Acceptable Use Policy
What you can and cannot build, deploy, or message through Inscendo. Forbidden categories, regulated-data restrictions, technical-abuse rules.
Inscendo: Acceptable Use Policy (AUP)
Effective Date: June 26, 2026 Version: 1.2 Provider: Inscendo Automation Inc.
This Acceptable Use Policy ("AUP") is incorporated into the Inscendo Master Subscription Agreement ("MSA") and applies to all use of the Service. Capitalized terms have the meanings given in the MSA. Customer is responsible for ensuring its users, contractors, and End-Users comply with this AUP. These restrictions apply equally to interactive, autonomous, scheduled, and "headless" use of the agent; operating the Service autonomously does not reduce Customer's responsibility for any action taken on Customer's behalf. Customer's use must also comply with the acceptable-use requirements of the third-party model provider(s) that power the Service, as Inscendo communicates them from time to time. Violation of this AUP is a material breach of the MSA and may result in immediate suspension or termination, fee forfeiture, and indemnity liability under the MSA.
1. Prohibited content and conduct
Customer shall not use the Service, or permit or facilitate any third party to use the Service, to do any of the following:
1.1 Illegal activity
(a) Violate any applicable law, regulation, court order, or rights of any third party: including without limitation laws governing telecommunications, telemarketing, electronic commerce, advertising, securities, lending, insurance, healthcare, employment, immigration, gambling, controlled substances, alcohol, tobacco, firearms, or export control; (b) Engage in fraud, deception, false advertising, or any deceptive trade practice prohibited by Section 5 of the FTC Act or any state consumer-protection statute; (c) Engage in unauthorized practice of law, medicine, accounting, or any other licensed profession; (d) Violate the Computer Fraud and Abuse Act, the Stored Communications Act, the Electronic Communications Privacy Act, or any analogous federal or state law; (e) Infringe, misappropriate, or violate any intellectual-property right (copyright, trademark, patent, trade secret), publicity right, privacy right, or moral right; (f) Upload, provide, or process through the Service any data that Customer obtained unlawfully, holds without authorization, or lacks a lawful basis and all required consents to process.
1.2 Harm to persons
(a) Harass, threaten, stalk, defame, libel, or intentionally inflict emotional distress on any person; (b) Generate, store, distribute, or facilitate child sexual abuse material ("CSAM"), grooming content, or any sexual content involving any minor; (c) Generate or distribute non-consensual intimate imagery ("revenge porn") or content depicting any identifiable person sexually without that person's verifiable consent; (d) Generate, distribute, or facilitate terrorism content, content that incites violence, content glorifying mass-casualty events, or content that materially assists self-harm or suicide; (e) Generate or distribute content that exploits or endangers minors or vulnerable adults.
1.3 Discrimination
Use the Service to make, support, or facilitate decisions in employment, credit, housing, insurance, healthcare, education, public accommodations, or access to essential services that violate the Civil Rights Act, the Fair Housing Act, the Equal Credit Opportunity Act, the Americans with Disabilities Act, the Age Discrimination in Employment Act, the Genetic Information Nondiscrimination Act, or any applicable state or local anti-discrimination law.
1.4 Security and service-harm
(a) Probe, scan, attack, or attempt to gain unauthorized access to any system, network, account, or data Customer is not authorized to access, whether owned by Inscendo, by any other Service customer, or by any third party; (b) Distribute, generate source code for, host, or facilitate the deployment of malware, ransomware, spyware, keyloggers, command-and-control infrastructure, or any other malicious code intended to cause damage or unauthorized access; (c) Conduct denial-of-service or distributed-denial-of-service attacks, traffic flooding, brute-force credential attacks, or any attack on the availability of any system; (d) Bypass, attempt to bypass, or assist in bypassing rate limits, the database mutation gate, outbound-destination allow-listing, sandbox isolation, the Browser Companion sensitive-field sensor, any content-moderation or safety control applied by the underlying third-party model provider, or any other safety, security, or technical protection measure of the Service or of any third-party service; (e) Reverse-engineer, decompile, or disassemble the Service, or attempt to extract model weights, prompts, embeddings, or training data; (f) Use the Service to develop, train, or improve a competing AI model, AI agent platform, or AI orchestration platform; (g) Use scraping bots, headless browsers, or the Browser Companion to extract or harvest data from any third-party site in violation of that site's terms of service, robots exclusion protocol, applicable anti-scraping caselaw, or rate limits; (h) Use the Service to circumvent paywalls, account limits, or per-user restrictions imposed by any third party; (i) Submit prompt injections, jailbreaks, or adversarial inputs intended to cause the agent to violate its safety constraints (other than for Customer's own authorized internal red-team testing of Customer's own configurations).
