Acceptable Use Policy

Totalum, Inc.

Effective: · Version 2.0 · Binds users registered before that date from

Part of the Terms of Service

This Acceptable Use Policy (the “Policy”) is incorporated into the Terms of Service by their Section 9. Capitalized terms have the meaning given there. Breaching this Policy is a material breach of the Terms and can lead to removal of content, unpublishing of a Project, suspension or termination of your Account, and, where the law requires it, a report to the authorities.

1. Scope: who and what this Policy covers

This Policy applies to everything you do with the Service and everything you make with it: your Input (prompts, files, code, designs, data), the Output the agent generates, your Projects, the apps you publish on a totalum-project.com subdomain or on a custom domain, your use of the HTTP API and the MCP server, and any action taken through your Account or API key by a team member, a script, an integration or an AI agent acting for you. If you are a whitelabel partner or an agency, it also applies to what your own customers and clients do through the Service, and you are responsible for making sure they comply.

The Service is built on models supplied by our Model Providers, whose usage policies apply to everyone who submits Input through it. You agree to comply with Anthropic's Usage Policy and its supported regions, and with the policies of any other Model Provider we identify in the product, as updated from time to time. Where this Policy and a Model Provider's policy differ, the stricter rule applies. This Policy states our rules in plain language so that you can tell, before you start, whether something is allowed; it is not a complete list of every unlawful act, and anything illegal where you are or where your users are is prohibited whether or not it appears below.

2. Prohibited uses

You must not use the Service, and you must not build, host, publish or operate anything with it, that does or is intended to do any of the following.

2.1 Illegal activity and infringement

  • Violate any law, regulation or court order applicable to you, to Totalum or to the people your app serves.
  • Infringe, misappropriate or violate anyone's copyright, trademark, patent, trade secret, right of publicity, privacy right or other right, including by uploading code, images, designs, text or data you have no right to use, or by publishing an app that distributes protected material without permission.
  • Facilitate the sale or trade of illegal goods or services, counterfeit goods, stolen data or credentials.

2.2 Child safety

  • Create, store, request, describe, distribute or provide access to child sexual abuse material or any sexualized depiction of a minor, whether real, fictional, drawn or AI-generated. We report such material to the National Center for Missing and Exploited Children and to the competent authorities.
  • Groom, exploit, endanger or facilitate contact with minors for sexual or abusive purposes, or build apps that do.

2.3 Sexually explicit services

  • Build or host pornography, sexually explicit chat or companion services, escort or prostitution services, or any other sexually explicit commercial service. Our Model Providers prohibit these uses and so do we.

2.4 Violence, terrorism and hate

  • Promote, incite, plan, glorify or provide material support for violence, terrorism or violent extremism, or recruit for such organizations.
  • Produce or host content that attacks, dehumanizes, harasses or threatens people on the basis of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability, age or any other protected characteristic.
  • Threaten, harass, bully, intimidate or abuse any person, or build tools for doing so.

2.5 Weapons and catastrophic-risk uses

  • Develop, design, market, manufacture or acquire weapons, or provide instructions for doing so, including firearms, explosives and any chemical, biological, radiological or nuclear material or device (CBRN).
  • Attack, disrupt or gain unauthorized control over critical infrastructure such as power grids, water systems, financial systems, transport, healthcare or emergency services.
  • Use the Service in any activity where failure could lead to death, personal injury or severe environmental or property damage, such as the operation of medical devices, vehicles, aircraft, weapons systems or industrial control systems.

2.6 Malware, intrusion and misuse of infrastructure

  • Create, distribute or host malware, ransomware, spyware, stalkerware, exploits or tools whose primary purpose is unauthorized access, denial of service or evasion of security controls.
  • Access, probe, scan or test any system, network or account without the explicit authorization of its owner, including credential stuffing, password spraying, brute-force attacks and exploitation of vulnerabilities. Authorized security research and testing of your own Projects is allowed; testing Totalum itself requires our written permission, and responsible disclosure to contacto@totalum.app is always welcome.
  • Launch or take part in denial-of-service attacks, run botnets or command-and-control infrastructure, or send traffic designed to overload any service.
  • Run cryptocurrency mining, proof-of-work computation, open proxies, VPN endpoints, Tor relays, bulk file-sharing hosts or any workload whose purpose is to consume our infrastructure rather than to run your app.

