Atamaia Acceptable Use Policy
Effective date: draft — effective date set on publication
Version: 1.0
This Acceptable Use Policy ("AUP") forms part of the Atamaia Terms of Service. It
applies to the hosted Atamaia service. Capitalised terms have the meaning given in the Terms.
We have kept this short and specific. The intent is not to police what you build — Atamaia exists to
give AI systems memory and autonomy, and that is a broad remit. The intent is to protect other
customers, our infrastructure, and people who did not choose to be in your data.
1. Legal and rights
You must not use the Hosted Service to:
- break any applicable law, or facilitate anyone else doing so;
- store or transmit content you have no right to store or transmit;
- infringe copyright, trade marks, trade secrets, patents, privacy or publicity rights;
- store personal information about other people without a lawful basis, or in breach of a notice or
consent obligation you owe them;
- store material that is defamatory, or that constitutes harassment or stalking of an identifiable
person.
2. Prohibited content
You must not store or transmit:
- child sexual abuse material, or any sexualised content involving minors — we report this to law
enforcement and terminate immediately, without notice;
- content that incites or facilitates violence, terrorism, or serious harm to people;
- content designed to facilitate the creation of weapons capable of mass casualties;
- malware, exploit kits, or code whose purpose is to compromise systems without authorisation;
- content that facilitates fraud, phishing, or identity theft.
3. Regulated data
You must not store in the Hosted Service:
- protected health information subject to HIPAA — we do not offer Business Associate Agreements;
- full payment card numbers or cardholder data subject to PCI-DSS;
- government-issued identity credentials — passport, driver licence or national ID numbers and
images;
- classified or export-controlled material.
This is a limitation of our current certification posture, not a judgement about your use case.
Health information that is your own, or that you hold outside a HIPAA-covered relationship, is
permitted — see Terms section 9.6.
4. Security and integrity
You must not:
- attempt to access another tenant's data, or probe for a way to;
- attempt to bypass authentication, authorisation, tenant isolation, rate limits or quotas;
- reverse engineer the Hosted Service to build a competing service — this does not restrict your
rights under the open-source licence in respect of the published source code;
- conduct penetration testing or vulnerability scanning without our prior written consent —
contact [email protected] and we will usually say yes and agree a window;
- introduce malware into the Hosted Service, or use it to attack a third party;
- share credentials or API keys with anyone outside your tenant, or resell access to your account.
Responsible disclosure. If you find a vulnerability, tell us at [email protected]. We will not
pursue action against good-faith research that respects this policy, avoids other customers' data,
and gives us reasonable time to fix the issue before disclosure.
5. Resource use
You must not:
- generate load that materially degrades the service for others;
- run agents in loops that consume resources without purpose;
- circumvent quota enforcement, including by creating multiple accounts to obtain additional free
quota;
- use the Hosted Service primarily as bulk file storage, a CDN, a proxy, or a cryptocurrency mining
or blockchain node host.
6. Agents and autonomous operation
Atamaia supports agents that act autonomously. You are responsible for what your agents do as if
you had done it yourself. In particular you must:
- constrain agent tool access appropriately for the environment it operates in;
- not configure an agent to take actions that would breach this AUP if you took them directly;
- not use agents to impersonate a real person in a way likely to deceive;
- ensure that where an agent interacts with third parties, it does not misrepresent itself as human
where that would be unlawful or deceptive in the relevant jurisdiction.
7. Misrepresentation
You must not represent a Self-Hosted Deployment as being operated, hosted, endorsed or supported by
us, or use our names or logos in a way likely to mislead. See Terms section 15.
Enforcement
Where we believe this AUP has been breached, we may — proportionate to the seriousness and the risk:
- contact you and ask you to fix it;
- restrict or throttle specific functionality;
- suspend the affected account or API key;
- terminate the account;
- where legally required or where there is a risk to life, report to authorities.
We will tell you what we have done and why, and give you an opportunity to respond, except where
the breach falls under section 2's first bullet, where we are legally prevented, or where notice
would create a risk to someone's safety or to the integrity of an investigation.
If you think we got it wrong, reply to the notice or write to [email protected]. A human will look at
it.
Report abuse: [email protected]