Acceptable Use Policy

Effective August 30, 2026Version 1.0

This Acceptable Use Policy (the "Policy") governs use of the services provided by Tessryx LLC ("Tessryx," "we," "us," or "our"), including the Tessryx application, APIs, MCP server, hosted infrastructure, and content served through the Services (collectively, the "Services").

This Policy applies to you and to anyone you authorize to access or use the Services through your account or workspace. You are responsible for the acts and omissions of your Authorized Users, agents, and others who use the Services through credentials or access you provide, to the extent provided in your agreement with Tessryx. You are also responsible for maintaining reasonable controls over sites, applications, workflows, and endpoints you operate through the Services.

This Policy does not make you responsible for independent conduct of unaffiliated public visitors merely because they access a site or application you operate.

Capitalized terms not defined here have the meanings given in the agreement governing your use of the Services. Suspected violations may be reported to abuse@tessryx.com.

#1. Scope of This Policy

Tessryx provides more than content storage. Customers can create workflows that execute on Tessryx infrastructure, make outbound network requests using customer-provided credentials, retrieve remote content, communicate with third-party APIs and AI providers, and serve pages and API routes through Tessryx-operated infrastructure. This Policy applies both to content and to the ways those capabilities are used.

Tessryx does not undertake a general obligation to monitor, review, or screen Customer Content or customer-operated sites, applications, workflows, or endpoints. We may investigate or review content or activity where reasonably necessary to enforce this Policy, protect the Services or third parties, respond to reports, or comply with applicable law. Taking action in one circumstance does not create a general duty to monitor or a duty to take the same action in another circumstance.

#2. Prohibited Content

You may not use the Services to create, store, process, publish, transmit, distribute, or serve content prohibited by this Section. Section 2.10 describes legitimate contexts that remain permitted and should be read together with the applicable restrictions.

#2.1 Unlawful Content

You may not use the Services for content that is unlawful under applicable law or that materially facilitates, solicits, or instructs unlawful activity.

#2.2 Child Safety

You may not use the Services for content that sexually exploits or abuses children, constitutes child sexual abuse material, sexualizes minors, or promotes, facilitates, or solicits the sexual exploitation or abuse of children. This prohibition applies to real, AI-generated, synthetic, fictional, and illustrated material to the extent prohibited by this Policy or applicable law.

#2.3 Violence, Harassment, Hatred, and Dangerous Acts

You may not use the Services to threaten or incite serious violence; promote, materially support, or recruit for terrorist, violent extremist, criminal, or other organizations engaged in organized violence where prohibited by law or where the content materially facilitates violent activity; engage in targeted harassment, intimidation, stalking, or bullying; or promote hatred, dehumanization, discrimination, or violence against a person or group based on a characteristic protected by applicable law.

The Services also may not be used to promote cruelty toward animals or to encourage, facilitate, or provide actionable instructions for dangerous conduct creating a substantial risk of serious physical injury or death.

#2.4 Self-Harm, Suicide, and Eating Disorders

You may not use the Services for content that promotes, encourages, or glorifies suicide or self-harm; provides actionable instructions for suicide or self-harm; or promotes, encourages, or provides actionable instructions for eating-disorder behavior or similar conduct reasonably likely to cause serious physical harm.

#2.5 Sexual Content

You may not use the Services to provide pornography, explicit depictions of sexual acts, explicit or sexualized nudity, or content primarily intended to cause sexual arousal. This prohibition includes pay-per-view and subscription-based pornographic content.

You also may not use the Services to create or facilitate non-consensual intimate imagery; generate or simulate nudity involving an identifiable real person without authorization; depict an identifiable real person as nude or engaged in sexual conduct without that person's consent; threaten to create or distribute such material; or solicit, facilitate, or promote prostitution, sexual services, or sex trafficking.

#2.6 Deception, Fraud, and Impersonation

You may not use the Services for fraud, phishing, credential harvesting, fake sign-in pages, fraudulent investment or commercial schemes, or other activity designed to materially deceive another person.

You may not impersonate a person or organization you do not represent or reproduce or materially imitate a third party's website, branding, identity, or interface in a manner intended or reasonably likely to deceive users concerning the identity, affiliation, sponsorship, or source of a site or service.

Deceptive synthetic or manipulated media that materially misrepresents a real person as having said, done, or endorsed something they did not is prohibited where the context does not reasonably make clear that the material is fictional, satirical, or synthetic. Materially false or deceptive information concerning emergencies, public safety, or medical treatment is also prohibited where it creates a reasonably foreseeable risk of serious physical harm.

