Skip to main content

Version 1.0 · Last updated 2026-09-09 · This policy is currently under legal review. Its wording may be refined before launch, and any material change will be announced in advance.

Acceptable Use Policy — GridBlitz

1. About This Policy

Welcome to the rulebook. GridBlitz works because most people show up to play in good faith — and this Acceptable Use Policy ("AUP") is the small set of rules that keep it that way. It covers what users can and can't do on the platform, what we may do to enforce the rules, and how you can report problems or appeal an enforcement decision.

GridBlitz is built for invite-only football-squares games among groups of people who already know each other — friends, family, coworkers, your weekly crew. It is not a public marketplace, a betting platform, or a money-handler. (See the GridBlitz Terms of Service ("Terms") Section 4 — Platform Description & Classification — and Section 1 of this AUP below for the full description of what the platform does and does not do.) The rules in this AUP exist to keep the platform usable for that community and to protect both you and GridBlitz from misuse.

A note on tone. This AUP uses plain English. Where a term has a specific legal or technical meaning, we explain it the first time it shows up. The substantive rules are binding; the plain-English explanations help you read what you're agreeing to.

How this AUP relates to other documents.

  • GridBlitz Terms of Service — the umbrella contract between you and GridBlitz. Section 6 of the Terms identifies the high-level categories of prohibited behavior; this AUP is the more detailed companion. If the AUP and Terms ever appear to disagree, the Terms control on the overall contract questions, and the AUP controls on the behavioral specifics it was written to govern.
  • GridBlitz Privacy Policy — describes how GridBlitz collects, uses, and protects your data. The AUP references the Privacy Policy for data-handling specifics (Sections 6.3 and elsewhere).
  • LEGAL_COMPLIANCE_FRAMEWORK_v1.md — the internal governance document that gave rise to the Critical Rules in Section 2 below. This AUP translates those Critical Rules into customer-facing prose.

Your acceptance. By creating an account, accessing the platform, or using any feature, you agree to this AUP alongside the Terms and the Privacy Policy. If you do not agree with any part of this AUP, do not create or use a GridBlitz account.


2. The Three Critical Rules

GridBlitz has three Critical Rules that apply to every user, every interaction, every game — no exceptions. The first two are about what GridBlitz IS as a platform; the third is about what GridBlitz IS NOT and how users must treat the platform's privacy posture.

Critical Rule 1 — GridBlitz Never Handles Money

GridBlitz does NOT, by design, ever collect, process, hold, transfer, or distribute money between players, between hosts and players, or between any participants in a Grid (the 10-by-10 digital game grid). Any money associated with a Grid is entirely offline between the Host (the user who creates the Grid) and that Host's Players (the users who join). See Terms Section 4 for the full description.

This rule shapes Section 4.6 below (Payment Misuse) — you cannot use GridBlitz to pretend or imply that the platform handles money, to initiate fraudulent chargebacks on legitimate Hosting purchases (a chargeback is when you dispute a charge with your card issuer to reverse the payment), or to organize illegal gambling operations under the cover of the platform.

Critical Rule 2 — Never Use Gambling Language on Platform Surfaces

GridBlitz is a SaaS coordination platform, not a gambling platform. The product UI, brand voice, marketing copy, and customer-facing surfaces never use gambling terminology (bet, wager, jackpot, payout as a platform function, "winning square," "losing square," prize pool managed by the platform, odds in a gambling sense). The user-facing term is Score Match — the Square whose row/column numbers correspond to the current score of the matchup the Grid is built around. See LEGAL_COMPLIANCE_FRAMEWORK_v1.md §3 for the full terminology rules.

This rule shapes Section 4.9 below (Misuse of the Invite-Only Posture) — you cannot use GridBlitz in a way that reframes the platform as a betting service or recasts your private game as a public gambling operation.

Critical Rule 3 — Private and Invite-Only (Always Emphasized)

GridBlitz is private and invite-only by design. Every Grid is host-controlled; there is no public game directory, no public leaderboard, no anonymous spectator access. The "private + invite-only" posture is not just marketing language — the platform's code is structured so anonymous requests cannot see Grid data, not just our written policy. The privacy posture is enforced in the software, not relied on as a promise.

