Tegy Acceptable Use Policy
Effective and last updated August 6, 2026
This Tegy Acceptable Use Policy (“AUP”) applies to all access to and use of the Tegy Service. It is incorporated into the Tegy Terms of Service or other agreement governing the Service (the “Agreement”). Capitalized terms not defined here have the meaning in the Agreement.
Customer is responsible for its Authorized Users, Customer Content, configurations, integrations, external actions, and outputs.
1Lawful business use
The Service may be used only for lawful business or professional purposes. You may not use it for personal, family, or household purposes or in a way that violates law, regulation, court order, contract, professional duty, or another person's rights.
You may not use the Service to facilitate, promote, generate, store, transmit, or conceal:
- fraud, scams, phishing, identity theft, deceptive commercial practices, money laundering, sanctions evasion, or unlawful financial activity;
- malware, ransomware, credential theft, destructive code, unauthorized surveillance, or instructions primarily designed to compromise systems or accounts;
- unlawful threats, harassment, stalking, extortion, exploitation, or material that promotes or coordinates violence;
- child sexual abuse material, sexual exploitation of minors, grooming, or any sexual content involving a minor;
- non-consensual intimate imagery or sexual content;
- unlawful discrimination or denial of legally protected rights;
- infringement or misappropriation of intellectual property, privacy, publicity, confidentiality, trade-secret, contractual, or other rights;
- impersonation or synthetic media intended to deceive a person about a material fact, source, authorization, or endorsement;
- fake reviews, testimonials, evidence, credentials, records, or endorsements intended to mislead; or
- another activity prohibited by an AI model, infrastructure, or integration provider whose service is used to fulfill the request.
2Systems, security, and abuse
You may not:
- gain or attempt unauthorized access to the Service, an account, system, network, model, prompt, key, credential, or data;
- probe, scan, or test vulnerabilities without Tegy's prior written authorization;
- bypass authentication, authorization, safeguards, rate limits, content filters, plan limits, fees, suspension, or provider restrictions;
- interfere with or degrade Service integrity, availability, performance, or another customer's use;
- introduce malware or use the Service to operate a botnet, denial-of-service activity, credential attack, scraping operation, or abusive automation;
- create multiple accounts or workspaces to evade restrictions, fees, credits, or enforcement;
- share individual credentials or make an account available to an unauthorized person;
- resell or sublicense the Service except under a written agreement;
- scrape, harvest, or collect personal information in violation of law or platform terms;
- reverse engineer or extract protected components, system prompts, model weights, source code, or non-public security information except where law prohibits restriction; or
- use the Service, non-public Service behavior, or outputs obtained through prohibited extraction to develop, train, or improve a competing service or model.
Good-faith security research is permitted only under Tegy's then-current written vulnerability-disclosure program or advance written authorization.
3Customer Content and third-party rights
You must have all rights, permissions, notices, consents, and lawful authority needed to submit Customer Content and instruct Tegy and its providers to process it. You may not submit information subject to a confidentiality, employment, platform, database, or other restriction that prohibits the intended use.
You are responsible for reviewing and complying with the terms governing connected services, APIs, MCP tools, model providers, data sources, and third-party content. Tegy's ability to connect a system does not establish that your use is authorized.
4Sensitive and specially regulated data
Unless Tegy expressly agrees in a signed writing that identifies the data and required controls, you may not submit or process:
- protected health information regulated by HIPAA or consumer health data subject to a state consumer-health-data law;
- full payment-card numbers, security codes, or other cardholder data subject to PCI DSS;
- nonpublic personal financial information subject to GLBA;
- consumer-report information used or obtained subject to FCRA;
- Social Security numbers, passport numbers, driver's-license numbers, state-identification numbers, tax identifiers, or similar government identifiers;
- biometric identifiers or templates used to identify a person;
- personal information collected from or about a person under 18 where law requires parental consent or special handling, including information collected through a child-directed service;
- student education records governed by FERPA;
- precise geolocation, genetic data, neural data, or similarly sensitive information used to profile an individual;
- classified information, controlled-unclassified information, export-controlled technical data, or government data requiring a specific authorization or environment;
- authentication secrets, private cryptographic keys, unredacted passwords, API keys, OAuth tokens, or other live credentials except through a field or secrets mechanism expressly designed for that credential; or
- another category requiring a certification, license, filing, contractual addendum, or technical environment Tegy has not expressly agreed to provide.
