Acceptable Use Policy

Last updated: 2 July 2026

This Policy supplements the Terms of Service and applies to every user, integration, and AI agent operated on the Alethe platform.

By using Alethe you agree NOT to engage in any of the following.

1. Illegal use

  • Use the Service for purposes illegal in your jurisdiction or in ours (Czech Republic / EU)
  • Distribute malware, spyware, ransomware, cryptominers, or other malicious code
  • Engage in fraud, identity theft, financial scams, money-laundering, or terrorism financing
  • Violate EU, UK, US, or UN sanctions; export controls; or trade restrictions
  • Process personal data without a lawful basis under GDPR
  • Use the Service to commit any criminal offence

2. Prohibited AI uses — Art. 5 EU AI Act

You must not use Alethe agents, content generators, or any AI feature for:

  • Subliminal techniques beyond a person's consciousness, materially distorting their behaviour in a way that causes harm
  • Exploiting vulnerabilities of a specific group (age, disability, social/economic situation) to materially distort behaviour
  • Social scoring by public authorities (or on their behalf) leading to detrimental treatment in unrelated contexts
  • Real-time remote biometric identification in publicly accessible spaces (limited exceptions under Art. 5(1)(h))
  • Emotion inference in workplace or education contexts (limited exceptions for medical or safety reasons)
  • Biometric categorisation by sensitive attributes (race, political views, trade-union membership, religious belief, sex life, sexual orientation)
  • Predictive policing based solely on profiling
  • Untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases

Use of Alethe for any Art. 5 prohibited practice constitutes a material breach that may trigger immediate termination plus referral to authorities.

2A. High-risk AI uses (Annex III) — you become the provider

Alethe's agents are general-purpose and are not intended for, and must not be changed into, a high-risk AI system within the meaning of the EU AI Act (Art. 6 + Annex III). You must NOT use Alethe agents to:

  • Screen, rank, filter, or evaluate natural persons for recruitment or employment (CV screening, candidate ranking, interview scoring), or for promotion, task allocation, monitoring, or termination of workers;
  • Score or assess the creditworthiness of natural persons, or set life / health insurance risk pricing;
  • Determine eligibility for essential private or public services or benefits;
  • Perform emotion recognition or biometric categorisation of natural persons;
  • Make admission or evaluation decisions in education / vocational training;
  • Any other Annex III high-risk purpose —

unless you expressly and in writing assume the EU AI Act "provider" obligations for that deployment. If you repurpose a general Alethe agent for a high-risk use, you become the provider of that high-risk AI system under Art. 25(1)(c) and bear the corresponding obligations (risk management, conformity assessment, registration, human oversight). Alethe ships no high-risk-purpose templates and assumes no provider obligations for your high-risk deployments.

Consequential automated decisions about people must keep a human in the loop (cf. Art. 22 GDPR). Configuring an agent to take such decisions without human review is a material breach.

3. Abuse of the Service

  • Attempt to reverse-engineer, decompile, or extract source code
  • Scrape, crawl, or harvest data from the Service at scale beyond reasonable API use
  • Overload, denial-of-service, or otherwise disrupt the Service or other tenants
  • Circumvent rate limits, access controls, prompt-injection defences, or other security measures
  • Use the Service to train competing AI models (the anti-training clause)
  • Bypass model safety filters via jailbreak prompts, prompt-injection chains, or similar techniques to elicit prohibited outputs
  • Use the Service to mine cryptocurrency or run unrelated workloads

4. Content prohibitions

You must not upload, generate, or transmit:

  • Child sexual abuse material (CSAM) — zero tolerance; report any incident to info@alethe.eu and to NCMEC / national authorities
  • Content that infringes copyright, trademark, patent, or trade-secret rights of others
  • Content that is defamatory, harassing, threatening, hateful, or that incites violence
  • Content that exploits, harms, or endangers minors (grooming, exploitation, age-inappropriate targeting)
  • Content that violates third-party privacy (including non-consensual intimate imagery, doxxing, stalking)
  • Content that misrepresents you or impersonates another person, organisation, or public figure without consent
  • Deepfakes of real people without their consent, or deepfakes used to deceive, defraud, defame, or harass
  • Synthetic CSAM, non-consensual deepfake intimate imagery, or "nudify" applications

5. Communication and outreach

  • Do not send unsolicited bulk communications (spam) via Alethe-powered agents or integrations
  • Comply with anti-spam laws in every jurisdiction you target — GDPR Art. 6 / e-Privacy Directive in EU; CAN-SPAM in US; PECR in UK; equivalents elsewhere
  • Honour unsubscribe requests within 24 hours for newsletter-style outreach, immediately for transactional opt-outs
  • Do not use AI to impersonate real humans (including your own staff) in a way that misleads recipients
  • Identify yourself and the sending organisation clearly in any outreach run through Alethe

6. Integration-specific rules

When you use Alethe's integrations:

  • Meta / Facebook / Instagram / Threads: comply with Meta Platform Terms, Community Standards, and Ad Policies. Do not run political ads targeted at restricted regions without their declared compliance flow.
  • Shopify: comply with Shopify Partner Program agreements and merchant-store ToS.
  • Slack: comply with Slack workspace owners' policies; do not relay messages from private channels to other workspaces without the workspace owner's authorisation.
  • Google Workspace: comply with Google API Services User Data Policy, including the "limited use" requirement for Gmail / Drive scopes.
  • Apollo / Hunter / Apify (contact lookup): comply with each provider's ToU and with GDPR Arts. 13/14 information duties toward subjects when you contact them.

