Acceptable Use Policy (AUP)
| Policy Item | Content |
|---|---|
| Document name | Usage Policy (Acceptable Use Policy / AUP) |
| Effective date | May 13, 2026 |
| Compiled on | June 10, 2026 |
| Who it applies to | Anyone who can submit input to TokenFlow's products and/or services (including via any authorized reseller or pass-through access) |
| Goal | Help users stay safe and promote responsible use of the products and services |
Overview
Our Usage Policy (also called the "Acceptable Use Policy" or "AUP") applies to anyone who can submit input to TokenFlow's products and/or services, including through any authorized reseller or pass-through access. We refer to all of these people as "users".
The Usage Policy is designed to help our users stay safe and to promote responsible use of our products and services. The Usage Policy is categorized by who may use our products and for what purposes. As our technology and the associated risks evolve, or as we learn of unexpected risks, we will update our policy.
To enforce this policy, TokenFlow may use detection, review, and monitoring mechanisms. If a user violates this policy, TokenFlow may restrict, suspend, or terminate access, and may also block, filter, or modify inputs or outputs that violate this policy.
Reading suggestion
If you provide output to end users in your product, please read "High-Risk Use Case Requirements" and "Guidelines for Other Use Cases" first. If you are unsure whether a particular use is compliant, we recommend self-checking against the "General Usage Standards" item by item.
General Usage Standards
Our general usage standards apply to all users and all use cases.
Do not violate applicable law or engage in illegal activity
Do not use our services to engage in, promote, or encourage illegal activity, including trafficking in controlled substances, human trafficking, prostitution, infringement of intellectual property, the abuse, exploitation, or harm of children (or attempts to harm children), and other acts that violate applicable laws and regulations.
Do not endanger critical infrastructure
Do not use our services to harm, damage, or disrupt critical infrastructure, including but not limited to telecommunications, healthcare, energy, transportation, water supply, financial services, election infrastructure, medical devices, financial markets, and military bases.
Do not compromise computer or network systems
Do not use our services to develop, deploy, assist, or automate the unauthorized exploitation of vulnerabilities, social engineering, malware, ransomware, denial-of-service attacks, botnet tools, unauthorized interception of communications or monitoring devices, the establishment of persistent access, the execution of automated operations that damage computer systems or networks at scale, or to help bypass security controls.
Do not develop or design weapons
Do not use our services to develop, design, produce, test, market, or unlawfully acquire weapons, explosives, or dangerous materials, nor to provide guidance on weaponization, delivery mechanisms, evading security controls, procuring precursors, or improving weapon capabilities.
Do not use our services to develop military applications, surveillance technology, or other technology that otherwise harms humans, including designing, developing, producing, or testing nuclear, biological, chemical, or radiological weapons, military-grade cyber capabilities, missiles, drones, or autonomous weapons systems.
Do not incite violence or hateful behavior
Do not use our services to incite, promote, advocate, or glorify extreme violence or identity-based violence against individuals or groups, nor to promote, glorify, facilitate, or advocate hatred against protected groups, or to engage in discrimination, intimidation, dehumanization, or violence based on protected attributes.
Do not infringe privacy or identity rights
Do not use our services to engage in, promote, incite, or facilitate stalking, harassment, bullying, or other forms of harassment, or to otherwise endanger or infringe people's rights to privacy, publicity, or other legal rights through unlawful or unauthorized means. This includes creating facial recognition systems used to identify people in private or restricted areas, or collecting, sharing, obtaining, or using private information, contact information, health information, biometric information, neural data, confidential information, or other personal data without consent.
Do not endanger child safety
Do not use our services to create, obtain, or distribute content that abuses, exploits, or sexualizes minors, including but not limited to child sexual abuse material (CSAM), grooming communications, sextortion, advice that helps conceal child abuse, role-play or descriptions placing minors in a sexual context, or any content that praises, glorifies, or encourages the sexual abuse of children.
Do not create psychologically or emotionally harmful content
Do not use our services to automatically generate or distribute content intended to cause psychological or emotional harm to people, including promoting self-harm or suicide, eating disorders, unhealthy exercise, or unattainable body image, or causing harm through bullying, harassment, abuse, humiliation, intimidation, or targeted harassment.
Do not create or distribute misinformation
Do not use our services to create or distribute, at scale, false, inaccurate, misleading, or deceptive content that causes economic, political, social, or public-health harm, including deceptive information about groups, entities, or individuals, or such content about public-health emergencies, civic procedures, laws, regulations, procedures, standards, or political or civic leaders.
Do not undermine democratic processes or engage in targeted campaigning
Do not use our services to undermine, damage, or disrupt fair and open democratic or civic processes, including through the distribution of disinformation, targeted voter suppression, the creation of fake grassroots movements, bulk contacting of voters or officials while concealing automation, or interfering with voting, counting, or certification processes.
