What this covers
This policy applies to everything routed through ModelBeat: the managed cloud endpoint, the console, and any licensed deployment where traffic reaches our managed endpoint. It applies to you, to your team, and to your end users. You are responsible for their use of the service as if it were your own.
It sits underneath the Terms of Service, which govern. Nothing here narrows them.
The provider policies flow through
ModelBeat routes to third party model providers. Each provider's own usage policy applies to the requests it serves, in addition to this one. A use that is permitted here but prohibited by the provider that ends up serving your request is still a violation, and we cannot route around it.
Routing is a per request judgement, so which provider serves you can change. If your use case sits close to a provider's line, do not rely on routing to keep you on the permissive side of it.
Which providers we use is on our sub-processor list, and it is also available on request.
Illegal content and conduct
The four sections that follow set out what you and your end users must not do with the service. They cover what you send, what you generate, and what you do with the output.
- Break the law, or infringe anyone's rights.
- Generate, solicit or distribute child sexual abuse material.
- Produce content that sexualises minors in any form, whether or not it depicts a real person.
- Generate intimate imagery of a real person without their consent.
- Facilitate trafficking, terrorism, or violent extremism.
- Produce material designed to defraud, including phishing content, false identity documents, or forged financial instruments.
Harm to people
- Harass, threaten, defame, or incite violence against a person or a group.
- Generate content designed to demean a person or a group on the basis of a protected characteristic.
- Provide instructions for self harm, or content that encourages it.
- Provide operational instructions for weapons capable of mass casualty: chemical, biological, radiological, nuclear, or high yield explosive.
- Impersonate a real person or organisation in a way designed to deceive.
Harm to systems
- Reach another customer's data, or attempt to.
- Exceed the scope your credentials grant.
- Attack, probe or degrade the platform, its providers, or the people running it.
- Generate malware, ransomware, or exploit code intended for unauthorised use.
- Work around rate limits, billing, safety guardrails, or the routing policy in force on your account.
Good faith security research is welcome and has a route of its own. Write to hello@neuralarc.ai before you start rather than testing under this policy.
Misuse of the service itself
- Resell raw access to the gateway as a substitute for a provider account, unless we have agreed to it in writing.
- Use the service to build a competing routing product, or to benchmark it for publication without our agreement.
- Create multiple accounts in order to claim promotional credit more than once, or to evade a suspension, a rate limit or a spend cap.
- Automate the creation of accounts.
Data you must not send us
Some categories are prohibited because the service is not built to receive them. Sending them creates risk for you as much as for us.
- Payment card numbers
- Payments are handled entirely by Stripe and card data never reaches our systems. Sending a card number through the gateway puts it somewhere it was never designed to be. This one is absolute.
- Credentials and secrets
- API keys, passwords, private keys. If you send one, treat it as compromised and rotate it.
- Special category personal data
- Health, biometrics, genetics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation. Not prohibited outright, but send it only if you have a lawful basis and have told us, so that the Data Processing Agreement and the routing residency rules can account for it. Do not send it by accident.
- Data about children
- The service is built for businesses and developers and is not designed for data about people under sixteen.
Regulated and high risk uses
Some uses are lawful but carry obligations that fall on you, as the person deploying the system. We are not in a position to discharge them for you, and routing does not change who is responsible.
- Do not make fully automated decisions with legal or similarly significant effects on people, in employment, credit, housing, insurance, education, benefits or immigration, without meaningful human review and the disclosures the law requires.
- Do not use the service for biometric identification, for inferring emotion in workplace or education settings, or for social scoring. These are prohibited or high risk practices under the EU AI Act.
- Do not present model output as professional advice, medical, legal or financial, without a qualified human in the loop.
- Tell your own users when they are interacting with an AI system, where the law requires it.
How we enforce this
We would rather fix a problem than close an account.
Where the issue is not urgent, we will tell you what we have seen, give you a reasonable opportunity to put it right, and only then restrict the account. Most violations turn out to be a misconfigured application rather than an intent to misuse the service, and they are resolved by an email.
Where the issue is urgent, meaning ongoing harm, an active attack, illegal content, or a legal obligation on us to act, we will suspend first and tell you immediately afterwards.
Depending on the severity we may contact you, apply a rate limit or a spend cap, disable a key, suspend the account, or close it. Where the law requires it we will preserve records and cooperate with lawful requests.
If you think we have got it wrong, reply to the notice. A suspension is reversible and we will look again.
Reporting abuse
If you believe someone is using ModelBeat in breach of this policy, write to hello@neuralarc.ai with the word "abuse" in the subject line. Tell us what you saw and when. You do not need to be a customer to report something.
Security vulnerabilities have their own process. Please use that rather than this one.
Changes
We will update this policy as the service and the law change. Where a change materially affects what you may do, we will give notice before it takes effect. The date at the top of this page is when it last changed.
Contact
Questions about this policy go to hello@neuralarc.ai.