This policy forms part of the Business Terms and applies to purchased Services, supported automation and custom agents.

1. Scope, application and status

1.1 This Acceptable Use Policy (AUP) forms part of the Agreement and applies to the Customer, each Authorised User and every person who accesses or uses the Services, Customer Content or Generated Output through the Customer's account, credentials, integrations or systems. The Customer must take reasonable steps to inform those persons of this AUP and remains responsible for their acts and omissions as provided in the Agreement.

1.2 The Customer must not, and must not attempt to, assist, encourage, enable, instruct or permit any other person to, use the Services, Customer Content, Generated Output or material derived from them for a purpose or in a manner prohibited by this AUP. This applies to direct use, automated workflows, integrations, combinations with another product and use of Generated Output after it has left the Services.

1.3 The examples in this AUP explain the scope of the stated categories and are not exhaustive lists of technical methods. The Provider may treat materially analogous conduct as falling within a category only where the conduct creates a substantially equivalent unlawful, safety, security, rights or service-integrity risk and, unless immediate action is permitted under Clause 11.4 of this policy, identifies the relevant category and basis to the Customer.

1.4 This AUP is incorporated at the version accepted under the Agreement, subject to its change process. The Provider will retain version information relevant to a material enforcement decision. A standalone update does not override an express Order or bypass Clause 22 of the Terms.

1.5 An upstream policy binds the Customer only to the extent identified before the relevant use and reasonably applicable to that Service or integration. Material changes follow Clause 22 of the Terms. The Provider may suspend an affected route where necessary to comply with an upstream obligation, subject to the Agreement’s proportionality, notice and remedy provisions.

2. Law, rights and data

2.1 The Services must not be used to commit, promote, facilitate or conceal an unlawful act; evade sanctions, export controls, a court order or a binding regulatory requirement; or offer, procure or distribute unlawful goods or services. The Customer must not use the Services in a manner that would cause the Provider or an upstream supplier to breach a legal restriction applicable to the supply of the Services.

2.2 The Customer must have all rights, permissions and lawful authority required for its Inputs, Customer Data, instructions, connected sources, integrations and intended use of Generated Output. The Services must not be used to infringe, misappropriate or otherwise violate intellectual property, database, privacy, publicity, confidentiality, trade secret or other rights, or to remove or falsify rights-management or provenance information.

2.3 The Customer must not collect, scrape, infer, combine, identify, re-identify, expose, disclose, sell or otherwise process personal data through the Services without an applicable lawful basis, appropriate authority and any notice, consent or other measure required by Applicable Data Protection Law. Material obtained from a public source must not be treated as free from privacy, confidentiality, database, contractual or other restrictions.

2.4 The Customer must not submit or process children's data, special-category or sensitive personal data, criminal-offence data, protected health information, payment-card data, authentication secrets, government identifiers, precise geolocation data, biometric data or other regulated data unless the relevant data type and purpose are expressly authorised in the Order and governed by any required DPA, security schedule or sector-specific addendum. Credentials supplied through the Provider's designated secure authentication or integration-connection mechanisms are permitted solely to authenticate authorised access and operate the agreed integration; this does not authorise placing passwords, tokens or other secrets in prompts, uploaded documents or other general content. Payment-card details may be supplied through the authorised payment interface under Clause 9.4 of the Terms. Authorisation for one data type or purpose does not authorise another.

2.5 The Customer must not state or imply that the Provider has reviewed, approved, endorsed or verified Generated Output, the Customer's use case or a resulting product, communication or decision, or that Generated Output constitutes professional advice.

3. Safety, exploitation and physical harm

3.1 The Services must not be used to create, obtain, promote or facilitate child sexual abuse material, grooming, sexual exploitation, human trafficking, forced labour or any other abuse or endangerment of a minor. The prohibition applies to real, synthetic, fictionalised and materially altered material and includes attempts to sexualise, locate or identify a minor for an exploitative purpose.

3.2 The Services must not be used to plan, enable or provide operational assistance for terrorism, violent extremism, assassination, kidnapping, serious violent wrongdoing, unlawful weapons activity or the development or use of chemical, biological, radiological or nuclear weapons. Legitimate safety, compliance, historical, journalistic or academic work must not include operational assistance that materially increases a person's ability to cause harm.

