Acceptable Use Policy
Last updated: 26 August 2026 · Effective: 26 August 2026
This policy applies to everyone who uses Olano Cloud. It forms part of the Olano Cloud Terms of Service, and breaching it is a material breach of that agreement.
It applies to you, to your Users, and to everything your Agents do — an automated action breaches this policy exactly as a manual one would. It also applies to anything you allow third parties to do through your Instance or your Agents.
The short version: don’t break the law, don’t harm people, don’t abuse the infrastructure, and don’t use the Model Gateway for anything other than running your own Agents.
-
Illegal and harmful activity
You must not use the Service to do, plan, promote or facilitate anything unlawful, or anything that:
- produces, solicits or distributes child sexual abuse material, or sexualises a minor in any way;
- produces or distributes non-consensual intimate imagery, or sexual content depicting a real person without their consent;
- harasses, stalks, threatens, defames, or incites violence or self-harm against anyone;
- promotes terrorism, violent extremism, or violence against a group on the basis of race, ethnicity, religion, sex, gender, sexual orientation, disability or any other protected characteristic;
- traffics in people, weapons, controlled substances, stolen goods or stolen data;
- facilitates fraud, deceptive commercial practice, money laundering, or the evasion of sanctions or tax;
- infringes copyright, trademark, patent, trade secret, privacy or any other right.
-
Security and integrity
You must not:
- develop, host or distribute malware, ransomware, exploit kits, botnets or command-and-control infrastructure;
- attempt to gain unauthorised access to any system, account, network or data, including other Instances, our control plane, or a third party’s systems;
- scan, probe, penetration-test or stress-test the Service or its infrastructure without our prior written permission;
- conduct or participate in a denial-of-service attack, or send from an Instance any traffic designed to overwhelm a third party;
- circumvent Instance isolation, our rate limits, Credit metering, spending caps, authentication, or any other technical restriction;
- reverse engineer or attempt to extract source code from the Service, except to the extent the law expressly permits despite this restriction.
Genuine security research on your own Instance is welcome. Report anything you find to [email protected] before disclosing it, and do not access anyone else’s data in the course of it.
-
Infrastructure abuse
An Instance is provisioned to run the Olano platform and your Agents. You must not use it to:
- mine cryptocurrency, or run any proof-of-work, staking, minting or comparable blockchain workload — this applies to every plan and especially to GPU plans;
- run a public proxy, VPN, exit node, torrent tracker, file-sharing service, or bulk email relay;
- host content or services unrelated to your use of the Olano platform;
- resell, sublicense or share access to the Instance, the Service or the Model Gateway with anyone outside your organisation, except through the platform’s own monetisation features;
- consume resources so as to degrade the Service for anyone else, or to evade the resource limits of the plan you pay for.
-
The Model Gateway
Credits are for running your own Agents on your Instance. You must not:
- resell Credits or Gateway access, or expose the Gateway as an API to people outside your organisation;
- use the Gateway to train, fine-tune or distil a competing model, or to benchmark it for a competitor without our written consent;
- deliberately circumvent the safety systems, usage policies or regional restrictions of an underlying model provider;
- obscure or misrepresent who is using the Service in order to obtain model access you would otherwise be refused.
Underlying providers have their own usage policies. Where a provider prohibits something, it is prohibited through the Gateway too.
-
Messaging, marketing and automated contact
Agents can contact people. When yours do, you are the sender, and you must not:
- send unsolicited bulk or commercial messages, on any channel, without the consent the law requires — including Singapore’s Spam Control Act and Do Not Call provisions, and equivalent rules wherever your recipients are;
- send to numbers or addresses obtained without a lawful basis, scraped, or bought without consent;
- ignore an opt-out, or make opting out difficult;
- breach the terms of the messaging platform you are using, including WhatsApp, Telegram, Slack, Discord and any email provider;
- impersonate a person or organisation, or misrepresent your identity, affiliation or purpose;
- conceal that a correspondent is automated where the law or the platform requires disclosure.
-
People, data and high-risk decisions
You must not use the Service to:
- make or materially inform decisions with legal or similarly significant effects on a person — employment, credit, housing, insurance, education, immigration, benefits, or the exercise of legal rights — without meaningful human review;
- perform biometric identification, emotion inference in a workplace or education setting, social scoring, or predictive policing, where the law restricts it;
- process special-category personal data (health, biometrics, sexual orientation, religion, political opinion, criminal records, children’s data) without a lawful basis and appropriate safeguards;
- operate safety-critical systems, or anything where failure could cause death, personal injury, or severe environmental or property damage;
- provide medical, legal, financial or other regulated professional advice to third parties without the qualifications, licences and human oversight your jurisdiction requires;
- generate content that deceptively depicts a real person or organisation, or that is presented as a genuine record, review, credential or official document when it is not.
-
Enforcement
We would rather ask you to fix something than switch it off, and where the circumstances allow that is what we will do. But we may, with or without notice depending on the seriousness and urgency:
- investigate suspected breaches;
- throttle, disable or restrict a feature, an Agent, a connector or an Instance;
- suspend or terminate your account under clause 18 of the Terms;
- preserve and disclose information where we are legally required to, or where there is a risk to life;
- report unlawful activity to the relevant authority.
Suspension or termination for a breach of this policy does not entitle you to a refund. We may act on a reasonable and good-faith belief that a breach has occurred or is imminent.
-
Reporting abuse
If you believe someone is using Olano Cloud in breach of this policy — including receiving messages from an Agent you did not consent to — tell us at [email protected] with as much detail as you can. We investigate every report.
-
Changes
We may update this policy as the Service, the law and the misuse we see all change. Material changes are notified under clause 20 of the Terms. Changes needed to address an urgent legal or safety risk take effect immediately.