Safe and lawful use
Acceptable Use Policy
Rules protecting users, infrastructure, third parties, and lawful public-beta distribution and operation.
Pre-publication draft: this document is not an approved public-beta contract. Publication and open registration remain disabled.
Document: aup
Version: 2026-08-29-public-beta-draft-1
Effective date: 2026-08-29
Canonical localized-content SHA-256: c2466cc6b48bfe8a0d0b19555635a2fdfa102c2f7420d20a0f0daffde437548b
Approved multilingual document SHA-256: ea98c5d5dda14940ee4fd50ef005b291a8128c32e5b90e73f1b02cd400a4e023
Abuse: abuse@gutmask.xyz
Unlawful and harmful activity
Do not use GutMask to break applicable law, facilitate harm, or violate another person's rights.
- No malware, phishing, spam, credential theft, stalking, unauthorized surveillance, exploitation, or handling of stolen data.
- No child sexual abuse material, non-consensual intimate material, trafficking, violent threats, or other illegal content.
- No infringement of intellectual-property, privacy, publicity, confidentiality, or contractual rights.
- Do not submit data or instructions you lack authority and a lawful basis to use.
Security and resource abuse
Do not bypass authentication, access controls, licence or entitlement checks, quotas, rate limits, isolation, signing verification, or safety controls.
- No denial of service, disruptive scanning, cryptomining, persistence, destructive testing, or access beyond explicit authorization.
- Good-faith research must follow the Vulnerability Disclosure Policy and stop at the minimum proof.
- Do not expose secrets, personal data, or customer content in reports or public disclosures.
- Do not use one account or licence to serve unrelated third parties or evade edition limits.
Sanctions, export controls, and end use
Do not request, access, download, export, re-export, transfer, or use GutMask where that action is prohibited by applicable sanctions, export controls, or end-use restrictions.
- Do not conceal identity, country, holder capacity, destination, end user, or end use to evade a control.
- Do not use GutMask for prohibited military, weapons, nuclear, missile, chemical, biological, surveillance, or other restricted end uses.
- A target-market country is not automatic authorization; the exact action requires a current approved jurisdiction record.
- The operator may request only the minimum facts needed for lawful screening and may return a waitlist or refusal where evidence is missing or use is prohibited.
Content, automation, and third parties
A user remains responsible for workflows, outputs, recipients, and actions performed through GutMask and must provide appropriate human review for consequential use.
- Do not misrepresent automated output as verified fact, professional advice, or another person's statement.
- Do not use third-party systems, data, or accounts without their separate authorization.
- Customer deployments remain responsible for their users, local security, and lawful configuration.
Enforcement, reports, and appeals
The operator may investigate and proportionately restrict, suspend, or terminate access to protect people, the service, or lawful distribution. Evidence is minimized and access is limited to assigned roles.
- Abuse reports and appeals: abuse@gutmask.xyz
- Security reports follow the Vulnerability Disclosure Policy: security@gutmask.xyz
- Where safe and lawful, the affected user receives the reason and a review channel.
- Mandatory legal rights, whistleblowing, lawful reporting, and authorized security research are not restricted.