3.3 The Services must not be used to encourage or facilitate suicide, self-harm, eating-disorder behaviour, harassment, stalking, doxxing, credible threats, non-consensual intimate imagery, unlawful discrimination or the targeting of a person or protected group for abuse or physical harm. The Customer must implement heightened safeguards where a workflow could foreseeably be used by, or materially affect, a vulnerable person.

3.4 The Services must not be deployed in an environment in which an error or delay could directly cause death, personal injury, severe environmental damage or material destruction of property unless the Order expressly permits that deployment and specifies the required testing, redundancy, qualified oversight, incident response and other safeguards.

4. Cyber security and security research

4.1 The Services must not be used to create, deploy or operate malware, ransomware, destructive code, credential theft, phishing, botnets, denial-of-service activity, unauthorised surveillance or another capability intended to compromise, disrupt, deceive or obtain unauthorised access to a person, account, device, network, data or system.

4.2 Security research, vulnerability assessment, penetration testing, scanning or exploitation is permitted only where the Customer has the system owner's express authorisation, acts within the authorised scope and applicable law, and complies with any Provider testing rules notified in advance. The Customer must not retain, disclose or exploit credentials, personal data or other material obtained beyond the authorised scope.

4.3 Testing directed at the Services, another customer's environment or an upstream supplier's systems requires the Provider's prior written approval or compliance with a vulnerability-disclosure policy that the Provider has published for that purpose. Unless that approval or policy expressly states otherwise, testing must not access another customer's data, degrade availability, use social engineering or publicly disclose a finding before the Provider has had a reasonable opportunity to investigate and remediate it.

4.4 The Customer must not bypass access controls or safety controls, probe non-public interfaces, or introduce code, files, prompts or instructions designed to damage, disable, overload or obtain unauthorised access to any part of the Services.

5. Deception, communications and synthetic media

5.1 The Services must not be used for fraud, scams, phishing, fabricated evidence, deceptive reviews, academic or professional dishonesty, identity theft or impersonation. The Customer must not misrepresent the source, authenticity, authority or evidential status of Generated Output or use it to create a materially false impression on which another person is reasonably expected to rely.

5.2 Where disclosure is required by law or reasonably necessary to avoid material deception, the Customer must clearly inform affected persons that they are interacting with an AI system or receiving AI-generated or AI-altered material. The Customer must not remove a disclosure, watermark or provenance control applied by the Services where removal would make the use unlawful or materially deceptive.

5.3 The Services must not be used to send spam, unlawful direct marketing, automated calls or other communications that breach consent, sender-identification, suppression-list, unsubscribe or opt-out requirements. The Customer is responsible for its contact lists, consent and suppression records and for every communication that it approves, schedules or configures.

5.4 The Customer must not use the Services for coordinated inauthentic behaviour, unlawful political campaigning, voter suppression, interference with an election or civic process, or targeted disinformation intended to manipulate a person's exercise of legal or democratic rights.

5.5 The Customer must obtain all rights and consents required to create or use a synthetic or materially altered likeness, voice, image, video or other representation of a person. Any label or machine-readable marking required by applicable law must be intelligible to the intended recipient and maintained when the material is distributed or republished.

5.6 The Customer must not use material generated by the Services to make a factual, comparative, performance or endorsement claim about a product or service unless the Customer holds evidence sufficient to substantiate that claim for the intended audience and territory.

6. High-impact and regulated uses

6.1 The Customer must not make a High-Impact Decision solely on Generated Output or use Generated Output in a manner that removes meaningful human review before the decision takes effect. A suitably trained and authorised person must consider relevant non-AI information, be able to question and override the Output and remain accountable for the decision.

6.2 High-Impact Decisions include decisions or recommendations concerning recruitment, work allocation, monitoring or termination; credit, debt collection or insurance; housing; education or assessment; healthcare; essential public or private services or benefits; legal services; and decisions made by or for a public authority. Inclusion in this list does not mean the use is permitted, classified or prohibited in every jurisdiction.

