Acceptable Use Policy
Version: 2026-08-08
Effective date: August 8, 2026
This Acceptable Use Policy (“AUP”) applies to every Infer by Flow7 account, workspace, API key, request, application, Customer Content item, output, integration, and downstream user. It protects customers, model and infrastructure suppliers, payment systems, and the public while preserving ordinary legitimate research, creative, commercial, and personal uses.
You must also comply with applicable law and the Model Terms for the model or route you select. A stricter lawful provider restriction applies only to the affected model or route.
1. Unlawful activity and rights violations
Do not use Infer to:
- commit, facilitate, solicit, or conceal unlawful activity;
- violate sanctions, export controls, court orders, or territorial restrictions;
- infringe intellectual-property, privacy, publicity, confidentiality, contractual, or database rights;
- unlawfully obtain, expose, sell, or exploit personal or confidential information; or
- evade a legal restriction that applies to you, your user, the selected model, or the destination of an output.
Legitimate commentary, analysis, research, parody, interoperability, and other protected activity are not prohibited merely because they concern a controversial subject.
2. Cyber abuse, intrusion, and malicious software
Do not use Infer to develop, deploy, or materially facilitate:
- malware, ransomware, destructive code, botnets, denial-of-service attacks, or unauthorized persistence;
- credential theft, phishing, account takeover, session hijacking, or secret exfiltration;
- exploitation of systems without authorization;
- evasion or disabling of security controls for harmful purposes;
- unauthorized surveillance or interception; or
- instructions whose primary purpose is to enable material cyber harm.
Good-faith defensive security, education, vulnerability research, incident response, malware analysis, capture-the-flag work, and authorized penetration testing are permitted when conducted within lawful authorization, with appropriate containment and harm minimization.
3. Fraud, deception, impersonation, and manipulation
Do not use Infer to facilitate scams, theft, payment fraud, money laundering, forged records, fake evidence, fraudulent credentials, market manipulation, deceptive reviews, or impersonation intended to cause harm or obtain value unlawfully.
Do not falsely present an automated system as a specific real person or conceal synthetic content when disclosure is required by law or necessary to avoid material deception. Satire, fiction, roleplay, and clearly disclosed synthetic media are not prohibited solely because they are fictional.
4. Violence, weapons, terrorism, and serious wrongdoing
Do not use Infer to plan, threaten, encourage, or materially facilitate terrorism, targeted violence, kidnapping, human trafficking, assassination, illegal weapons acquisition, explosives, or evasion of safeguards intended to prevent imminent serious harm.
Legitimate news reporting, historical analysis, policy debate, safety research, fiction, harm prevention, and lawful professional work may discuss such topics when contextualized and not used to facilitate wrongdoing.
5. Child sexual exploitation and abuse
Any child sexual abuse material, grooming, sexual exploitation of a minor, or sexual content involving a person under 18 is prohibited. Infer may preserve evidence and report apparent child sexual exploitation as required or permitted by law.
Do not create or distribute nonconsensual intimate imagery, sexual extortion, trafficking content, or sexualized impersonation of a real person without consent.
6. Harassment, hate, doxxing, and exploitation
Do not use Infer to threaten, stalk, harass, dox, extort, dehumanize, or incite discrimination or violence against an individual or protected group. Do not facilitate trafficking or exploit children, elderly people, people with disabilities, or others in vulnerable circumstances.
Ordinary criticism, political disagreement, analysis of hateful content, counterspeech, and discussion of protected characteristics are not prohibited unless they cross into unlawful or materially harmful conduct.
7. Privacy, credentials, and sensitive data
Do not:
- submit personal data you have no right or lawful basis to process;
- collect passwords, private keys, API secrets, authentication tokens, or payment-card security data;
- identify anonymous people or infer highly sensitive traits unlawfully;
- conduct persistent or biometric surveillance without lawful authority and appropriate safeguards;
- submit protected health information subject to HIPAA without an applicable signed agreement;
- submit children’s data, biometric templates, government authentication credentials, or similarly high-risk data unless Infer has expressly approved the use and route; or
- use output to violate privacy, confidentiality, or data-protection law.
