1. About this policy
This Acceptable Use Policy (the “Policy”) sets out what you may and may not do with Kirak Studio (the “Service”) and with the kirak.io website. It applies to you, your Users, and — through you — anything your Applications or End Users do on the Service. It is part of the Terms of Service, and terms defined there have the same meaning here.
You are responsible for all use of your Account and for the content and conduct of your Applications. If your End Users or customers do something through your Application that would breach this Policy, that is your responsibility to prevent and address.
2. Prohibited content and use
You must not use the Service to store, host, generate, transmit, or make available any content, or to carry out any activity, that:
Illegal and harmful
- is unlawful under any law that applies to you or to us, or promotes or facilitates unlawful activity;
- involves child sexual abuse material (CSAM) or any sexualisation of minors — we have zero tolerance, will remove it immediately, will preserve evidence, and will report it to the relevant authorities;
- is sexually explicit or pornographic, or operates an adult-content service — prohibited regardless of whether it is legal where you or your users are located;
- offers, promotes, or operates real-money gambling, betting, lotteries, or similar — prohibited regardless of local legality;
- promotes or incites violence, terrorism, or serious harm, or promotes hatred or discrimination against people based on a protected characteristic;
- harasses, bullies, threatens, defames, or stalks any person, or discloses another person’s private information without a lawful basis (doxxing).
Security and abuse
- distributes malware, ransomware, spyware, or other malicious code;
- operates command-and-control infrastructure, botnets, exploit kits, or phishing or credential-harvesting pages;
- sends spam or bulk unsolicited messages, or otherwise breaches anti-spam or electronic-marketing law (including the UK Privacy and Electronic Communications Regulations and the US CAN-SPAM Act);
- engages in fraud, deception, impersonation, or the creation of fake accounts, reviews, or engagement;
- scrapes, harvests, or collects personal data without a lawful basis or in breach of a website’s terms.
Cryptocurrency
- performs cryptocurrency mining, coin minting, or any proof-of-work computation — prohibited on all plans;
- operates a cryptocurrency exchange, mixer or tumbler, token sale or ICO, or custodial wallet service without our prior written approval.
Intellectual property
- infringes or misappropriates any patent, copyright, trademark, trade secret, or other proprietary right, or distributes pirated or counterfeit material.
Regulated data
- stores or processes Protected Health Information as defined by the US Health Insurance Portability and Accountability Act (HIPAA), or uses the Service in any way that would make Sizmic a “business associate” — the Service is not HIPAA-eligible and we do not sign Business Associate Agreements;
- stores or processes payment card data in a way that would place Sizmic in scope for PCI DSS beyond redirecting payments to a compliant payment processor;
- stores or processes special category personal data (such as data about health, race, religion, sexual orientation, or biometric or genetic data) without configuring the Service appropriately and having a lawful basis to do so.
3. Prohibited technical practices
You must not:
- circumvent, disable, or interfere with usage limits, quotas, rate limits, metering, or billing;
- use the Free plan or Staging instances as permanent production infrastructure, or create multiple accounts to evade limits or free-tier restrictions;
- probe, scan, load-test, or penetration-test the Studio platform, its APIs, or its infrastructure without our prior written permission (you may of course test your own Application);
- attempt to gain unauthorised access to the Service, other customers’ data, or any account, system, or network;
- disrupt or degrade the Service, the underlying infrastructure, or other customers, including through denial-of-service attacks or deliberate resource exhaustion;
- reverse engineer, decompile, or disassemble the Studio software, except to the extent this restriction is prohibited by law;
- share account credentials, or use automated means to create accounts;
- run open proxies, VPN or anonymisation services, or Tor exit nodes;
- run public BitTorrent trackers, or use the Service for large-scale peer-to-peer file distribution;
- use the AI Build Agent to generate any content or code prohibited by section 2, including malware, exploits, phishing pages, or instructions for wrongdoing.
4. High-risk uses
You must not use the Service in any situation where a failure or defect could lead to death, personal injury, or severe physical, environmental, or property damage — for example in the operation of medical devices, life-support systems, emergency services, aircraft or other vehicle navigation or control, nuclear facilities, or weapons systems — unless you have a separate written agreement with us that expressly covers that use. The Service is provided “as is” and is not designed or supported for these uses.
5. Reselling and providing the Service to others
You may build, deploy, and operate backends for your own clients, including on the Agency plan.
You may not, without a separate written partner agreement with us:
- resell, sublicense, rent, lease, or white-label the Service;
- provide Studio accounts, console access, or the AI Build Agent to third parties as a service; or
- act as a hosting or platform provider to third parties using the Service as the underlying infrastructure.
The distinction: delivering a finished backend to a client is fine; giving third parties access to Studio itself is not.
6. Reporting abuse
To report content or activity that breaches this Policy, email abuse@kirak.io with the URL or account involved and a description of the issue. We review reports and take action where appropriate, but we do not undertake to monitor the Service and are not responsible for Customer Content.
7. Enforcement
If we reasonably believe you have breached this Policy, we may — with or without notice, depending on the severity and the risk to others — take any of the following steps, limited to what is reasonably necessary:
- ask you to remove or remediate the content or activity;
- remove or disable access to the offending content;
- throttle, restrict, or suspend the affected Application, Instance, or Account;
- terminate your Account under the Terms of Service;
- preserve information and cooperate with law enforcement; and
- report the matter to the relevant authorities where required or appropriate.
A suspension or termination under this Policy does not entitle you to any refund, and does not limit any other rights or remedies we have.
Where the breach is minor and curable and does not create a risk to others, we will normally give you notice and a chance to fix it first.
8. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified as described in the Terms of Service. Your continued use of the Service after a change takes effect means you accept the updated Policy.
9. Contact
Abuse and Policy questions: abuse@kirak.io
General legal contact: legal@kirak.io