Acceptable use policy
The short list of things you must not do with this website or with our applications, including the features that use a model. It exists so the rules are written down, not because we expect trouble.
- Effective
- Last updated
- Version
- 1.0.0
Scope Link to this section: Scope
This policy applies to everyone who uses this website and everyone who uses our applications. For the website it forms part of the terms of service. Where an application has its own terms, it forms part of those as well.
Nothing we build has been released yet, so today the website is the only place this policy has anyone to apply to. The rules for the applications are written down now rather than added later, when they would read as a response to whatever went wrong.
What you must not do Link to this section: What you must not do
- Break the law, or use our software to help anyone else break it.
- Infringe anyone's intellectual property, privacy or other rights.
- Upload, link to or transmit malware, or anything designed to interfere with software or hardware.
- Probe, scan or test the security of the site, an application or the infrastructure behind either, except under the responsible disclosure policy.
- Try to gain unauthorised access to any part of the site or an application, its server, or any connected system.
- Interfere with availability for other people — including any denial-of-service attempt.
- Circumvent rate limits, access controls, licence checks, or any other measure we use to protect the site or an application.
- Use the contact form to send unsolicited commercial messages, chain letters, or bulk submissions.
- Impersonate anyone, or misrepresent your affiliation with a person or organisation.
- Harvest personal data from the site or an application, including scraping any email address for a mailing list.
Acceptable use of AI features Link to this section: Acceptable use of AI features
Some features in our applications use a model. Some of those models run on your device; others send what you give them to a hosted provider. Which arrangement a feature uses is stated for that feature rather than left for you to guess, and the rules below apply either way.
You must not use an AI feature to:
- Generate, request, or attempt to generate material that sexually exploits or abuses a child. There is no context in which this is permitted, and it is the one item on this page we treat as a matter for the authorities rather than a matter of access.
- Generate content that harasses, threatens, or is directed at a specific person or group in order to intimidate them.
- Impersonate a real person or organisation in order to deceive — text, voice or images presented as genuinely theirs when they are not.
- Generate malware, exploit code, or working instructions whose purpose is to compromise a system.
- Attempt to extract the underlying model, its weights, its system prompt, or the data it was trained on, by any means — including prompting designed to make it disclose them.
- Use the output to train, fine-tune, evaluate into, or otherwise build a competing model or service.
- Automate use of a feature beyond ordinary personal or business use, including scripted or bulk access that degrades the feature for other people.
Where a feature sends what you give it to a hosted model, that processing is carried out by [MODEL_PROVIDER] — this detail has not been filled in yet. That provider has its own acceptable use policy, and it applies to your input in addition to this one. We do not control how they enforce it. A breach can end with your access suspended by them, by us, or by both — and a suspension by them is not one we are able to reverse.
Where a feature runs its model on your device, nothing you give it reaches a provider, so this policy is the only one that applies. That does not make the list above optional.
Automated access, crawling and AI training Link to this section: Automated access, crawling and AI training
Automated access is governed by /robots.txt. It states plainly what is allowed and what is not, and it is the authoritative answer rather than a hint.
Crawling in a way that contradicts robots.txt is a breach of these terms. That applies equally to search indexing, archiving, dataset collection and crawling for machine-learning training data — the purpose does not change the answer.
- Identify yourself honestly in the user-agent string. Disguising a crawler as a browser is a breach in itself.
- Keep request rates reasonable. This is a small site on modest infrastructure.
- Do not attempt to defeat rate limiting, whether by rotating addresses or otherwise.
If you want to crawl this site for something robots.txt does not permit, ask. The answer may well be yes; we would rather be asked than have it done quietly.
Enforcement Link to this section: Enforcement
We may block access for anything on this page, with or without notice. Where an application has accounts, we may suspend one. Where the conduct appears criminal we may report it, and we will cooperate with a lawful request from law enforcement.
We aim to respond proportionately. A misconfigured crawler gets an email; a deliberate attack does not.
Reporting a problem Link to this section: Reporting a problem
To report misuse of this site, or of one of our applications, write to contact@littlestone.world. Please include what you saw, when, and anything that would help us find it.
Security vulnerabilities go to the address on the security page instead — that route has a safe-harbour statement attached to it, and this one does not.
Changes to this policy Link to this section: Changes to this policy
The "last updated" date at the top moves whenever this content does.