← Back to home

AI Features Acceptable Use Policy

Last updated: September 25, 2026

PLEASE READ AND MAKE SURE YOU UNDERSTAND THIS AI FEATURES ACCEPTABLE USE POLICY (THE “POLICY”). BY CONNECTING AN AI PROVIDER CREDENTIAL OR USING ASK AI OR IN-PROJECT AI CALLS WITHIN THE SERVICE, YOU AGREE TO BE BOUND BY THIS POLICY IN ADDITION TO OUR TERMS OF SERVICE. IF YOU DO NOT WISH TO BE BOUND BY THIS POLICY, PLEASE DISCONTINUE YOUR USE OF THESE FEATURES IMMEDIATELY.

1. Purpose & Scope

This Policy governs every way a ByteRun account can call out to a third-party AI provider through the Service: the in-editor Ask AI assistant and code running inside your own project that calls an AI provider through ByteRun’s own credential-resolution layer. ByteRun sits between you and providers like OpenAI and Anthropic — resolving and injecting credentials on your behalf rather than you calling those providers directly — and this Policy exists because those providers require exactly that kind of platform to hold, and enforce, an equivalent policy of its own.

This Policy supplements, and does not replace, our Terms of Service. Where the two overlap, this Policy’s enforcement path in Section 7 is the narrower, AI-specific instrument; it does not limit our broader rights under the Terms.

2. Relationship to Provider Policies

Connecting a key does not only bind you to ByteRun’s rules — it binds you to that provider’s own usage policy too, and we enforce both. Whichever provider an organization or member connects, that provider’s own usage policy applies in full and is incorporated into this Policy by reference. A prompt or output that a provider’s own policy forbids is forbidden under this Policy as well, even where Sections 4 and 5 below do not separately spell it out.

3. Who This Policy Binds

  • A member who connects a personal key: bound for every project where they use it, in every organization they belong to.
  • An organization admin who connects an organization key: bound on behalf of the organization, and responsible for every member who then uses that shared connection.
  • Any member of an organization with an organization-level connection: bound the moment they use an AI feature against it, whether or not they personally added the key.

4. Prohibited Uses

You may not use an AI feature of the Service — or build something whose primary purpose is to use one — to do any of the following:

  • Illegal activity: anything that would be illegal to carry out yourself is prohibited to generate assistance for.
  • Harm to minors: any content sexualizing or endangering children. This is zero-tolerance and results in immediate suspension.
  • Weapons & CBRN uplift: designing or improving weapons, or chemical, biological, radiological, or nuclear materials capable of mass harm.
  • Malware & intrusion: writing malware, exploits, or code intended to gain unauthorized access to a system you do not own or are not authorized to test.
  • Fraud & impersonation: phishing infrastructure, fake reviews, deceptive impersonation of a real person or organization, or scam content.
  • Spam & manipulation: bulk unsolicited messaging, coordinated inauthentic behavior, or artificially inflating engagement.
  • Privacy violations: unauthorized surveillance, scraping to deanonymize an individual, or processing another person’s sensitive data without a lawful basis.
  • Circumventing safeguards: prompt-injecting or otherwise attempting to bypass a provider’s own content policy or extract its system prompt.
  • Intellectual property infringement: generating content that infringes another party’s copyright, trademark, or right of publicity, or falsely claims authorship.
  • Abusive load: automation designed to exhaust ByteRun’s or a provider’s rate limits, or to resell access to a connected key.

5. High-Risk Uses

Some uses are not prohibited outright, but our AI features are not qualified to make a final decision unsupervised. If an AI-assisted output feeds into a decision about a real person’s credit, employment, housing, insurance, immigration status, or legal rights, or into a medical diagnosis or treatment, a qualified human must review that output before it is acted on. Do not wire an AI feature’s output directly into an automated decision pipeline that skips that review.


6. Your Responsibilities Under BYOK

Under our bring-your-own-key (“BYOK”) model, the account being billed by the provider — and the account whose standing is at stake with that provider — is the one that owns the connected key, not ByteRun’s.

  • You are responsible for keeping your own OpenAI or Anthropic account in good standing. A suspension at the provider level is outside ByteRun’s control to reverse.
  • Do not share a personal key with anyone it was not issued to. Use an organization connection instead if others need shared access.
  • You are responsible for the content of your own prompts and the code your projects send to a provider, including code written by another member of a shared workspace.
  • We encrypt a stored key at rest and only ever decrypt it server-side to make a call on your behalf.

7. Enforcement

A violation of this Policy suspends the AI feature involved, not your account — unless the violation is severe enough that the two converge under our Terms of Service. We forward a hashed member identifier with every AI-provider call, which allows a provider to attribute an abuse report back to a specific account without exposing your identity to that provider.

Where we confirm a violation, we generally follow a graduated response:

  1. Warning: for a first-time, non-severe violation, we will notify you of the specific provision violated and what continued access requires.
  2. AI-feature suspension: Ask AI and in-project AI calls may be disabled for the specific member or organization involved, without affecting any other part of your account.
  3. Account-level action: reserved for the zero-tolerance categories in Section 4, or for repeated violations following a feature suspension, and handled under our Terms of Service.

8. Reporting a Violation

If you become aware of a project misusing an AI feature, or you receive an abuse notice that references ByteRun, please report it to support@byterun.io with as much detail as you can share, including any provider reference ID in the notice.

9. Changes to This Policy

We may update this Policy as our AI features change, including as underlying providers update their own usage policies. We will reflect the “Last updated” date above when we do, and will announce material changes to every organization with an active AI connection. Your continued use of an AI feature after a revision is posted constitutes acceptance of that revision.

10. Contact & Support

For any questions regarding this Policy, please contact us at support@byterun.io. ByteRun is operated by Sashidhar Thallam, an individual residing in India.

See also our Terms of Service and Privacy Policy.