Acceptable Use Policy

Version 1.0. First published 5 August 2026.

This Policy is incorporated into the Terms of Service, so agreeing to the Terms is agreeing to it, with no separate acceptance, and it applies to everyone who uses the Service, including anyone you give access to. It changes separately from the Terms so that we can tighten a prohibition quickly when the law changes, without reopening the whole agreement.

It is written in three tiers: things nobody may do, things you may do only with particular safeguards, and things you must tell people about.

Section 6 describes what we can and cannot detect; read it before you rely on any of this being enforced automatically.

1. Tier 1: prohibited outright

You must not use the Service, or allow it to be used, to:

Break the law. Do anything unlawful, or infringe anyone’s rights.

Child sexual abuse material. Create, request, distribute or possess child sexual abuse material, or sexualise a minor in any way. You must also not develop, train, fine-tune, adapt, supply, or offer to supply any model, program, service or information designed or optimised to produce such material, and you must not use the Service to generate training data for anything of that kind. This bullet is drafted wider than “do not make the images” on purpose. UK law already criminalises the images themselves, including wholly synthetic pseudo-photographs and prohibited images, and the Crime and Policing Act 2026 criminalises the generator itself, including a fine-tuned model, as its provisions are brought into force. This Policy does not wait for commencement dates: everything in this bullet is prohibited here now.

Intimate images without consent. Create, request or enable intimate or sexual images of a person without their consent. This covers wholly synthetic and “deepfake” images that appear to depict an identifiable person just as much as real ones, and it covers building or supplying any tool for that purpose. UK law reaches the purported image, not only the genuine one.

Weapons capable of mass casualties. Develop them, or seek or provide meaningful uplift towards chemical, biological, radiological or nuclear harm.

Terrorism. Promote, encourage or facilitate terrorism. Create, distribute, transmit, or provide a service that enables others to obtain terrorist publications. Generate information likely to be useful to a person committing or preparing an act of terrorism.

Attacks on systems. Attack or disrupt computer systems or critical infrastructure, or access them, in each case without authorisation. Create or deploy malware. Authorised security testing of your own systems, or of a system whose owner has instructed you, is not prohibited by this bullet, and the word “without authorisation” governs all three verbs.

Fraud and impersonation. Defraud, defame, harass or impersonate anyone.

Deception about authorship. Present AI-generated content as human-authored in a context where a recipient’s decision would reasonably be influenced by believing a person wrote it. We mean, at least: journalism, product or service reviews, political and electoral communication, academic submissions, evidence in legal or regulatory proceedings, and communications with a person in vulnerable circumstances.

EU AI Act prohibited practices. Deploy the Service to: manipulate people using subliminal or deceptive techniques in a way that causes or is likely to cause significant harm; exploit vulnerabilities arising from a person’s age, disability, or social or economic situation in a way that causes or is likely to cause significant harm; carry out social scoring; infer emotions in a workplace or an educational setting; scrape facial images without targeting to build a recognition database; carry out biometric categorisation to infer protected characteristics; or perform real-time remote biometric identification in a publicly accessible space. From 2 December 2026 that list also prohibits AI systems for generating non-consensual intimate imagery and child sexual abuse material, which sections above already prohibit here. That addition also works at provider level, and we hold ourselves to it: it catches placing on the market a system for which such material is a reasonably foreseeable and reproducible outcome absent adequate safeguards. Our safeguards are: a written assessment of every model, before it is served, of whether it is made or adapted for such material; the same pre-acceptance screening for any optimisation work (clause 18 of the Terms); and enforcement on reports, authority notices and traffic anomalies. Section 6 describes what we can and cannot detect.

Sanctions and export control. Use the Service in connection with a chemical, biological, nuclear or missile end use, or for the benefit of a person or place subject to sanctions. If you learn that anything you are doing with the Service may be intended for a sanctioned destination or end use, tell us promptly; once we are informed in writing by a competent authority that a licence is needed, we have no discretion to continue without one, and we may suspend affected service immediately. We apply the same rule on our own knowledge: where we know, or have grounds to suspect, a controlled end use, we act as if we had been notified, whether or not we have been.

Circumvention and misrepresentation. Circumvent rate limits, access controls or safety systems. Attempt to extract, reconstruct or reverse engineer model weights or parameters through systematic querying. Resell the Service while misrepresenting where it comes from.

Regulated data we have not agreed to handle. Send protected health information, payment card data, or other data whose processing needs a compliance regime we have not agreed to in writing. We do not offer a business associate agreement.

2. Tier 2: high-risk uses, permitted only with safeguards

You may build in these areas, but not without a person in the loop.

Decisions about individuals. If output contributes to a decision with a legal or similarly significant effect on someone (employment, credit, insurance, housing, education, immigration, benefits, healthcare, or access to essential services), a qualified human must review it before it takes effect, and that person must be able to change the outcome. A human who rubber-stamps is not review.