1.5 Authentication and impersonation
(a) Misrepresent identity, affiliation, or authority: including impersonating any individual, company, brand, government official, or AI system; (b) Use stolen, fraudulent, or unauthorized credentials, payment methods, or accounts; (c) Permit account sharing or sublicense access in violation of the MSA; (d) Generate "deepfake" audio, video, or imagery of any identifiable person without the person's verifiable consent and clear disclosure; (e) Conduct "AI washing" or other deceptive AI-related claims that violate FTC guidance.
1.6 Communications abuse
(a) Send unsolicited bulk communications ("spam") in any medium, including email, SMS, MMS, RCS, voice, fax, push, or in-app; (b) Send any SMS, MMS, or RCS message in the United States without (i) prior express written consent of the recipient sufficient under the TCPA and applicable state mini-TCPA law, (ii) registration of the applicable A2P 10DLC campaign with the carriers, (iii) compliance with CTIA Messaging Principles and the TCR Campaign Registry, and (iv) a clear and conspicuous opt-out mechanism (e.g., "Reply STOP") on every campaign; (c) Send messages in any Forbidden Category identified in Schedule 1 without first obtaining a written exception from Inscendo; (d) Send any commercial email that violates CAN-SPAM (15 U.S.C. § 7701 et seq.): including without limitation false or misleading headers, deceptive subject lines, missing physical postal address, missing unsubscribe link, or failure to honor opt-out within ten (10) business days; (e) Place any voice call that violates the TCPA, including artificial-voice or pre-recorded calls without prior express written consent and without compliance with TRACED Act, STIR/SHAKEN, or applicable state robocall laws; (f) Spoof caller ID, originating number, or sender identity; (g) Generate or send phishing, smishing, vishing, or social-engineering content; (h) Engage in lead-laundering, sweepstakes-based consent collection, or any other practice the FTC, FCC, or AAGs have designated as deceptive.
1.7 Regulated data and high-risk uses
(a) Process Protected Health Information as defined under HIPAA without a separately executed Business Associate Agreement with Inscendo (none currently offered); (b) Process Cardholder Data as defined under PCI-DSS within Inscendo's environment (Customer must use Stripe's hosted/tokenized fields and not handle card data through the Service or the agent); (c) Process biometric identifiers (including face geometry, voiceprints, retina scans, and fingerprints) regulated under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act (CUBI), the Washington biometric law, or similar laws, without a separately executed addendum; (d) Process classified information, controlled unclassified information, ITAR-controlled technical data, or any data subject to export-control jurisdiction; (e) Process the personal information of any individual under 18 (and, in particular, any individual under 13 in a manner that would require COPPA verifiable parental consent); (f) Process the personal data of any individual located in the European Economic Area, the United Kingdom, Switzerland, the People's Republic of China, the Russian Federation, Brazil, or any other jurisdiction whose data-protection law would impose extraterritorial obligations on Inscendo; (g) Use the Service in connection with any High-Risk Use as defined in MSA § 11.3; (h) Use the Service to make, support, or substantially automate any "consequential decision", including hiring, firing, promotion, compensation, lending, credit, insurance underwriting, housing, eviction, healthcare diagnosis or treatment decisions, education enrollment, or access to essential services, without a documented human reviewer in the loop, individual notice to affected persons, and applicable bias and impact testing under the Colorado AI Act, the Illinois Human Rights Act, NYC Local Law 144, EEOC guidance, and successor authorities; (i) Use the Service to set up or operate biometric categorization, social scoring, predictive policing, or untargeted facial-recognition scraping; (j) Use the Service to develop or operate weapons (including chemical, biological, radiological, nuclear, or autonomous weapons) or to materially assist any party in doing so.
1.8 Sanctions, export, and prohibited regions
(a) Use, access, or distribute the Service from or for the benefit of any Sanctioned Jurisdiction or person on a Restricted Party List (MSA § 17); (b) Export, re-export, or transfer the Service or AI Output in violation of U.S. export-control or sanctions laws (EAR, ITAR, OFAC).
