1Scope
This Acceptable Use Policy (the "Policy") forms part of the Terms of Service between you and Neox and applies to the Neox desktop client, command-line tools, website, APIs, and cloud services (collectively, the "Service").
The Policy applies in both usage modes. Even when you use your own API keys (BYOK) and requests do not pass through our servers, you may not use the Neox client for activities prohibited here. You must also comply with the usage policies of whichever model provider you use.
If you let others use the Service through your account, you are responsible for their conduct as if it were your own.
The prohibitions below are examples, not an exhaustive list. We reserve the right to act on conduct that is not listed but is equivalent in nature or harm.
2Prohibited: Malware and Unauthorized Access
You may not use the Service to develop, generate, refine, obfuscate, or distribute code or techniques intended to harm other people's systems, including:
- viruses, worms, trojans, ransomware, spyware, keyloggers, botnet clients, or other malware;
- exploit code, privilege-escalation chains, or attack payloads targeting systems you are not authorized to test;
- tools for circumventing security controls, including cracking software licences, bypassing DRM, password cracking, or credential stuffing;
- phishing pages, spoofed login screens, or content designed to steal credentials, payment details, or one-time codes;
- denial-of-service tooling, or scripts for traffic amplification or resource exhaustion against others.
You may not use the Service to scan, probe, penetrate, or otherwise access any network, server, account, or data without express written authorization.
Exception: authorized security research is permitted. If you perform penetration testing, vulnerability research, or red-team work, you must hold written authorization from the owner of the target system and stay within its scope. The burden of proof is on you.
3Prohibited: Illegal and Harmful Content
Child sexual exploitation content is subject to zero tolerance. On detection we terminate the account permanently and without refund, report to law enforcement and relevant hotlines as required by law, and preserve evidence. No warning, no appeal window.
You may not use the Service to generate, upload, store, or distribute:
- child sexual abuse material (CSAM), or any sexualized depiction of minors — real, drawn, or AI-generated;
- non-consensual intimate imagery, or sexualized deepfakes of real people;
- content that is criminal in an applicable jurisdiction, including terrorist propaganda, recruitment material, and violent extremist content;
- actionable instructions for committing violence, building weapons (including biological, chemical, radiological, and nuclear), or manufacturing explosives;
- content that encourages suicide, self-harm, or eating disorders;
- operational guidance for manufacturing or trafficking drugs or other controlled goods.
4Prohibited: Abuse Directed at People
- Harassment and bullying
- Generating or sending content that threatens, intimidates, or humiliates specific individuals; assisting stalking; organizing pile-ons against a person.
- Hateful content
- Attacking, demeaning, or inciting hatred or violence against people based on race, ethnicity, national origin, religion, gender, sexual orientation, disability, or other protected characteristic.
- Spam
- Bulk generation or delivery of unsolicited commercial email, comments, direct messages, or signups; generating text variants to defeat spam filters; operating fake-account farms.
- Disinformation and impersonation
- Generating fabricated news, forged official statements, or falsified evidence intended to mislead; impersonating real individuals, organizations, or government bodies; producing fake reviews, ratings, or manufactured public opinion.
- Fraud
- Facilitating scams, pyramid or Ponzi schemes, money laundering, identity theft, or financial fraud of any kind.
You may not use the Service to generate misleading election-related content, including fabricated statements by candidates, false information about voting times, locations, or eligibility, or mass-produced content posing as authentic voter opinion.
5Prohibited: Infringing IP and Privacy
You may not use the Service to infringe intellectual property rights, including reproducing, adapting, or distributing copyrighted works without authorization, or circumventing technical protection measures. You are responsible for ensuring that what you submit and how you use Output do not infringe third-party rights.
You may not use the Service to violate the privacy of others, including:
- processing personal data without a lawful basis, or using the Service for doxxing;
- processing special-category data (health, biometric, religious belief, sexual orientation) without a legal basis and appropriate safeguards;
- building facial recognition databases, or performing biometric tracking and identification without consent;
- conducting mass surveillance, or tracking individuals to suppress freedom of expression or association.
6High-Risk Uses Require Human Review
In the contexts below, AI Output must not produce legal or similarly significant effects on a person without qualified human review and final human decision-making.
