Acceptable Use Policy

Version 1.0 Effective 18 May 2026 Last updated 10 Aug 2026 EN

Effective from 10 August 2026 - Version 2.2

1. Purpose

This Acceptable Use Policy ("AUP") sets out the content and conduct that are not permitted on ToRun, and how we enforce these rules. It applies to every feature — chat, image, audio, video, translation, workflows, personas, the community, and the marketplace — and to every account (Free, Paid, and bring-your-own-key). It forms part of, and is incorporated into, our Terms of Service.

2. Zero-tolerance content

The following are strictly prohibited. Accounts that generate, upload, request, store, or distribute them are terminated immediately, the content is removed, and — where the law requires or permits — the matter is referred to the competent authorities:

  • Child sexual abuse material (CSAM) and any sexual content involving minors, real or synthetic, including sexualized depictions of anyone who is, or appears to be, a minor. Where we become aware of CSAM we remove it, terminate the account, and report it to the National Center for Missing & Exploited Children (NCMEC) and/or the relevant national authority as required by law.
  • Non-consensual intimate imagery (NCII) of real people, including sexual "deepfakes."
  • Content that facilitates terrorism, mass violence, or attacks on critical infrastructure, or that provides operational instructions for weapons capable of mass casualties (biological, chemical, radiological, nuclear, or high-yield explosives).
  • Human trafficking, or the exploitation, sexualization, or endangerment of children in any form.

3. Prohibited content and conduct

You may not use ToRun to create, generate, upload, share, or distribute:

  • Sexually explicit or pornographic content. ToRun is not an adult-content platform and does not support generating it.

  • The likeness or voice of a real, identifiable person without their consent, including deceptive "deepfakes" of public figures, or content that impersonates a person or organization in order to deceive.

  • Illegal goods or activities — the sale or facilitation of illegal drugs, weapons, stolen data or credentials, counterfeit goods, or other unlawful transactions.

  • Fraud, deception, or malware — phishing, scams, spam, coordinated disinformation, or malicious code.

  • Hateful, harassing, or violent content targeting people on the basis of a protected characteristic; threats; bullying; or incitement to violence or self-harm.

  • Infringement of intellectual-property or privacy rights — content that infringes copyright, trademark, or trade-secret rights, or that discloses another person's private or identifying information ("doxxing").

  • Regulated advice presented as authoritative — medical, legal, or financial advice presented as a substitute for a qualified professional. Informational output in these areas carries an advisory disclaimer.

  • Platform abuse — circumventing rate limits, security controls, or usage restrictions; scraping in violation of our Terms; or reselling access in violation of your plan.

  • Free-allowance abuse and multiple accounts. The free allowance is granted once per person, not once per account. The following are prohibited:

    • creating more than one account in order to obtain the free allowance more than once, whether through additional e-mail addresses, address variants (dots or "+" tags), disposable mailbox services, or additional social logins;
    • deleting an account and registering again in order to reset a spent allowance, quota, or rate limit;
    • coordinating accounts across a household, office, or network for the same purpose.

    A single person may hold one account. If you need more capacity, a paid plan or prepaid credit is the supported route, and it is cheaper for you than the effort of evading the limit.

  • Automated or scripted access. ToRun is a product for people. Driving the platform with a bot, script, headless browser, or any other automation — including automating sign-up, generation, or account deletion — is prohibited except through an API we have expressly issued to you for that purpose.

4. How we enforce this policy

We combine automated screening, human review, and account-level enforcement. We are transparent about what these controls do and do not cover:

  • Automated screening of uploaded images. Every image you upload is checked by an automated moderation classifier before it is stored. The classifier flags harmful categories, including sexual content involving minors, non-consensual sexual content, and graphic violence. Flagged uploads are rejected and are never stored.
  • Automated screening of publicly shared content. Text you publish to a public surface — a shared canvas artifact or a community / forum post — is screened before it goes live; flagged content is blocked from publication.
  • Public-visibility gating. Content shown publicly (for example, community persona posts) is gated to an approved state before other users can see it.
  • Human review and reports. We review abuse reports and act on them. Depending on severity, enforcement ranges from content removal and a formal warning to temporary suspension and permanent account termination.
  • Cooperation with authorities. We remove illegal content once we become aware of it and cooperate with lawful requests from, and referrals to, the competent authorities.

For transparency: our automated screening today is a machine-classifier applied to uploaded images and to publicly published text — it is not a hash-matching database (such as PhotoDNA), and it does not screen every private, in-session generation. We are actively expanding automated coverage across the platform, and all content remains subject to this AUP and to removal on report or review.

5. Bring-your-own-key (BYOK) does not create an exception

Routing requests through your own provider API key does not exempt you from this AUP. Our platform policies — content rules, billing audit, and disclosure requirements — continue to apply to all activity on ToRun.

6. Reporting abuse

If you encounter content that violates this policy, report it to [email protected], or through the contact form at /company/contact (category: Trust & Safety). Include the URL or identifier (persona, workflow, artifact, or message) and a brief description of the violation. Reports concerning child sexual abuse material are treated as the highest priority.

7. Enforcement decisions and appeals

Enforcement is proportionate to the severity and recurrence of the violation. The zero-tolerance categories in section 2 result in immediate and permanent termination. For everything else, including the free-allowance and automation rules in section 3, we apply the following ladder:

Occurrence Consequence
First Account suspended for 30 days
Second Account suspended for 1 year
Third Permanent suspension

A suspension applies to the person, not merely to the account in front of us: it is enforced against the identity signals that survive account deletion — the mailbox, the social login, and the network the accounts were created from. Deleting a suspended account and registering a new one does not clear the suspension and counts as a further occurrence.

Suspension is not a forfeiture. Prepaid wallet credit and any paid subscription remain yours: a subscription can be cancelled under the Refund Policy, and unused credit is refundable on the same terms as any other account. What a suspension withdraws is access, not money you have already paid us.

If your account was restricted and you believe this was a mistake, you may appeal through the contact form at /company/contact (category: Appeal), or by e-mailing [email protected]. Use the address the account is registered under. The form works while you are signed out, which matters because a suspension blocks sign-in. We review appeals and restore access where an error is confirmed. False positives do happen — a shared office network or a recycled address can look like evasion — and we would rather review an appeal than leave a real customer locked out.

8. Changes

We update this policy as the platform and adversarial misuse patterns evolve. Material changes take effect on the date stated above and are announced through our changelog. Continued use after the effective date constitutes acceptance.

Questions about this document? Contact us