This rule is load-bearing for the rest of this AUP. The prohibited behaviors in Section 4 below are calibrated around the assumption that GridBlitz hosts run small private games for people they already know, not public marketplaces. Behavior that violates the private-and-invite-only posture — for example, using GridBlitz to invite hundreds of strangers from public forums, or scraping the platform to build a competing public-squares site — is a Critical Rule 3 violation and is treated as such (Section 4.9).


3. Definitions

Defined terms used in this document. Where a term is also defined in the GridBlitz Terms of Service Section 2, the Terms definition controls and is reproduced here for convenience.

  • GridBlitz, the Platform, we, us, our — the GridBlitz SaaS coordination platform and its accompanying services
  • You, your, User — any individual who creates an account, accesses, or uses GridBlitz
  • Account — your registered identity on GridBlitz, created at signup
  • Host — a User who creates a Grid and manages the participants, schedule, and any offline money arrangements with those participants
  • Player — a User who is invited to and joins a Grid hosted by another User
  • Grid — a 10-by-10 digital game grid on GridBlitz, organized around a real-world NFL matchup
  • Square — an individual cell of a Grid (also "Tile" in some technical contexts)
  • Score Match — a Square whose row/column number combination corresponds to the current or final score of the matchup the Grid is built around
  • AUP — this Acceptable Use Policy
  • Acceptable Use Policy violation — behavior prohibited by Section 4 below
  • Enforcement action — an action GridBlitz takes in response to an AUP violation (Section 5)
  • Report — a notification submitted to GridBlitz alleging an AUP violation (Section 6)

4. What's Prohibited

The following behaviors are prohibited on GridBlitz. The list below is the enumeration that ToS Section 6 points at — it is the detailed companion the Terms reference. The list is not exhaustive; GridBlitz reserves the right to enforce against conduct that violates the spirit of the AUP even if not explicitly listed.

Quick reference — 9 categories of prohibited behavior:

  • 4.1 — Harassment, threats, and abusive behavior
  • 4.2 — Spam and unwanted communications
  • 4.3 — Impersonation and identity misrepresentation
  • 4.4 — Multi-account abuse and enforcement evasion
  • 4.5 — Automated access and scraping
  • 4.6 — Payment misuse and chargeback fraud
  • 4.7 — Illegal activity
  • 4.8 — Bypassing safeguards
  • 4.9 — Misuse of the invite-only / private posture

Each sub-section below describes a category of prohibited behavior, includes concrete examples to help you recognize it, and explains why the rule exists. We do NOT publish specific thresholds or detection mechanisms — per LEGAL §9 (Enforcement Disclosure Boundaries), publishing those would let bad actors engineer around our safeguards. See Section 5.5 below for the full statement of what we don't disclose.

4.1 Harassment, Threats, and Abusive Behavior

You may not use GridBlitz to harass, threaten, intimidate, demean, or abuse other Users.

Examples:

  • Sending threatening messages or invitations to another User
  • Repeatedly contacting a User who has indicated they want no further contact (use the Block feature in Account Settings to enforce this on your side; see Terms Section 7 and Privacy Policy Section 2.2)
  • Using a Grid's Square name, Grid name, or other custom Content field to direct abuse at another User
  • Coordinating with others to harass a User across multiple Grids

Why this matters: GridBlitz is built for private group games among people who already know each other. Harassment within the platform undermines the social trust the private-and-invite-only posture is built on (Critical Rule 3).

4.2 Spam and Unwanted Communications

You may not use GridBlitz to send unsolicited bulk communications, to send invitations at industrial scale, or to repeatedly contact Users who have not engaged with your prior outreach.

Examples:

  • Sending invitations to Users you have no real-world connection with (Critical Rule 3 emphasis: GridBlitz is for groups of people who already know each other)
  • Using automated tools (bots, scripts, scraped contact lists) to send invitations at scale
  • Repeatedly inviting the same User after they have declined or ignored prior invitations
  • Promoting external products, services, or Grids hosted off-platform via invitation messages

Why this matters: GridBlitz's invitation system is calibrated for personal invites from a Host to their actual social network. High-volume or automated invitation behavior breaks that calibration and degrades the platform for every other User.

