Acceptable Use Policy
Effective Date: July 27, 2026
This Acceptable Use Policy (the “AUP”) expands on Section 7 of our Terms of Serviceand is incorporated into them by reference. It applies to everyone who uses Raileon LLC’s platform and services, and to every AI agent operating under your account. Breaking this policy is breaking the Terms. We may update this policy as the platform changes; the Effective Date above shows when it was last revised.
1. General Principle
Raileon is built for lawful business use. You may use the platform for the work your organisation actually does, within the law, and within the terms of the services you connect to it.
You are responsible for what your agents do on your behalf. An agent is not a separate legal actor. When an agent sends an email, posts a message, updates a record, or produces a document under your account, that action is treated as your action. This includes actions taken by agents you configured, agents your team configured, and agents running on a schedule while nobody is watching.
In practice, that means you agree to:
- Configure agents with instructions and permissions that keep them inside this policy.
- Review and approve consequential output before it leaves your workspace — anything that commits you, advises someone, moves money, or reaches a third party.
- Keep your account credentials secure and make sure everyone you invite understands these rules.
- Hold the rights and permissions needed for any data, files, or credentials you bring into the platform.
“I didn’t know the agent did that” is not a defence under this policy. If you cannot supervise an automation, do not run it.
2. Prohibited Content and Conduct
Do not use Raileon, or allow your agents to be used, to do any of the following:
- Break the law. Any activity that violates applicable local, state, federal, or international law, including sanctions and export-control rules.
- Infringe intellectual property.Copying, distributing, or generating material that infringes copyright, trademark, patent, or trade-secret rights, or that misappropriates someone else’s confidential information.
- Harass, threaten, or abuse. Content that harasses, threatens, defames, or incites violence or hatred against a person or group. Sexual content involving minors is prohibited absolutely and will be reported to the authorities.
- Distribute malicious code. Creating, hosting, or transmitting malware, ransomware, spyware, exploits, or any code designed to damage or gain unauthorised access to a system.
- Commit fraud. Phishing, business-email compromise, invoice fraud, fake reviews, pyramid or advance-fee schemes, or any scheme that deceives people out of money, credentials, or data.
- Impersonate. Passing yourself or an agent off as another person, business, or public body, or misrepresenting your affiliation with one.
- Interfere with others.Attempting to access another customer’s workspace, data, or container, or interfering with any other user’s use of the platform.
3. Prohibited AI Uses
Some uses are off-limits regardless of intent, because the failure mode lands on someone other than you. Do not use Raileon agents for:
- Unsupervised professional advice to third parties. Legal, medical, or financial advice delivered to a client, patient, or consumer without a qualified human reviewing it first. Agents may research, draft, and summarise for your licensed professionals; they may not be the last step before the advice reaches the person relying on it.
- Automated decisions about people.Decisions with legal or similarly significant effect — employment, credit, housing, insurance, or education — must have meaningful human review before they take effect. An agent may rank, summarise, or flag; a human decides.
- Biometric identification. Identifying or categorising individuals from faces, voices, gait, or other biometric characteristics, including building or querying a biometric database.
- Surveillance of individuals.Covert monitoring, tracking, or profiling of people — employees, competitors, customers, or members of the public — without their knowledge and a lawful basis.
- Disinformation and deceptive synthetic media. Generating false or misleading content intended to deceive, including political disinformation, fabricated news, astroturfing, or synthetic audio, images, or video presented as a real person or real event.
If your use case sits close to one of these lines, ask us at admin@raileon.com before you build it. We would rather scope it with you than shut it off later.
4. Communications and Outreach
Your agents can send email and post to chat platforms such as Discord and Telegram on your behalf. That reach is the point of the product, and it is also the fastest way to cause real-world harm, so the rules here are strict.
- No unsolicited bulk email. Only contact people who have an existing relationship with your business or who have opted in. Do not use agents to blast purchased, scraped, or harvested contact lists.
- Comply with anti-spam law. CAN-SPAM in the United States, and the equivalent rules wherever your recipients are (CASL, GDPR, PECR, and others). Accurate sender details and subject lines, a working unsubscribe mechanism, and a valid physical postal address in commercial mail.
- Honour opt-outs. Process unsubscribe and stop-contacting requests promptly and make sure your agents respect the suppression list. An agent that keeps emailing someone who opted out is a violation of this policy, whether or not you noticed.
- Do not pass an automated message off as human-authored. Do not claim a named person wrote something an agent generated, and do not deny that a conversation is automated when someone asks. See our AI Disclosure for what we expect you to tell recipients.
- Respect platform rules. Discord, Telegram, and any other service you connect have their own terms and rate limits. Follow them.
You are responsible for reviewing and approving consequential communications before they go out. If a message would bind you, advise someone, or damage a relationship if it were wrong, a human should read it first.
5. Regulated Data Limits
Data you may not put into Raileon
- Protected health information (PHI). Raileon is not a HIPAA business associate and we do not offer a Business Associate Agreement. Do not upload, transmit, or have your agents process PHI as defined by HIPAA. If your work involves patient data, Raileon is not the right tool for it.