2.7 Fraud, deception and impersonation

  • Commit or facilitate fraud, scams, phishing, pyramid or Ponzi schemes, advance-fee fraud, fake charities, fake giveaways or any other deceptive practice, including building lookalike sites of banks, payment providers, government bodies or other brands.
  • Write, buy, sell or publish fake reviews, testimonials or endorsements, or manipulate ratings and rankings.
  • Impersonate any person or organization, or misrepresent your affiliation with one, including through cloned websites, spoofed email or automated accounts.
  • Create deepfakes or synthetic images, audio or video of real people without their consent, or non-consensual intimate imagery of anyone.
  • Generate or spread disinformation presented as fact, or deceptive content designed to mislead the public on matters of public interest.

2.8 Spam and unsolicited messaging

  • Send bulk, automated or unsolicited email, SMS, direct messages, comments or notifications, whether through your app, through our email delivery, or through the referral and share-to-earn programs. Invite only people you actually know, disclose that you receive Credits, and comply with CAN-SPAM, the TCPA, the GDPR and ePrivacy rules, Spain's LSSI, Canada's CASL and the rules of the platform you post on.
  • Harvest email addresses, phone numbers or social profiles for marketing without consent, or send messages that hide the sender or lack a working unsubscribe.

2.9 Privacy violations

  • Track, monitor or surveil people without a lawful basis and, where required, their consent, including covert location tracking, keystroke logging or reading private communications.
  • Perform facial recognition or other biometric identification of people without their explicit consent and a lawful basis.
  • Collect, compile or publish personal information about individuals for the purpose of harassment or exposure (doxxing), or scrape personal data from other sites or services in breach of their terms or of data-protection law.
  • Process personal data of your users in ways your own privacy notice does not disclose or the law does not allow (see Section 4).

2.10 Elections, political manipulation and discrimination

  • Interfere with elections or democratic processes, including voter suppression, misinformation about how or when to vote, impersonation of candidates or officials, and undisclosed political campaigning by automated accounts.
  • Build systems for personalized political targeting or persuasion of individuals, or micro-targeted political messaging, unless expressly permitted in writing by us and by our Model Providers.
  • Make or support decisions that discriminate against people unlawfully on the basis of a protected characteristic, or build profiling systems that have that effect, including in credit, insurance, housing, employment and education.

2.11 Regulated goods and services

  • Offer gambling, betting, lotteries or sweepstakes, financial services (lending, payments, investment advice, cryptocurrency exchanges, money transmission), pharmaceuticals, controlled substances, alcohol, tobacco, vaping products or firearms only where you hold every license and authorization the law requires in each place you offer them, and never to anyone under the legal age. Totalum does not verify your licensing; you are responsible for it and must show it to us on request.

2.12 Misuse of the Service and of the Model Providers

  • Circumvent, disable or interfere with our metering, Credit accounting, rate limits, plan limits, safety systems, abuse detection, sandbox isolation, the “Made with Totalum” badge on free-plan sites, or any Model Provider's safety measures or usage policies, including through prompt injection or jailbreak techniques aimed at making the agent violate this Policy.
  • Access the Service by any means other than the interfaces we document (the platform, the HTTP API and the MCP server), including scraping, crawling or automated account creation.
  • Extract, copy or reverse-engineer Totalum Materials (our software, prompts, agents, templates, runtime components or models) to build, train or improve a competing app builder, coding agent or foundation model, or to benchmark the Service for publication without our consent.
  • Resell, sublicense or proxy raw access to the Model Providers' models through the Service. The API and MCP server are for building and operating apps, not for wholesale model access.
  • Use Output or Input at scale to train, fine-tune or distill AI models, or use the Service to develop models that compete with the Model Providers.
  • Register more than one free Account per person, share Accounts, or use fake identities, disposable identities or false billing information.
  • Use the Service from, or for the benefit of anyone in, a region subject to comprehensive US sanctions or unsupported by our Model Providers (Terms, Section 3.5).

3. High-risk uses: human review and AI disclosure

Some uses are allowed only with safeguards, because the consequences of a wrong Output are serious and because our Model Providers require them. If your Project makes, recommends or materially supports decisions in any of the following areas, this Section applies to you: legal services and advice; healthcare, medical, psychological or pharmaceutical advice, diagnosis or treatment; financial advice, credit, lending, insurance underwriting or claims; employment (recruiting, screening, evaluation, dismissal); housing and tenancy; education and academic assessment; government benefits, immigration or public services; safety-critical operations; and journalism, media or public-information content produced at scale.

