Acceptable use
Royden So, Hong Kong SAR. Effective 25 August 2026.
This policy is part of the terms of service. It applies to everyone who signs in, with any credential, on any deployment of this preview.
It's short on purpose. Two of these rules are the ones that actually get broken, and both are at the top.
1. Keep the login inside your organisation
- Share it with colleagues, contractors and advisers working on this engagement. That's what it's for.
- Don't post it in a public channel, a shared document outside your organisation, a ticket, or anywhere it gets indexed.
- Don't pass it to another agency, a vendor, or a friend who wants a look, without asking us first. We'll usually say yes, and we'd rather issue them their own.
- Tell us within two business days if it's been shared further than intended, or if someone with it has left.
- Sign out on a machine that isn't yours.
Everything done with your credential is attributed to your organisation. There's no way for us to tell your people apart.
2. Don't put other people's data in here
Prototypes run on fabricated placeholder data, and this site is built to hold a design conversation, not a customer record. If you need to point at a real case, describe it: order from a repeat customer, mid-size, second return, and we'll build a placeholder that matches.
Also keep out:
- credentials, API keys, tokens and passwords for anything, yours or ours
- another party's confidential material you're not free to share
- anything under an embargo or an NDA that doesn't cover us
- files you haven't scanned, and anything executable
3. Don't take the work outside the review
- No public screenshots, recordings, walkthroughs, livestreams or social posts of unreleased work.
- No sharing a share link, a QR code or an exported file outside the group in section 1.
- No presenting the material externally, to an investor, a customer or a conference, without our written agreement.
- No downloading, extracting or reconstructing source you weren't given, and no reverse engineering.
- No using what you see here to brief a competing build.
Ask, and most of these turn into a yes with a date attached. The terms set out what a licence covers, and section 8 there explains why the answer sometimes waits for an invoice.
4. Don't stress the site
- No scraping, crawling, bulk downloading or automated access of any kind.
- No penetration testing, vulnerability scanning, brute forcing or any other security testing. If you want an assessment, ask and we'll arrange one properly.
- No attempt to reach another workspace, another client's material, or any route your login isn't scoped to.
- No probing, interfering with, or overloading the infrastructure.
- No uploading malware, and no using the site to store or transmit anything unrelated to the engagement.
If you find a security problem by accident, and it happens, tell us at contact@roydenso.com and stop there. We'll thank you properly, and we won't come after anyone who reports something in good faith and doesn't go further into it.
5. What you write
Comments here are read by real people, in a small room, usually about work that isn't finished. Be direct about the work, which is the point of the tool, and don't make it about the person.
Nothing unlawful, harassing, defamatory, discriminatory or infringing, and nothing you wouldn't want read aloud in the project meeting, because it effectively will be.
6. What happens if this is broken
Depending on what happened, we may remove the content, rotate the credential, suspend the access, withdraw it, or in a serious case end the engagement and pursue what the terms allow.
In almost every case the first step is an email asking what happened. Most breaches here are somebody being helpful in a hurry.
7. Reporting something
A lost credential, a screenshot that got out, a security worry, a comment that shouldn't be there: contact@roydenso.com. Fastest is best, and nothing you report in good faith will be held against you.