Content policy
The network cannot read what it carries
That is the design, and it decides what a policy can honestly promise.
What we can enforce
Entry and relay nodes see ciphertext and a next hop, so no rule about content is enforceable there without breaking the protocol. Only the exit sees a destination and a payload, and only for the request it is handling.
An exit operator may therefore restrict which destinations it will submit to — a policy about endpoints, not about people. A client whose request is refused simply builds another path. Neither we nor any operator can retroactively identify who sent something, because that information is not retained anywhere: it never exists in one place to begin with.
What we ask of users
Do not use Erebus for anything unlawful where you are, and do not use it to attack the network it fronts: flooding a destination with requests routed through volunteers' nodes is an attack on the volunteers as much as on the target.
Privacy is not an excuse for fraud. Hiding your position from the public is legitimate; hiding it from an obligation you have already entered into is not, and the protocol makes no attempt to help with that.
What we ask of operators
Publish your exit policy, do not log what you do not need, and do not attempt to strip layers you are not addressed by; a node that tampers with a packet is detected at the exit and, once staking exists, is slashed for it.
Reports
Abuse and vulnerability reports go to the issue tracker or @Erebusorg. For what the protocol does and does not hide, the FAQ is more useful than this page.