Effective version: community-plugin-publishing-v1. A Hub listing is not a Raydo safety review, quality certification, endorsement, warranty, or guarantee.
The publisher is solely responsible for the plugin archive, signed descriptor, download service, documentation, support, legal compliance, intellectual-property rights, privacy disclosures, security maintenance, and every claim made about the plugin. The publisher must control the enrolled signing key and the HTTPS location in the descriptor.
Raydo Hub stores the signed descriptor and bounded catalog metadata. It does not host the plugin archive, proxy package downloads, inspect every package, configure user Connections, grant access, review the package for a user, enable it, or execute it.
Publishers must not list malware, credential theft, surveillance without lawful consent, destructive or deceptive software, unlawful content, infringement, spam, evasion tooling, undisclosed data collection, packages that impersonate Raydo or another publisher, or content designed to bypass Raydo review, approval, Connection, grant, audit, or execution controls.
Descriptors must not contain secrets, private keys, authentication tokens, private package bytes, raw provider responses, user Connection data, or personal data that is unnecessary for the public listing.
Plugin archives remain on publisher-controlled infrastructure. Availability, bandwidth, package integrity at the declared digest, incident response, and removal of compromised downloads are the publisher's responsibility. Raydo Desktop verifies the signed descriptor and exact package and manifest digests, then installs the package disabled in needs-review. Users must separately review, configure Connections, grant exact resources, and enable the plugin.
Raydo may block or remove a release, suspend a publisher, preserve a bounded audit record, and act without advance notice when a report, security signal, legal request, policy violation, or platform risk warrants it. Repeated, coordinated, or severe violations may result in permanent publisher suspension and rejection of related keys or releases.
Reports must be accurate and limited to the information needed to investigate. Do not submit credentials, private package content, user Connection data, or unrelated personal information.
A publisher may appeal a moderation action by contacting support@raydo.ai with the publisher ID, release ID, reason for the appeal, and non-sensitive supporting evidence. An appeal does not automatically restore a listing, and Raydo may keep a release blocked while review is pending.
Public catalog metadata, publisher identity, key fingerprint, descriptor digest, declared permissions and effects, moderation status, and bounded audit events may be retained to operate and secure the directory. Plugin archives and user Connection data are outside Hub custody. See the Privacy Policy for Raydo's general data practices.
Submitting a Community plugin requires explicit acceptance of this active version of the terms. Acceptance creates no guarantee of listing, continued availability, endorsement, or certification.