1.The principle
Your assistant speaks in your name, on your website, to your customers. So the rule underneath all of this is simple: you are responsible for what your assistant says and does.
This policy forms part of the Terms of Service. Breaking it is a breach of contract, and the serious items in clause 3 are grounds for immediate termination.
2.What you may not do
- Anything unlawful, or that promotes, facilitates or conceals unlawful activity.
- Deceive people about who they are dealing with, what they are buying, or what it costs.
- Harass, threaten, defame, or incite violence or hatred against anyone.
- Generate or distribute sexual content involving minors, or any non-consensual intimate imagery. This is reported, not just terminated.
- Impersonate a person, a business or a public authority.
- Infringe someone else's intellectual property, or import content into a knowledge base that you do not have the right to use.
- Distribute malware, phishing pages, or content designed to steal credentials.
- Run scams, fake stores, fraudulent investment offers, or anything on our payment provider's prohibited-business list.
- Circumvent quotas, rate limits, billing, or the safety behaviour of the assistant.
- Probe, scan or load-test our infrastructure without written permission — the security disclosure policy tells you how to ask, and we say yes.
- Resell or white-label the Service as your own product without a written partner agreement.
- Use the Service to build a competing product, or to benchmark it for publication without telling us first.
3.Uses that would change what this product legally is
This is the clause to read, even if you skip the rest
Under the EU AI Act we are the provider of this AI system and you are the deployer. Deploying it for certain purposes would make it a high-risk AI system — and would make us the provider of one, with a conformity regime attached that a business of our size cannot carry.
So these are not discouraged. They are prohibited, and we will terminate immediately for them.
| You must not use an assistant to… | Why |
|---|---|
| Recruitment, candidate screening, or any decision about hiring, promotion or termination | Annex III(4). Using the assistant here would make it a high-risk AI system. |
| Assessing creditworthiness, credit scoring, or pricing life and health insurance | Annex III(5)(b)–(c). |
| Deciding access to education, admissions, or evaluating learning outcomes | Annex III(3). |
| Determining eligibility for essential public or private services, including benefits and emergency services | Annex III(5)(a) and (d). |
| Inferring emotions of a person in a workplace or an educational setting | Article 5(1)(f) — a prohibited practice, not merely high-risk. |
| Manipulative or deceptive techniques that distort behaviour and cause significant harm, or exploiting age, disability or economic vulnerability | Article 5(1)(a)–(b) — prohibited outright. |
| Social scoring, or evaluating people on behaviour or predicted personal characteristics | Article 5(1)(c) — prohibited outright. |
The same prohibition keeps you and us out of the Colorado AI Act and comparable US state rules on consequential decisions. If your intended use is anywhere near this line, email legal@integrable.cloud and ask before you build it. We would rather have that conversation early than terminate an account later.
4.Data you must not put in
Some categories of data carry obligations we have not built for, and no plan or configuration changes that. Do not collect these through an assistant, and do not load them into a knowledge base.
| Category | Why not |
|---|---|
| Protected health information | We are not HIPAA compliant and we do not sign Business Associate Agreements. There is no configuration that makes this permitted. |
| Payment card numbers, CVVs and expiry dates | We are not a PCI DSS environment. Payments go through our merchant of record and card data never reaches our infrastructure — do not ask a visitor to type one into a chat. |
| Government identifiers — Aadhaar, PAN, Social Security and national ID numbers | Aadhaar has its own statutory regime, and the rest carry identity-theft risk out of proportion to any support use case. |
| Personal data of anyone under 18 | India's DPDP Act sets the threshold at 18 and requires verifiable parental consent. Do not deploy the assistant on a service directed at children. |
| Special category data — health, biometrics, genetics, sexual orientation, religious or political belief, trade union membership | GDPR Article 9 requires a specific legal basis that a support conversation will not have. |
| Credentials, API keys and secrets | Nobody should be typing these into a chat box, and no legitimate support flow requires it. |
A visitor can still type anything
You cannot fully prevent someone typing a card number or a symptom into a chat box, and we are not asking you to. What this clause requires is that you do not design an assistant to ask for these things, and that you do not rely on us to handle them safely if they appear. If a visitor volunteers something in this list, delete it — you can, from the dashboard, immediately.
5.Do not hide that it is an AI
The assistant tells people they are talking to an AI. That disclosure is our obligation as provider under Article 50 of the EU AI Act, and it satisfies comparable laws including California’s bot disclosure statute and Utah’s AI Policy Act.
You must not:
- remove, hide or obscure the disclosure
- configure an assistant to deny being an AI, or to claim to be a named human employee
- present AI-generated output as having been written or reviewed by a person when it was not
Giving your assistant a name and a personality is fine. Telling people it is a person is not.
6.Messaging, consent and marketing
If you connect WhatsApp, Telegram, email or any other channel, the consent is yours to obtain. That means:
- Opt-in before a business-initiated message, as the platform's own policy and the recipient's local law require — including the TCPA in the United States, CASL in Canada, and the platform rules Meta applies to WhatsApp.
- A working unsubscribe in every marketing message, honoured promptly.
- No unsolicited bulk messaging, no purchased lists, and no messaging people who have opted out.
- Compliance with the messaging platform's own policies, which apply to you directly and which we cannot waive.
A platform that suspends your channel for a policy breach is acting on its own terms; we cannot appeal it for you.
7.Children
Do not deploy an assistant on a website or service directed at children, and do not use one to knowingly collect the personal data of anyone under 18. India’s DPDP Act sets the threshold at 18 and requires verifiable parental consent, which is higher than the GDPR’s 13 to 16 and COPPA’s 13 — and we have built for none of them. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright.
8.How we enforce this
We would rather fix a problem than close an account, and most breaches are a misconfiguration rather than intent.
| Situation | What we do |
|---|---|
| Something looks wrong, and it is probably a mistake | We email you and ask. You get a reasonable period to fix it. |
| A clear breach, no immediate harm | We tell you what is wrong and set a deadline. If it is not fixed, we suspend. |
| Serious breach — clause 3, unlawful content, active harm, or a security risk to others | Immediate suspension or termination, without notice. We will tell you why. |
| Child sexual abuse material, or a credible threat to life | Immediate termination and a report to the appropriate authority. |
If you think we got it wrong, say so — write to legal@integrable.cloud or use grievance redressal. A human reads it, and we do reverse decisions.
9.Reporting abuse
If an assistant built on our platform is doing something it should not be, tell us at abuse@integrable.cloud. Include the website it is on and, if you can, a transcript or a screenshot.
We acknowledge every report within one business day and tell you the outcome once we have acted, unless doing so would compromise an investigation. You do not need an account to report something, and you can do it anonymously.
Security vulnerabilities go to security disclosure instead — that route has its own commitments, including that we will not pursue researchers acting in good faith.