Acceptable Use Policy
Effective Date: September 9, 2026 Last Updated: September 9, 2026
This Acceptable Use Policy is part of the Terms of Service and applies to everything you do with the Xantly website, API, and dashboard (the "Service").
The restricted-purposes list is adapted from the 37signals Use Restrictions Policy, published free to use under CC BY 4.0. The AI-specific restrictions are the ones you already agreed to in Sections 2.1 of the Cloud Service Standard Terms and 1.2 of the AI Addendum, restated here so they are easy to find.
Restricted purposes
When you use the Service, you acknowledge that you may not:
- Collect or extract information or user data from accounts which do not belong to you.
- Circumvent, disable, or otherwise interfere with security-related features of the Service.
- Trick, defraud, or mislead us or other users, including by making false reports or impersonating another user.
- Upload or transmit, or attempt to upload or transmit, viruses or any type of malware, or an information collection mechanism.
- Interfere with, disrupt, or create an undue burden on the Service or the networks it connects to. This includes attempting to exceed your rate limits by distributing traffic across accounts.
- Harass, annoy, intimidate, or threaten others, or any of our people engaged in providing any portion of the Service to you.
- Use the Service in a manner inconsistent with any applicable laws or regulations.
Accounts found to be in violation of any of the above are subject to suspension or cancellation without prior notice.
Restrictions carried over from the Terms of Service
From Section 2.1 of the Cloud Service Standard Terms, you will not, and will not allow anyone else to:
- Reverse engineer, decompile, or attempt to discover the source code or underlying ideas or algorithms of the Service, except where the law prohibits that restriction.
- Provide, sell, transfer, sublicense, lend, distribute, rent, or otherwise allow others to access or use the Service. Reselling gateway access is a separate arrangement; talk to us first.
- Remove any proprietary notices or labels.
- Copy, modify, or create derivative works of the Service.
- Conduct security or vulnerability tests on, interfere with the operation of, cause performance degradation of, or circumvent access restrictions of the Service. If you want to test us, email security@xantly.com and we will arrange it.
- Access accounts, information, data, or parts of the Service you are not explicitly authorized to access.
- Use the Service to develop a competing service or product.
- Use the Service with any High Risk Activity, or with any activity prohibited by applicable law.
- Use the Service to obtain unauthorized access to anyone else's networks or equipment.
- Submit content you do not have the rights to submit.
From Section 1.2 of the AI Addendum, you will not, and will not allow anyone else to:
- Use the AI Services for decision-making in a regulated industry or capacity without proper human oversight and review, in compliance with applicable laws and applicable professional ethics, guidelines, and rules.
- Use the AI Services to violate, misappropriate, or otherwise infringe the intellectual property or other proprietary rights of others.
- Falsely state that Output was created by a human.
High Risk Activities
Section 13.20 of the Cloud Service Standard Terms defines a High Risk Activity as any situation where the use or failure of the Service could reasonably be expected to lead to death, bodily injury, or environmental damage. The examples it gives are full or partial autonomous vehicle technology, medical life-support technology, emergency response services, nuclear facility operation, and air traffic control. The Service is not designed, tested, or sold for these, and you must not use it for them.
Prohibited Data
Section 13.27 of the Cloud Service Standard Terms defines Prohibited Data, and Section 3.2 says you must not submit it unless the Key Terms authorize it. Xantly's Key Terms do not authorize it. Do not send us:
- Protected health information regulated by HIPAA.
- Credit, debit, bank account, or other financial account numbers.
- Social security numbers, driver's licence numbers, or other unique and private government ID numbers.
- Special categories of data as defined in the GDPR.
- Other similar categories of sensitive information identified by applicable data protection law.
This applies to the content of your prompts as much as to anything you type into the dashboard. If you need to send data of these kinds through an AI gateway, contact enterprise@xantly.com before you do.
What happens if you break these rules
Section 2.2 of the Cloud Service Standard Terms lets us suspend your access, with or without notice, if you breach the restrictions above or use the Service in a way that materially and negatively affects the Service or others. We will try to tell you first where that is practical, and we will restore your access once the underlying issue is resolved.
Investigating an account is a measure of last resort, and it is governed by the Privacy Policy.
How to report abuse
Report abuse, or a security vulnerability, by emailing security@xantly.com. For abuse, include detail about the account, the content or behaviour you are reporting, and how you found it. We will not disclose your identity to anyone associated with the reported account.
Changes and questions
We may update this policy to address new threats, regulatory requirements, or changes to the Service. Significant changes will be announced by email or in the dashboard.
Questions go to legal@xantly.com.
Attribution
The restricted-purposes list is adapted from the 37signals Use Restrictions Policy by 37signals LLC, used under CC BY 4.0. 37signals does not endorse Xantly. Changes were made: two restrictions that do not apply to an API product were dropped, a rate-limit clause was added, and the AI and data restrictions from the Terms of Service were restated.