1.9 Browser Companion-specific abuses
(a) Attach the Browser Companion to any browser session, account, or system Customer or its End-User is not authorized to access; (b) Attach the Browser Companion to any session containing material covered by attorney-client privilege, work product, or any third-party confidentiality obligation that would be breached by transmission to Inscendo or its AI model provider; (c) Attach the Browser Companion in violation of any third-party site's terms of service, anti-automation rule, or rate limit; (d) Use the Browser Companion to interact with any system in a manner that would be unauthorized access or fraud under the Computer Fraud and Abuse Act, 18 U.S.C. § 1030, or analogous state laws; (e) Disable, weaken, modify, or attempt to circumvent the sensitive-field sensor or any other safety mechanism in the extension; (f) Distribute a modified version of the Browser Companion or repackage it.
2. Forbidden Industries and Categories
The categories listed in Schedule 1 (Forbidden Categories) are flatly prohibited unless Customer obtains prior written approval from Inscendo following Customer's submission of a written use-case justification, applicable license documentation, and compliance program details. Approval is granted in Inscendo's sole discretion and may be conditioned on additional terms (additional indemnification, additional fees, third-party audits, or BAAs/addenda where applicable).
Examples of Forbidden Categories include third-party debt collection or debt consolidation; payday and high-cost short-term loans; credit-repair and credit-score-improvement promotions; third-party lead generation and consumer-data brokerage; "get-rich-quick" or work-from-home schemes; multi-level-marketing and pyramid schemes; illegal drugs; cannabis and CBD where federally illegal or state-illegal in the recipient's jurisdiction; prescription drugs without verified pharmacy licensure; gambling and sports-betting; the S.H.A.F.T. categories (sex content, hate content, alcohol [age-gated], firearms and ammunition, tobacco and vaping); cryptocurrency and digital-asset promotions where federally restricted; political advertising in any jurisdiction with applicable regulation; and phishing/smishing.
3. Carrier and regulator pass-through
Customer is responsible for, and shall pay or reimburse Inscendo within fifteen (15) days of invoice for, any fines, penalties, blocks, suspensions, or chargebacks levied by any wireless carrier (including without limitation T-Mobile/Sprint Sev-0 messaging fines, AT&T 10DLC penalties, Verizon enforcement actions), payment processor (including Stripe), regulator (FTC, FCC, state AG), or rights-holder, that are attributable to Customer's use of the Service. T-Mobile Sev-0 messaging-violation fines, for example, range from US $500 to US $2,000 per incident as of the effective date of this AUP and are subject to change by the carrier; the carrier's then-current schedule applies.
4. Reporting and enforcement
4.1 Reporting violations. Anyone may report a suspected AUP violation to support@inscendoiq.com. Reports should include: the conduct alleged, the affected URL or account if known, and the reporter's contact information for follow-up. Inscendo will review reports promptly but does not commit to specific response times.
4.2 Inscendo's response. Inscendo may, in its sole discretion and without prior notice: (a) investigate using automated log analysis, log review, and limited human review; (b) suspend or restrict Customer's access; (c) remove or quarantine offending content, capsules, widgets, automations, or AI Outputs; (d) disable specific tools, integrations, or features; (e) require Customer to take remedial action; (f) terminate the Customer's account and forfeit any remaining Wallet Funds; (g) report violations to carriers, payment processors, law enforcement, or rights-holders as it determines appropriate; and (h) charge any pass-through penalties under § 3.
4.3 Right of removal. Inscendo reserves the right to remove or refuse to publish any content, capsule, widget, automation, or AI Output, with or without notice, for any reason or no reason. The Service is not a public forum and is not subject to public-square viewpoint-neutrality obligations.
4.4 Cooperation. Customer shall cooperate in good faith with any investigation, including providing logs, configurations, and consent records on request.
4.5 Child-safety reporting. Inscendo has zero tolerance for child sexual abuse material ("CSAM") and child sexual exploitation. If Inscendo becomes aware of apparent CSAM or child-exploitation activity, it may, and where required by law will, report it to the National Center for Missing & Exploited Children (NCMEC) and to law enforcement, preserve related records as required, and suspend or terminate the responsible account. This § 4.5 operates regardless of any other provision of the MSA, the AI Code of Conduct, or this AUP.
5. Updates to this AUP
Inscendo may update this AUP from time to time. Material adverse changes will be communicated by posting and email notice. Continued use after the effective date of an update constitutes acceptance.
Schedule 1: Forbidden Categories
Cross-reference: § 2 of this AUP. The categories below are prohibited unless Customer holds a written exception executed by Inscendo. Inscendo may amend this Schedule from time to time.