Minimize personal data and use zero-retention or
no-training controls when appropriate. Do not treat
zero-retention as permission to submit unlawful data.
8. High-impact and consequential decisions
Do not use Infer output as the sole basis for a decision that materially affects a person’s:
- employment or worker evaluation;
- housing;
- credit, lending, or financial eligibility;
- insurance;
- education or admissions;
- healthcare, diagnosis, or treatment;
- legal rights or immigration status;
- access to essential goods or services; or
- safety or emergency response,
when law prohibits the use or requires qualified human review, notice, explanation, testing, appeal, or other safeguards.
A lawful assistive use is permitted when qualified people retain meaningful review, the system is tested for the context, affected people receive required disclosures and rights, and the customer complies with applicable AI, civil-rights, consumer, professional, and sector-specific law.
9. Regulated and professional activities
Do not present model output as individualized medical, legal, financial, tax, investment, or other licensed professional advice without appropriate qualified review and required licenses.
Do not use Infer to prescribe controlled substances, evade regulatory requirements, make unlawful automated trading or market-manipulation decisions, or provide an automated emergency/crisis decision where a failure could cause serious harm.
General education, drafting, brainstorming, translation, summarization, administrative assistance, and decision support are permitted when not misleading and appropriately reviewed.
10. Spam and automated communications
Do not generate or send unsolicited bulk messages, unlawful marketing, deceptive outreach, fraudulent lead generation, or communications that violate consent, sender identification, unsubscribe, telemarketing, platform, or anti-spam rules.
Applications that automate communications must use appropriate rate limits, suppression lists, consent records, identification, and opt-out controls.
11. Model, platform, supplier, and payment integrity
Do not:
- bypass rate limits, safety controls, privacy settings, payment controls, model restrictions, country controls, or supplier terms;
- falsify model identity, usage, tokens, prices, receipts, refunds, or routing information;
- abuse retries, idempotency, caching, promotions, top-up limits, or multiple accounts;
- scrape or probe non-public infrastructure or reveal confidential supplier/route information;
- interfere with provider-health checks, metering, billing, or fraud systems;
- share, sell, or publicly embed an Infer API key;
- operate an unauthorized credential-resale service; or
- claim a route is a direct provider relationship, endorsement, or partnership when it is not.
You may build products that use Infer for your own users when you maintain your own access controls and comply with these Terms, the AUP, Model Terms, and all required flow-down obligations.
12. Circumvention and location masking
Do not falsify identity, address, ownership, tax status, customer type, location, end user, or end use to obtain a payment method, model, or route that is unavailable to you. A VPN is not prohibited by itself, but Infer may require verification or deny a transaction when location signals conflict or indicate evasion, fraud, or a restricted territory.
13. Enforcement
Infer may reject a request, filter content, restrict a model or route, reduce limits, revoke credentials, place funds on hold, suspend an account, preserve evidence, notify a provider, or report conduct when reasonably necessary.
Enforcement may consider severity, intent, actual or likely harm, history, cooperation, and remediation. Urgent safety, fraud, sanctions, security, or provider action may occur without advance notice. When the issue is limited to one model, route, payment method, or feature, Infer may restrict that component rather than the entire account.
14. Appeals and reports
To appeal an enforcement decision or report abuse, use the Infer support request form, choose “Security or abuse,” and include the account and decision reference. Do not include unnecessary sensitive content or credentials.
15. Changes and contact
Infer may update this AUP to reflect law, safety, security, supplier, or product changes. A material change will identify its effective date and be communicated when required.
- Abuse and appeals: Infer support request form
- Security reports:
security@flow7.org - Legal questions:
legal@flow7.org
The current operator and postal address are in the Legal Operator Notice.