Tessryx may treat deceptive impersonation as a violation of this Policy independently of whether the conduct also gives rise to an intellectual property claim.

#2.7 Private Information

You may not publish, distribute, sell, or traffic in another person's sensitive private information without authorization or another lawful basis where doing so is reasonably likely to facilitate harm, fraud, harassment, or identity theft. This includes non-public authentication credentials, identity documents, financial account information, and similar sensitive information.

You also may not solicit or coordinate efforts to unlawfully locate, obtain, or reveal another person's private information.

#2.8 Illegal and Regulated Goods and Services

You may not use the Services to unlawfully offer, sell, distribute, or facilitate the acquisition of controlled substances, weapons, counterfeit goods, stolen property, or other prohibited goods, or to provide actionable instructions for unlawfully obtaining or trafficking in them.

You may not offer or facilitate gambling, financial, medical, or other regulated services without licenses, registrations, approvals, or other authorizations required by applicable law. Fraudulent financial services, wallets, payment services, banking services, investments, human trafficking, and other unlawful human exploitation are prohibited.

#2.9 Malicious Code and Intellectual Property

You may not use the Services to deploy or distribute malware, credential-stealing software, malicious code, command-and-control infrastructure, or exploits for malicious, unauthorized, or harmful purposes.

You also may not use the Services for content that infringes, misappropriates, or otherwise violates another person's copyright, trademark, patent, trade secret, right of publicity, or other intellectual property or proprietary right. Copyright infringement notices are handled separately under the Tessryx DMCA Policy.

#2.10 Legitimate Uses

The preceding restrictions are not intended to prohibit legitimate documentary, educational, journalistic, scientific, safety, or research material merely because it discusses sensitive subjects. Legitimate criticism, commentary, news reporting, and awareness-raising are also permitted where they do not themselves promote, facilitate, or materially enable prohibited conduct.

Fiction, satire, parody, and artistic works are permitted subject to the other provisions of this Policy, including restrictions concerning deceptive or non-consensual depictions of real people.

Lawful adult-product businesses and publishers of adult literature may use the Services provided that content served through the Services complies with Section 2.5. AI companion and conversational products are likewise permitted if they comply with Section 2.5 and all other provisions of this Policy.

Nothing in this Section permits content prohibited by Section 2.2. Where context is unclear, Tessryx may request additional information before determining whether content violates this Policy.

#3. Prohibited Conduct

You may not:

  • access or attempt to access an account, tenant, system, data, or resource you are not authorized to access;

  • probe, scan, test, or attempt to compromise the security of the Services or a related system or network without authorization, or circumvent security or authentication measures;

  • interfere with another customer's use of the Services or with the security, availability, integrity, or performance of the Services;

  • reverse engineer, decompile, disassemble, or attempt to derive non-public source code or components of the Services, except to the extent applicable law prohibits that restriction;

  • resell, sublicense, rent, or commercially provide access to the Services except as expressly authorized by your agreement with Tessryx;

  • create or use accounts, workspaces, identities, or automated methods to evade a suspension, enforcement action, or applicable usage restriction;

  • register accounts using misappropriated identities or contact information; or

  • remove, obscure, or alter proprietary notices included in the Services except as expressly permitted.

#4. Outbound Requests and Third-Party Systems

Workflows can make outbound HTTP, gRPC, and other supported requests, including scheduled and event-driven requests, using credentials customers configure. Because those requests originate through Tessryx infrastructure, they may affect Tessryx and third parties even when the destination is outside the Services.

You may not use the Services to:

  • access or send requests to a system you are not authorized to access, or materially circumvent authentication, rate limits, IP-based controls, geographic restrictions, or other technical protections;

  • impose an unreasonable or unauthorized burden on third-party systems, including through denial-of-service traffic, unauthorized load testing, or abusive high-concurrency activity;

  • conduct bulk scraping, harvesting, or extraction where you lack authorization or another lawful right to collect or use the applicable data;

  • operate Tessryx primarily as a general-purpose proxy, relay, VPN, tunnel, or open gateway for routing, forwarding, anonymizing, or disguising unrelated network traffic; or

  • send unsolicited bulk email or messages or materially facilitate their transmission.

The restriction on general-purpose network routing does not prohibit outbound requests reasonably integral to an application, workflow, or automation built using the Services.

You must have the rights, permissions, and authorizations necessary to use credentials you configure with Tessryx and to make requests initiated through those credentials.

#5. Fetching Remote Content

The Services may retrieve content from URLs or other remote resources at your instruction and store or process that content through Tessryx infrastructure.

You may not instruct the Services to retrieve content from a system you are not authorized to access or to copy, store, process, or publish content where you lack the rights or lawful basis necessary for the applicable use.