4.3 Impersonation and Identity Misrepresentation

You may not misrepresent your identity on GridBlitz.

Examples:

  • Creating an Account using another person's name, photo, or contact information without their permission
  • Pretending to be a celebrity, public figure, GridBlitz employee, GridBlitz support agent, or representative of a brand you don't represent
  • Setting a display name, Square name, or Grid name designed to make other Users believe you are someone you are not
  • Falsely claiming GridBlitz endorsement, partnership, or affiliation in any Content you create

Why this matters: GridBlitz's invite-only model depends on Users being able to identify the actual people inviting them and joining their Grids. Identity misrepresentation breaks that trust.

4.4 Multi-Account Abuse and Enforcement Evasion

Each User is permitted one Account on GridBlitz per the Terms Section 3.3. You may not create multiple Accounts to evade enforcement actions (suppression, suspension, ban — see Section 5 below).

Examples:

  • Creating a new Account after GridBlitz has suspended or terminated your prior Account
  • Using a different email address or sign-in method to circumvent an enforcement decision applied to your primary Account
  • Maintaining several Accounts to inflate your apparent invite reach, fabricate Players in a Grid, or game any other platform feature

Why this matters: Enforcement decisions exist to protect Users and the platform from misuse; evasion attempts undermine that protection and trigger additional enforcement.

4.5 Automated Access and Scraping

You may not use automated tools (bots, scripts, scrapers, headless browsers — browser-like programs that run without a visible window, often used to automate web actions — or any other programmatic interface) to access, extract, or interact with GridBlitz, except where GridBlitz explicitly offers a public API for that purpose.

Examples:

  • Running a script to harvest Grid data, User display names, or other content from the platform
  • Building a third-party tool that scrapes GridBlitz to display or compete with GridBlitz functionality
  • Using automation to claim Squares, send invitations, or perform any other action that the platform expects to come from a real User
  • Figuring out how the platform's hidden connection points work and calling them directly, outside of the normal app screens (sometimes called "reverse-engineering")

Why this matters: Automated access at scale costs GridBlitz real money in infrastructure load, distorts safeguards calibrated for human-paced interaction, and undermines the private-and-invite-only posture (Critical Rule 3) by treating private game data as a public scrapeable resource.

4.6 Payment Misuse and Chargeback Fraud

You may not misuse GridBlitz's host-side purchase system or its third-party payment processor (Stripe — the company we use to process card payments; the same service many SaaS apps rely on).

Examples:

  • Initiating a chargeback on a legitimate GridBlitz Hosting purchase without first contacting GridBlitz support to resolve a billing question
  • Using stolen payment-method information to purchase GridBlitz Hosting access
  • Reselling GridBlitz Hosting credit to other parties as a commercial offering (your Hosting credit is for your own use)
  • Implying or claiming (in Grid names, Square names, marketing of your private game, or any other surface) that GridBlitz processes money between participants — that's not what the platform does (Critical Rule 1)

Why this matters: GridBlitz charges Hosts for SaaS access (Terms Section 4.2 and Section 9), not for any role in the offline money flow among Hosts and Players. Payment misuse threatens both the host-to-platform billing relationship and the platform's regulatory posture.

Required disclaimer per LEGAL §8 + Brand Voice §17: "The host manages payments directly with the group." GridBlitz does not process, hold, or distribute money between game participants.

4.7 Illegal Activity

You may not use GridBlitz to organize, facilitate, promote, or coordinate any activity that is illegal in your jurisdiction or in the United States.

Examples:

  • Using a Grid to run a gambling operation in a jurisdiction where private money pools are illegal (you are responsible for jurisdictional compliance per Terms Section 5.3)
  • Coordinating fraud, money laundering (disguising illegal earnings to make them appear legitimate), illegal sales, or any other criminal activity on the platform
  • Sharing illegal content (e.g., copyrighted material you don't have rights to, content that violates child-protection law)

Why this matters: GridBlitz is a digital coordination platform for private football-squares games among people who already know each other. Using it as cover for illegal activity exposes you (and potentially GridBlitz) to criminal liability and is not a legitimate use of the platform.

4.8 Bypassing Safeguards

You may not bypass, attempt to bypass, or circumvent any technical safeguard, rate limit, access control, security mechanism, or feature gate that GridBlitz uses to operate the platform safely.