Ordinary business contact information, professional communications, and personal information incidental to legitimate business documents may be processed subject to the Agreement and DPA.
5AI outputs and high-impact uses
You may not use an output as the sole or determinative basis for a decision that materially affects a person's legal rights, employment, housing, credit, lending, insurance, education, immigration, access to government benefits, medical treatment, or physical safety.
If you use the Service to assist with a high-impact or regulated activity, you must:
- determine that the use is lawful and appropriate;
- use a qualified human reviewer with authority to reject or change the output;
- independently verify material facts and sources;
- test for reasonably foreseeable errors, discrimination, and harmful bias;
- provide notices, explanations, appeal or review rights, and disclosures required by law;
- maintain appropriate records of the human decision and basis; and
- not represent an AI output as licensed professional advice or a guaranteed fact.
You may not use the Service to make fully autonomous decisions about weapons, critical infrastructure, emergency response, medical treatment, or another activity where an error is reasonably likely to cause death, serious bodily injury, or catastrophic property or environmental harm.
6Communications and external actions
You may not use the Service to send spam, unlawful marketing, deceptive messages, or communications that violate consent, opt-out, telemarketing, platform, or anti-spam requirements. You must identify yourself accurately and honor legally required opt-outs.
Before authorizing an integration or agent to send, post, purchase, delete, file, edit, or otherwise act externally, you are responsible for reviewing scopes, recipients, content, price, and consequences. You must use confirmation or human-review controls appropriate to the risk.
You may not use the Service to record or transcribe a call, meeting, conversation, or other communication without giving every required notice and obtaining every consent required by applicable law before capture begins. You may not submit an existing recording or transcript unless you have the rights and lawful authority required for Tegy and its providers to process it.
7Provider rules
Use of AI models, infrastructure, integrations, and connected services must comply with the applicable provider's acceptable-use and safety policies. Tegy may apply the more restrictive rule where provider access depends on it and may block a request, model, tool, or feature that creates provider or Service risk.
8Enforcement
Tegy may investigate suspected violations and may, in its reasonable discretion and without advance notice where urgency requires:
- block inputs, outputs, models, providers, integrations, actions, or content;
- remove or quarantine content;
- throttle or rate-limit activity;
- revoke credits or credentials;
- suspend or terminate a user, workspace, account, or feature;
- preserve relevant evidence;
- notify an affected customer or provider; or
- report unlawful conduct to authorities where required or appropriate.
Tegy is not obligated to monitor all use or Customer Content and assumes no duty to take a particular action in every case. A decision not to act in one instance does not waive enforcement in another.
Where Tegy determines it is commercially reasonable and safe, Tegy may limit enforcement to the affected user, content, integration, or feature and may restore access after a curable issue is resolved. Tegy is not liable for a good-faith decision to act or not act under this AUP except to the extent liability cannot be limited by law, and any liability remains subject to the Agreement.
Customer will reasonably cooperate with an investigation and promptly remediate a violation. Customer is responsible for costs, claims, and harm arising from its violation as provided in the Agreement.
9Reporting
Report suspected abuse, prohibited content, security issues, or unauthorized account use to security@tegy.io. Include enough information for Tegy to identify and evaluate the issue. Do not send live credentials or additional sensitive data in the report.
10Updates
Tegy may update this AUP by posting a revised version and changing the Last Updated date. Updates take effect on the stated date. Tegy may make an update effective immediately when reasonably necessary for law, security, abuse prevention, or a provider requirement. For an existing paid customer, another material restriction will apply at the next renewal or earlier affirmative acceptance, and Tegy will provide reasonable advance notice.
This AUP supplements the Agreement. If there is a conflict, the Agreement controls except that the additional use restrictions and provider requirements in this AUP apply.
