Acceptable Use Policy
Effective date pending publicationVersion 1.0
This Acceptable Use Policy (the "Policy") governs all use of the services provided by Tessryx LLC ("Tessryx," "we," "us"), including the Tessryx application, API, MCP server, and any content served from our infrastructure (together, the "Services").
This Policy applies to you, to anyone you permit to use your account, and to anyone who uses a site, page, or endpoint you build on the Services. You are responsible for their compliance as if it were your own. Capitalized terms not defined here have the meaning given in the agreement between you and Tessryx governing the Services.
To report a violation, email abuse@tessryx.com.
#1. What this Policy covers
Tessryx does more than store content. Workflows you author execute on our infrastructure, make outbound network requests using credentials you supply, fetch remote content on your instruction, call language models, and serve pages and API routes at public URLs on hostnames we operate. Sections 4 through 9 address those capabilities specifically, because they create risks that a general content policy does not reach.
We do not monitor Customer Content and have no obligation to do so. Nothing in this Policy creates a duty to review, screen, or police what you publish.
#2. Prohibited content
You may not create, store, publish, transmit, or serve content that falls into any of the categories below. Section 2.10 sets out what remains permitted, and should be read alongside them — several of these categories have legitimate counterparts, and we do not intend to prohibit those.
#2.1 Unlawful content
Content that is unlawful, or that facilitates unlawful activity.
#2.2 Child safety
Content that sexually exploits or abuses children, constitutes child sexual abuse material, sexualizes a minor, or promotes or facilitates harm to children. This applies equally to AI-generated, fictional, and illustrated depictions.
#2.3 Violence, harassment, hatred, and dangerous acts
- Threats of violence, incitement to violence, or celebration of violence
- Promotion of, or support for, organizations known for violent activity
- Targeted harassment, intimidation, or bullying of a person or group
- Content attacking or demeaning a person or group on the basis of race, ethnicity, nationality, religion, sex, gender, sexual orientation, age, disability, or health status
- Cruelty toward animals
- Content encouraging or instructing dangerous or high-risk behaviour likely to cause serious injury or death
#2.4 Self-harm, suicide, and eating disorders
- Promotion, encouragement, or glorification of suicide or self-harm
- Instructions for self-harm or suicide, or graphic depiction of either
- Content promoting or instructing eating-disorder behaviour or harmful dieting
#2.5 Sexual content
- Explicit sexual acts, or content intended to cause sexual arousal
- Explicit or sexualized nudity
- Pornography, and pay-per-view or subscription adult content
- Tools, techniques, or instructions for generating or simulating nudity from an image
- AI-generated or digitally altered content depicting an identifiable person as nude or sexualized
- Non-consensual intimate imagery, including synthetic or manipulated media, and threats to distribute it
- Solicitation or promotion of sexual services, escort services, or sex trafficking
#2.6 Deception and impersonation
- Fraudulent schemes, fake giveaways, fake investment offers, and deceptive commercial practices
- Phishing in any form, including fake sign-in pages and pages designed to collect credentials, payment details, or other sensitive information
- Impersonating a person or organization you do not represent
- Reproducing a known commercial website using its real name, branding, or logos. We treat this as impersonation rather than as a copyright matter, and we may remove it without waiting for a complaint from the rights holder
- Deepfakes and manipulated media that falsely portray a real person, including fabricated political endorsements
- False or misleading information concerning public safety, emergencies, natural disasters, or medical treatment for serious illness
#2.7 Private information
- Publishing or distributing another person's private information — home address, telephone number, identity documents — without their consent
- Publishing, distributing, or trafficking in another person's passwords or account credentials
- Soliciting others to locate or reveal private information about a person
#2.8 Illegal and regulated goods and services
- Trade in, promotion of, or instructions for obtaining controlled substances, unlicensed weapons, counterfeit goods, or stolen property
- Offering gambling, financial services, or other regulated services without the licences or approvals they require
- Falsely offering financial services, including fraudulent wallets, payment services, or banking
- Content facilitating or advertising human exploitation
#2.9 Malicious code and intellectual property
- Malware, exploits, or malicious code, and command-and-control infrastructure
- Content infringing or misappropriating any copyright, trademark, patent, trade secret, right of publicity, or other proprietary right
#2.10 What remains permitted
The categories above are aimed at content that promotes, facilitates, or depicts the conduct described. They are not intended to prohibit:
- Documentary, educational, journalistic, and research content, including material about child safety, self-harm, extremism, or cybersecurity, provided it does not include graphic depictions or usable instructions;
- Criticism, commentary, and awareness-raising, including about the subjects above;
- Fiction and artistic work, provided it complies with the other categories and, where it could be mistaken for a real depiction of a real person, is clearly identified as fictional or synthetic;
- Lawful adult products and businesses — retailers of adult products, publishers of adult literature, and similar — provided the site itself complies with Section 2.5; and
- AI companion and conversational products, provided they comply with Section 2.5 and every other section of this Policy.
