Skip to content

Acceptable use policy

Last updated: September 7, 2026

This policy applies to everything you send through the INFRO API and everything you do with what comes back. It forms part of the terms of service and is kept separate because it is the document you should be able to hand to a colleague, and because it changes when capabilities change rather than when a contract does.

The short version

Do not use INFRO to break the law, to harm people, or to circumvent the metering and safety systems of the platform or of the providers behind it. Everything below is that sentence made specific enough to apply.

INFRO is developer infrastructure sold to businesses and to the people building them. Accounts are for organisations and developers aged 18 or over. It is not a consumer content service, it hosts and publishes nothing, and it is not sold for the generation of adult, romantic, or companion content of any kind.

Prohibited uses

Illegal activity and content

  • Anything unlawful in your jurisdiction or ours, including generating, storing or distributing child sexual abuse material — which is reported to the relevant authorities without notice and without exception.
  • Fraud, phishing, malware, credential harvesting, or content designed to deceive somebody into a transaction or a disclosure.
  • Circumventing access controls, including generating content designed to defeat authentication, CAPTCHA, or content moderation systems.

Harm to people

  • Harassment, stalking, doxxing, or content targeting a private individual.
  • Impersonating a real person or organisation, in text or in synthetic media, without their documented consent — the image, video, and voice boundaries are stated in full below.
  • Content promoting self-harm, or presenting medical, legal or financial output as professional advice without a qualified human in the loop.

Synthetic media, likeness, and adult content

These have their own heading because image, video, and audio models are on the catalog, and because this is the boundary that matters most. Each is prohibited outright: there is no approval path, no enterprise exception, and no configuration that unlocks one.

  • Deepfakes and face swaps. Generating, editing, or swapping a real person’s face or likeness into any image or video without their documented consent.
  • Voice cloning and synthetic impersonation. Cloning a real person’s voice, or generating speech or video attributed to a real person or organisation, without their documented consent.
  • Sexual and adult content. Pornographic or sexually explicit generation of any kind, “nudify” or undressing tools, and AI companion, romantic, or erotic chat products.
  • Non-consensual intimate imagery, whether captured or generated.
  • Anything involving minors. Sexual content depicting minors in any form, generated or otherwise, is reported to the relevant authorities without notice and without exception. Products directed at children under 18 are not permitted.
  • Electoral and political deception. Synthetic media of candidates, officials, or election processes presented as genuine.

Harm to the platform

  • Reselling raw inference as a competing gateway. Building a product on INFRO is the intended use; re-exposing the API surface itself is not.
  • Sharing an API key outside your organisation, or embedding one in a client application where an end user can extract it. An INFRO key is a bearer credential that spends on your own provider accounts — a leaked one runs up your provider's invoice, not ours, which is why per-key spend limits exist.
  • Deliberately evading rate limits or spend limits, including by rotating keys or accounts to obtain capacity you were not issued.
  • Load testing beyond your rate limit without telling us first. Ask; the answer is usually yes and we would rather schedule it than page somebody.

Upstream provider terms apply too

INFRO routes your requests to third-party model providers, and their own acceptable-use policies apply to the traffic they serve — even though you never choose which one serves a given request. This is the clause most likely to surprise you, so it is stated plainly: a use permitted here may still be refused by the model that runs it, and a provider may terminate capacity for a workload it considers outside its terms.

In practice the union of the major providers’ policies is close to the list above. Where it is not, the request fails at the provider and fails over like any other refusal. If you are planning a workload that sits near a boundary — security research, content moderation, medical or legal output — write to sales@infro.io before you build it rather than after.

What we can and cannot see

INFRO does not inspect your prompts or completions. Content logging is off by default and is a per-organisation opt-in with a retention window you choose — see privacy. There is no content classifier, no scanning pipeline, and no human review of traffic.

So enforcement is not proactive, and this policy does not pretend otherwise. We act on what reaches us: an upstream provider’s report, a complaint from a third party, a legal demand, or an operational signal that does not require reading content — an unusual usage pattern, a payment dispute, a key behaving as though it has been copied.

Safety systems still run on every request

Not inspecting content is not the same as no moderation. Every request is executed by an upstream model provider, and each of them applies its own safety classifiers and refusal behaviour to the traffic it serves. INFRO does not disable, weaken, or route around those systems, and offers no “unfiltered”, uncensored, or jailbroken variant of any model. A prompt that a provider refuses is refused here too, and attempting to defeat those systems is itself a violation of this policy.

How enforcement works

In the order we prefer, and we go no further down the list than the situation requires:

  1. We contact you. Almost every case is a misunderstanding, a leaked key, or a customer who did not know an upstream refused something. A conversation resolves it.
  2. We restrict a capability. A model, a modality, or a rate — narrow, reversible, and it leaves the rest of your workload running.
  3. We suspend. Traffic stops; your account, your data and your provider connections are untouched, and reinstatement is a conversation rather than a new signup.
  4. We terminate. Only for the categories above that have no innocent reading, for a repeated violation after suspension, or where the law requires it.

Immediate suspension without prior contact is reserved for material we are legally obliged to act on at once, and for active harm to the platform or to another customer. It is the exception and it is written here so it is never a surprise.

Termination ends the subscription at the close of the current period, and the refund policy says what happens to the part of it already paid for. Your provider accounts are yours throughout: nothing INFRO does to your account changes what you owe a provider or your access to it. Mandatory legal and payment-provider remedies still apply.

Reporting a violation

If a INFRO customer is using the platform against this policy, write to support@infro.io with whatever evidence you have. If you have found a security vulnerability in INFRO itself, that is a different address and a different process — see security.

Changes

We update this policy as the platform’s capabilities change. Material changes are announced by email to account owners at least 30 days before they take effect, except where a change is required by law or by an upstream provider, in which case it takes effect when they do and we tell you as soon as we can.

Questions about whether something is permitted are welcome before you build it: sales@infro.io. An answer costs us an email and saves you a rewrite.