Legal
Legion Acceptable Use Policy
Version 1.0 ยท Effective October 7, 2026
What renters and providers may not do on Legion, and what Ambient will do about illegal activity or misuse, including suspension, termination, preservation of evidence and disclosure to authorities.
1. Who this policy applies to
This Acceptable Use Policy (the "Policy") applies to everyone who uses Legion, the GPU rental marketplace operated by Mechanus Labs Inc. ("Ambient," "we," "us"). That includes:
- renters, and anyone who uses or connects to a renter's rental;
- providers, and anyone with access to a provider's host.
You are responsible for anyone who uses Legion through your account, rentals, or hosts.
This Policy is part of the Legion Terms of Use. Terms defined there have the same meaning here.
In short: any illegal activity or misuse of Legion's systems is grounds for immediate suspension and termination of your account, without notice. We may preserve, retain, and secure anything on Legion's systems or on hosts connected to Legion as evidence. We may disclose it to law enforcement and other authorities and cooperate with their investigations, as the law permits or requires. Section 2 explains this in full.
2. Enforcement
2.1 Suspension and termination
Any illegal activity or misuse of Legion's systems, and any violation of this Policy, is grounds for immediate suspension and termination of your account, without notice. This applies to renters and providers alike.
We may take any of the steps in this section, alone or together, when we reasonably believe that a violation has occurred, is occurring, or is about to occur. We may also take them while we investigate.
Depending on the circumstances, we may:
- suspend or terminate your account, and any other account we reasonably believe is connected to you;
- stop, isolate, or end any rental, and stop allowing connections to it;
- withdraw any host from the marketplace and stop sending rentals to it;
- revoke API keys, SSH certificates, and other credentials;
- block container images, network destinations, or traffic; and
- refuse future access.
2.2 Preservation and retention of evidence
When we investigate suspected illegal activity or misuse, or when the law requires it, we may preserve, retain, and secure anything on Legion's systems or on hosts connected to Legion that may be relevant. This includes:
- workloads, running or stopped containers, and container images;
- files and other data in a rental;
- logs, connection and audit records, and network records, including egress decisions and the destinations a rental contacted;
- billing records, account information, and host information.
We may do this directly, through the Legion agent, or by requiring the provider of the host to do it. We may keep preserved material for as long as reasonably needed for the investigation and any resulting legal proceedings, or for as long as the law requires.
- Deletion is suspended. Normal deletion at the end of a rental, or on account closure, does not apply to preserved material while it is preserved.
- No change of ownership. Preserving material does not transfer its ownership to Ambient. We handle it only for the purposes in this section.
2.3 Disclosure to authorities
We may disclose preserved material, and any other information about you, your account, your rentals, or your hosts, to law enforcement, regulators, and other competent authorities. We may also cooperate with their investigations. We do so when the law requires it, and otherwise when the law permits it and we believe in good faith that disclosure is necessary to:
- respond to legal process;
- investigate or prevent illegal activity, fraud, or abuse;
- protect the security and integrity of Legion, its users, or providers; or
- protect anyone from harm.
2.4 Credits and earnings
If we terminate your account for a violation, and to the extent the law permits, we may:
- withhold your unused credits and any pending or unpaid provider earnings;
- reverse earnings for rentals connected to the violation; and
- offset amounts you owe us, including the costs of responding to the violation.
2.5 Reporting
We may report violations, and the people responsible for them, to law enforcement and other authorities. We may also report them to affected third parties and to the operators of networks or services that were targeted.
2.6 No duty to monitor
We do not routinely inspect the contents of workloads. We do monitor operational, security, and network signals to detect abuse, as described in the Privacy Policy, and we act on reports. Not acting on a violation does not waive our right to act on it, or on any other violation, later.
3. Prohibited uses (renters and providers)
You may not use Legion, or help or allow anyone else to use it, for any of the following.
3.1 Illegal content and activity
- Any activity that is illegal where it takes place, where the host is located, or where its effects are felt.
- Storing, processing, or distributing content that is illegal, including content that facilitates violence, terrorism, human trafficking, or the sexual exploitation of anyone.
