Acceptable Use Policy
This policy explains what is and is not permitted on Compass, and how we enforce it. It binds both you and your end users.
Our standard of judgment is simple: whether a use would cause foreseeable harm to real people. The lists below cannot cover every situation. If you encounter an edge case, write to [email protected] and ask first, rather than launching and explaining later.
1. Absolute Prohibitions
Once confirmed, the following uses result in immediate account termination and, where necessary, a report to law enforcement, with no grace period for appeal.
- Generating, distributing, or retrieving child sexual abuse material (CSAM), or any content that sexualizes minors.
- Planning or facilitating terrorism, violent extremism, or genocide, or recruiting for such causes.
- Acquiring, manufacturing, or modifying weapons, including explosives, chemical, biological, and radiological materials, and guidance on circumventing weapons controls.
- Developing or deploying malware, ransomware, or botnets, or conducting penetration, scanning, or denial-of-service attacks against unauthorized targets.
- Generating non-consensual sexualized content, including deepfakes of real individuals.
- Facilitating human trafficking, forced labor, or child exploitation, or stalking or harassing specific individuals.
2. High-Risk Uses Requiring Additional Safeguards
The following uses are not prohibited, but you must provide qualified human review, clear disclaimers, and an accessible human appeal channel; failure to do so constitutes a violation.
3. Platform Integrity
- Do not circumvent rate limits, regional restrictions, or free-credit rules through multiple accounts, proxy pools, falsified identities, or similar means.
- Do not embed Compass keys in clients, plugins, or mirror sites distributed to the public, and do not resell gateway access in any form.
- Do not scrape or bulk-probe our model lists, routing strategies, or upstream channel configurations.
- Do not interfere with the stable operation of the service, including abnormally high-concurrency load testing. If you need to run load tests, contact us in advance to arrange a window.
4. Applications Serving End Users
- Clearly inform users that they are interacting with an AI; do not pose as a human or impersonate a specific real person.
- Provide users with a channel to report harmful output, and apply input and output moderation for high-risk categories.
- Do not use models to analyze users’ sensitive personal information (health, biometrics, sexual orientation, religion, etc.) without their knowledge.
- If your product serves users under 18, you must separately document your safeguards and confirm them with us.
5. Content Moderation
Some upstream providers perform content safety determinations on their side. Requests rejected upstream are returned with a 400 or 403 status, with the provider’s category identifier included in the error body. These determinations are made by the provider and we cannot overturn them case by case, but for clear false positives you may submit the request id and we will raise it with the provider.
6. How We Enforce
- Except in the circumstances described in Section 1, we notify before acting and, where possible, state the triggering cause and the range of request ids involved.
- You may appeal to [email protected] within 30 days of receiving a notice; we commit to responding within 10 business days.
- For service interruptions caused by false positives, we compensate you with call credits equivalent to the duration of the interruption.