Acceptable Use Policy

Effective
21 September 2026
Last updated
21 September 2026
Version
1.0

This policy applies to everyone who uses the ZeroCredit AI platform, dashboard or API, including your team members and any application you build on our API. It forms part of our Terms of Service.

1. Unlawful and harmful activity

  • Any use that breaks applicable law, or that infringes intellectual property, privacy or other rights.
  • Fraud, impersonation, phishing, or deceptive content intended to mislead people about its origin.
  • Generating child sexual abuse material, or sexual content involving minors, in any form.
  • Content that incites violence, promotes terrorism, or is intended to harass or threaten a person.
  • Unlawful surveillance, tracking or profiling of individuals, including unlawful biometric processing.
  • Creating deceptive synthetic media of real people for fraudulent, defamatory or electoral manipulation purposes.

2. Attacks on the platform and other customers

  • Attempting to access another organisation's account, keys, requests, analytics or data.
  • Probing, scanning or penetration-testing our systems without our prior written consent.
  • Uploading or transmitting malware, or using the API to build or distribute malicious code.
  • Denial-of-service activity, traffic floods, or deliberately abusive retry behaviour.
  • Circumventing authentication, rate limits, quotas, budgets or plan entitlements.
  • Stealing or trading credentials, including provider API keys, ZeroCredit API keys or OAuth tokens.
  • Reselling or sublicensing access to the service except where your agreement expressly permits it.

3. API and automation

  • Automated traffic must stay within the rate limits and any limits agreed in your plan or order form.
  • Keep your ZeroCredit API keys secret. Do not embed them in client-side code, public repositories or shared documents; rotate a key immediately if it may have been exposed.
  • Do not use one account to circumvent a suspension, limit or unpaid balance on another.
  • Do not misrepresent your identity or your organisation when requesting access or support.

4. Third-party provider rules

Requests you send are executed by the AI provider you selected or entitled us to use. You must comply with that provider's own usage policies, and you must not attempt to bypass a provider's safety systems, content filters or regional restrictions — including through prompt manipulation, obfuscation or routing choices. A provider may independently block, throttle or terminate access for policy breaches, and we cannot override that decision.

6. How we enforce this policy

We enforce this policy with the controls the platform actually has: request rate limiting, quota and budget enforcement, credential validation, audit logging of privileged actions, and anomaly detection on usage and spend patterns. We do not read customer prompts routinely, and we do not monitor content for quality or commercial purposes.

Where we reasonably believe this policy has been breached, we may limit, suspend or terminate access — with notice where practicable, and immediately where there is a security, legal or fraud risk. Serious or repeated breaches may result in termination under the Terms of Service.

7. Reporting abuse

Report suspected abuse, security issues or infringing use to support@zerocreditai.com. Include enough detail to let us investigate, and never include API keys, passwords or other secrets in your report. Complaints can also be raised through our grievance process.