Acceptable Use Policy

Effective 23 August 2026 · Operated by Clean APIs

This policy sets out what you may not do with Clean APIs. It forms part of our Terms of Service, and it applies to everything you send through the API, everything you build on it, and anything you do to the platform itself.

Upstream model providers impose their own usage policies. Activity we permit may still be refused by the provider serving your chosen model.

Illegal activity

Do not use the service to plan, carry out, or facilitate anything unlawful, including:

  • fraud, scams, phishing, or identity theft;
  • money laundering or sanctions evasion;
  • trafficking in people, drugs, weapons, or stolen goods;
  • infringing copyright, trademarks, patents, or trade secrets.

Harm to people

Do not generate or facilitate:

  • Child sexual abuse material, or any sexualised content involving minors. We report this to the authorities and terminate the account immediately, without warning.
  • content that sexually exploits or endangers anyone;
  • instructions for weapons capable of mass casualties — explosives, chemical, biological, radiological, or nuclear;
  • encouragement of suicide, self-harm, or eating disorders;
  • threats, targeted harassment, stalking, or doxxing;
  • incitement to violence, or hatred against people based on race, ethnicity, national origin, religion, gender, sexual orientation, disability, or another protected characteristic.

Malicious code and unauthorised access

Do not use the service to create or improve:

  • malware, ransomware, spyware, keyloggers, or botnets;
  • exploits or intrusion tooling aimed at systems you do not own and are not authorised to test;
  • credential-stuffing, password-cracking, or CAPTCHA-defeating tools;
  • techniques for evading security software or hiding an intrusion.

Security research on your own systems, authorised penetration testing, CTF exercises, defensive tooling, and education are all permitted. If your work sits near this line, tell us at [email protected] beforehand.

Deception and impersonation

Do not use the service to:

  • impersonate a real person or organisation, including generating their likeness or voice without consent;
  • build deepfakes intended to deceive;
  • run disinformation or coordinated inauthentic behaviour campaigns;
  • manipulate elections, or produce political messaging that conceals its true origin;
  • fabricate reviews, ratings, engagement metrics, or poll results;
  • present AI output as human-authored where that misleads someone materially — in academic submissions, journalism, or legal filings, for example.

Spam

Do not use the service to generate unsolicited bulk email, SMS, comments, or messages, to create doorway pages or mass low-value SEO content, or to power engagement farming.

Privacy and surveillance

Do not use the service to:

  • process other people's personal data without a lawful basis;
  • build mass surveillance systems, or track individuals without consent;
  • perform facial or biometric identification of private individuals;
  • infer protected characteristics in order to discriminate;
  • scrape personal data at scale in breach of a site's terms.

High-stakes decisions

Do not present model output as professional advice, and do not let it decide, without qualified human review, matters such as:

  • medical diagnosis, treatment, or medication;
  • legal advice or the outcome of a case;
  • credit, insurance, employment, housing, or immigration decisions;
  • safety-critical control of vehicles, aircraft, medical devices, or industrial machinery.

Building software for these domains is fine. Removing the qualified human from the decision is not.

Platform abuse

Do not:

  • circumvent rate limits, token accounting, or billing;
  • register multiple accounts to collect extra free allowances;
  • share or resell API access without a written agreement;
  • attempt to extract or reproduce model weights;
  • scan, probe, or load-test our infrastructure without written permission;
  • send deliberately malformed requests intended to destabilise the platform.

How we enforce this

We do not read your prompts. We do not store prompt or response content, so enforcement is driven by usage patterns, abuse reports, provider notifications, and payment signals.

Depending on severity, we may:

  • contact you for an explanation;
  • throttle or revoke specific API keys;
  • suspend the account pending investigation;
  • terminate the account, forfeiting remaining balance;
  • report the matter to law enforcement.

Child sexual abuse material and credible threats to life are acted on immediately, without prior notice. For everything else we aim to warn first where it is safe to do so.

Reporting a violation

If you believe someone is misusing Clean APIs, email [email protected] with whatever detail you have. Reports are treated confidentially.

Appeals

If you think we acted on your account in error, reply to the enforcement notice or email [email protected]. A person will review it. Include any context that explains the activity.


Questions about this document? Email [email protected].