ACCEPTABLE USE POLICY
Last updated: August 17, 2026
This policy applies to AStack accounts, APIs, SDKs, session runtimes, and generated or rendered output. It supplements the Terms of Service.
PROHIBITED USE
Illegal or harmful activity
- Content or activity that violates applicable law or another person's rights
- Fraud, phishing, malware, credential theft, or instructions intended to facilitate a crime
- Sexual exploitation, child sexual abuse material, or content promoting violence or terrorism
- Targeted harassment, doxxing, or unlawful discrimination
Non-consensual synthetic media
- Using a real person's likeness or voice without the permission required for that use
- Impersonation intended to deceive people about the identity of a speaker or depicted person
- Removing required disclosures from synthetic media or presenting generated output as authentic evidence
Platform and credential abuse
- Exposing, selling, sharing, or using API keys without authorization
- Bypassing authentication, rate limits, session limits, billing controls, or renderer access controls
- Accessing another customer's data, session, gateway, or renderer
- Deliberately degrading the service or consuming capacity through abusive automation
- Creating accounts to evade a suspension or exploit signup credits
YOUR APPLICATION
- You are responsible for the behavior of your application and its end users.
- Provide notices and obtain consent appropriate to the voice, image, text, and personal information you process.
- Review generated output before using it in high-impact or automated decisions.
- Implement any content moderation, age controls, disclosures, or human review required for your use case.
- AStack does not currently promise a platform-level content-moderation service.
ENFORCEMENT
AStack may reject requests, revoke credentials, stop sessions, or suspend an account when needed to protect the service, investigate suspected abuse, comply with law, or enforce this policy.
Report suspected abuse through the support form. Include relevant identifiers and timestamps, but do not send API keys, session secrets, or unnecessary personal data.