Security & Abuse Policy
Security & Abuse Policy
This Security & Abuse Policy describes prohibited conduct that threatens Normal Survival, NormalSMP, World Venture Projects infrastructure, community safety, and business operations. It supplements our Acceptable Use Policy and Terms of Service.
Effective date: 2026-08-14 · Legal bundle c3e9f1a2-8b47-4d15-9c6e-0a2f7d4b8e91 (v1.3.6)
All users must comply. Violations may result in moderation action, permanent bans, benefit forfeiture, provider referrals, and—where appropriate—referral to law enforcement.
Scope
This policy applies to all use of Normal Survival, NormalSMP, World Venture Projects Services worldwide, including game servers, websites, forums, Discord, and related systems operated by World Venture Projects.
Community rules: Rules
Prohibited automation and botting
You must not:
- Use unauthorized bots, scripts, or automated clients to play, farm, vote, or interact with Services
- Deploy macro or autoclicker tools beyond what server rules explicitly allow
- Operate bot networks or coordinate automated accounts to manipulate gameplay, economies, or leaderboards
- Use AFK exploitation beyond permitted rules to gain unfair advantage
Allowed automation is only what we explicitly permit in server rules or written announcements.
Network and infrastructure attacks
You must not:
- Launch or participate in DDoS, volumetric floods, or denial-of-service attacks against our servers, websites, or providers
- Abuse packets, proxies, or VPNs to bypass rate limits or stress-test systems without written authorization
- Attempt to disrupt hosting, payment, or authentication systems
Authorized security testing requires prior written approval from [email protected].
Real-world harm and harassment
You must not:
- Dox or publish private personal information (real name, address, phone, school, workplace, family details) to harass or intimidate
- Engage in SWATing, stalking, or credible threats of real-world violence
- Coordinate harassment across platforms targeting our staff, players, or business
- Encourage others to commit the above conduct
In-game trash talk is not an excuse for publishing private information or credible threats.
Child sexual exploitation, CSAM, and grooming are covered by our Child Safety Policy and are zero-tolerance.
Account and credential abuse
You must not:
- Phish or social-engineer staff or players for passwords, emails, or payment details
- Take over accounts without authorization or sell compromised accounts
- Share, buy, or sell stolen credentials connected to our Services
- Impersonate staff, World Venture Projects, Mojang, Microsoft, or payment processors
Report suspected account compromise to [email protected] immediately.
Exploitation and interference
You must not:
- Use hacked clients, duping, or game exploits; report bugs to [email protected] instead. We may review client software described in the Client Software Review List; listing a name does not mean it is banned or that we disclose how we review it.
- Withhold critical security vulnerabilities to attack later; follow responsible disclosure below
- Attack infrastructure to extort, ransom, or coerce the operator
- Coordinate disruption campaigns intended to damage operations, revenue, or reputation
Responsible disclosure
If you discover a security vulnerability affecting our Services:
- Email [email protected] or [email protected] with details
- Do not exploit it beyond minimal proof needed to demonstrate impact
- Do not publicly disclose until we have had reasonable time to remediate (typically 90 days unless we agree otherwise)
We appreciate good-faith reports and may acknowledge reporters at our discretion.
Detection and evidence
We may use logs, anti-cheat tools, moderation records, payment signals, hosting telemetry, and user reports to investigate abuse. We may preserve evidence as long as needed for enforcement, legal compliance, or dispute resolution. We do not publish detection methods, review signals, or a complete inventory of what we check. The Client Software Review List is illustrative only.
Enforcement
We apply proportionate enforcement based on severity, history, and risk. Ban reviews follow the Ban & Appeal Policy.
- Warning, mute, or kick
- Temporary ban and suspension of digital benefits
- Permanent ban and forfeiture of access and associated benefits per Terms of Service
- Provider referral to payment processors, hosts, or platforms for fraud or chargeback abuse
- Law enforcement referral where conduct appears to violate applicable criminal or computer-misuse laws (for example DDoS, unauthorized access, or doxing). We use conditional language: we may report; we do not guarantee prosecution.
We may act on related accounts, IP ranges, or devices when reasonably linked to abuse.
Reporting abuse
Report security incidents, DDoS, doxing, or coordinated abuse to:
- Abuse reports: [email protected]
- General support: [email protected]
- Legal: [email protected]
Include relevant usernames, timestamps, URLs, and evidence where available.
No waiver of mandatory rights
Nothing in this policy limits non-waivable consumer or privacy rights in your jurisdiction. Mandatory law always applies where it cannot be contractually excluded.
Changes
We may update this policy by posting a new version with a new effective date and bundle UUID. Continued use after the effective date constitutes acceptance where permitted.