3.2 Child sexual abuse material
- Producing, storing, processing, distributing, or seeking child sexual abuse material (CSAM), or any sexual content involving minors, including synthetic or AI-generated content.
- We report apparent CSAM to the National Center for Missing & Exploited Children (NCMEC), as U.S. law requires, and to other authorities as appropriate. We preserve related material as the law requires. We immediately terminate the accounts involved.
3.3 Malware, botnets, phishing and spam
- Creating, distributing, hosting, or controlling malware, ransomware, or botnets, or running command-and-control infrastructure.
- Phishing, credential harvesting, or impersonation.
- Sending spam or unsolicited bulk messages.
3.4 Attacks on third parties and unauthorized access
- Denial-of-service attacks, including DDoS attacks, against anyone.
- Scanning, probing, or testing the vulnerability of any system or network without the authorization of its owner.
- Accessing or attempting to access any system, account, or data without authorization, including brute-forcing credentials.
- Running open proxies or relays that allow others to hide the origin of traffic used for any of the above.
3.5 Attacks on Legion, hosts and other users
- Attempting to escape container isolation or to reach the host's operating system, other containers, or the provider's network.
- Tampering with, disabling, reverse engineering, or circumventing Legion's runtime, the Legion agent, network controls, metering, or monitoring.
- Accessing or interfering with another user's rentals, hosts, accounts, or data.
- Probing, scanning, or testing the vulnerability of Legion without our written permission. If you have found a security issue, tell us at support@ambient.xyz.
3.6 Circumventing controls and billing
- Circumventing or attempting to circumvent egress controls, network policy, rate limits, quotas, access controls, or usage limits.
- Avoiding or manipulating charges, metering, credits, or earnings, including by misreporting usage or hardware.
- Creating accounts to evade a suspension, a limit, or a ban.
3.7 Cryptocurrency mining
- Mining cryptocurrency in a rental, unless the host's listing expressly permits it.
3.8 Infringement and privacy
- Infringing or misappropriating anyone's intellectual property or other rights.
- Collecting, processing, or disclosing personal data in violation of the law.
- Harassing, threatening, defaming, or exploiting anyone.
3.9 Sanctions and export controls
- Using Legion, or making a host available, in violation of sanctions or export-control laws.
- Using Legion from, for the benefit of, or on behalf of sanctioned countries, regions, or persons.
- Using Legion for any prohibited end use, including the development or production of weapons of mass destruction.
3.10 Reselling access
- Reselling, sublicensing, or otherwise providing access to Legion, rentals, or hosts to third parties without our written permission.
4. Additional rules for providers
Providers have physical and administrative control of their hosts. Because of that, providers must also not:
- access renters' workloads. You must not intercept, inspect, record, copy, or modify any renter's workload, container, files, memory, storage, credentials, or network traffic, or allow anyone else to do so;
- tamper with, modify, or circumvent the Legion agent or the network rules it applies, or run rentals outside the agent's control;
- misrepresent a host's hardware, location, ownership, or performance, or manipulate benchmarks;
- run your own workloads, including mining, on GPUs while they are assigned to a rental;
- connect a host you do not have the legal right to use for this purpose; or
- ignore a request from us to preserve a rental's data or to keep a host connected during an investigation.
5. Additional rules for renters
Renters must also not:
- use a rental to attack, probe, or interfere with the host it runs on or the provider's network; or
- use Legion to store or process data you are not permitted to place on hardware operated by a third party (see Data Handling).
6. Reporting abuse
To report abuse on Legion, including traffic from a Legion rental or host, a security issue, or a suspected violation of this Policy, email support@ambient.xyz with "Legion abuse" in the subject. Where you can, include:
- what happened, and when (with time zone);
- the source and destination IP addresses, hostnames, or URLs involved;
- any rental or host identifier you have; and
- any logs or other evidence.
Do not send us child sexual abuse material, even as evidence. Report it directly to NCMEC's CyberTipline (report.cybertip.org) or to your local authorities, and tell us that you have done so.
Law enforcement and other authorities can contact us at the same address.
7. Changes to this Policy
We may update this Policy. Each version has a version number and an effective date. You must accept a new version before you can continue using Legion, as described in the Terms of Use.
8. Contact
Questions about this Policy: support@ambient.xyz