Scope
This policy applies to everyone using the Platform, and to everything sent through an API key issued on your account, including requests made by your own users, if you build on top of it.
It forms part of the Terms of Service. Where a model provider's policy is stricter than this one, the stricter policy applies.
Content you may not generate
Do not use the Platform to generate, distribute or store:
- Sexual content involving minors, in any form and without exception.
- Intimate imagery of a real person created or shared without their consent.
- Content that harasses, threatens or incites violence against a person or group.
- Content designed to deceive about a real person or organisation. Impersonation, fabricated statements, or synthetic media presented as genuine.
- Malware, exploit code, phishing material, or anything else built to compromise systems or credentials.
- Material that is illegal in the place it is created, sent or received.
Category boundaries need legal and policy input before enforcement can be consistent.
- Where lines fall on adult content, political content and medical or legal advice
- Any permitted research, security or journalistic exceptions, and how they are approved
- Mandatory reporting obligations that apply to us, and to which categories
Things you may not do to the Platform
- Circumvent rate limits, quotas or billing, including by spreading load across accounts created for that purpose.
- Share, sell or publish API keys, or give access to anyone who has not agreed to these terms.
- Probe, scan or test the security of the Platform without written authorisation.
- Interfere with service for other customers, whether deliberately or through uncapped automation.
- Misrepresent the Platform's involvement in your product, or imply an endorsement that does not exist.
Commercial boundaries are not settled.
- Whether reselling API access is permitted, and on what terms
- Whether outputs may be used to train or evaluate competing models
- Whether authorised security testing is offered, and how to request it
If you build on top of the API
Exposing the API to your own users does not transfer responsibility for what they do with it. Traffic on your key is your traffic.
- Apply your own controls to what your users can submit and receive.
- Make it clear to your users when they are interacting with AI-generated output.
- Have a route for your users to report problems, and act on it.
- Keep your own terms consistent with this policy.
Model provider policies
Each model is run by a provider with its own acceptable use rules. A request that satisfies this policy can still be refused by the provider serving it, and repeated refusals may be treated as a breach here.
Pass-through of provider policies needs to be documented.
- Where the current provider list and their policies are published
- How you are notified when a provider policy changes
Reporting abuse
If you believe the Platform is being used in breach of this policy, tell us. Include the request identifier where you have one. It is the fastest route to the activity in question.
No reporting channel exists yet.
- Abuse reporting address and any web form
- What information a report should contain
- Acknowledgement and response expectations
Enforcement
Where this policy is breached we may restrict, suspend or terminate access. The response depends on what happened. Some breaches warrant a conversation, others do not.
The enforcement process is not defined.
- Which breaches lead to immediate suspension without notice
- Whether warnings are issued, and how
- Appeal route and who decides
- Effect of enforcement on a remaining credit balance
- When law enforcement or a regulator is involved