Skip to content
TarraOne

Acceptable Use Policy

The conduct rules for TarraOne and TarraCoata services: no spam, API abuse, malware, illegal activity, reverse engineering, attacks or AI misuse.

Effective: 1 August 2026

This Acceptable Use Policy ("AUP") applies to everyone who uses TarraOne, the TarraCoata website and any service we operate. It supplements the TarraOne SaaS Terms of Service and the Terms of Use. Violating this policy may lead to suspension or termination.

1. General principle

Use our services lawfully, respectfully and within the capacity you have paid for. Do not use them in a way that harms other users, third parties, or the integrity and availability of the platform.

2. Prohibited conduct

Spam and unsolicited messaging

  • Sending bulk unsolicited email, SMS or WhatsApp messages from or through the platform.
  • Uploading purchased, scraped or otherwise non-consented contact lists.
  • Using deceptive sender names, subject lines or headers, or omitting an unsubscribe mechanism.
  • Continuing to message recipients who have opted out.

API abuse

  • Exceeding published rate limits, or engineering around them through rotation of keys, accounts or IP addresses.
  • Sharing, reselling or publishing API credentials.
  • Polling at frequencies that materially exceed documented guidance.
  • Using the API to build a competing product or to bulk-extract the service's data or models.

Malware and harmful code

  • Uploading, storing, linking to or transmitting viruses, ransomware, worms, trojans, exploit kits, keyloggers or any code intended to damage or gain unauthorised access to a system.
  • Hosting phishing pages, credential harvesters or command-and-control infrastructure.

Unlawful activity

  • Any use that violates applicable law, including data protection, consumer protection, sanctions, export control, anti-money-laundering, or intellectual property law.
  • Storing or distributing content that is defamatory, harassing, hateful, or that sexualises minors.
  • Processing personal data without a lawful basis, or in breach of a data subject's rights.

Reverse engineering

  • Decompiling, disassembling, or otherwise attempting to derive the source code, models, prompts or architecture of the service, except to the extent that such restriction is prohibited by law.
  • Copying the design, structure, user interface or documentation to create a substitute service.
  • Circumventing licensing, plan limits, feature gating or authentication.

Attacks on the service

  • Denial-of-service or amplification attacks, resource exhaustion, or load testing without prior written permission.
  • Unauthorised scanning, penetration testing or vulnerability probing outside the responsible disclosure process in the Security Policy.
  • Attempting to access another workspace, account, record or dataset.
  • Interfering with logging, monitoring, backups or security controls.

AI misuse

  • Prompt injection, jailbreaking, or any attempt to bypass safety filters and system instructions.
  • Generating disinformation, impersonation of real individuals or organisations, or synthetic media intended to deceive.
  • Using AI features for mass content generation for spam, SEO manipulation or automated harassment.
  • Extracting, distilling or replicating the underlying models, prompts or system configuration.
  • Submitting other people's confidential or special-category data into AI features without a lawful basis.
  • Relying on AI output for legal, medical or financial decisions in breach of the AI Usage & Disclaimer.

3. Customer responsibility

You are responsible for the conduct of every user in your workspace, for the content you upload, and for the legality of the data you process. You must promptly remove violating content once you become aware of it.

4. Reporting violations

Report abuse to [abuse@tarracoata.com] with the workspace, URL or message identifier and a description. We investigate every credible report.

5. Enforcement

Depending on severity and repetition we may: issue a warning; throttle or restrict a feature; remove violating content; suspend the account; terminate the subscription without refund; or report the matter to law enforcement. Where the violation poses immediate risk — active attack, malware distribution, illegal content — we act first and notify afterwards.

6. Appeals

If you believe enforcement was applied in error, write to [support@tarracoata.com] within 30 days. We review appeals within 10 business days.

7. Changes

We update this policy as threats and features evolve. The current version and date appear at the top of this page.

Legal question?

For privacy, data protection or contracting matters:

tarracoatainfo@gmail.com
Back to the Legal Center