Acceptable use policy

Effective 5 August 2026

This policy forms part of the terms of service. It applies to you, to your team, and to anyone using an assistant you have deployed. Where a breach is serious or ongoing we may suspend a workspace, and we will tell you why.

Do not deceive people about the AI

This is the rule we care most about, because breaking it harms your visitors rather than us.

  • Do not instruct the assistant to deny being an AI, or to claim to be a human.
  • Do not give it the identity of a specific real person, a named employee, a public figure, or anyone else.
  • Do not remove, obscure or translate away the AI disclosure. It is editable so you can word it for your own users, not so you can hide it.

Our position under Article 50 of the EU AI Act is set out on the AI transparency page. That page explains why the disclosure cannot be switched off, and what remains your responsibility as the deployer.

Do not use it for these purposes

  • Anything unlawful where you operate, or where your visitors are.
  • Generating content that harasses, defames, or sexualises anyone, or that exploits or endangers a child.
  • Infringing anyone's copyright, trade mark or other rights, including uploading content you have no right to use.
  • Medical, legal or financial advice presented as authoritative, or as a substitute for a qualified professional.
  • Political persuasion, electoral messaging, or anything designed to manipulate a person's vote.
  • Collecting personal data from visitors under a false pretext, or more of it than your stated purpose needs.

Do not misuse the platform

  • No probing, scanning or load-testing our infrastructure without written permission. Our disclosure policy is the route for security research, and we will give you a workspace to test against.
  • No circumventing quotas, rate limits or plan limits, including by spreading one deployment across several accounts.
  • No embedding an assistant on an origin you do not control, and no sharing a widget ID to let others spend your quota.
  • No reselling or white-labelling the service without a partner agreement.
  • No using the service to build a competing model, including by extracting outputs at scale for training data.

Personal data in tools

If you connect a tool that can return one person's data, an order lookup, an account status: it must verify identity on its own terms. The assistant tells you whether a shopper appears to be signed in on your store, but that signal is not cryptographically signed and must not be treated as authentication. Ask for an order number and an email, the way a support agent would.

Reporting a breach

If you believe an assistant built on this platform is breaching this policy, write to our contact form with the URL. We investigate every report and will tell you the outcome unless doing so would itself cause harm.