Acceptable Use Policy

Last updated 21 August 2026.

This policy forms part of the Terms of Service for Morke, operated by Two Dice Ltd., 7 Bell Yard, London, WC2A 2JR, United Kingdom.

What this is

A short list of things you may not do with a Morke connection, and what we can do about them. It exists because our exit addresses are shared: what one account does through them lands on everyone else using the same node, and on us.

What you may not do

Through a Morke connection, do not:

  • Attack other systems. That covers port scanning, brute-force attempts, denial-of-service traffic, and exploiting machines you do not own.
  • Send spam, or run mail-sending infrastructure through the tunnel.
  • Distribute malware, or run phishing pages, botnet controllers or other command-and-control infrastructure.
  • Handle child sexual abuse material in any way. There is no circumstance in which this is tolerated and no appeal against acting on it.
  • Do anything that is illegal where you are, or illegal where the exit node is.
  • Get around an age check or another access control that a service is legally required to apply.
  • Resell access, share your account beyond your own devices, or work around the device limit.
  • Run automated bulk traffic that degrades the service for other people on the same node.

What we can and cannot see

We keep no record of what you connect to. No destination, no DNS query, no browsing history, at any retention. The Privacy Policy lists every row we do keep.

It follows that we generally cannot tell that any of the above is happening. We are not watching for it.

How we find out

From other people. The operator of a system that was attacked, a provider forwarding a report about one of our addresses, or a rights holder sending a notice. Those reports name an address and a time, which is all the outside world can see.

We keep no record of what any account did, so in almost every case a report tells us that something happened without telling us who did it. To be exact about the one row that comes closest: we hold, for a couple of hours, that an account had traffic on a given node during a 10-minute window. That covers everyone on that node in that window and says nothing about any particular connection, so it cannot answer a report either. It is listed in the Privacy Policy with every other row.

What we do about it

When a report is credible we act on the node: blocking traffic, changing what a node will carry, or taking an address out of service. Those measures affect everyone on that node, which is why they are a last resort.

Suspending an account is possible only when something other than a traffic record points at one, such as abuse of our own API or a report that names an account. When that happens we suspend it, which stops the activation key from working on every device at once. We do not refund the remaining time on an account suspended for breaching this policy.

If you think we have got it wrong, email team@twodice.tech with your Account ID and we will look at it again and tell you what we decide. Never send us your activation key.

Reporting abuse

Email team@twodice.tech. Include the address involved, the timestamp with its timezone, and what happened. We acknowledge reports within 30 days.

We will usually not be able to tell you who was responsible. What we can do is stop the traffic.

Send copyright notices to team@twodice.tech with the address, the timestamp and its timezone, and the work concerned. The same limit applies: we keep no record of what any account did, so we cannot identify a user in response to a notice. We can act on the node.

Changes to this policy

We update this page when the service changes or when a new kind of report starts arriving. The date at the top is the date the text last changed.