- medical diagnosis, treatment plans, medication advice, or mental-health crisis intervention;
- legal advice, sentencing recommendations, or immigration and asylum eligibility determinations;
- credit decisions, insurance underwriting and pricing, hiring and termination decisions, housing access;
- critical infrastructure control, including power, water, transport, and industrial control systems;
- safety-critical engineering systems, including control code for aviation, automotive, medical devices, and nuclear facilities;
- law enforcement decisions, risk profiling, and automated measures that restrict rights.
If you operate in a regulated industry, you are responsible for your own compliance with applicable rules (such as HIPAA, GLBA, PCI DSS, or the EU AI Act). The Service provides no assurance for such compliance absent a separately signed written agreement.
7Prohibited: Circumventing Limits and Platform Abuse
You may not take steps to circumvent the technical or contractual limits we place on the Service, including:
- evading quotas, rate limits, concurrency limits, or metering;
- creating multiple accounts to obtain additional free allowance, or using disposable email addresses, virtual numbers, or automated scripts to sign up in bulk;
- sharing or reselling account credentials so that more people or systems use the Service than your plan permits;
- using proxies, VPNs, or spoofed device fingerprints to hide account linkage or evade geographic restrictions;
- attempting to bypass, disable, or induce the model to bypass safety filters and content protections (including prompt injection and jailbreak techniques).
You may not reverse engineer, decompile, or disassemble the Service, or attempt to obtain its source code, model weights, system prompts, or internal implementation, except where applicable law expressly prohibits that restriction.
Without our prior written consent, you may not resell, distribute, rent, or lease the Service, or use it to offer a substantially equivalent competing product to third parties.
8Automation, Scraping, and Resource Use
The Service includes agent and automation capabilities, and ordinary automated use is encouraged. The following is not:
- issuing requests in a way that places unreasonable load on the Service or other users, or deliberately triggering rate limits to probe system boundaries;
- scraping third-party websites without authorization, in breach of the target site's terms, or in disregard of robots.txt;
- scraping or bulk-collecting our website, documentation, or API responses to build a competing dataset or train a model;
- using the Service as a proxy, relay, or traffic launderer to obscure the origin of requests;
- running persistent idle tasks unrelated to real work in order to occupy resources or inflate usage metrics.
We may rate-limit or temporarily degrade anomalous traffic to protect the stability of the Service. Doing so is not a breach on our part.
9How We Enforce
We identify violations through automated abuse signals, user reports, and human review. We do not proactively read your code or prompt content; detection relies primarily on metadata, traffic patterns, and security events.
Where we find a violation, we take one or more of the following actions, weighing severity, intent, repetition, and actual harm:
- Warning
- For a first, unintentional, minor violation we will normally notify you and ask you to remediate within a stated period.
- Feature limits
- Reduced rate limits, restriction of specific capabilities, or a requirement for additional verification.
- Suspension
- Temporary loss of account access during an investigation or until remediation is complete.
- Termination
- Permanent closure of the account and end of service, for serious violations, repeat violations, or failed remediation.
- Escalation
- Reporting to law enforcement or relevant bodies and preserving evidence, where required by law or necessary to protect someone's physical safety.
For serious breaches — including CSAM, credible threats of violence, malware distribution, large-scale fraud, or attacks on third-party systems — we terminate immediately, without prior notice, and no fees already paid are refunded. This matches the "no refund on termination for cause" rule in the Terms of Service.
If you believe an action was mistaken, you may appeal within 30 days of the notice, with supporting information. We will re-review and respond within a reasonable time. Terminations relating to CSAM are not subject to appeal.
10Reporting Abuse
If you see someone using Neox in breach of this Policy, email support@neox-dev.com with "Abuse report" in the subject line.
To help us act, please include where possible: identifying details of the account or content, when it happened, the specific conduct you observed, and any supporting screenshots or links. If there is an urgent risk to physical safety, mark the subject "Urgent".
We treat reports confidentially unless disclosure is required by law or necessary for the investigation. We do not reveal a reporter's identity to the reported party.
11Changes to This Policy
We may update this Policy from time to time to address new forms of abuse, legal developments, or changes in what the Service can do. We give advance notice of material changes by in-product notice or email.
Changes made to address urgent security or legal risk may take effect immediately, with notice as soon as practicable afterwards. Continued use after changes take effect constitutes acceptance of the updated Policy.