Examples:

  • Exploiting a security vulnerability instead of reporting it through Section 6 below
  • Manipulating client-side code to access surfaces or features your Account is not authorized for
  • Tampering with the bot-protection layer (e.g., Cloudflare Turnstile — the service that helps tell humans apart from bots without making you solve a CAPTCHA puzzle) on the account-creation, email-sign-in-link, or password-reset paths
  • Attempting to extract another User's session token, password, or other credential

Why this matters: Safeguards protect every User from harm and protect GridBlitz from threats that would degrade the experience for everyone. Bypassing them is treated as severe AUP violation regardless of whether you "succeeded" — the attempt itself is the violation.

4.9 Misuse of the Invite-Only / Private Posture (Critical Rule 3 Emphasis)

You may not use GridBlitz in a way that violates or circumvents its private-and-invite-only design.

Examples:

  • Publicly listing a GridBlitz Grid for anonymous strangers to join (e.g., posting a Grid invite link on a public forum or social-media post and accepting all comers without vetting)
  • Building, marketing, or operating a service on top of GridBlitz that re-exposes Grid data publicly
  • Reframing GridBlitz publicly as a "public squares marketplace" or a "betting service" or any other characterization that misrepresents the platform's classification
  • Using GridBlitz's invitation system as a substitute for a public sign-up funnel that GridBlitz does not offer by design

Why this matters: The private-and-invite-only posture (Critical Rule 3) is not optional and not just marketing. It is structural to GridBlitz's compliance posture, its trust commitments to Users, and its actual product design. Users who treat the platform as if it were public undermine the foundation the rest of the AUP is built on.


5. How We Enforce

GridBlitz reserves the right to take enforcement action against AUP violations. The platform uses three categories of enforcement action, described below in increasing severity.

Quick reference — 3 enforcement categories:

  • §5.1 — Suppression (silent): a specific action you attempt is filtered or blocked, but your Account is unaffected. You won't be notified.
  • §5.2 — Suspension (temporary): your Account is restricted for a period; you may still sign in but can't perform certain actions.
  • §5.3 — Termination (permanent): your Account is closed permanently.

Plus §5.4 (Silent Enforcement Principle — why suppression is silent), §5.5 (What we don't disclose), and §5.6 (Appeals).

5.1 Suppression (Silent)

The platform may silently filter or block specific actions you attempt — for example, an invitation you send may not be delivered to its recipient, or a join request you submit may not reach the Host. You will not be notified that the action was suppressed; from your perspective, the action appears to have succeeded normally, but the downstream effect does not occur.

Suppression is the default enforcement layer for behavior the platform identifies as inconsistent with the AUP (e.g., suspected spam, suspected bot activity, attempted contact with a User who has blocked you). It does not affect your overall Account status — you can continue to use the platform normally; only specific actions are filtered.

Suppression is silent by design (see Section 5.4 below for why).

5.2 Suspension (Temporary)

For more serious or repeated AUP violations, GridBlitz may suspend your Account temporarily. While suspended, you may still be able to sign in but you will not be able to perform certain actions (host new Grids, send invitations, claim Squares, etc.). The product UI will display a generic "your account is restricted" indication; we will not disclose the specific behavior that triggered the suspension or the specific threshold you crossed (Section 5.5).

Suspension is typically used as a circuit-breaker (a temporary stop to prevent further damage while we investigate) — to interrupt ongoing AUP-violating behavior while we review the situation. Suspensions may be lifted on their own (after a cool-down period) or via an appeal you initiate (Section 5.6).

5.3 Termination (Permanent)

For the most severe AUP violations (Section 4.7 Illegal Activity, Section 4.8 Bypassing Safeguards, persistent Section 4.4 Multi-Account Abuse, or any AUP violation that creates direct risk to other Users or to the platform), GridBlitz may terminate your Account permanently.

Termination follows the procedure in Terms Section 7.3 (Effect of Termination). Your access to the Platform ends; you may be subject to the cascading-anonymization sweep (the process that replaces your identifying information with placeholders across audit logs, historical Grid records, and other surfaces; full mechanics in Privacy Policy Section 8) described in Terms Section 7.1 + Privacy Policy Section 8. Certain provisions of the Terms (intellectual property, disclaimers, dispute resolution, indemnification, severability) survive termination.