Section 2.2 has no exceptions of any kind.
Where we are uncertain whether content falls inside an exception, we may ask you about it before acting.
#3. Prohibited conduct
You may not:
- probe, scan, or test the vulnerability of the Services or any system or network, or breach or circumvent any security or authentication measure;
- access any account, tenant, data, or resource you are not authorized to access;
- interfere with any other customer's use of the Services, or with the integrity or performance of the Services;
- reverse engineer, decompile, or attempt to derive the source code or underlying ideas of the Services, except where that restriction is unenforceable by law;
- resell, sublicense, rent, or otherwise make the Services available to a third party except as expressly permitted by your agreement with us;
- use the Services to build a substantially similar or competing product;
- create accounts by automated means, create accounts to evade a suspension or a usage limit, or register accounts using disposable or misappropriated email addresses; or
- remove, obscure, or alter any proprietary notice in the Services.
#4. Outbound requests to third-party systems
Workflows make outbound HTTP and gRPC requests, on a schedule or on request, using credentials you store with us. Those requests originate from our infrastructure and carry our reputation. Accordingly, you may not use the Services to:
- send requests to any system you are not authorized to access, or in a manner that violates that system's terms of service, robots directives, or API terms;
- circumvent, or assist anyone in circumventing, a third party's rate limits, IP-based access controls, authentication, geographic restrictions, or other technical protections;
- place an undue burden on any third party's website, API, network, or infrastructure, including through denial-of-service traffic, load testing you are not authorized to conduct, or high-concurrency request patterns;
- conduct bulk scraping, harvesting, or extraction of data you do not have the right to collect;
- operate the Services, in whole or in substantial part, as a general-purpose proxy, relay, VPN, tunnel, or open gateway to route, forward, anonymize, or disguise the origin of network traffic. This does not prohibit outbound requests that are integral to an application or automation you have built on the Services; it prohibits using us as network infrastructure for traffic that is not; or
- send unsolicited bulk email or messages, or facilitate their sending.
You represent that you are authorized to use every credential you store with us and to make every request your workflows make with it.
#5. Fetching remote content
The Services will retrieve content from a URL you specify and store it on our infrastructure. You may not instruct the Services to fetch content that you do not have the right to copy, store, and publish, and you may not use this capability to retrieve content from systems you are not authorized to access. Content you cause us to fetch is Customer Content, and you are responsible for it exactly as if you had uploaded it yourself.
#6. Published pages, hostnames, and namespaces
Content you publish is served from hostnames we operate, including
*.tessryx.app, *.tessryxusermedia.com, and *.tessryxuserdata.com, and from
custom domains routed through our infrastructure. You may not:
- publish phishing pages, credential-harvesting forms, or any page designed to deceive a visitor about who operates it;
- impersonate Tessryx, suggest that Tessryx endorses or operates your site, or publish content at a Tessryx-operated hostname that a visitor would reasonably read as coming from us;
- publish files at reserved or well-known paths in a manner that misrepresents the security contacts, ownership, or policies applicable to a Tessryx hostname;
- register, hold, or traffic in slugs, tenant names, subdomains, or other namespace entries for resale, or squat on names associated with third parties; or
- claim or attempt to claim a custom domain you do not control.
You are responsible for the DNS records you create to route a custom domain to us, and for removing them when you stop using that domain. Records left pointing at our infrastructure after a domain is removed are your responsibility.
#7. Sign-in and visitor identity
If you gate a page behind Tessryx sign-in, you may not:
- use sign-in primarily to collect, enumerate, or build a record of Tessryx accounts rather than to provide the gated experience;
- present a sign-in wall in a way that misrepresents what a visitor is signing in to, or who operates the site; or
- operate multiple sites under materially unrelated identities for the purpose of linking visitors across them without disclosing to those visitors that the sites share an operator.