6.3 The Customer must not use the Services to provide a regulated or reserved service, including diagnosis or treatment, legal representation, investment execution, credit underwriting or another activity requiring professional authorisation, unless the use is lawful, controlled by appropriately qualified and authorised persons, expressly permitted in the Order and subject to all safeguards required by the Provider and applicable law.

6.4 The Services must not be used for unlawful social scoring, biometric categorisation, biometric identification, emotion recognition, predictive policing, exploitative manipulation, subliminal techniques or another AI practice prohibited by law applicable to the relevant deployment. A use relying on a statutory exception may proceed only if the Customer has documented the exception and the Order expressly permits the use.

6.5 Before a use that could materially affect a person's rights, health, safety, livelihood or access to an essential service is deployed, the Customer must conduct and document proportionate testing, risk assessment, human-oversight and escalation arrangements; monitor the workflow in use; maintain records sufficient to explain material decisions; and provide notices, instructions and avenues for challenge or review where required by law.

7. Seats, access and commercial integrity

7.1 The Customer must not pool or share named Seats, resell access or operate a service bureau unless an Order permits it. Creating or configuring custom agents is allowed where included in the Plan, but does not create additional human Seats, authorise resale or waive applicable authorisation, security or usage controls. Individual and standing authorisations follow Clause 5.3 of the Terms and do not override this AUP. Seat reassignment follows Clause 3.3 of the Terms.

7.2 The Customer may use Generated Output in its own products, services and business activities subject to the Agreement, but must not state or imply that the Provider supplies, endorses or accepts responsibility for the Customer's product, service, advice or deliverable.

7.3 Except to the extent a restriction cannot lawfully be excluded, the Customer must not reverse engineer, decompile, disassemble, copy, frame, mirror, index or scrape the Services; seek to discover source code, model weights, system prompts or non-public components; or use extraction or repeated-query techniques to reproduce a material part of the Services.

7.4 The Customer must not use the Services, Generated Output or non-public performance information to train, fine-tune or distil a model, develop a competing service, or publish a benchmark or comparative test unless the Order or the Provider's prior written approval expressly permits the activity and specifies any methodology and disclosure conditions.

7.5 The Customer must not coordinate accounts, Seats, identities, trials or payment methods to evade a disclosed allowance, restriction or promotional condition, or conceal the person responsible for use.

8. Service integrity, automation and resource protection

8.1 The Customer must not bypass usage measurement, an agreed allowance, disclosed rate or concurrency controls, billing, access or safety systems, or manipulate retries or task classification to evade an expressly agreed charge. An Unlimited feature does not acquire a hidden fixed allowance through internal cost measurement.

8.2 Automated access is permitted only through interfaces and automation controls that the Provider supports for that purpose and within the technical and commercial limits applicable to the Plan. The Customer must not use scripts, bots, robotic process automation, headless browsers or scrapers against an interface not designated for automated access.

8.3 The Customer must not use the Services as a general-purpose model endpoint, relay, proxy, gateway or compute platform, or for cryptocurrency mining or distributed computation unrelated to the Customer's business.

8.4 The Customer must not submit work or configure agents in patterns that materially degrade availability, interfere with other customers or circumvent the purchased usage model. Legitimate temporary peaks are assessed under the Fair Use and Usage Policy. Reaching a Limited Plan’s allowance alone is handled under its disclosed exhaustion rules, not treated as misconduct.

9. Third-party services and connected data

9.1 The Customer must not connect or instruct the Services to access a Third-Party Service unless the Customer has the rights, internal authority and lawful basis required for that access and complies with the applicable third-party terms. Access scopes must be limited to what is reasonably required for the Customer's intended workflow.

9.2 Before connecting communications, records or monitoring data concerning personnel or other individuals, the Customer must complete any assessment, notice, consultation, agreement or data-protection impact assessment required by applicable privacy, communications or employment law.

9.3 The Customer must promptly revoke a credential, integration scope or Seat when it is no longer required and must not use a Third-Party Service in a manner that causes the Provider to breach a supplier term that has been validly flowed down under Clause 1.5 of this policy.

