Draft — pending counselv0.1Effective Pending
DRAFT — for counsel review. Not legal advice, and not yet in effect.
Acceptable Use Policy
Version 0.1 (draft) · Effective [Effective Date] · [Neivan Legal Entity, Inc.]
This Acceptable Use Policy (the "AUP") governs your use of the Synapse platform, the Synapse Recorder desktop agent, the Jarvis assistant, and related services (collectively, the "Service") provided by [Neivan Legal Entity, Inc.] ("Neivan"). This AUP is incorporated into the Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service.
You are responsible for your own conduct and for the conduct of every Authorized User under your account. Violations may result in suspension, restriction, or termination as described in Section 9 and the Terms of Service.
1. Prohibited Content and Conduct
You must not use the Service to create, store, transmit, or process content, or to take actions, that:
- are unlawful, fraudulent, defamatory, harassing, threatening, or that incite violence;
- exploit or endanger minors, or that constitute child sexual abuse material;
- promote discrimination or harm against people based on a protected characteristic;
- contain malware, or that are designed to disrupt, damage, or gain unauthorized access to any system or data;
- infringe or misappropriate any intellectual property, privacy, publicity, or other rights of a third party; or
- are otherwise harmful, deceptive, or objectionable in a manner that exposes Neivan, the Service, or other customers to legal or reputational risk.
2. No Illegal, Infringing, or Harmful Use
You must use the Service only for lawful business purposes and in compliance with all applicable laws, regulations, and third-party rights, including data-protection, intellectual-property, consumer-protection, export-control, and anti-spam laws. You must not use the Service to violate any law or to enable a third party to do so.
3. Observation, Monitoring, and Recording
The Service includes observation and capture features, including cloud activity-metadata observation, the Synapse Recorder (active-window data, accessibility metadata, and optional redacted screen frames), and teach-by-demonstration capture. These features are consent-gated and subject to redaction and retention controls. You must not:
- enable or use any observation, monitoring, recording, or capture feature without providing all notices and obtaining all consents and authorizations required by applicable law, including workplace-privacy, employee-monitoring, and recording-consent laws (including one-party and all-party / two-party consent requirements);
- use observation or capture to unlawfully surveil, profile, or track employees or other individuals, including covert monitoring where prohibited;
- attempt to disable, weaken, or circumvent redaction, consent gates, retention limits, or transparency notices provided by the Service; or
- direct observation at individuals or systems you are not lawfully entitled to observe.
You are solely responsible for the lawful basis for any monitoring or recording you enable and for honoring any rights of individuals to be informed, to object, or to withdraw consent.
4. Security and Platform Integrity
You must not, and must not permit any Authorized User or third party to:
- probe, scan, or test the vulnerability of the Service or any related system, or breach or circumvent any security or authentication measure;
- access the Service or any data, account, or tenant you are not authorized to access, or attempt to defeat tenant isolation;
- scrape, crawl, harvest, or use automated means to extract data from the Service except through interfaces we expressly provide;
- interfere with or disrupt the integrity or performance of the Service, including by denial-of-service activity or by sending excessive load; or
- reverse engineer, decompile, or attempt to derive source code, models, or underlying components, except to the extent that restriction is prohibited by law.
Report security issues to [[email protected]].
5. AI-Specific Misuse
Because the Service generates and acts on AI Output, you must not:
- use the Service to make or substantially automate prohibited or high-risk decisions about individuals (such as employment, credit, housing, insurance, education, legal status, or access to essential services) without meaningful human review and oversight, and without complying with applicable law;
- present AI Output as professional advice (legal, financial, medical, tax, or otherwise) or as a substitute for a qualified professional;
- submit another person's personal data to the Service without a lawful basis and any required notice or consent for that processing, including processing by third-party model providers acting as sub-processors;
- attempt to use the Service to generate content that violates Section 1, to extract another party's confidential data, or to deceive individuals about whether they are interacting with AI where disclosure is required; or
- attempt to manipulate, jailbreak, or inject instructions to cause the Service or its AI providers to bypass safety, security, or policy controls.
You remain responsible for reviewing AI Output and agent actions before relying on them.
6. Connected-Account Misuse
When you connect tools (such as email, calendar, drive, CRM, or custom APIs) via OAuth or API keys so that agents can read data and take actions on your behalf, you must not:
- connect a system you are not authorized to connect, or grant scopes or keys you are not authorized to grant;
- configure agents to take actions in a connected system that exceed your authorization or that violate that system's terms or applicable law;
- use connected-account access to exfiltrate data for an unlawful purpose, to send unlawful or unsolicited bulk messages, or to impersonate another person or organization; or
- share or expose vaulted credentials or API keys outside the protections the Service provides.
You are responsible for the actions your agents take in connected systems.
7. Rate, Seat, and Usage-Limit Circumvention
You must not:
- exceed or circumvent the seat caps, rate limits, usage caps, or wallet controls of your plan, including by sharing credentials, creating shadow accounts, or splitting usage to evade limits;
- misrepresent your company-size band to obtain a lower subscription tier than your actual usage requires; or
- use automated or other means to obtain a benefit you have not paid for or to defeat metering, billing, or quota controls.
If your usage exceeds your plan, you agree to upgrade or true-up as described in the Billing Terms.
8. Customer Responsibility and Enforcement Cooperation
You must take reasonable steps to ensure your Authorized Users comply with this AUP, and you must promptly address any violation you become aware of. You will cooperate with reasonable requests from Neivan to investigate or remediate suspected violations.
9. Enforcement and Suspension
9.1 Action we may take. If we reasonably believe this AUP has been or is likely to be violated, we may, with or without notice depending on the severity: investigate; remove or disable offending content or configurations; throttle, restrict, suspend, or terminate access (in whole or in part); revoke a connected-account authorization; or take any other action permitted by the Terms of Service or law.
9.2 Emergency action. Where there is a risk of imminent harm to the Service, other customers, or third parties, or a legal obligation, we may act immediately and provide notice afterward where practicable and lawful.
9.3 No waiver. Our failure to enforce any provision is not a waiver, and our remedies under this AUP are in addition to those in the Terms of Service.
This is a first-pass draft for internal review only. It is not legal advice and is not in effect until reviewed and approved by counsel and formally published. Questions: contact [[email protected]].