[ policy // effective 2026-07-18 ]
Acceptable Use Policy
Vanishhub exists so that ordinary private communication stays private. That mission dies the moment the platform becomes useful for causing harm, so these rules are enforced even though we cannot read your content.
Prohibited
- Child sexual abuse material, in any form, without exception.
- Distributing malware, phishing kits, or stolen credentials, or using share links as a payload-delivery mechanism for attacks.
- Content or conduct that is illegal where we operate.
- Harassment campaigns, doxxing, or threats directed at individuals.
- Spam, bulk unsolicited mail, or abuse of the privacy email service for fraud.
- Attempting to breach, enumerate, or degrade the platform itself.
How enforcement works here
We cannot inspect encrypted content, and we don’t want to. We act on what we can see: abuse reports with share links, mail-flow patterns, payload sizes and frequencies, and account behavior. When a report is substantiated we remove the ciphertext, revoke the share, and may terminate the account that created it. We comply with legally valid orders under Switzerland law, and we resist and narrow requests that are overbroad or unlawful. We can only ever hand over what we hold. For pastes and files that is ciphertext we cannot decrypt. Stored mail is now the same: each mailbox is sealed to a key only its owner unlocks, so we cannot read messages already in a mailbox, and mail between two vanishhub accounts is end-to-end encrypted and never visible to us. The one residual exposure is the border — to exchange mail with the outside world we necessarily see an inbound or outbound message in the clear for the moment it crosses our systems, before it is sealed or as we hand it to a remote server. A valid order could compel us to capture future mail at that border for a named mailbox, but not to decrypt mail already stored. We say so plainly rather than imply a protection it does not have.
Jurisdiction
Vanishhub is operated from Switzerland, and Switzerland law governs this policy and our data-handling obligations. We answer only to legally valid Switzerland orders — or foreign requests routed through Switzerland’s mutual legal-assistance process — and we reject demands that lack force under Switzerland law. We chose a jurisdiction with strong privacy protections deliberately. What we can disclose, and what we have never been compelled to do, is published on our warrant canary.
Reporting abuse
Send the share link (or the offending email address) and a short description to abuse@vanishhub.io. A human reads every report. If the report concerns content we host, include the full link — without it there is nothing we can locate.
Retention
Expired and burned content is deleted, not archived. Contact-form submissions keep only your message and the reply handle you gave us. We keep aggregate service counters, not per-user activity trails. Anything we must retain operationally is documented in the architecture notes we publish with the code.