Content you cause Tessryx to retrieve is treated as Customer Content and is subject to the same responsibilities as content you submit directly.

#6. Published Pages, Hostnames, and Domains

Customer Content may be served from Tessryx-operated hostnames, including *.tessryx.app, *.tessryxusermedia.com, and *.tessryxuserdata.com, as well as custom domains routed through Tessryx infrastructure.

You may not use a Tessryx-operated hostname or custom-domain functionality for phishing, credential harvesting, deceptive impersonation, or other conduct designed to mislead visitors concerning who operates a site. You may not falsely suggest that Tessryx sponsors, endorses, authors, or operates customer-created content.

You may not use reserved or well-known paths to misrepresent security contacts, ownership, authorization, or policies applicable to Tessryx infrastructure. You also may not register or hold Tessryx namespace entries primarily for resale or abusive cybersquatting, or claim a custom domain you do not control or are not authorized to use.

You are responsible for maintaining DNS records associated with custom domains you connect to the Services and for removing or updating those records when you stop using the applicable domain with Tessryx.

#7. Sign-In and Visitor Information

If you allow or require visitors to use Sign in with Tessryx, you may not use the sign-in functionality primarily to enumerate, profile, or build a database of Tessryx accounts rather than to provide the applicable site or application experience. You also may not misrepresent what a visitor is signing in to or who operates the site.

You may not operate multiple sites under materially unrelated identities for the purpose of linking or tracking visitors across them without appropriately disclosing the common operator or relationship.

Where you determine the purposes and means of collecting or using personal information from visitors, members, customers, or other individuals through a site or application you operate, you are responsible for complying with applicable privacy and data protection laws. Depending on the circumstances, this may include providing required privacy notices, establishing an appropriate legal basis, obtaining required consents, honoring applicable privacy rights, and maintaining reasonable access and security controls.

Tessryx processes Customer Personal Data on your behalf as described in the Data Processing Addendum.

#8. Sensitive and Regulated Data

Unless Tessryx expressly agrees otherwise in a separate written agreement, the Services are not designed or authorized for regulated or highly sensitive data requiring specialized legal, contractual, or technical safeguards beyond those expressly provided for the Services.

You may not submit to the Services, or cause the Services to store or process:

  • protected health information subject to HIPAA or other health information subject to specialized health-data requirements;

  • payment card data that would require Tessryx to act as a payment card processor or assume PCI DSS obligations applicable to processing cardholder data;

  • government-issued identification numbers, financial account or bank account numbers, or biometric identifiers used to uniquely identify an individual;

  • Personal Data concerning children under 13; or

  • data subject to ITAR or other export-control requirements that the Services are not expressly authorized to process.

Tessryx may identify additional categories of regulated or highly sensitive data as prohibited where the Services are not designed or authorized to process them.

Tessryx is not a HIPAA business associate and does not agree to act as one unless Tessryx expressly enters into a written Business Associate Agreement. Tessryx does not provide the Services as a payment card processing service and does not agree to assume PCI DSS obligations applicable to a customer's processing of cardholder data.

You are responsible for determining whether the Services are appropriate for information you submit or process and for complying with laws applicable to your collection and use of that information.

Submitting prohibited data does not expand the scope of the Services, modify Tessryx's role, create a contractual obligation for Tessryx to satisfy a specialized regulatory regime, or constitute Tessryx's agreement to process that data.

To the fullest extent permitted by applicable law, Tessryx is not responsible for claims, losses, or liabilities arising from your submission or processing of data prohibited by this Section. Nothing in this Section excludes or limits liability to the extent it cannot lawfully be excluded or limited.

#9. Artificial Intelligence and Language Models

Customers may configure workflows to communicate with third-party AI or language model providers using accounts, subscriptions, credentials, or connections supplied or authorized by the customer. Tessryx does not operate those third-party models, and your relationship with the applicable provider is governed by that provider's terms and policies.

You are responsible for complying with the terms and usage policies applicable to the AI providers you choose to use. You may not use AI through the Services to:

  • generate content prohibited by Section 2;

  • create or distribute deceptive or non-consensual synthetic media involving an identifiable real person in violation of this Policy or applicable law;

  • use AI-generated or manipulated content in violation of applicable election, advertising, disclosure, impersonation, or similar laws;

  • operate an AI system subject to specialized regulatory requirements, including requirements applicable to high-risk AI systems, without independently determining and satisfying the requirements applicable to your use;

  • provide regulated professional services where applicable law requires licensure, supervision, review, or another authorization you do not have; or

  • develop or materially facilitate the development of chemical, biological, radiological, nuclear, or other weapons in violation of applicable law.