Do not use our services for political campaigning or lobbying, or to generate campaign material intended to influence political, judicial, social, or economic outcomes at scale, including outputs for advocacy campaigns, personalized or targeted messages with political opinions, interactive campaign chatbots, misleading political synthetic media, or voter suppression material.
Do not use for criminal justice, censorship, surveillance, or prohibited law-enforcement purposes
Do not use our services for any predictive policing, prosecution, sentencing, parole or detention decisions, lie detection or similar applications, facial recognition, emotion recognition, social scoring, government censorship, battlefield management, non-consensual communication or location tracking, biometric classification used to infer protected attributes, or mass surveillance, or any other prohibited law-enforcement purpose.
Do not engage in fraudulent, abusive, or predatory practices
Do not use our services to create or distribute fraudulent, false, or misleading content intended to deceive, defraud, or exploit people, including but not limited to schemes, scams, phishing, forged documents, fake products, fake reviews, fake interactions, spam, and other fraudulent behavior.
Do not use our services to impersonate individuals, organizations, entities, or real public figures in order to deceive, mislead, or defraud others. Do not use our services to conduct or facilitate gambling, payday loans, high-cost credit products, exploitative debt collection, or other exploitative economic activities. Do not use our services for other illegal, fraudulent, or deceptive activities, or to generate or distribute spam.
Do not abuse our platform
Do not use our services in violation of our platform policies, including but not limited to attempting to break our safeguards, evade the model's built-in limits, extract model weights, system prompts, hidden rules, training data, or response patterns in any unauthorized way, engage in jailbreaking, prompt injection, unauthorized model scraping, replication, training, fine-tuning, or distillation, or violate the usage limits we enforce on TokenFlow, including rate limits.
Do not generate sexually explicit content
Do not use our services to generate sexually explicit content, including content with an explicit purpose or for sexual gratification. This includes using our services to generate pornographic content (whether text or image), explicit sexual acts, fetishes, sexual fantasies, erotic chat, or incest sexual content. This restriction does not apply to content used for legitimate sexual and reproductive health purposes, or scientific, educational, or artistic purposes.
High-Risk Use Case Requirements
Certain use cases pose a higher risk of harm because they affect areas critical to public welfare and social equity. For these use cases, given the potential risks to individuals and consumers, we believe relevant human expertise should be integrated and that end users should be aware when AI is involved in producing output. Therefore, for the "high-risk use cases" described below, we require you to implement these additional safeguards:
Additional safeguards (required)
- Human in the loop: When using our products or services to provide advice, recommendations, or subjective decisions that directly affect individuals or consumers, a qualified professional in that field must review the content or decision before it is disseminated or finalized. You or your organization are responsible for the accuracy and appropriateness of that information.
- Disclosure: If the model output is presented directly to individuals or consumers, you must disclose to them that you are using AI to help generate your advice, decisions, or recommendations. This disclosure must be provided at least at the start of each session.
"High-risk use cases" include:
| Category | Description |
|---|---|
| Legal | Use cases related to legal interpretation, legal guidance, or decisions with legal impact |
| Healthcare | Use cases related to healthcare decisions, medical diagnosis, patient care, treatment, mental health, or other medical guidance. Health advice (e.g. about sleep, stress, nutrition, exercise, etc.) does not fall into this category |
| Insurance | Use cases related to health, life, property, disability, or other types of insurance underwriting, claims processing, or underwriting decisions |
| Finance | Use cases related to financial decisions, including investment advice, loan approvals, and determining financial eligibility or creditworthiness |
| Employment and housing | Use cases related to decisions about a person's employability, resume screening, hiring tools, or other employment decisions, or decisions about housing eligibility (including rentals and housing loans) |
| Academic testing, certification, and admissions | Use cases related to standardized testing companies that administer school admissions (including evaluating, grading, or ranking prospective students), language proficiency, or professional certification exams; institutions that evaluate and accredit educational institutions |
| Media or professional journalistic content | Use cases related to using our products or services to automatically generate content and publish it for external consumption |
Guidelines for Other Use Cases
The following use cases (whether or not they are high-risk use cases) must comply with the additional guidelines provided.
- All consumer-facing chatbots, including any external-facing or interactive AI agents, must disclose to users that they are interacting with an AI rather than a human. This disclosure must be provided at least at the start of each chat session.
- Products serving minors, including organizations that give minors the ability to interact directly with a product that incorporates our API, must comply with the additional guidelines outlined in our Help Center articles.
- Agentic use cases must still comply with the Usage Policy. We provide examples of uses prohibited by the policy in the context of agentic use cases in our Help Center articles.
- Model Context Protocol (MCP) servers listed in our connector directory must comply with our directory policy.