5.4 Silent Enforcement Principle

Enforcement actions other than suspension and termination operate silently — you experience the outcome (an invitation that doesn't arrive, a join request that goes nowhere) without an explanation of why or even an acknowledgment that anything happened. This is intentional design, not an oversight.

We understand this can feel opaque, especially if you're on the receiving end. The reason it works this way is the same in every social platform that takes harassment seriously: silent enforcement protects every other User from the bad behavior without creating social signaling, without exposing the platform's detection mechanisms, and without giving bad actors a feedback loop they can use to engineer around the safeguards. If users knew the exact moment a safeguard fired, they could test until they found the edge of it — which would weaken the protection for everyone else.

This principle is consistent with our broader product design — see Terms Section 7.2 (Enforcement Actions by GridBlitz) for the umbrella commitment.

5.5 What We Don't Disclose

Consistent with LEGAL §9 (Enforcement Disclosure Boundaries) and the silent enforcement principle in Section 5.4 above, GridBlitz does not publicly disclose:

  • The specific thresholds that trigger enforcement actions (e.g., "X invites per hour triggers suppression")
  • The detection mechanisms or algorithms used to identify AUP violations
  • The internal rate limits, trust-scoring, or moderation logic that informs enforcement decisions
  • Whether a specific User has been suspended, suppressed, blocked by another User, or flagged for review (relationship state is private to each User)

This is not because we are hiding the rules — the rules are this AUP, and the rules are public. We don't disclose the detection mechanisms because publishing them would let bad actors engineer around them, which would weaken the safeguards for every legitimate User.

5.6 Appeals

If you believe an enforcement action against your Account was a mistake, you may appeal by contacting GridBlitz through the support channel described in Terms Section 7.2. The appeal process, response window, and substantive review approach are described in the Terms; this AUP does not duplicate that substance.

In an appeal review, we will reconsider the action on the merits. We will not, however, disclose the specific detection logic or threshold values that informed the original decision (per Section 5.5 above) — that confidentiality protects the integrity of the safeguards for every other User.


6. Reporting Problems

GridBlitz takes AUP violations seriously and depends on Users to report behavior they see that violates this AUP. This Section describes what you can report, how to report it, what happens after a report, and what NOT to do with the reporting mechanism.

6.1 What You Can Report

The following are appropriate things to report to GridBlitz:

  • Harassment, threats, or abuse directed at you or someone you can see in a Grid you participate in (Section 4.1)
  • Spam or unwanted invitations at unusual scale (Section 4.2)
  • Impersonation — an Account that appears to be impersonating you, someone you know, or a public figure (Section 4.3)
  • Suspicious account activity — Accounts that appear to be bots, scrapers, or coordinated multi-account operations (Section 4.4, 4.5)
  • Payment fraud or chargeback abuse affecting you or your Grid (Section 4.6)
  • Illegal activity organized on or facilitated by GridBlitz (Section 4.7)
  • Security vulnerabilities — flaws in the platform that could be exploited (Section 4.8). Please report responsibly; do not exploit or share the vulnerability before contacting us
  • Misuse of the invite-only posture — accounts treating GridBlitz as a public marketplace (Section 4.9)

You can also report behavior you're uncertain about; we'd rather hear about a possible issue than miss one.

6.2 How to Report

GridBlitz offers two reporting channels:

In-app reporting (primary). (to be finalized before launch) This is the recommended primary channel — it captures contextual data (which Grid, which User, what timestamp) automatically and routes directly to the GridBlitz trust-and-safety queue.

Email fallback. (to be finalized before launch) Use the email fallback if you cannot reach the in-app form (for example, if someone is impersonating GridBlitz in an email to you and you want to report that from outside the platform, or if your Account is suspended and you want to appeal).

Both channels reach the same internal review queue; the in-app form is faster to triage because of the automatic context.

When reporting, please include: a description of what happened, the User's display name or other identifiable information (if you can provide it), the Grid context (if applicable), approximate timestamp, and any specific concerns about urgency (for example, "this is a threat to my physical safety" should be reported with that framing so the queue triages appropriately).

