Acceptable Use Policy
This policy is incorporated into Terms of Service. Breaching it is a breach of those Terms. The Service is operated by GPT LLM ORAGLE Ltd. Liability Co., a Wyoming close limited liability company, registered office 30 N Gould St, Ste N, Sheridan, WY 82801, United States.
1. Why this policy is strict
The Service publishes on your behalf to third-party social platforms using applications and API credentials held by the Company. If one customer abuses a platform, the platform penalises the application, not just that customer. A single spam campaign can suspend the app for every customer at once.
That is why the rules below are enforced actively and why suspension can be immediate.
2. You must
- Comply with all applicable laws, including advertising, consumer protection, marketing, anti-spam, data protection, export control, and sanctions laws.
- Comply with the terms, developer policies, community guidelines, automation rules, and messaging policies of every platform you connect, including Meta (Facebook, Instagram, Threads), TikTok, X, LinkedIn, Google (YouTube and Google Business Profile), Pinterest, Reddit, Mastodon instances, Bluesky, Discord, Telegram, Tumblr, VK, Odnoklassniki, and WordPress hosts.
- Hold the rights, licences, releases, and consents needed for everything you publish, including music, stock media, fonts, likenesses, trademarks, and user-generated content you repost.
- Have documented authority for every account you connect. If you manage a client's account, hold a written mandate.
- Have a lawful basis and, where required, prior consent before sending outbound direct messages, and honour opt-outs immediately.
- Disclose paid partnerships, sponsorships, endorsements, and material connections as the law and the platform require.
- Disclose AI-generated or synthetic content where the law or the platform requires it.
- Keep your account secure, enable multi-factor authentication, and report suspected compromise to
security@oraglegpt.org. - Respect platform rate limits and the Service's own quotas.
3. You must not - content
Do not create, upload, schedule, publish, or store content that:
- Is unlawful, or promotes unlawful activity.
- Is child sexual abuse material, or sexualises minors in any way. This is reported to the relevant authorities and results in immediate, permanent termination.
- Is non-consensual intimate imagery, or sexual content involving a person who has not consented to its distribution.
- Incites or threatens violence, or promotes terrorism, violent extremism, or a designated terrorist organisation.
- Constitutes hate speech, or attacks or dehumanises people on the basis of a protected characteristic.
- Harasses, bullies, stalks, doxes, or targets an individual for abuse.
- Facilitates human trafficking, exploitation, or the sale of prohibited or regulated goods where you lack the required authorisation.
- Infringes copyright, trademark, patent, trade secret, publicity, or privacy rights.
- Is fraudulent, deceptive, or a scam, including phishing, fake giveaways, investment fraud, and "pig butchering".
- Impersonates a person, brand, or organisation, or falsely implies affiliation or endorsement.
- Is synthetic media presented as a genuine recording of a real person or event, including deepfakes used to deceive.
- Contains health, medical, financial, or legal claims that are false, misleading, or that you cannot substantiate.
- Contains election, civic, or public-health disinformation.
- Contains malware, exploits, or links to them.
4. You must not - conduct on connected platforms
- Spam. Bulk unsolicited posting, comment spam, hashtag stuffing, repetitive near-duplicate posting across many accounts, or mass unsolicited direct messaging.
- Inauthentic behaviour. Operating accounts that misrepresent who is behind them, coordinated inauthentic behaviour, sockpuppets, or ban evasion.
- Engagement manipulation. Buying or exchanging followers, likes, views, comments, subscribers, or reviews; engagement pods; vote manipulation; review gating or fake reviews.
- Automation abuse. Automating actions a platform reserves for humans, including automated following, unfollowing, liking, commenting, connection requests, or auto-DMs, where the platform's automation rules prohibit it. Several platforms prohibit automated direct messaging outright.
- Rate-limit evasion. Rotating credentials, accounts, apps, or IP addresses to exceed a platform's limits, or retrying in a way designed to defeat throttling.
- Scraping. Collecting platform data other than through the API scopes you granted, or retaining platform data beyond what the platform permits.
- Reselling platform data. Selling, licensing, or transferring data obtained from a platform through the Service.
- Misusing scopes. Using data obtained under one scope for a purpose the user did not authorise.
- Connecting accounts you do not control or for which your mandate has ended.
- Publishing on behalf of a client after the engagement ends.
5. You must not - conduct against the Service
- Circumvent authentication, authorisation, tenant isolation, quotas, entitlements, or billing.
