Acceptable Use Policy
Effective date: July 31, 2026
1. Introduction
This Acceptable Use Policy ("AUP") supplements the Terms of Serviceand is incorporated into them by reference. It governs your use of Riven Inc.'s products, services, websites, and applications (collectively, the "Services"). Capitalized terms used but not defined here have the meaning given in the Terms of Service. By using the Services, you agree to comply with this AUP. Violations may result in suspension or termination of your account.
2. Absolute Prohibitions
The following uses are strictly prohibited under all circumstances. We will act immediately upon discovery of any violation and will cooperate fully with law enforcement.
- Child sexual abuse material (CSAM): Generating, storing, distributing, or facilitating access to any material that sexualizes minors. We report all detected CSAM to the National Center for Missing & Exploited Children (NCMEC).
- Weapons of mass destruction: Generating content that assists in the development, production, or use of biological, chemical, nuclear, or radiological weapons, including synthesis instructions for harmful agents.
- Critical infrastructure attacks: Targeting, disrupting, or gaining unauthorized access to critical infrastructure, including power grids, water systems, healthcare systems, transportation networks, and emergency services.
3. Prohibited AI-Specific Uses
- Deepfakes without consent: Creating synthetic media that depicts a real person without their informed consent, including non-consensual intimate imagery or deceptive impersonation.
- Coordinated disinformation: Generating and disseminating content in coordinated campaigns designed to deceive the public or manipulate public opinion at scale.
- Malware and exploit code: Generating functional malware, ransomware, exploits, or code designed to cause harm, exfiltrate data, or gain unauthorized access.
- Credential stuffing tools: Generating tools or lists intended for automated credential stuffing, account takeover, or brute-force attacks.
4. Prohibited Platform Conduct
- Circumventing rate limits, quotas, or usage controls.
- Sharing API keys or account credentials with unauthorized parties.
- Reselling access to the Services without an applicable enterprise agreement.
- Reverse-engineering, model extraction, or attempting to reconstruct the Services' underlying models or proprietary technology.
- Impersonating another person, organization, or Riven personnel.
- Using the Services to violate any applicable law or regulation.
5. Jailbreaking and Prompt Injection
Intentionally bypassing, circumventing, or defeating the safety guardrails, content filters, or usage restrictions of the Services is prohibited. This includes jailbreaking attempts, prompt injection attacks designed to override system instructions, and any technique intended to make the Services produce outputs that would otherwise be blocked. Authorized security research is addressed separately in Sections 9 and 13.
6. Political and Electoral Manipulation
Using the Services to engage in political or electoral manipulation is prohibited, including:
- Creating deceptive political content designed to mislead voters about candidates, ballot measures, or election procedures.
- Engaging in voter suppression, including false information about voting methods, locations, or eligibility.
- Creating fake political movements or astroturfing campaigns that fabricate grassroots support.
- Generating synthetic media of political figures intended to deceive voters about their statements, actions, or positions.
7. Biometric and Surveillance Abuse
Using the Services to conduct unauthorized surveillance or process biometric data without consent is prohibited, including:
- Unauthorized facial recognition or identification of individuals without their consent.
- Biometric categorization based on race, ethnicity, religion, or other protected characteristics.
- Emotion inference or affect recognition applied to individuals without their informed consent.
- Location tracking or monitoring of individuals without their knowledge and consent.
8. Multi-Account Abuse and Ban Evasion
Coordinating activity across multiple accounts to circumvent limits, amplify prohibited content, or evade enforcement is prohibited. This includes automated or programmatic account creation, evading bans or suspensions by creating new accounts, and using the Services through proxies or other means intended to obscure the identity of a banned user.
9. High-Risk Uses — Permitted with Controls
The following high-risk uses are permitted only when the stated controls are in place:
- Healthcare: permitted for administrative and operational uses, not for diagnosis. A Business Associate Agreement (BAA) is available for covered entities handling protected health information.
- Legal research: permitted for research and drafting assistance, not as a substitute for professional legal advice.
- Financial analytics: permitted for data analysis and modeling, not as investment or financial advice.
- Security research: permitted only when conducted against systems you own or are authorized to test, and consistent with Section 13.
- Educational tools for minors: permitted only on dedicated, controlled surfaces — not on consumer surfaces. Compliance with COPPA and FERPA is required.
10. AI Disclosure Requirement
If you deploy AI outputs to end users — for example, through a chatbot, agent, or content-generation feature — you must clearly disclose to those end users that they are interacting with, or consuming content generated by, an AI system. Disclosure must be clear, prominent, and presented in a manner appropriate to the medium of delivery.
11. Human-in-the-Loop for High-Risk Uses
When deploying the Services for uses that could materially affect individuals' legal, healthcare, financial, employment, housing, or other consequential rights, a qualified human professional must review the outputs before any action is taken. AI outputs must not be the sole basis for decisions about credit, employment, housing, government benefits, healthcare, or legal status. The reviewer must have the competence to evaluate the output in context and the authority to override it.
12. Enforcement
We may take enforcement action when we become aware of a violation, including: issuing a warning; throttling or limiting access; suspending an account; or terminating an account entirely. We may act without prior notice where necessary to prevent ongoing or imminent harm. We cooperate with law enforcement and will report CSAM to NCMEC. We reserve the right to remove content, disable features, and take any other action we deem appropriate to protect the Services and our users.
13. Responsible Disclosure
If you believe you have discovered a security vulnerability, please report it to [email protected]. We will acknowledge your report within 5 business days. We will not pursue legal action against security researchers who act in good faith, avoid disrupting services, and provide us a reasonable opportunity to remediate before any public disclosure.
14. Reporting Violations
To report a violation of this AUP, contact [email protected]. Please include sufficient detail to allow us to investigate, including relevant identifiers, timestamps, and a description of the conduct.
15. Contact
Questions about this AUP? Contact us at [email protected].