Acceptable Use & User Content Policy
What you may and may not do with Dispatch and its AI agents, the licence you give us to host your content, your responsibility for AI-generated output, and how we moderate and handle reports.
This Acceptable Use & User Content Policy (the “Policy”) is part of the Terms of Service. It applies to everyone who uses Dispatch, including demo visitors, and to all content submitted to or generated in the Service. Capitalised terms not defined here have the meaning given in the Terms.
The short version. Use Dispatch for legitimate work. Don’t use agents to harm people, break the law, deceive, spam or attack systems. You own and are responsible for what you put in and what you approve. Review AI output before you rely on it. Report problems to abuse@asrar.example.
1. What “User Content” means
User Content is everything that users submit to or create in the Service, including card titles and inputs, attachments, comments and mentions, prompts and extra instructions, templates, schedules, custom tool definitions, integration settings, and the artifacts and messages AI agents produce for you (“AI Output”). User Content is Customer Content under the Terms.
2. Your responsibilities
You are responsible for your User Content and for the actions you approve. In particular, you confirm that:
- you own your User Content or have all rights, licences and permissions needed to submit it and to have agents process it;
- where User Content contains personal data about other people, you have a lawful basis to process it and have given any notice the law requires;
- you will review AI Output, citations and every proposed side-effecting action before relying on, publishing or approving it;
- you will not use the Service in a way that breaks the law or this Policy, and you will make sure members of your workspace do the same.
3. Prohibited content
You must not submit, generate, store or distribute through the Service content that:
- is illegal, or promotes or facilitates illegal activity;
- sexually exploits or endangers minors in any way (we report such content to the competent authorities);
- harasses, threatens, bullies or incites violence against any person or group, or promotes hatred based on protected characteristics;
- promotes terrorism or violent extremism;
- infringes intellectual-property, privacy, publicity or other rights of others, including uploading documents you have no right to share;
- contains personal data you are not permitted to process, or special-category data (health, biometrics, religion, political opinions…) without a clear lawful basis;
- is deceptive: impersonates a person or organisation, misrepresents your identity or affiliation, or is designed to mislead (including fabricated reviews, fake news or deepfakes presented as real);
- contains malware, exploits or code designed to damage or gain unauthorised access to systems;
- is sexually explicit content involving real people without their consent.
4. Prohibited uses of agents, tools and integrations
You must not use the Service, its agents or its tools to:
- Send unsolicited communications — bulk or commercial email, messages or posts without the recipients’ consent, or in breach of anti-spam laws;
- Access systems without authorisation — scan, probe, attack or test the security of systems you do not own or have permission to test; attempt to reach private networks or internal services through the fetch or custom HTTP tools;
- Scrape unlawfully — collect data in breach of a website’s terms, its robots rules or the law, or build datasets of personal data about individuals;
- Bypass safeguards — circumvent approval gates, usage or rate limits, plan restrictions, authentication or tenant isolation, or chain requests to avoid them;
- Make high-stakes decisions without human review — use AI Output as the sole basis for decisions with legal or similarly significant effects on people (employment, credit, housing, insurance, education, access to essential services, law enforcement);
- Provide regulated advice — present AI Output as professional medical, legal, financial or tax advice without review by a qualified professional;
- Cause serious harm — plan or assist with weapons, dangerous substances, critical-infrastructure attacks, self-harm, or covert surveillance and tracking of individuals;
- Manipulate — generate disinformation, political propaganda at scale, or content intended to manipulate elections or public health;
- Build competing models — use the Service or AI Output to develop foundation models that compete with our model providers, where their terms forbid it;
- Abuse the Service — overload it, interfere with other customers, resell it without our written permission, or reverse engineer it except as permitted by law.
5. Licence to host and process User Content
You keep ownership of your User Content. To run the Service, you grant Asrar Studio SARL a worldwide, non-exclusive, royalty-free licence to host, store, reproduce, process, transmit, display and adapt User Content, solely to provide, maintain, secure and support the Service for you and your workspace — for example to show a card to your teammates, send inputs to an AI model, run the tools you enabled, render and export artifacts, and keep backups. This licence:
- does not allow us to sell your User Content, to use it for advertising, or to use it to train or fine-tune AI models;
- extends to our subprocessors only as needed to provide the Service;
- ends when the User Content is deleted from the Service, subject to backup rotation (35 days) and legal retention obligations.
Content you choose to make public (for example a shared artifact link) may be viewed by anyone with the link until you revoke it.
6. AI-generated output
- You are responsible for how you use AI Output. Agents can be wrong, incomplete or outdated, and can misattribute sources. Check facts and citations before relying on them.
- Label where appropriate. If you publish AI Output, follow the disclosure rules that apply to you (for example transparency obligations for AI-generated content) and do not present it as human-written where that would mislead.
- Approvals are your decision. When you approve a side-effecting action, you authorise it as if you performed it yourself. Read the exact payload shown in the approval sheet before approving.
- No guarantee of uniqueness. Similar prompts can produce similar output for other users.
- Untrusted inputs. Web pages and files processed by agents are treated as data, not instructions. If you notice an agent following instructions embedded in content, report it to security@asrar.example.
7. Moderation and enforcement
We do not pre-screen User Content. We may review content when it is reported to us, when we detect abuse (for example through rate limits, spam signals or automated safety checks on AI requests), or when required by law. Access to Customer Content by our staff is limited, logged and only for support, security or legal reasons.
If we reasonably believe that content or activity violates this Policy, we may, proportionately to the severity:
- warn the user or workspace owner and ask for a correction;
- block a specific run, tool or integration, or remove or restrict the content;
- temporarily suspend an account or workspace;
- terminate an account or workspace for serious or repeated violations;
- report illegal content to the competent authorities where required.
Unless doing so would be unlawful or create a risk of harm, we will tell you what action we took and why, and you can appeal by replying to our notice or writing to legal@asrar.example within 30 days. A different person from the one who made the original decision will review your appeal.
8. Reporting content and abuse
Anyone — user or not — can report content or behaviour that they believe violates this Policy or the law by writing to abuse@asrar.example. Please include:
- the link to the content, workspace or artifact concerned, or enough detail for us to locate it;
- why you believe it is illegal or violates this Policy;
- your name and email address (you may report anonymously, but we may not be able to follow up);
- for intellectual-property claims, identification of the protected work, a statement that you are the rights holder or authorised to act for them, and a statement of good faith.
We acknowledge reports within 72 hours and act on them without undue delay. We do not reveal the reporter’s identity to the person reported, except where required by law. Users whose content is removed following a copyright notice may submit a counter-notice to legal@asrar.example.
9. Security research
We welcome good-faith security research. Report vulnerabilities to security@asrar.example, give us reasonable time to fix them before disclosure, only use accounts you own, and do not access, modify or delete other customers’ data. We will not take legal action against research carried out within these rules.
10. Changes to this Policy
We may update this Policy to address new risks or legal requirements. We will announce material changes at least 30 days in advance (or sooner where required to address a legal or safety issue) and publish every version on the version history page.
11. Contact
Abuse reports: abuse@asrar.example · Legal: legal@asrar.example · Security: security@asrar.example.