  • Qualified human review. A qualified person must review every consequential decision or piece of advice before it takes effect or reaches the person concerned. The agent and its Output may assist that person; they must not replace them. Automated decisions that produce legal or similarly significant effects on individuals must comply with Article 22 of the GDPR, the California ADMT regulations, Colorado's automated-decision law and comparable rules, including notices, explanations, human review and the right to contest.
  • Disclosure that AI is involved. You must tell the people affected that AI is used in the process, clearly and before they rely on it. Any consumer-facing chatbot, assistant or agent you build must disclose at the start of the interaction that the user is talking to an AI system and not to a human, and must do so again whenever a user asks. This is required by Article 50 of the EU AI Act (Regulation (EU) 2024/1689), by Utah's Artificial Intelligence Policy Act, by California's rules on companion chatbots and AI transparency, and by our Model Providers, and it applies to every app whether or not one of those laws formally reaches you.
  • Marking of generated content. Where your app publishes AI-generated text, images, audio or video to the public, you must mark it as AI-generated where the law requires it (for example Article 50(2) and 50(4) of the EU AI Act), and you must not strip provenance markings that the Service or the Model Providers embed.
  • No professional advice without a professional. Output is not legal, medical, financial, tax, security or other professional advice, and your app must not present it as such unless a licensed professional stands behind it and the app says so.
  • Prohibited AI practices. You must not build systems that Article 5 of the EU AI Act prohibits: manipulative or deceptive techniques that distort behaviour and cause harm, exploitation of vulnerabilities due to age, disability or social situation, social scoring, untargeted scraping of facial images, emotion recognition in workplaces or schools, biometric categorization inferring protected characteristics, or predictive policing of individuals. Systems that fall in the “high-risk” categories of Annex III of the EU AI Act may be built with the Service only if you, as their provider or deployer, carry out every obligation that regulation imposes; Totalum does not do so for you and does not warrant that the Service or any Output is suitable for a high-risk system.

If you are unsure whether your use is high-risk, ask us at contacto@totalum.app before you launch. We may ask you to describe your safeguards and may decline to host a Project that lacks them.

4. Rules for the apps you publish

When you publish a Project, you are its publisher, operator and provider, and the controller or business for the personal data it processes (Terms, Section 10). In addition to everything above, the following rules apply to every published app.

  • Your own legal documents. If your app collects any personal data, including through forms, accounts, analytics, cookies or third-party scripts, it must display your own privacy notice, obtain cookie consent where the law requires it (the EU, the UK, Quebec and other opt-in jurisdictions), and provide your own terms of use, legal notice and a way to complain. Spain's Law 34/2002 (LSSI) requires the legal notice and cookie information on any site directed to Spain; the GDPR, the CCPA and the other laws in our Privacy Policy apply to you in your own right. You must not point your users to Totalum's policies as if they governed your app; they do not.
  • Children. You must not build or host an app directed to children under 13 (or the higher age that applies where your users live, such as 14 in Spain and 16 under the default GDPR rule for information-society services) unless you comply with every obligation of an operator under COPPA, the GDPR Article 8 and comparable laws, including verifiable parental consent, and you have told us in writing. You must not knowingly collect personal data from children below those ages without such consent, and you must not show targeted advertising to, or sell the data of, users you know to be minors.
  • Data categories that need our written agreement. Do not store in a Project protected health information subject to HIPAA, full payment-card numbers or security codes subject to PCI DSS, data subject to the Gramm-Leach-Bliley Act, criminal-record data, biometric identifiers or templates, precise geolocation of individuals collected covertly, or any data subject to a specific legal regime, unless we have agreed in writing that the Service is suitable for it. Special categories of personal data under Article 9 of the GDPR (health, sexual orientation, religion, political opinion, ethnicity, genetic and biometric data, trade-union membership) may be processed only if you hold a valid legal basis and have documented it. Payments in your app must go through a payment provider (for example Stripe) that handles card data on its own systems.
  • Security is yours. You are responsible for authentication and authorization, input validation, secret management, dependency updates, rate limiting, backups of anything critical, and for fixing vulnerabilities in your app, whether the agent wrote the code or you did. You must not leave admin panels, databases, API keys or debug endpoints exposed. If you learn of a breach affecting your users, you must handle the notifications the law requires of you; we will assist as the Data Processing Addendum provides.
  • Domains. You must own or be authorized to use every custom domain you connect, keep its registration and DNS in order, and not connect domains that are confusingly similar to someone else's brand.
  • Third-party services in your app. Payment, email, AI, maps, analytics, advertising and other services you integrate through your own keys are contracts between you and their providers. You must comply with their terms, obtain the consents they require from your users, and bear their fees and risks. Totalum's email delivery from your app may be used only for transactional and consented messages under Section 2.8.
  • Content you host. If your app lets its users upload or post content, you must moderate that content so that it complies with this Policy and with the law, provide your users with a way to report illegal content, and respond to notices you receive. Where your app is a user-to-user service under the UK Online Safety Act or an online platform under the EU Digital Services Act, you are its provider and must meet the duties those laws impose.
  • Accessibility and consumer rules. Where your app sells to consumers, you are responsible for pricing, withdrawal, information and accessibility requirements (for example the European Accessibility Act and the ADA), for the truth of its marketing claims and for its compliance with sector rules.

