1. Prohibited Activities
The Services are built to give you recommendations, analysis, and decision support, and to act on your behalf where you configure them to. Nothing in this AUP prohibits you from relying on AI Output to inform your decisions or from using it as input to your own judgment. Instead, this AUP draws a line around genuine abuse, and sets out the responsibilities that come with using intelligent, action-taking software.
You may not use the Services, and may not permit anyone using your account to use the Services, to engage in any of the following. You are responsible for the conduct of your Authorized Users under this AUP.
- Unlawful use. Use the Services in violation of any applicable law, regulation, or court order, or to promote, facilitate, or engage in any illegal activity.
- Intellectual-property infringement. Upload, generate, or distribute content that infringes or misappropriates any patent, copyright, trademark, trade secret, or other intellectual-property or proprietary right of any party.
- Security violations. Attempt to gain unauthorized access to, breach, defeat, or circumvent any security or authentication measure of the Services, our systems, or any related network, or test the vulnerability of our systems without our prior written authorization.
- Network and system abuse. Interfere with or disrupt the integrity or performance of the Services or the data they contain, including through denial-of-service attacks, flooding, or imposing an unreasonable or disproportionately large load on our infrastructure.
- Malware. Upload, transmit, or distribute any virus, worm, ransomware, Trojan horse, or other malicious code, or any material designed to interrupt, damage, or limit the functionality of any software, hardware, or network.
- Unauthorized access. Access or use any account, data, or portion of the Services that you are not authorized to access, or share your credentials, API keys, or access tokens with, or otherwise enable access by, unauthorized persons.
- Interference. Use any robot, scraper, or other automated means to access the Services in a manner that sends more requests than a human could reasonably produce, or otherwise bypass any measure we use to restrict access to the Services.
2. AI-Specific Restrictions
Because the Services use artificial intelligence to generate AI Output and to take actions you configure, the following additional restrictions apply. You may not:
- Generate unlawful or harmful content. Use the Services to generate content that is unlawful, harmful, harassing, abusive, defamatory, or that exploits or endangers any individual, or that is otherwise prohibited by applicable law.
- Engage in prohibited AI practices. Use the Services for any purpose that is unlawful or that constitutes a prohibited artificial-intelligence practice under applicable law — including, by way of example, unlawful biometric categorization or identification of individuals, social scoring of individuals, or subliminal, manipulative, or deceptive techniques that materially distort a person's behavior, in each case where prohibited or restricted by the EU AI Act or comparable laws applicable to you or your Authorized Users.
- Infer emotions or biometrics unlawfully. Use the Services to infer the emotions of individuals, or to categorize or identify individuals on the basis of biometric data, in any setting or manner that applicable law prohibits or restricts.
- Pose as a human or impersonate others. Deploy or use AI Output to impersonate any person or organization, or to interact with people as though it were human, without making the disclosure that applicable law requires — including any bot-disclosure or automated-interaction notice obligations that apply to you or your Authorized Users.
- Develop weapons or CBRN capabilities. Use the Services to develop, design, or facilitate weapons of any kind — including chemical, biological, radiological, or nuclear capabilities — or for any other purpose that creates a risk of serious physical harm to people.
- Extract or clone the AI to build a competing model. Use the Services, AI Output, or any observed behavior of the Services to extract or reconstruct model weights or training data, or to train, build, or improve any artificial-intelligence model, product, or service that competes with the Services.
- Attack or extract the AI. Attempt to manipulate, attack, or compromise the Services or the AI models, prompts, or skills that power them — including through prompt-injection or jailbreak attempts; efforts to extract, copy, or reconstruct training data, model weights, system or skill instructions, or other underlying models or intelligence; reverse engineering or deriving the source code, models, or skills of the Services; scraping or harvesting AI Output or content beyond the limits we set; exfiltrating credentials, API keys, or access tokens; or misusing any integration, connector, or Automated Action to obtain data or capabilities you are not authorized to access.
- Bypass safeguards. Attempt to bypass, disable, or circumvent any content filter, safety measure, rate limit, usage quota, or other safeguard we apply to the Services.
- Misrepresent the relationship or the output. Present AI Output to any third party as your own licensed professional advice — financial, investment, legal, tax, accounting, or otherwise — without your own qualified human review, or represent that GritFlow is your licensed adviser or that GritFlow has reviewed, approved, or stands behind your use of the AI Output. GritFlow is not your adviser, and AI Output is not a substitute for the judgment of a qualified professional who is responsible for the advice you give.