6.3 What Happens After a Report

After you submit a report:

  1. Acknowledgment. (to be finalized before launch) GridBlitz will acknowledge receipt of your report.
  2. Review. A member of the GridBlitz trust-and-safety team reviews the report on the merits. The review may involve looking at the reported User's account activity, the Grid context, audit-log entries (see Privacy Policy Section 2.6), and other internal signals.
  3. Action (or no action). If the review concludes that AUP violation occurred, GridBlitz takes appropriate enforcement action per Section 5 above. If the review concludes that no violation occurred, no enforcement action is taken. Either outcome may not be visible to you — see "What you will and won't be told" below.
  4. Privacy preserved throughout. GridBlitz does not disclose the identity of the reporter to the reported User. We do not disclose the reported User's specific enforcement outcome to the reporter beyond a general acknowledgment (Section 5.5).

What you will and won't be told.

You will be told: that your report was received; in some cases, a general confirmation that GridBlitz acted on the report (without specific enforcement details).

You won't be told: whether the reported User was suspended, banned, or otherwise sanctioned (relationship state is private per Section 5.5); the specific evidence or signals that informed our review; the specific threshold values or detection logic used.

This is intentional. Disclosing specifics would expose the safeguards to circumvention and reveal private state about other Users.

6.4 Bad-Faith Reports

You may not knowingly submit a false report ("bad-faith report") — for example, reporting a User for harassment when no harassment occurred, or reporting an Account as an impersonator when you know it's the legitimate person.

Bad-faith reports are themselves an AUP violation (Section 4.1 — abusive behavior — when used to harass a specific User; or Section 4.7 — illegal activity — when the false report alleges criminal conduct). Bad-faith reports may result in enforcement action against the reporter.

Submitting a report in good faith based on an honest concern, even if review later concludes no violation occurred, is NOT a bad-faith report. We expect Users to err on the side of reporting; the AUP violation is knowingly false reporting, not mistaken reporting.


7. Account Holders' Responsibilities

This Section extends Terms Section 5 (User Responsibilities) with AUP-specific obligations for Hosts and Players.

7.1 Host Responsibilities

As a Host, you are responsible for:

  • Inviting only Players you intend to invite (per Critical Rule 3 — Section 2 above; private-and-invite-only)
  • Doing your best to invite people you trust to follow the rules — you're not strictly liable for what your invitees do, but if you knowingly invite someone you have reason to believe will violate the AUP on your Grid, that's relevant to any enforcement action against you
  • Managing reports of behavior in your Grid — if a Player in your Grid reports behavior by another Player, work with that Player to resolve it (block, release Squares, escalate to GridBlitz via Section 6 above if needed)
  • Compliance with any host-managed money rules in your jurisdiction (per Terms Section 5.1 + Section 5.3)
  • Not using your Host role to coerce, pressure, or manipulate Players into participating, contributing money offline, or otherwise acting against their interests

7.2 Player Responsibilities

As a Player, you are responsible for:

  • Treating your Host and fellow Players respectfully in any communication channel inside or related to a Grid you joined
  • Settling any offline money commitments with your Host per the Host's rules — see Terms Section 5.2 + Section 4.5 What We Do NOT Share in the Privacy Policy
  • Reporting AUP violations you observe in Grids you participate in (per Section 6 above)
  • Not using GridBlitz Player surfaces to harass, spam, or impersonate other Users (Sections 4.1, 4.2, 4.3)

8. Changes to This Policy

GridBlitz may update this AUP over time — adding new prohibited categories as new abuse patterns emerge, clarifying existing rules, complying with new laws, or refining enforcement procedures. When we make a material change (a change that meaningfully expands what's prohibited, alters enforcement procedures, or restricts behavior previously allowed), we will notify Users at least (to be finalized before launch) before the changes take effect, by:

  • Email to the email address on file with your Account, AND/OR
  • An in-app banner or notification on next sign-in

If you do not agree with a material change to this AUP, your options are: (a) stop using the Platform before the effective date, or (b) request Account deletion per Terms Section 7.1 + Privacy Policy Section 8.