5. API keys, MCP and AI agents acting for you

  • Keys are secrets. API keys give full access to your Account's Projects and Credits. Store them in server-side environment variables or a secrets manager; never embed them in client-side code, mobile apps, public repositories, prompts you share, or screenshots. Rotate a key immediately if you suspect exposure and tell us at contacto@totalum.app.
  • The key holder is responsible. Every request that carries your key, and every action an AI agent, MCP client, script, workflow tool or integration takes with it, is treated as yours. An agent acting for you is bound by this Policy exactly as you are: instructing an agent to do something you could not do yourself is a breach by you. If you give an agent autonomy, you must supervise it, keep it within the limits of this Policy, and be able to stop it.
  • Rate limits and quotas. Respect the rate limits, project-creation limits, concurrency limits and pagination rules in our documentation. Do not spread load across multiple Accounts or keys to evade them, retry aggressively on errors, or poll endpoints at intervals shorter than documented.
  • Building products on the API. You may build products and services on the API and the MCP server, including for your own customers, subject to the Terms (Section 10.5 for whitelabel and agency use). Your product must not present the API as raw access to a Model Provider, must not remove our attributions where the Terms require them, and must flow this Policy down to its users.
  • Automated account creation and testing. Do not create Accounts programmatically, run load tests against the Service, or test the Service's security without our written consent.

6. Fair use of resources

Hosting and agent usage are metered in Credits, but metering is not a license to use the Service in ways that harm it or other users. We may throttle, limit, suspend or unpublish a Project, and we may end an agent run, where it consumes disproportionate CPU, memory, bandwidth, storage, database operations or model capacity in a way that threatens the stability, security or cost of the Service, for example while under attack, while running prohibited workloads under Section 2.6, while serving very large files or streaming, or while looping without progress. We will notify you and, where practicable, work with you to bring the Project within reasonable limits or to move it to an Enterprise arrangement suited to its needs.

7. How we enforce this Policy

We describe our moderation here so that you know what to expect, as Article 14 of the EU Digital Services Act requires of hosting providers. We do not monitor Your Content generally and we are not obliged to. Enforcement rests on three inputs: automated signals (for example malware and phishing signatures, sanctioned-region and fraud indicators, abnormal resource use, payment disputes and safety refusals returned by the Model Providers), reports from users, rights holders, trusted organizations and authorities under Section 8, and orders from courts or competent authorities.