3. Your Responsibilities for Consequential Decisions and Actions
The Services are designed to support and, where you enable it, to act on real-world decisions. That capability is a feature, not something this AUP restricts. With it, though, comes responsibility: when you use AI Output or Automated Actions to make or carry out consequential decisions about individuals — including decisions affecting a person's employment, housing, credit or lending, insurance, healthcare, education, legal rights, access to essential services or government benefits, or financial, investment, tax, or other significant interests — you remain responsible for:
- Appropriate human review. Putting meaningful, qualified human review and oversight in place that is proportionate to the stakes of the decision, including the ability to review and override outcomes before they take effect.
- Notices and consents. Providing any notices, obtaining any consents, and offering any appeal, explanation, or human-review rights that apply to the individuals affected.
- Legal compliance. Determining and meeting your own obligations under applicable law — including consumer-protection, anti-discrimination, privacy, automated-decision-making, sector-specific, and professional-licensing requirements — for the decisions you make and the actions you take.
- Professional review where it's regulated. Where the decision or output falls within a regulated profession (such as client-specific investment recommendations, securities transactions, tax positions, legal advice, or accounting or audit opinions), having an appropriately licensed professional review and approve it before you rely on it or present it to others.
GritFlow provides the intelligence and the tools; you decide how to use them and remain accountable for the outcomes. This section restates responsibilities that already apply to you — it does not transfer them to GritFlow, and it does not stop you from using AI Output as input to your decisions.
4. Platform and Generated-Application Use
If your use of the Services includes building, configuring, or deploying applications, automations, or agents, the following additional terms apply:
- No unlawful or harmful applications. Do not use the platform to build, host, or deploy any application, automation, or agent that is unlawful, infringing, deceptive, or designed to harm individuals or to carry out any activity prohibited by this AUP.
- Human review and compliance for deployed actions. Do not use a deployed application, automation, or Automated Action to take consequential actions about individuals — of the kind described in Section 3 — without appropriate human review and oversight and compliance with applicable law. You are responsible for the conduct and outputs of the applications and automations you build and deploy, and for the actions they take, to the same extent as if you took those actions yourself.
5. Sensitive and Regulated Data
Unless expressly authorized in the applicable Order, DPA, or security exhibit, you may not upload or process regulated or sensitive data categories that require additional safeguards, including protected health information, payment-card data subject to PCI DSS, government identifiers, children's personal information, biometric data, or special-category/sensitive personal information.
Where an Order authorizes financial, accounting, tax, or investment-related records, you must process them only within the agreed environment and safeguards.
6. Customer Data Responsibilities
You are responsible for the Customer Data you submit to the Services. You may only submit Customer Data that you are authorized to submit and to have processed by the Services. In particular, you agree that:
- You have all rights, permissions, and consents necessary to provide the Customer Data to the Services and to have it processed to generate AI Output;
- Your Customer Data does not violate any law or regulation or infringe or misappropriate any third party's rights; and
- You will not submit data that you are contractually or legally prohibited from disclosing, or that includes sensitive or regulated categories of data beyond what your Order and Data Processing Addendum permit your account to process (see Section 5).
You are responsible for the accuracy, quality, and legality of your Customer Data and the means by which you acquired it.
7. Fair Use and Resource Limits
The Services are provided on a shared infrastructure and may be subject to usage limits, quotas, or rate limits described in your Order, in our documentation, or as we otherwise communicate. You agree to use the Services in a manner consistent with those limits and with fair, good-faith use.
We may apply technical or operational controls to protect the stability, security, and availability of the Services for all customers, and we may contact you to address usage that materially exceeds normal patterns or that degrades the experience of other customers.
8. Enforcement
We may investigate any suspected violation of this AUP. If we determine, in our reasonable discretion, that you or an Authorized User has violated this AUP, we may take any action we consider appropriate, including issuing a warning, removing or disabling offending content, throttling usage, and suspending or terminating your access to the Services in accordance with our Terms of Service.
Where activity poses an imminent security, legal, or safety risk, we may act immediately and without prior notice. We may also report suspected unlawful activity to, and cooperate with, law enforcement and other authorities as required or permitted by law. We are not liable for any action taken in good faith to enforce this AUP.
9. Reporting Violations
If you become aware of any actual or suspected violation of this AUP, please report it to us by email at legal@gritflowai.io. Please include enough detail to allow us to identify and investigate the issue, such as the nature of the activity, the affected resources, and any relevant dates and times. We appreciate your help in keeping the Services safe and secure.
10. Changes to This Policy
We may update this AUP from time to time. If we make material changes, we will provide notice by posting the updated AUP with a new “Last updated” date and, where appropriate, by email or in-product notice. Changes are effective when posted unless stated otherwise, and your continued use of the Services after the effective date constitutes acceptance of the updated AUP.
11. Contact Us
Questions about this Acceptable Use Policy can be directed to:
GritFlow AI, LLC — Attn: GritFlow AI, LLC · 41 Peabody St, Nashville, TN 37210, United States
Email: legal@gritflowai.io · Web: gritflowai.io