Non-material changes (typo corrections, clarifications, examples added to existing categories, contact-information updates) take effect immediately and are recorded in the changelog at the top of this document.

Each version of this AUP is preserved with its effective date. You may request the current and historical versions from GridBlitz at any time per Section 9.


9. Contact Information

Questions about this AUP, AUP reports, or appeals may be directed to:

  • Operating Entity: (to be finalized before launch)
  • Trust & Safety Email / In-App Form: (to be finalized before launch)
  • Mailing Address: (to be finalized before launch)

For general account support, billing questions, or technical issues unrelated to AUP, use the support channel reachable from within the Platform.


10. Standard Clauses

What this section covers (plain English): four standard housekeeping commitments that apply to this AUP — what happens if a court strikes down part of this AUP, whether our not enforcing something means we've waived it forever, whether we can transfer this AUP to another company, and which state's law governs disputes about it. These mirror the same four clauses in our Terms of Service Section 14 and Privacy Policy Section 15.

  • Severability — if a court or regulator strikes down any provision of this AUP, the rest stays in effect to the maximum extent permitted by applicable law
  • No waiver — GridBlitz's failure to enforce any provision of this AUP is not a waiver of that or any other provision
  • Assignment — GridBlitz may transfer its rights and obligations under this AUP in connection with a merger, acquisition, or sale of assets, subject to the Business Transitions clause in Privacy Policy Section 4.4
  • Governing law and dispute resolution — disputes about this AUP are governed by the same law and resolved through the same mechanism as the GridBlitz Terms of Service (see Terms Section 12) (to be finalized before launch)

Appendix A — Required Disclosures Summary

The following disclosures are made consistent with the GridBlitz LEGAL_COMPLIANCE_FRAMEWORK_v1.md governance authority:

  1. Platform Classification (per CLAUDE.md §1 + LEGAL §1). GridBlitz is a SaaS coordination platform, not a gambling platform, betting service, financial intermediary, or prize authority.
  2. Money-Handling Statement (per LEGAL §3 Critical Rule 1). GridBlitz does not collect, process, hold, transfer, or distribute money between participants. All Player–Host money flows are offline and outside the Platform.
  3. Private and Invite-Only Posture (per LEGAL §3 Critical Rule 3 + ADR-019 Hosted-Game Privacy Invariant). GridBlitz is private and invite-only by design; this is structurally enforced, not just messaged.
  4. Enforcement Disclosure Boundaries (per LEGAL §9 + PRD §31 P-5 Silent Enforcement). GridBlitz may enforce this AUP; it does NOT publicly disclose enforcement thresholds, detection logic, suppression triggers, rate-limiting algorithms, or moderation logic.
  5. 18+ Age Requirement (per ADR-025 + Terms Section 3.1). Users must be at least 18 years old; this AUP applies equally to all adult Users.
  6. Reporting Channels (per Section 6.2 above). GridBlitz offers two reporting channels — in-app primary and email fallback; both route to the same internal review queue.
  7. Appeals Mechanism (per Section 5.6 + Terms Section 7.2). Enforcement decisions are appealable via the support channel described in Terms Section 7.2.
  8. Audit Log of Enforcement (per ADR-022). Enforcement events are recorded in GridBlitz's internal audit log (Privacy Policy Section 2.6) for compliance defense and incident review; the audit log is internal to GridBlitz, not a User-facing surface.

Appendix B — Definitions Cross-Reference

For convenience, key terms used in this AUP and where they live:

  • GridBlitz / Platform / we / us / our — Section 3 above + Terms Section 2
  • You / your / User — Section 3 above + Terms Section 2
  • Account — Section 3 above + Terms Section 2
  • Host / Player / Grid / Square / Score Match — Section 3 above + Terms Section 2
  • AUP / Acceptable Use Policy violation / Enforcement action / Report — Section 3 above
  • Suppression / Suspension / Termination — Section 5.1, 5.2, 5.3 respectively
  • Silent enforcement — Section 5.4
  • Bad-faith report — Section 6.4
  • Material change — Section 8
  • Cascading anonymization — Privacy Policy Section 8.3 (cross-reference)
  • Better Auth, audit log, scrypt, defense-in-depth — Privacy Policy Section 2 + Section 12 cross-reference