  • Human review. A member of our team reviews the facts before we take action against Your Content or your Account. Automated systems may block a request, pause an agent run or hold a payment on their own, but a decision to remove content, unpublish a Project, suspend or terminate an Account is made by a person, except in urgent cases.
  • Urgent cases. Where content is manifestly illegal (for example child sexual abuse material, live phishing or malware distribution), where an active security incident threatens the Service or its users, or where a court order or legal obligation requires immediate action, we act first and review afterwards.
  • Proportionate measures. Depending on the severity, the harm, whether the breach is repeated and whether it appears deliberate, we may: warn you; require you to fix the problem within a deadline; remove or disable specific content; unpublish a Project; restrict a feature, the API or the MCP server; rate-limit or throttle; withhold promotional Credits obtained through abuse; suspend your Account; or terminate it. We apply these measures diligently, objectively and proportionately, with due regard to your rights and legitimate interests and to those of the people affected, including freedom of expression.
  • Statement of reasons. When we restrict Your Content or your Account we will tell you, in writing, what measure we took, which content or Project it concerns, the facts and circumstances we relied on, whether automated means were used to detect or decide, the provision of this Policy or of the law that was breached, and how you can appeal, unless a law or a request from law enforcement prevents us from doing so or the content is deceptive high-volume commercial content.
  • Appeal. You may appeal any measure by replying to the notice or writing to contacto@totalum.app within six months, explaining why you believe the decision was wrong and attaching any evidence. A person who was not involved in the original decision will review it and answer without undue delay. Decisions are reversed where the appeal shows that the content was not in breach or that the measure was disproportionate. You may also use the courts or the alternative-dispute-resolution routes described in the Terms.
  • Law enforcement. Where we become aware of information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person has taken place, is taking place or is likely to take place, we will promptly inform the law-enforcement or judicial authorities of the country concerned and provide the relevant information, as Article 18 of the Digital Services Act requires. We also respond to lawful requests from authorities as described in the Privacy Policy.
  • Preservation of evidence. We may retain copies of content we remove, and related Account records, for as long as necessary to handle appeals, legal claims, regulatory requests and repeat-infringer tracking.

8. Reporting abuse or illegal content

Anyone, whether or not a Totalum user, can report content hosted on the Service that they believe is illegal or violates this Policy. We designed this channel to meet Article 16 of the EU Digital Services Act and to be easy to use.

Send your report to contacto@totalum.app with the subject line “Abuse report” and include:

  1. the exact URL or URLs of the content, and, where relevant, the Project or app concerned;
  2. a sufficiently substantiated explanation of why you consider the content illegal or in breach of this Policy, citing the law or the section you rely on where you can;
  3. your name and email address, unless the report concerns child sexual abuse material or another offence where you prefer to stay anonymous; and
  4. a statement that you believe in good faith that the information and allegations in your report are accurate and complete.

We confirm receipt by email without undue delay, review reports in a timely, diligent, non-arbitrary and objective manner, prioritizing those that are complete, precise and submitted by authorities or trusted organizations, and we tell you our decision and how to challenge it. Even where our support tools draft a reply with AI assistance, a person makes the decision. Repeated manifestly unfounded reports may be disregarded after a warning.

  • Copyright. Copyright complaints follow the DMCA procedure in Section 13 of the Terms of Service, including the required contents of a notice and the counter-notice process. Send them to contacto@totalum.app or by post to c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States.
  • Trademark, defamation, privacy and other rights. Send these to contacto@totalum.app with the information above, identifying the right you hold and, for trademark complaints, the registration details.
  • Security vulnerabilities. Report vulnerabilities in the Service or in a published app to contacto@totalum.app. Good-faith researchers who respect this Policy, do not access other users' data, and give us reasonable time to fix an issue will not face action from us for that research.
  • Urgent threats. If someone is in immediate danger, contact your local emergency services first, then tell us.

Reports must be made in good faith. Knowingly false reports may lead to suspension of the reporter's Account and, in the case of copyright, to liability under 17 U.S.C. § 512(f).

9. Repeat violations and termination

We keep records of breaches by Account. A second breach of this Policy after a warning, or a first breach that is serious, deliberate or causes harm to others, may result in suspension or termination of your Account and of all Projects in it, under Section 15 of the Terms. We terminate, in appropriate circumstances, the Accounts of users who repeatedly infringe others' intellectual-property rights, generally after three valid notices that are not successfully countered, and sooner for flagrant cases. We may also refuse to open new Accounts for people or organizations whose Accounts we have terminated for breach. Termination for breach does not entitle you to any refund of fees or Credits, and the retrieval period in Section 14 of the Terms may be shortened or withheld where continued access would perpetuate the breach.

10. Changes and contact

We may update this Policy for the reasons and with the notice described in Section 21 of the Terms, for example when the law, our Model Providers' policies or the risks we see change. Material changes are announced by email and in the platform at least 30 days before they take effect; changes that only tighten rules already implicit in the law, or that are needed for safety, may take effect on posting. The version in force is always the one published at this address, with its effective date at the top.

Questions about whether a planned use is permitted: contacto@totalum.app. Abuse and illegal-content reports: contacto@totalum.app. Security: contacto@totalum.app. Postal address for legal notices: Totalum, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States.

Related documents

This document can be printed or saved as a PDF from your browser.

© 2026 Totalum, Inc.