Professional advice. Legal, medical, financial and similar advice must be reviewed by someone qualified to give it before it reaches the person relying on it.

Vulnerable people and minors. If your product is used by people in vulnerable circumstances, or is likely to be accessed by under-18s, you are responsible for the additional protections that context requires.

You are also responsible for satisfying yourself where your use falls under the EU AI Act’s high-risk regime, and for meeting the obligations that regime puts on you.

3. Tier 3: what you must tell people

They are talking to an AI. If your product lets people interact with model output, you must ensure they are informed they are interacting with an AI system, unless that is obvious from the context to a reasonably well-informed person.

Deep fakes and public-interest text. If you publish AI-generated or manipulated image, audio or video content that appreciably resembles real people or events, disclose that it is artificially generated. If you publish AI-generated text to inform the public on a matter of public interest without a human editorially responsible for it, disclose that too.

About marking. Where the law requires machine-readable marking of synthetic content, that duty falls on the provider of the AI system. For the API itself that is us, and we say plainly where we stand on it in the Terms of Service. Where you build the model into a product of your own, you are likely the provider of that product, and the duty is yours as well as ours; ours does not discharge yours. Our outputs do not currently carry any machine-readable provenance marking. If you need it today, you have to add it.

If markers or provenance metadata are present in an output, you must not strip or alter them.

4. If you give others access

If you resell, aggregate or otherwise make the Service available to other people:

  • You must impose restrictions on them at least as protective as this Policy, and pass on the disclosure obligations in section 3.
  • You remain responsible for what they do, and their breach of this Policy is your breach of it.
  • You must not knowingly give access to anyone we could not lawfully serve ourselves under the sanctions and export control provisions of the Terms.
  • If we ask for information reasonably needed to investigate a report of misuse or to meet a legal obligation, you must provide it within 10 working days, or sooner where a competent authority sets a shorter deadline.

5. Reporting misuse, and legal notices

Report misuse of the Service to abuse@cyan.kiwi. Contracts, subpoenas, formal legal notices, and notices from law enforcement or competent authorities go to legal@cyan.kiwi. Security vulnerabilities go to security@cyan.kiwi.

We acknowledge reports of misuse within two working days, review them, and act on what we find. Where a competent authority gives us notice about unlawful content, we act within the time the law allows.

Where we become aware of apparent child sexual abuse material, we will report it to the appropriate authority, such as the Internet Watch Foundation or the National Crime Agency, and we will preserve related account records where the law requires it. Section 6 describes what we can and cannot detect, which is why this commitment runs from awareness.

6. What we can and cannot detect

This section exists so that nothing above reads as a promise of surveillance we do not perform.

We do not conduct bulk content surveillance of traffic, and Output does not currently carry watermarks. The API relays your request to the model and relays the response back. Enforcement is reactive: we act on reports, on notices from authorities, and on billing or traffic anomalies.

We do not store the content of requests or responses, so in the ordinary case there is nothing for us to review, produce or preserve. Two caveats, because “nothing” would be an overstatement:

  • Error messages reach our infrastructure logs and can contain limited request data.
  • Our infrastructure logs record the calling IP address and user agent.

Both live only for the infrastructure-log retention period published in the Privacy Notice, which is the single source for how long anything is kept.

We do not ask for, or store, identifiers for your own end users. If your requests reach us through an aggregator, we see the aggregator, not the person who typed the prompt, and section 4 is how obligations reach them.

7. Enforcement

If you breach this Policy we may warn you, restrict your access, suspend it, or terminate the agreement. We aim to use the least disruptive step that addresses the problem, and where the breach can be fixed we will normally tell you and give you a chance to fix it.

We may suspend or terminate immediately and without notice where the breach is serious or unlawful, where a competent authority directs it, or where continuing would expose us or a third party to imminent harm or legal liability. Everything in Tier 1 is treated as serious.

Breach of this Policy is a material breach of the Terms of Service. This is the only threshold: there is not a separate, gentler standard elsewhere in our documents.

8. Model services and published models

Where we quantize, train or evaluate a model for you, or where you send us model weights or a dataset, the following also apply.

You must not send us weights or data you do not have the rights to give us, and you must not ask us to produce an artifact whose creation or supply would breach Tier 1. We screen every such engagement before accepting it and record the assessment (clause 18 of the Terms of Service). We will refuse, and will stop, work we assess as designed or optimised for a Tier 1 purpose, and we may decline to explain our reasoning in detail where doing so would help someone route around it.

The models we publish under our own name on public model hubs are covered by clause 12 of the Terms of Service. Downloading one of those does not put you under this Policy, but it does put you under that model’s upstream licence, and this Policy governs anything you send back through the Service.

9. Changes

We may update this Policy. Material changes are handled under the change clause in the Terms of Service, except that we may tighten a prohibition immediately where a change in law or an imminent risk of harm requires it, publishing the change here with a new version and date at the same time.