Purpose and scope
This Acceptable Use Policy applies to every user, workspace, API client, integration, agent, and item of Customer Content that accesses or uses Corporate Suite. It is incorporated into the Terms of Service. Customers must ensure their users and anyone acting through their accounts follow it.
Law, rights, and deception
Do not use the Service to:
- violate law, regulation, court order, sanctions, export controls, or another person's legal rights;
- infringe privacy, publicity, intellectual-property, confidentiality, or contractual rights;
- impersonate a person or organization, misrepresent affiliation, forge origin, commit fraud, or distribute materially deceptive content;
- harass, stalk, threaten, exploit, defame, or facilitate violence or abuse; or
- create, solicit, store, or distribute child sexual abuse material or any sexual exploitation content. We may report apparent child exploitation as required by law.
Security and platform integrity
- Do not gain or attempt unauthorized access to accounts, data, systems, or networks.
- Do not scan, probe, penetration-test, or disclose vulnerabilities without prior written authorization under our security reporting process.
- Do not upload malware, destructive code, credential stealers, or content designed to evade security controls.
- Do not interfere with availability, overload infrastructure, bypass rate or usage limits, defeat isolation, or obscure abusive traffic.
- Do not share credentials, automate login in an unsupported way, scrape protected areas, or use the Service to operate a competing hosted service without permission.
Communications and external actions
You may not use Corporate Suite to send spam, phishing, unwanted bulk communications, or messages that violate consent, opt-out, caller-identification, telemarketing, or email-marketing laws. Contact lists and connected mailboxes must be lawfully obtained and used.
Agents may prepare external communications, but a human must approve their recipients, material claims, attachments, and dispatch unless Customer has a separately authorized, bounded automation with equivalent review and revocation controls.
High-impact decisions and surveillance
Do not use the Service as the sole basis for decisions that determine a person's eligibility, selection, or access in employment, housing, education, credit, insurance, healthcare, legal services, or essential government services.
Any permitted supporting use must be lawful, tested for relevant risks, transparent to affected people where required, supervised by a qualified human, and include a meaningful way to contest or correct the result. Do not conduct unlawful biometric identification, emotion inference, location tracking, workplace surveillance, or profiling of sensitive traits.
AI and agent misuse
- Do not bypass safeguards, conceal prohibited intent, or use agents to scale conduct that would violate this Policy if performed manually.
- Do not present generated content as verified fact when accuracy matters without appropriate review.
- Do not use output to create malicious code, weapons instructions intended to cause harm, non-consensual intimate imagery, or deceptive political persuasion targeted using sensitive personal data.
- Do not allow an agent to spend funds, sign agreements, delete records, change permissions, publish content, or contact third parties without the human approval required by the Service and our AI Terms.
Sensitive and regulated data
Do not submit data you lack authority to process. Unless a signed agreement expressly covers it, do not use the Service for protected health information regulated by HIPAA, full payment-card or bank-account credentials, government-classified data, export-controlled technical data, passwords or private cryptographic keys, or special-category data at a scale or for a purpose that requires controls the Service does not provide.
Where sensitive data is lawfully used, minimize it, restrict permissions, apply appropriate retention, and avoid placing it in prompts unless necessary for the requested feature.
Fair use of resources
Do not consume disproportionate resources, run unauthorized cryptocurrency mining, use automated means to avoid metering, create accounts to evade plan limits, or resell Working Credits. We may apply documented rate, storage, concurrency, and usage limits to protect reliability and equitable access.
Enforcement and reporting
We may investigate suspected violations and remove content, restrict a feature, suspend an account, preserve evidence, or terminate access as reasonably necessary and consistent with the Terms. We consider the nature, severity, duration, intent, history, remediation, and risk of harm. Immediate action may be required for security threats, child safety, unlawful content, or risk to others.
Report abuse to [email protected]. Include the workspace, relevant URL or identifier, description, and supporting context. Do not send passwords or unnecessary sensitive data.