Where you collect a name, email address, or other personal information from a visitor yourself, you are the controller of that information. You must provide your own privacy notice and handle requests about it directly.
#8. Sensitive and regulated data
The Services are not designed for, and are not certified for, regulated data. You may not submit to the Services, or cause the Services to process:
- protected health information subject to HIPAA;
- cardholder data subject to PCI DSS;
- government-issued identification numbers, financial account numbers, or biometric identifiers;
- personal information of children under 13, or under the applicable age of digital consent in the visitor's jurisdiction; or
- data subject to export control regulations, including ITAR.
Tessryx is not a HIPAA business associate and is not a payment card processor. The Services are neither HIPAA nor PCI DSS compliant. We have no liability under any agreement with you for data of the kinds listed in this section, notwithstanding anything to the contrary in that agreement.
#9. Language models and AI
Workflows can call a language model using an API key you supply. Your relationship with that model provider is your own; we are not a party to it.
You must comply with the usage policies of any model provider you configure. You may not use the Services to:
- generate content prohibited by Section 2;
- generate content that is presented as human-authored where doing so is deceptive or unlawful;
- generate synthetic media depicting a real person without their consent;
- produce content for use in electoral campaigning, or in any application classified as high-risk under the EU AI Act, without independently satisfying the obligations that apply;
- provide medical, legal, or other regulated advice as a substitute for a licensed professional; or
- develop weapons, including chemical, biological, radiological, or nuclear weapons.
You are responsible for output your workflows generate and publish. We make no representation that model output is accurate, lawful, or fit for any purpose.
#10. Connected AI clients
You may connect AI assistants, agents, and other clients to your workspace through our MCP interface or our API. If you do:
- you are responsible for what that client does with your credentials, including anything it creates, modifies, deletes, or publishes;
- you must scope its access to what it needs, and revoke access you no longer use; and
- where your workspace holds personal information about other people — visitors, members, or your own customers — you are responsible for deciding whether disclosing it to that client's operator is consistent with your obligations to them.
You may not connect a client in order to circumvent any limit, restriction, or control in this Policy or in the Services.
#11. Platform integrity and limits
The Services enforce execution budgets, concurrency ceilings, schedule frequency floors, write rate limits, storage and bandwidth caps, and other per-tenant resource limits. You may not circumvent, or attempt to circumvent, any of them, including by distributing work across accounts. You may not use the Services for cryptocurrency mining, distributed computing unrelated to your application, or as a storage or distribution point for data obtained without authorization.
#12. Third-party infrastructure policies
The Services run on infrastructure operated by third parties, including Amazon Web Services and Cloudflare. Your use of the Services must comply with those providers' acceptable use policies, as they may be updated. A violation of an upstream provider's policy is a violation of this Policy.
#13. Enforcement
Violation of this Policy is a material breach of your agreement with us.
We may investigate suspected violations, and we may remove or disable access to content, restrict functionality, suspend an account, or terminate an account — immediately and without prior notice where we reasonably believe the conduct is unlawful, poses a security or integrity risk, exposes us to liability, or threatens harm to a third party. Where circumstances allow, we will give notice and an opportunity to cure.
We may report unlawful activity to law enforcement and to relevant authorities, and we will report apparent child sexual abuse material to the National Center for Missing & Exploited Children as required by law.
We are not obligated to monitor Customer Content, and no enforcement action we take or decline to take creates a duty to take any other action.
#14. Reporting a violation
Email abuse@tessryx.com with the URL or resource, a description of the conduct, and how we can reach you.
Copyright infringement claims are handled separately under our DMCA Policy and should be sent to our designated agent at dmca@tessryx.com.
Security vulnerabilities should be reported to security@tessryx.com. Content, workflows, and pages authored by our customers are outside the scope of our vulnerability disclosure program; report those to the operator of the site in question.
#15. Changes
We may update this Policy by posting a revised version, effective on posting. If a change materially expands the restrictions applicable to you, we will make reasonable efforts to notify you in advance.
Questions about this Policy: legal@tessryx.com
Tessryx LLC, 8605 Santa Monica Blvd #347695, West Hollywood, CA 90069