Acceptable use
Short version: build a real business. Do not use an autonomous employee to do things you would be ashamed to sign your name to.
This page is written to be read, not to be survived. If anything here is ambiguous, the reading that protects the people affected by your company is the correct one.
What this is for
Starting and running a legitimate business: building a product, researching a market, writing your own marketing, talking to people who agreed to hear from you, and selling something that exists.
What will get your account closed
- Phishing, credential harvesting, or any page that impersonates a real company, person or institution. This is the fastest route to termination, because one such page on a shared domain endangers every other customer's site.
- Fabricated reviews, testimonials, endorsements or credentials — including AI-written reviews presented as a customer's.
- Unsolicited bulk email. Your employee will send mail on your behalf; you are responsible for having a lawful basis to contact each recipient, and every message carries a working opt-out.
- Malware, exploit kits, credential stuffing, denial-of-service tooling, or anything whose purpose is to break into systems you do not own.
- Selling regulated goods or advice you are not licensed to sell — securities, prescription medicines, legal or medical guidance presented as professional counsel.
- Sexual content involving minors, content sexualising real people without consent, or non-consensual intimate imagery. Reported to the relevant authorities, not merely removed.
- Targeted harassment of a private individual, or doxxing.
- Scraping or reselling data in breach of a third party's terms, and using our service to launder that activity through a shared reputation.
- Automating fraud: fake orders, card testing, chargeback abuse, or moving money you are not entitled to.
Why we are strict about the shared domain
Every company hosted with us starts life on a subdomain of one shared domain. If a single page on it is flagged as phishing, browsers can block the entire domain, and every other customer's site goes dark with it, within hours. That is why abuse enforcement here is faster and less forgiving than you might expect from a young product — the cost of being slow is borne by people who did nothing wrong.
How we enforce it
For clear-cut abuse — phishing, malware, illegal content — we disable the page or the company immediately and tell you why. For anything ambiguous we contact you first and give you a chance to explain or fix it, because an autonomous employee can do something you did not intend, and we would rather know which of those happened. Repeat or deliberate abuse ends the account.
You are responsible for what it does
Your employee acts on your instructions and under permissions you enable, so its actions are yours in the same way an assistant's would be. That is why irreversible actions wait for your approval, why the spend ceiling is a hard limit, and why every action is receipted: so that "I did not know" is never the honest answer.
Reporting abuse
If you have found something hosted by us that breaks these rules, tell us and we will act. Include the URL. We would rather hear it from you than from a browser blocklist.