- Access another tenant's data, or attempt to.
- Probe, scan, or load-test the Service without prior written authorisation from
security@oraglegpt.org. Coordinated vulnerability disclosure is welcome; unauthorised testing is not. - Reverse engineer, decompile, or extract source code, except where mandatory law permits.
- Interfere with the Service or its infrastructure, including denial of service, resource exhaustion, or abuse of retry and webhook mechanisms.
- Use the Service to build a competing product, or to benchmark and publish results without consent.
- Resell or provide the Service to third parties, except under an express reseller or OEM agreement.
- Share credentials or exceed your licensed seat count.
- Use automated means to create accounts, or use the Service through an undisclosed intermediary.
- Upload special category data, health data, payment card data, government identifiers, or data subject to sector-specific regimes such as HIPAA, PCI-DSS, FERPA, or GLBA, unless separately agreed in writing.
6. You must not - misuse of AI features
- Generate content prohibited by section 3.
- Generate synthetic media of a real person without their consent, or use it to deceive.
- Attempt prompt injection, jailbreaks, or extraction of system prompts, credentials, or another tenant's data. The Service applies injection heuristics and blocks and records such attempts.
- Enable autonomous public publishing without a human approval boundary for content in a regulated, health, financial, legal, political, or crisis context.
- Use AI features to generate content at a volume or cadence designed to evade a platform's spam detection.
- Configure an AI provider you are not authorised to send the workspace's data to, or send data across a region boundary your own obligations prohibit.
- Present AI output as human-authored where a law or platform requires disclosure.
You remain responsible for reviewing AI output before it is published. AI output can be wrong, biased, or infringing.
7. Messaging and outbound contact
- Direct messages, review replies, and outbound care messages must comply with the originating platform's messaging policy, including any messaging window, template requirement, or prohibition on promotional content.
- Do not import contact lists you did not lawfully collect, and do not message people who have not consented where consent is required.
- Honour opt-outs, unsubscribes, and blocks immediately and permanently.
- Do not use the Service for cold outreach at scale on platforms that prohibit it.
8. Security research
We welcome good-faith vulnerability reports at security@oraglegpt.org. Please:
- test only against your own tenant;
- do not access, modify, or exfiltrate another tenant's data;
- do not run denial-of-service or physical or social-engineering attacks;
- give us reasonable time to remediate before disclosure.
Safe harbour. We will not pursue legal action, and will not support action by others, against security research that follows the rules above in good faith. We treat such research as authorised testing. We do not currently operate a paid bug bounty, so no monetary reward is offered or implied. We aim to acknowledge a report within 2 business days and to give you a remediation timeline within 10 business days.
9. Enforcement
We may, proportionately to the risk:
- warn you and require remediation;
- remove or quarantine specific content;
- disable a connected account or a specific capability;
- throttle publishing or API access;
- suspend a user, a workspace, or the whole account;
- terminate the agreement;
- preserve evidence and report to law enforcement, a platform, or a regulator where the law requires it or the conduct is serious.
Where practical we give notice and an opportunity to cure. Where the risk to individuals, to the platform relationship, or to the Service is urgent, we act first and notify promptly.
Platform-directed action. If a platform instructs us to remove content, disable a connection, or delete data, we will comply, even if that removes content from your workspace.
Appeals. Email legal@oraglegpt.org within 30 days of an enforcement action with the reference from the notice. Appeals are reviewed by someone who was not involved in the original decision, and we aim to respond within 10 business days. If we uphold the action we will tell you which part of this policy was breached and what, if anything, would let us restore access.
10. Reporting abuse
To report content or conduct on the Service that breaches this policy, email legal@oraglegpt.org with the workspace, the content or account, what rule you believe was broken, and any evidence. To report a security issue, email security@oraglegpt.org. Reports of child sexual abuse material are escalated immediately and are reported to the relevant authorities.
11. Changes
We update this policy as platform rules and law change. The "Last updated" date reflects the current version. Material changes are announced to workspace administrators at least 30 days in advance, unless a platform or a legal requirement forces a faster change.
12. Contact
GPT LLM ORAGLE Ltd. Liability Co.
30 N Gould St, Ste N
Sheridan, WY 82801
United States
Abuse and appeals: legal@oraglegpt.org
Security: security@oraglegpt.org
Privacy: privacy@oraglegpt.org