- Cardholder data. Do not put full payment card numbers, magnetic-stripe data, or security codes (CVV/CVC) into the platform. Raileon is not PCI DSS certified. Subscription payments are handled by our payment processor and card details never reach your workspace.
Data that needs care
Attorney-client privileged material.You may process privileged and confidential client material, but do it deliberately. Content you submit is processed by third-party AI providers under contracts that prohibit training on your data, and your workspace runs in an isolated per-customer container — but the decision about whether a particular disclosure is consistent with privilege, your engagement terms, and your clients’ expectations is yours, not ours. Where informed client consent is required, get it first.
Your professional obligations are your own. If you are a lawyer, accountant, financial adviser, or other regulated professional, you remain responsible for your bar rules, licensing body, competence and supervision duties, conflict checks, and client confidentiality obligations. Using an AI agent does not transfer any of that to us.
6. Scraping, Crawling, and Connected Services
Agents can browse the web and act inside services you connect. When they do, they act under your name and your credentials, so they follow your obligations to those sites and services.
- Respect
robots.txtand other robots directives, published crawl policies, and rate limits. - Comply with the terms of service of every site and connected application. If a service prohibits automated access, do not automate it.
- Do not circumvent paywalls, logins, CAPTCHAs, IP blocks, or any other technical access control.
- Do not bulk-harvest personal data, contact details, or copyrighted databases.
- Only connect credentials that belong to you or that you are authorised to use, and only grant the scopes the task actually requires.
7. Resource Abuse and Fair Use
Your workspace runs in a dedicated container with finite CPU, memory, storage, and network capacity, sharing host infrastructure with other customers. Use it for the agent work you subscribed for. Specifically, do not:
- Mine cryptocurrency, or run distributed computing, model training, or rendering workloads unrelated to your agents.
- Proxy, relay, tunnel, or anonymise third-party network traffic through your container, or operate it as a VPN or open proxy.
- Use the platform as general file storage, a content delivery network, or a torrent client.
- Launch denial-of-service attacks, load tests, or traffic floods against us or anyone else.
- Deliberately generate excessive API volume, run runaway loops, or otherwise consume shared capacity in a way that degrades service for other customers.
If your usage threatens the health of the host or other tenants, we may throttle or pause the offending workload while we contact you. We will always tell you what we did and why.
8. Security
Isolation between customers is the single most important property of this platform. Do not test it uninvited.
- No reverse engineering. Do not decompile, disassemble, or otherwise attempt to derive the source code, system prompts, model configuration, or underlying architecture of the platform.
- No unauthorised security testing. Penetration testing, vulnerability scanning, fuzzing, and automated security tooling against Raileon infrastructure require prior written authorisation from security@raileon.com. Unauthorised testing is treated as an attack.
- No escaping your tenancy.Do not attempt to break out of your container, reach the host, access another customer’s network or data, or escalate privileges.
- No competitive extraction. Do not benchmark the platform for publication, or use its outputs to develop, train, or fine-tune a competing AI model or service.
Responsible disclosure
If you find a vulnerability, tell us at security@raileon.comand give us a reasonable window to fix it before disclosing it publicly. We will not pursue action under this policy against good-faith research that reports promptly, stops at proof of concept, does not access, modify, or exfiltrate anyone else’s data, and does not degrade the service. Include enough detail for us to reproduce the issue.
9. Enforcement
Most violations are mistakes — a misconfigured agent, an outreach list that should not have been imported. We handle those with a conversation, not a shutdown. Our normal escalation is graduated:
| Step | When we use it | What happens |
|---|---|---|
| 1. Notice | First or minor violation, or something that looks like a misconfiguration. | We email you, explain the problem, and give you a deadline to fix it. Service keeps running. |
| 2. Suspension | The notice deadline passed, the behaviour repeats, or the violation is serious. | We pause the offending agents or the workspace. Your data stays intact and you can still reach us and your billing portal. |
| 3. Termination | Suspension did not resolve it, or the violation is severe enough that continuing is not an option. | We close the account under the Terms. The 30-day data export window applies unless the law forbids it. |
Immediate suspension without prior notice is reserved for cases where waiting would cause damage: active harm to a person, clearly illegal activity, an active security threat or compromised account, sustained abuse of shared infrastructure, or a binding legal demand. We will tell you what happened as soon as we reasonably can after acting.
Appeals. If you think we got it wrong, email admin@raileon.com with your account details and what you believe we misread. A human reviews every appeal and we aim to respond within five business days. If we were wrong, we restore service and say so.
Enforcement under this policy does not entitle you to a refund of fees already paid, and it does not limit any other remedy available to us under the Terms of Service.
10. Reporting a Violation
If you have received something abusive from a Raileon agent, or you believe a customer is using the platform against this policy, tell us. Pick whichever address fits:
- Abuse, spam, or misuse — admin@raileon.com
- Security vulnerabilities or an attack in progress — security@raileon.com
- Privacy and data-protection concerns — privacy@raileon.com
Please include what happened, roughly when, and anything that helps us trace it — full email headers, message links, screenshots, or the sending address. Tell us how to reach you if we need more detail. We review every report, act where the report holds up, and we do not retaliate against people who report in good faith.
Raileon LLC
Miami, Florida
admin@raileon.com