Vultr is now claiming full perpetual commercial rights over all hosted content
A major cloud provider, Vultr, briefly updated its terms of service to grant itself a perpetual, irrevocable, royalty‑free license to use, modify, and commercialize all “user content” on its platform, triggering alarm among customers hosting private or proprietary data. Commenters debated whether the clause was standard legal boilerplate limited to what’s “necessary to provide the service” or an overreach that could enable data mining, AI training, or resale of customer content, with particular concern about enforceability outside the US. Following sustained backlash and media coverage, Vultr removed the contentious language and issued a clarification, though many users say the incident has already damaged their trust and are evaluating alternative hosts.
Problematic ToS Clause
- Main focus is a Vultr ToS clause granting the company a perpetual, irrevocable, sublicensable, royalty‑free worldwide license over “user content,” including rights to modify, create derivative works, distribute, and “commercialize” it.
- Clause ends with “for purposes of providing the Services to you,” but also says “in any way [Vultr] deems appropriate,” which many see as contradictory and dangerously broad.
Interpretations and Legal Debates
- One camp argues this is standard service-provider boilerplate to legally allow caching, CDN, backups, and similar operations.
- Others counter that phrases like “perpetual,” “irrevocable,” “commercialize,” and “any way deemed appropriate” go far beyond what is technically necessary.
- EU‑based commenters say such ToS terms would likely be unenforceable or heavily limited there, but note that legal unenforceability does not prevent misuse or data leaks in practice.
- Debate over whether “Services” and “User Content” refer only to public community content (forums, marketplace) or also to all data on hosted VMs; text is seen as ambiguous.
Privacy, AI, and Data Use Concerns
- Strong concern that Vultr could use private data (e.g., SaaS customer data, Nextcloud instances, legal documents, photos) for AI training, resale, or other commercial uses.
- Some see this as part of a wider trend where hosted data is treated as free input for AI or advertising, even in paid services.
Technical Limits of Protecting VPS Data
- Discussion notes that encrypting disks on a VPS does not protect against a hostile provider: snapshots can include RAM (and keys), and decrypted data can be inspected in-flight.
- Conclusion: if you don’t trust the provider, you should self‑host or only send encrypted backups where keys never touch the VPS.
Customer Reactions and Alternatives
- Several users report planning or starting migrations to other hosts (Hetzner, Linode, DigitalOcean, smaller VPS providers).
- Hetzner is praised for price and performance but criticized as “ban‑happy” and sometimes unfriendly in support.
- Some argue that all cloud use ultimately requires trust; others now view Vultr as too risky regardless of legal nuance.
Vultr’s Response and ToS Change
- Later in the thread, it’s noted that Vultr removed the controversial sentence and published a statement claiming it was meant only for public community content.
- Many remain skeptical, seeing this as backtracking under pressure rather than evidence of benign intent, and worry it could quietly return.
Broader Reflections on ToS and Legalese
- Strong sentiment that ToS are too long, vague, and one‑sided for non‑lawyers who must still “agree.”
- Calls for regulation or norms requiring plain‑language summaries, clearer scoping (e.g., “only what’s technically necessary”), and penalties for overreaching clauses.
- Some appreciate the backlash as a useful deterrent against stuffing maximalist rights into boilerplate contracts.