Acceptable Use Policy
Last updated: EFFECTIVE_DATE
This Acceptable Use Policy (the "Policy") explains what you may and may not do when you access or use the Mareel Waters API, Documentation, Account, developer portal and related services (together, the "Services"). It is general information and not legal advice.
Scope and relationship to the Terms of Service
This Policy forms part of, and is incorporated by reference into, our Terms of Service. It applies to every Customer, Account holder and end user who accesses the Services through any channel, including the web API at https://mareelearth.com, the developer portal, the admin surfaces, and any iOS or Android applications we may publish (planned, not yet released). Defined terms used here, such as API, Endpoint, API Key, Account, Plan / Tier, Usage, Usage Event, Output (modelled tide/forecast values), Customer and Consumer, have the meanings given in the Terms of Service.
Where this Policy and the Terms of Service overlap, the two are intended to be read together. If there is a direct conflict between this Policy and the Terms of Service on a specific point, the Terms of Service prevail. We may update this Policy from time to time to reflect changes in the Services, the law, or operational and security needs, and the version published at /legal/acceptable-use applies to your use from its effective date.
Your right to use the Services is conditional on your compliance with this Policy. A breach of this Policy is a breach of the Terms of Service and may trigger the suspension, throttling and termination rights described below and in the Terms of Service.
You are responsible for all activity that occurs under your Account and API Keys, including activity by your own end users, employees, contractors and any application you build on the Services. You must ensure that anyone acting on your behalf, and any downstream user of an application you build, complies with this Policy.
Prohibited uses
You must not use the Services, and must not permit or enable any third party to use the Services, to do any of the following.
Illegal content or activity
- Engage in, facilitate, or promote any activity that is unlawful under the laws applicable to you or to us, including the laws of Sweden and the European Union.
- Infringe the intellectual property rights, privacy rights, or other rights of any person.
- Process, transmit or store content that is unlawful, defamatory, or that you have no lawful basis to process, including any Personal Data for which you lack a valid legal basis under the GDPR.
Abuse and interference
- Interfere with, disrupt, degrade, or impair the integrity, performance or availability of the Services or the underlying infrastructure, including our self-hosted servers and the Cloudflare Edge (Cloudflare) that fronts them.
- Transmit malware, worms, or any code of a malicious or destructive nature, or use the Services to deliver such content to others.
- Use the Services in any way that imposes an unreasonable or disproportionate load on our systems relative to your Plan / Tier.
Exceeding or circumventing rate limits and quotas
- Attempt to exceed, bypass, disable, or otherwise circumvent any rate limit, request quota, concurrency limit, or other usage control associated with your Plan / Tier.
- Distribute requests across multiple Accounts, API Keys, IP addresses or applications in order to defeat per-Account or per-Tier limits.
- Manipulate request patterns, headers, or coordinates with the intent of evading metering, billing, or capacity controls applied to your Usage and Usage Events.
Scraping, bulk extraction and dataset reconstruction
- Systematically scrape, harvest, or bulk-extract Output in order to build, train, populate, or reconstruct a standing copy of, or a substantial part of, our underlying tide, datum, or forecast dataset.
- Iterate the API across grids of coordinates and times for the purpose of mirroring or warehousing the modelled dataset rather than serving genuine, application-level demand.
Reselling or redistributing raw Output as a competing dataset
- Resell, sublicense, redistribute, or otherwise make available the raw Output as a standalone data product, data feed, or dataset that competes with, or substitutes for, the Services.
- Repackage Output as a bulk dataset for download or transfer. You may use Output within your own application or service to deliver value to your end users, as permitted by the Terms of Service, but the Output must not be the product itself.
Reverse engineering
- Reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, models, harmonic constants, inference methods, or internal structure of the Services, except to the extent this restriction is prohibited by mandatory applicable law.
- Attempt to derive, reconstruct, or infer our proprietary synthesis or modelling techniques from observed Output.
Security probing and attacks
- Probe, scan, or test the vulnerability of the Services or any associated system or network without our prior written authorisation.
- Attempt to gain unauthorised access to any Account, API Key, server, data, or part of the Services, or breach or circumvent any authentication, authorisation, or security measure, including the Authentication Cookie (signed JWT) mechanism.
- Conduct, facilitate, or participate in any denial-of-service or distributed denial-of-service activity against the Services or the Edge (Cloudflare).
Sharing API Keys
- Share, sell, lease, publish, embed in client-side code in a recoverable form, or otherwise disclose your API Key to any party not authorised to act on your behalf.
- Continue to use an API Key that you know or suspect has been compromised. You must keep your API Keys confidential and rotate them promptly if exposure is suspected. We store API Keys only in hashed (sha256) form and cannot recover the original value for you.
Automated account creation and free-tier evasion
- Create Accounts by automated means, in bulk, or under false or misleading details.
