Acceptable Use Policy

Last updated: September 11, 2026

1. General

Customers may use the service only for lawful purposes and in compliance with this policy, the Terms of Service, and the usage policies of the underlying model providers. You must understand and comply with these usage restrictions; continued use of the service constitutes acceptance of them.

2. Credential sharing prohibited

Your account and API keys are issued to you personally and must not be shared with, sold to, resold through, or disclosed to any third party. Sharing, publishing, or circulating your API keys, session credentials, or account access is a material breach of this policy. You are responsible for all usage made with your credentials. If you believe a key has been compromised, revoke it immediately in the dashboard or contact support so it can be revoked for you.

3. Prohibited content and uses

You may not use the service to: generate or distribute illegal content; create or distribute child sexual abuse material or any content that abuses, exploits, or endangers minors; generate non-consensual intimate imagery or deepfakes of real people; engage in fraud, impersonation, or disinformation at scale; build malware, weapons, or other harmful systems; scrape credentials or attack the platform or third parties; or circumvent rate limits, billing, or safety filters. Content that promotes violence, terrorism, or hatred against identifiable groups is prohibited, as is any use restricted by applicable Canadian law or the usage policies of the upstream model providers.

4. Abuse prevention and monitoring

We actively prevent abuse and fraud: requests are rate-limited and metered, spending caps are enforced per key and per account, keys can be bound to allowlisted IP addresses, and content moderation endpoints are available for screening. Intended use cases are reviewed at registration and accounts found misusing the service are suspended. Suspicious activity may be investigated and reported to law enforcement where required by law.

5. Data requirements

You must not submit data you lack the right to process, including personal data without a lawful basis. Prompt and response content must comply with applicable data protection law.

6. Security

API keys are confidential. Report leaked keys immediately so they can be revoked. You are responsible for all usage made with your keys.

7. Enforcement

Violations may result in warnings, key revocation, account suspension, or termination, with or without notice, and may be reported to law enforcement where required.