10. Account security, reporting and cooperation

10.1 The Customer must protect its accounts and integrations and promptly report suspected compromise, unauthorised use or serious AUP issues to contact@shinobiops.ai. Do not include passwords, access tokens or unnecessarily sensitive content in the initial report.

10.2 On reasonable request, the Customer must provide information and cooperation proportionate to a suspected violation, including the relevant use case, responsible users, data categories, affected systems, safeguards and remedial action. The Provider need not require legally privileged material, and neither party must disclose information where prohibited by law; the parties will cooperate on a lawful alternative where reasonably available.

10.3 The Customer must preserve relevant account and workflow records while a suspected serious violation is being assessed, subject to applicable law and ordinary retention limits, and must not obstruct, mislead or retaliate against a person who reports a good-faith safety, security or compliance concern.

11. Investigation and enforcement

11.1 The Provider may use automated controls and proportionate human review to detect and investigate suspected violations, validate the Customer's stated use case and protect the Services, users, upstream suppliers and third parties. Access to Customer Content for that purpose remains subject to the confidentiality, security and data-protection provisions of the Agreement.

11.2 Where the Provider reasonably believes that a violation has occurred or is likely, it may request information or remediation; prevent an affected Output or External Action; remove, block or quarantine affected content; restrict an integration, feature or processing layer; apply rate, concurrency or queueing controls; suspend affected access under Clause 20; or terminate under Clause 21.

11.3 Where reasonably practicable, the Provider will give prior notice, identify the principal concern and apply a measure proportionate to the nature, likelihood, severity and reversibility of the risk. It will limit the measure to the affected account, Seat, workflow, data, integration or feature and to the period reasonably necessary to address the concern.

11.4 The Provider may act without prior notice where it reasonably considers immediate action necessary to prevent unlawful activity, material harm, unauthorised access, a serious security threat, severe service instability, breach of an upstream supplier requirement or rapidly accruing exceptional cost, or where notice would materially prejudice an investigation or safety measure. Unless prohibited by law, the Provider will notify the Customer promptly afterwards and identify available remediation.

11.5 If the Customer provides credible evidence that the suspected violation did not occur or has been adequately remediated, the Provider will review the measure and restore affected access when the relevant risk has been resolved. Restoration does not prevent reasonable safeguards directed to recurrence.

11.6 The Provider may preserve evidence and report apparent unlawful conduct or an imminent threat to a competent authority, affected platform or potential victim where required by law or reasonably necessary to protect persons or systems. A voluntary disclosure of Customer Content will be limited to what the Provider reasonably considers necessary for that purpose.

11.7 This AUP does not require the Provider to monitor every use, communication, item of Customer Content or Output and does not make the Provider responsible for the Customer's business, decisions or compliance. A failure to detect or act on one violation is not a waiver of the right to act on that or another violation later.

12. Reinstatement and consequences

12.1 Restoration may be conditional on proportionate remediation, safe configuration, valid outstanding payments or reasonable commitments against recurrence. Additional charges, capacity or Plan upgrades require agreement under the Fair Use and Usage Policy; suspension is not authority to force a purchase.

12.2 Except as expressly provided in the Agreement, no refund or credit is due for a period in which access was proportionately restricted or suspended because of a violation by the Customer or a person for whom it is responsible. This does not exclude a credit or refund required because the Provider acted in error, maintained a measure after the relevant risk was resolved or otherwise breached the Agreement.

12.3 A serious or repeated violation may constitute a material breach. Whether a breach is capable of remedy, the cure period and termination consequences are determined under Clause 21 and applicable law; this Schedule does not make every breach within a category automatically irremediable.

13. Changes to this aup

13.1 The Provider may update this AUP for changes in law, Services, material threats or upstream requirements under Clauses 12.2 and 22 of the Terms. Necessary protective measures may take effect sooner under the existing enforcement powers. New paid features, unrelated new obligations or changes outside the agreed mechanism require the applicable agreement rather than being imposed as AUP enforcement.

13.2 An amendment applies prospectively and will not make use completed before its effective date a breach. The Provider will identify the effective date or version and retain or otherwise make available sufficient information for the Customer to determine the version applied to a material enforcement decision.

← Back to home