Misuse of an integration may result in the integration being disabled platform-wide or per-tenant.

6A. Data-acquisition and scraping tools — you are the Controller

Alethe exposes tools that let your AI agents acquire data from external sources (web scraping via Apify and other actors, web_scrape, contact_lookup, and contact-data providers). When you direct these tools, you are the data Controller of the resulting personal data and Alethe acts as your Processor. You agree that:

  • The lawful basis is yours. You must hold a documented lawful basis (typically a legitimate-interest assessment) for every scrape or lookup you run that touches personal data. Acquiring data labelled "GDPR-compliant" does not by itself give you a lawful basis for your use of it.
  • You must inform the people (GDPR Art. 14). Where you collect personal data about people from a source other than those people, the duty to inform them is yours — Alethe's own privacy policy cannot discharge a duty owed to people who never visited Alethe. Alethe provides a Czech/EU-language Art. 14 notice template to assist; deploying it is your responsibility. (Cf. CNIL v Kaspr, €240,000, 2024.)
  • Public data only — no login / auth-bypass. Do not use these tools to access data behind a login, supply session cookies or credentials, or circumvent authentication, rate limits, CAPTCHAs, or other access controls. The platform blocks login/auth-bypass scraping; attempting to defeat that block is a material breach.
  • No special-category data (GDPR Art. 9). Do not target or knowingly collect health, biometric, political, religious, trade-union, sexual-orientation, or other Art. 9 data. The platform applies a fail-closed filter; you must not work around it.
  • Respect source terms. Honour the target's Terms of Use and robots.txt. Authenticated / logged-in scraping of platforms that forbid it (e.g. LinkedIn) is prohibited and is not offered by Alethe.
  • Minimise and bound retention. Collect only what you need; honour access, objection, and erasure requests for the data you acquire.
  • Bring-your-own provider account (advanced). Where Alethe offers it, you may connect your own scraping/data-provider account (e.g. your own Apify credentials). In that case you operate as Controller and data importer directly.

Breach of this section is a material breach and may result in the data-acquisition tools being disabled per-tenant or platform-wide.

6B. Email and inbox-reading agents

When you connect a mailbox (e.g. Gmail / Workspace) for an agent to read or triage:

  • You are the Controller of the personal data in the mailbox — including the data of third parties (senders, recipients, people discussed) who are not your account holder. You must have a documented lawful basis (typically legitimate interest) and provide the transparency those people are due (including, where relevant, telling your own staff and correspondents that an AI processes the mail).
  • Alethe processes mailbox content as your Processor, in memory by default, does not persist raw message bodies beyond what the task requires, does not train any model on your email content, and applies the same fail-closed special-category filter as the data-acquisition tools.
  • You must comply with Google's API Limited Use requirements for restricted mail scopes and must not use inbox access for advertising, resale, or generalised profiling.
  • Monitoring an employee's mailbox carries additional proportionality + worker-information duties (GDPR Art. 88 and national law); meeting them is your responsibility.

7. Multi-tenancy and isolation

  • Do not attempt to access another organisation's data, agents, workflows, or prompts
  • Do not attempt to exfiltrate other tenants' data via prompt injection or cross-tenant leakage attacks
  • Report any suspected isolation breach to info@alethe.eu — bug-bounty considered in good faith

8. Resource use

  • Reasonable use only — burst patterns are fine; sustained 100% utilisation of shared resources is not
  • Each plan has documented credit + rate limits; circumventing them by spawning multiple accounts is a breach

9. Reporting violations

Report abuse to info@alethe.eu. We investigate all reports and may:

  • Issue a warning
  • Suspend or terminate the offending account / organisation
  • Remove offending content and AI artefacts
  • Report to law enforcement when required (CSAM is always reported; serious cybercrime usually is)

We act on validated CSAM reports within 24 hours and report to national authorities and NCMEC.

10. Enforcement

Alethe may, at our discretion:

  • Suspend access pending investigation
  • Terminate the agreement without refund for material breach (including any breach of Sections 1, 2, 4, or 7 above)
  • Cooperate with regulators (ÚOOÚ, ČOI, AI Office, EU Commission) and law enforcement on documented requests
  • Disclose information necessary to prevent imminent harm to persons