A. Financial services
A1. Third-party debt collection A2. Third-party debt consolidation, debt settlement, debt elimination, debt reduction A3. Credit repair, credit-score improvement, "remove negative items" services A4. Payday loans; auto-title loans; high-cost short-term loans (loans with APR > 36% or terms < 60 days) A5. Third-party loan-application or loan-aggregator services for auto, mortgage, student, or personal loans A6. Cryptocurrency, digital-asset, NFT, or token-issuance promotions, advisories, or trading platforms A7. "Get-rich-quick," investment-tip, work-from-home, or income-claim schemes A8. Multi-level-marketing, pyramid, or matrix-based compensation schemes A9. Tax-relief, IRS-resolution, or "settle-for-pennies-on-the-dollar" tax services A10. Foreign-exchange (forex) or contract-for-difference (CFD) brokerages targeting U.S. retail consumers A11. Unregistered securities offerings or solicitations
B. Lead generation and data brokerage
B1. Third-party lead generation, lead resale, lead syndication, or lead-aggregator services where the lead is sold or transferred to multiple buyers B2. Sale, resale, or sharing of consumer personal information for the purpose of marketing by third parties B3. People-search, background-check, or skip-tracing services targeting consumers B4. Operation of any data-broker business required to register under the California or Texas data-broker statutes without registration
C. Health, drugs, and medical
C1. Sale, advertising, or fulfillment of prescription drugs without verified pharmacy license C2. Sale, advertising, or fulfillment of illegal drugs or drug paraphernalia (federal scheduling controls) C3. Cannabis, marijuana, THC products, or CBD products in any jurisdiction where their sale is federally or state-illegal in the recipient's jurisdiction C4. Telehealth, prescribing, diagnostic, or treatment services without a separate written addendum (HIPAA BAA prerequisite) C5. Mental-health crisis-line operations C6. Weight-loss, supplement, or dietary advice making efficacy claims
D. Gambling and adult content
D1. Casino, sports-betting, daily fantasy sports, and gambling sites or apps (subject to all applicable state licensing) D2. Lottery, sweepstakes, or contest of chance services that do not comply with federal and state law (no-consideration sweepstakes excluded) D3. Adult sexual content, escort services, "sugar dating" sites, or any sex-work platform D4. Pornography distribution platforms
E. S.H.A.F.T.
E1. Sex content, sex-work platforms, escort services E2. Hate speech, white-supremacist content, content promoting genocide or violence against any protected class E3. Alcohol: permitted only with age-gating and compliance with state laws (TABC for Texas) E4. Firearms, ammunition, gun parts, gun accessories, conversion devices, "ghost gun" components: prohibited via the Service's outbound communications channels E5. Tobacco, electronic-cigarette, vaping, kratom, and nicotine products
F. Communications-abuse categories
F1. Phishing, smishing, vishing, or other social-engineering content F2. "AI-girlfriend," "AI-companion," or any AI-mediated romantic or erotic chat targeting consumers F3. Robo-calling, mass-dialing, or auto-dialer campaigns to wireless numbers without TCPA-compliant consent F4. SMS-survey or "vote and win" campaigns operated as covers for marketing F5. Sweepstakes-based consent harvesting or "pre-checked" consent flows
G. Critical infrastructure and high-risk applications
G1. Operational technology / industrial control systems (SCADA, PLC) for energy, water, transit, or chemical facilities G2. Aviation, marine, rail, mass-transit dispatch or control G3. Healthcare clinical decision support that is not human-verified G4. Election infrastructure, vote-counting, or voter-registration systems G5. Critical financial-market trading or clearing infrastructure G6. Autonomous-vehicle control G7. Weapons systems
H. Law-enforcement / surveillance
H1. Real-time facial-recognition by U.S. state or local law enforcement H2. Predictive policing or criminal-risk profiling that uses protected characteristics H3. Untargeted scraping of facial images from the internet for biometric databases H4. Stalkerware, "find my partner," or covert-monitoring applications targeting any individual without that individual's verifiable consent
I. Generative-content abuses
I1. CSAM, non-consensual intimate imagery, sexual deepfakes I2. Identity-theft toolkits, fraud documents (fake IDs, fake utility bills, fake employment letters) I3. Disinformation campaigns at scale, especially targeting elections, public-health emergencies, or financial markets I4. Malware development tooling for offensive use (offensive security firms working under written engagement letters with target consent are subject to a separate addendum)
[End of AUP and Schedule 1]