicated on sections 1591 or 2421A.

Practical consequence for the document set. If you host user content, the policy needs a companion intellectual-property process with a designated agent and a repeat-infringer rule, and it needs to point at that process rather than absorb it. Mixing them produces a policy that does neither job well.

Verified against 47 U.S.C. 230(e)(2) and 230(e)(5) at uscode.house.gov on 2 August 2026. Subsection (e)(5) added by Pub. L. 115-164, sec. 4(a), April 11, 2018.

The policy names the conduct; the agreement carries the rightWhere a document set drafted at different times comes apart

An acceptable use policy on its own does almost nothing. It is a list of conduct. The power to suspend an account, terminate a subscription, withhold a refund, and disclaim liability for doing so lives in the agreement the customer actually signed or clicked. Three things have to be true for the policy to work: the agreement has to incorporate the policy by reference, the agreement has to give you the right to modify the policy and say how notice of changes is given, and the termination and refund clauses in the agreement have to match the enforcement ladder in the policy. When those documents are written months apart, by different people or different models, that last one is the one that fails.

The five-minute check. Open your terms of service and your policy side by side. Find the sentence in the agreement that incorporates the policy. Find the termination-for-cause clause. Find the sentence about prepaid fees. If any of the three is missing, the policy is decoration.
Questions I get about acceptable use policiesSection 230, cure periods, refunds, enforcement, carve-outs
Does Section 230 protect me when I suspend a paying customer?

It protects the moderation decision. Section 230(c)(2)(A) covers action voluntarily taken in good faith to restrict access to material the provider considers objectionable. The customer’s claim is usually breach of the agreement they paid under, which turns on whether your policy gave you the right to suspend on those facts and what happens to their prepaid balance.

Should my policy require notice and a cure period?

Split it. Immediate suspension without notice for a closed list of defined conduct, notice and a real cure period for everything else. A blanket cure period is the window during which the abuse continues at your cost, and the calculator on this page prices that window at your own numbers.

Do I have to refund prepaid fees when I terminate for cause?

That depends on what your paper says, and the answer belongs in the agreement rather than only in the policy. Silence is the expensive option: it invites the argument that a pro-rata refund is owed. Say expressly what happens to prepaid amounts on a termination for cause, and make the policy and the agreement agree.

What does Section 230 not cover?

Section 230(e)(2) leaves intellectual property law untouched, so copyright and trademark claims run on their own tracks and need their own process. Section 230(e)(5), the FOSTA carve-out, removes the protection, other than the good-faith filtering protection, for the trafficking claims it lists.

Can I just use the free generator below?

For a straightforward product with a small set of predictable abuse patterns, a generated policy plus a careful read is a defensible starting point, and I built the generator so that it would be. Where I would not rely on it alone: when the policy has to line up with a negotiated agreement’s termination and refund clauses, when you host user-generated content at scale, when the product carries payments or regulated data, or when you have already suspended someone and they are disputing it.

Free acceptable use policy generator: a starting draft, not a finished policyFill the form and the document builds in place with live preview. Word, PDF, and print export. Use it to get the prohibited-conduct list on paper before you write the enforcement ladder.
Read this before you use the output. This generator assembles a standard acceptable use policy from your form inputs. It does not know what your product is actually abused for, what your subscription agreement says about termination and refunds, or whether you are staffed to run the process it describes. It is not legal advice, and using it does not make me your attorney.

You now have a draft I have never read. It is a sound prohibited-conduct list and an incomplete policy, because it was assembled from your form inputs and it does not know what your agreement says about termination or refunds. If this policy will actually govern paying accounts, the $750 flat fee covers me redlining exactly what you just generated and wiring it to your agreement, up to three revision rounds by email.

Send me this draft: $750

Work with me on it

If one document is all you need, buy the one document. I will tell you when a policy is all you need, and when the termination and refund clauses in the agreement underneath it are the real problem.

Most platforms land here

Acceptable use policy, drafted or redlined

$750
  • Drafted around what your product is actually abused for, or redlined against the draft you generated
  • Written comments on the enforcement ladder, immediate-suspension categories, prepaid fees, and how the policy attaches to your agreement
  • Up to three rounds of email revisions
Request this package, $750

Full policy stack or complex platform

$1,200
  • The policy plus the terms of service and enforcement or appeals language that have to agree with it
  • A marketplace with several user classes, or a platform carrying regulated or user-generated content
  • Coordination with your DMCA process, DPA, and API terms where they overlap
Request this package, $1,200

Written attorney consultation

$240
  • One narrow question answered in writing: the cure period, the refund clause, the suspension you already made
  • Send the draft and your question; get issues, risks, and next steps
  • Not a full redline; the honest choice when you need an answer, not a document
Request this package, $240

Every engagement starts with a conflict check and written confirmation of scope. Overflow beyond the flat fee is billed at $300 per hour by invoice, and I tell you before that happens. No free consultations, case evaluations, or document review.

Disclaimer. This page is general legal information, not legal advice. Using the generator, reading this page, or emailing me does not create an attorney-client relationship; that requires a conflict check and a written engagement agreement. Generated documents are starting drafts. Statutes, regulations, and cases change; every citation on this page was verified against the primary source on 2 August 2026 at uscode.house.gov, for 47 U.S.C. 230 and 15 U.S.C. 45. I am licensed in California. I do not carry professional liability (malpractice) insurance, and I give you that disclosure in writing with every engagement agreement.

Sergei Tokmakov, Esq. · California Bar #279869 · owner@terms.law