Acceptable Use Policy
What this protects
Three things: children, the integrity of discovery, and a shared metered platform. Our whole proposition is that a ranking can be honest — that a small loved game can out-rank a large one and that a clone can never outrank or outbid the original — so attempts to manipulate it are treated as attacks on the product, not as edge cases.
Allowed
Finding and joining servers to play. Building applications on the API within the rate limits, quotas and data surfaces of your plan, using your own keys. Using the keyless anonymous tier from the extension or a comparable anonymous client within its throttle. Claiming a Roblox game you actually own, viewing its analytics, and running honest sponsored campaigns for it.
Child safety — absolute
You must not use RIIP or any data from it to solicit, groom, sexualise, exploit or endanger a child; to locate, track or contact a specific child, including by hopping into the servers they occupy; to direct a child off-platform; to share age-inappropriate material through any surface; or to advertise anything that would be unlawful or unsafe to market to children. This is enforced without warning, and credible concerns are reported to the appropriate authorities and platforms.
Discovery integrity
Do not clone or impersonate another game to hijack its discovery, or buy a placement against an original you have copied — a likely clone or a game below the quality floor is ineligible for a sponsored slot at any bid, and working around that with a second account is itself a breach. Do not manufacture ranking signals with bots, alt accounts or incentivised traffic, generate invalid campaign traffic, claim a game you do not own, or strip the sponsored label when redistributing results.
Platform & API integrity
Do not circumvent rate limits, quotas, free allowances or the monthly billable cap — including by rotating IPs or minting accounts to multiply a free tier — and do not use the keyless anonymous tier as a substitute for a metered plan. Do not farm the signup bonus, probe for vulnerabilities outside our disclosure route, access another user's data, or register a webhook endpoint that resolves to a private address. Keep keys secret, request only the scopes you need, rotate on exposure, honour Retry-After, and verify webhook signatures and timestamps.
Enforcement
We escalate from the lightest effective action: algorithmic quality and clone dampening, then throttling, a warning and remediation window, campaign or content action, credential revocation, account suspension, and finally termination and referral. Child-safety risks, live attacks and fraud go straight to the strongest step. Every campaign is reviewed by a person before it first serves, flags from automated signals, operators and user reports are triaged to a reversible recorded decision, and every privileged operator action is written to an append-only audit trail. Decisions can be appealed.
This page summarises the document. The complete text is being finalised with counsel and will be published here on approval — email help@riip.gg for the current draft in the meantime.