Last updated: 2026-08-27T00:00:00.000Z

Acceptable Use Policy

Draft pending legal review. Prepared in-house and reviewed against Singapore law and Paddle’s seller terms by AI on 2026-08-26. That is not a substitute for a Singapore-qualified lawyer, and checkout does not open until this review is complete. Not legal advice.

This policy applies to everyone who uses Thorp. It forms part of the Terms of Use.

The rule

Automate only what you are entitled to do yourself.

Thorp manages browser profiles stored on your machine. It does not hold an identity, and it does not make an unauthorised action permissible. It gives an automated process the same reach you have when you sit at the keyboard, and no more.

“Authorised” means that you have permission for the specific account, system, data, action and method of access from every person legally entitled to control that access. Possession of a password, or permission from an account holder, is not sufficient if a system owner, employer, client or applicable service term does not permit the relevant access or automation.

Permitted

Not permitted

You may not use Thorp to:

  1. Access any account, system or data without the specific authority described above.
  2. Transfer, rent, sell or share a browser profile, persistent login state or account where the account holder or applicable service terms do not permit it, or create accounts using another person’s identity documents or personal data.
  3. Bypass or defeat authentication, multi-factor authentication, CAPTCHAs, access controls, rate limits or other security or anti-abuse measures — whether or not the affected account is your own.
  4. Use profiles, device fingerprints, proxies, accounts or identities to evade a suspension, ban, access limit, rate limit, anti-abuse decision or other enforcement measure.
  5. Impersonate another person, create a materially false identity, or misrepresent a person, device, organisation or commercial relationship.
  6. Conduct fraud, payment fraud, phishing, credential stuffing, ad fraud, engagement manipulation, spam or bulk unsolicited messaging.
  7. Carry out automated social-media marketing or automated engagement optimisation, solve CAPTCHAs on behalf of anyone, or pursue any activity whose purpose is to infringe or evade a third-party service’s terms, restrictions or enforcement.
  8. Collect personal data unlawfully, or process it in breach of applicable data protection law.
  9. Distribute malware, or use the Software as part of an attack on any system.
  10. Do anything unlawful in Singapore, in any jurisdiction where you operate, or in any jurisdiction where the target service operates. This includes, without limitation, offences under the Singapore Computer Misuse Act and equivalent computer access laws elsewhere.

What we can and cannot see

We do not proxy, mirror or receive your traffic. Your browsing, your credentials and your automation stay on your machine. This means two things at once:

Reports and consequences

We act on a report only where we have reasonable grounds to believe this policy has been materially breached, or where we are served with a valid legal request. A report on its own is not reasonable grounds.

Before suspending or terminating a paid licence we will, so far as lawful and practicable: make reasonable enquiries; tell you what we believe happened; and give you a reasonable opportunity to respond or to put it right. Where the risk is serious and immediate we may suspend first, but we will still tell you and hear you promptly afterwards.

If a report turns out to be wrong, we restore the licence and extend the term by the time you lost. If we cannot restore it, we refund the unused part of the term. We may act immediately and without notice only where required by law or by a valid legal request, or where the conduct presents a serious and immediate risk to another person.

We do not hold your traffic or credentials, so we usually cannot independently confirm the underlying activity. That is a reason to make enquiries and hear you — not a reason to act without doing so.

To report abuse, or to raise a platform complaint, write to support@thorp.run with the licence reference and the specific activity concerned.

Why this policy is short and specific

We would rather lose a sale than take one from someone who needs the rules to be vague. A tool that holds live logins depends on being trusted by the people who use it and by the platforms those people work with. Broad language protects nobody. Specific prohibitions tell you exactly where the line is.