You are responsible for reviewing and determining the appropriateness of AI output generated, used, or published through your workflows. Tessryx does not warrant that output generated by a third-party AI provider is accurate, complete, lawful, non-infringing, or suitable for a particular purpose.

#10. Connected AI Clients and Agents

You may connect AI assistants, agents, and other clients to a workspace through the Tessryx MCP interface or API. You are responsible for authorizing those connections, configuring the scope of access granted, and reviewing actions taken through that authorization.

You should limit access to information and functionality reasonably necessary for the intended purpose and revoke access that is no longer needed. Where a workspace contains personal information relating to visitors, members, customers, or other individuals, you are responsible for determining whether providing the connected client with access to that information is consistent with your legal, contractual, and privacy obligations.

You may not use an assistant, agent, API, or other mechanism to circumvent a restriction, safeguard, usage limit, or enforcement measure imposed by this Policy or the Services.

#11. Platform Integrity and Resource Limits

Tessryx may enforce execution budgets, concurrency limits, schedule-frequency limits, write-rate limits, storage and bandwidth limits, and other controls reasonably designed to maintain the availability, security, and integrity of the Services.

You may not circumvent or attempt to circumvent those controls, including by using multiple accounts, workspaces, identities, integrations, or technical methods for the purpose of evading an applicable limit.

The Services may not be used for cryptocurrency mining, distributed computing unrelated to an application or workload legitimately operated through the Services, or as a storage or distribution point for data obtained without authorization.

#12. Third-Party Infrastructure

The Services rely on infrastructure and services provided by third parties, including Amazon Web Services and Cloudflare. You may not use the Services in a manner that causes Tessryx to violate restrictions applicable to Tessryx's use of that infrastructure or that materially threatens Tessryx's continued access to those services.

Where reasonably practicable, Tessryx will identify the relevant restriction and provide an opportunity to cure before taking action based solely on an upstream provider requirement. Tessryx may take immediate action where reasonably necessary to prevent or address service disruption, a security or legal risk, unlawful activity, or a binding provider requirement.

#13. Enforcement

A violation of this Policy may constitute a material breach of your agreement with Tessryx depending on the nature, severity, frequency, and consequences of the violation.

Tessryx may investigate suspected violations and, where reasonably appropriate, remove or disable access to content, restrict affected functionality, suspend access, or terminate an account in accordance with the Customer Terms.

Tessryx may take immediate action without prior notice where we reasonably believe action is necessary to address unlawful activity, fraud, abuse, a material security or integrity risk, imminent harm, potential liability to Tessryx or third parties, or another circumstance requiring prompt action. Where circumstances reasonably permit, we may provide notice and an opportunity to cure.

We may preserve or disclose information where reasonably necessary to investigate violations, protect the Services or others, comply with applicable law or valid legal process, or enforce our agreements. We may report suspected unlawful activity to appropriate authorities and will make reports concerning apparent child sexual abuse material to the National Center for Missing & Exploited Children where required by applicable law.

Tessryx does not undertake a general obligation to monitor Customer Content. An enforcement action we take, or decline to take, in one circumstance does not create an obligation to take the same or any other action in another circumstance.

#14. Reporting Abuse and Security Issues

Suspected abuse or violations of this Policy should be reported to abuse@tessryx.com. Please identify the relevant URL or resource, describe the conduct, and provide contact information if you would like us to follow up.

Copyright infringement claims are handled separately under the Tessryx DMCA Policy and should be directed to our designated copyright agent at dmca@tessryx.com.

Potential security vulnerabilities affecting Tessryx should be reported to security@tessryx.com. Security issues relating solely to content, workflows, applications, or pages controlled by a Tessryx customer may fall outside Tessryx's vulnerability disclosure process and should ordinarily also be reported to the applicable customer.

#15. Changes to This Policy

Tessryx may update this Policy from time to time to reflect changes to the Services, security or abuse risks, operational requirements, or applicable law.

Unless a different period is required by law or reasonably necessary to address fraud, abuse, security, unlawful activity, or another urgent risk, a change that materially expands the restrictions applicable to existing customers will take effect after reasonable advance notice.

Other changes may take effect when the revised Policy is posted or as otherwise provided in the Customer Terms. The Effective Date above identifies when the current version became effective.

#16. Contact

Questions about this Policy may be directed to legal@tessryx.com. Reports of suspected abuse or Policy violations should be directed to abuse@tessryx.com.

Tessryx LLC
8605 Santa Monica Blvd #347695
West Hollywood, CA 90069