- Register multiple Accounts, or use disposable identities, in order to evade the limits, quotas, or pricing of the free Plan / Tier or any trial. Plan entitlements and prices are described at /pricing.
Safety-critical use is prohibited
The Output consists of modelled tide and, in future, forecast and water-state estimates. It is provided "AS IS", without warranty of any kind. Modelled values can be exceeded or undercut by real conditions: actual water levels can rise above the HAT (Highest Astronomical Tide) or fall below the LAT (Lowest Astronomical Tide) under the influence of weather, including storm surge, atmospheric pressure and wind. Computed datums and Chart Datum values provided through the Services are non-official unless explicitly sourced from a hydrographic office.
You must not use the Services, the API, or any Output:
- As the sole or primary basis for navigation, for safety-of-life-at-sea decisions, or for any safety-critical or life-critical decision.
- In any context where failure, inaccuracy, or unavailability of the Output could lead to death, personal injury, or serious environmental or property damage, unless the Output is combined with official, authoritative sources and appropriate independent safeguards, and a qualified human retains responsibility for the decision.
This prohibition mirrors the safety disclaimer in the Terms of Service and on our Attribution and Disclaimers page. The Services are not certified or warranted for navigation or safety-of-life use.
Child-directed use is prohibited
You must not use the Services in connection with any online service, application, or feature that is directed to children, nor use the Services to knowingly collect, process, or transmit Personal Data from children under the age of 13 (or the higher minimum age set by applicable law in your jurisdiction), unless you have implemented and maintain independent compliance with the U.S. Children's Online Privacy Protection Act (COPPA) and all other applicable child-protection and data-protection laws, including, where relevant, the GDPR provisions on children's data.
You are solely responsible for that compliance, including obtaining any required verifiable parental consent. We do not provide the Services as a means of obtaining COPPA-compliant or child-appropriate consent, and we do not act as your compliance mechanism for child-directed services.
Fair use and capacity protection
The Services are a shared platform delivered from finite, self-hosted compute capacity fronted by the Edge (Cloudflare). To protect availability and performance for all Customers, your use must be reasonable and consistent with the entitlements of your Plan / Tier.
We operate fair-use principles even where a numeric limit is not separately stated. Usage that is abnormal in volume, pattern, or concurrency, that appears designed to extract the dataset, or that materially degrades the experience of other Customers, may be treated as a breach of this Policy. Where your needs exceed the limits of your current Plan / Tier, the appropriate route is to move to a higher tier as described at /pricing, or to contact us, rather than to engineer around the limits.
We may apply technical controls, including rate limiting, request shaping, and bot-management at the Edge (Cloudflare), to protect the capacity and integrity of the Services.
Consequences of breach
If we reasonably determine that you have breached this Policy, or to protect the security, integrity, capacity, or lawful operation of the Services, we may take one or more of the following actions, with or without prior notice depending on the severity and urgency of the issue:
- Throttle, rate-limit, or temporarily degrade your access to one or more Endpoints.
- Suspend your Account, application, or specific API Keys.
- Revoke one or more API Keys.
- Terminate your Account and your access to the Services, in accordance with the Terms of Service.
- Remove or disable access to offending content or configurations.
- Report the matter to law enforcement, regulators, or other competent authorities where we are legally required to do so, or where we reasonably believe it is necessary to prevent or address unlawful activity or harm.
Wherever it is practical and lawful to do so, we will aim to give you notice and an opportunity to remedy a breach before taking the more serious of these steps. For breaches that are severe, that threaten security or availability, or where immediate action is required by law, we may act first and notify you afterwards. Suspension or termination under this Policy does not, by itself, entitle you to a refund, and our other rights and remedies under the Terms of Service and at law are unaffected.
Reporting and abuse contact
If you become aware of any use of the Services that breaches this Policy, of a security vulnerability, or of any suspected compromise of an Account or API Key, please tell us promptly.
- General support and abuse reports: [email protected]
- Legal and formal notices, including law-enforcement requests: [email protected]
Please include enough detail for us to investigate, such as the relevant Endpoints, timestamps, and a description of the activity. Do not include more Personal Data than is necessary to describe the issue.
Related policies
This Policy should be read together with our Terms of Service and our Privacy Policy, and with our Attribution and Disclaimers page, which sets out data-source credits and the full not-for-navigation disclaimer. Plan entitlements and prices are at /pricing.
General notice
This Policy provides general information about acceptable use of the Services and is not legal advice. The Services are operated by LEGAL_ENTITY, REGISTERED_ADDRESS (organisation number ORG_NUMBER, VAT number VAT_NUMBER). This Policy is governed by Sweden, with the courts of the courts of Sweden, with Stockholm District Court (Stockholms tingsratt) as court of first instance having jurisdiction, as set out in the Terms of Service.
Last updated: EFFECTIVE_DATE