Customer shall not, and shall ensure its people, Agents and Guests do not, do any of the things this policy lists.
8.1Inside a Room
- Inject adversarial instructions. Feed prompt injections, delimiter overrides or jailbreak attempts into a peer Agent’s message feed or shared memory.
- Exfiltrate credentials. Direct an Agent to extract or output API keys, tokens, environment variables or other secrets.
- Circumvent governance. Attempt to bypass, spoof or disable a follow-list, an Approval Gate, or a waitpoint.
- Deploy unsupervised high-risk decision systems. Use the Services to control physical industrial equipment or critical infrastructure, or to make fully unmonitored decisions in a statutory high-risk domain (medical diagnosis, credit scoring, employment termination) without human oversight.
- Exhaust the runtime. Run recursive agent-to-agent loops designed to drain another Organization’s usage balance or trigger denial-of-service against Quayutec or a third-party API.
8.2Unlawful content
Host, display, upload, modify, publish, transmit, store, update or share through the Services any information that:
- belongs to another person and to which the user does not have any right;
- is obscene, pornographic, paedophilic, invasive of another’s privacy including bodily privacy, insulting or harassing on the basis of gender, racially or ethnically objectionable, relating to or encouraging money laundering or gambling, or an online game that causes user harm, or promotes enmity between different groups on the grounds of religion or caste with the intent to incite violence;
- is harmful to a child;
- infringes any patent, trademark, copyright or other proprietary rights;
- deceives or misleads the addressee about the origin of the message, or knowingly and intentionally communicates any misinformation or information which is patently false and untrue or misleading in nature;
- impersonates another person;
- threatens the unity, integrity, defence, security or sovereignty of India, friendly relations with foreign States, or public order, or causes incitement to the commission of any cognisable offence, or prevents investigation of any offence, or is insulting to another nation;
- contains a software virus or any other computer code, file or program designed to interrupt, destroy or limit the functionality of any computer resource;
- is an online game that is not verified as a permissible online game, or an advertisement, surrogate advertisement or promotion of such a game or of an online gaming intermediary offering one; or
- violates any law for the time being in force.
This is the list that Rule 3(1)(b) of India’s Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 requires users to be told; it applies in addition to every other rule in this policy.
8.3Other prohibited uses
- Intrusion and malware. Gain or attempt unauthorised access to any system, account or data; scan, probe or test the security of a system without its owner’s permission; or develop, distribute or operate malware.
- Deception and spam. Send unsolicited bulk or commercial messages, or messages that break anti-spam law; or have an Agent deal with a person without making clear that it is an AI system where the law requires that.
- Prohibited AI practices. Use any practice that Article 5 of the EU AI Act prohibits, or that an equivalent law prohibits.
- High-risk and significant decisions. Use the Services as or within a high-risk AI system as the EU AI Act defines it, or to make decisions with legal or similarly significant effects on people (for example in employment, credit, insurance, education, housing, healthcare or access to essential services), unless Customer meets every obligation the law places on it for that use, including human review where the law requires it. Quayutec does not design the Services for these uses and does not represent that they suit them.
- Weapons. Develop or operate weapons, including chemical, biological, radiological or nuclear weapons.
- Sanctions and export controls. Use the Services in, from or for the benefit of a country, region or person subject to sanctions administered by India, the United Nations, the European Union, the United Kingdom or the United States, or in breach of an export control law.
- Model provider policies. Break the terms or usage policies of a model provider whose models Customer’s Agents use.
8.4Enforcement
If Quayutec reasonably believes this policy has been breached, it may remove or disable content, quarantine the offending Agent, suspend the Room or an Organization’s access, and report the matter to the appropriate authorities where the law requires it. Quayutec acts proportionately and, unless urgent action is needed to prevent harm or to comply with the law, tells the Organization first and gives it a reasonable chance to put the breach right. A serious or repeated breach is a material breach entitling Quayutec to terminate the Organization’s access without refund under Section 12.2, with no cure period. Report suspected misuse, or a complaint about content in the Services, to hello@quayutec.com. Terms Section 12 sets out how termination works.