Acceptable Use Policy

Last updated: August 2026

1. Who This Applies To

This Policy defines what counts as legitimate use of Workspacefy and what does not. It forms an integral part of the Terms of Service: breaching it means breaching the agreement.

It applies to you, to the people you invite into your workspaces, to the API credentials you issue, and to the AI assistants you connect. You are responsible for the use made under your account and through the credentials and connections you created, even when the one operating was another person or an automated system.

2. Prohibited Conduct

Do not use the platform to:

  • Carry out, facilitate or conceal any illegal activity.
  • Distribute malware, malicious code or content that damages third-party systems.
  • Send spam, unsolicited bulk messages or phishing scams.
  • Violate third-party rights, including intellectual property, privacy and likeness.
  • Publish content that incites violence, hatred or discrimination, or that involves the exploitation of minors.
  • Attempt to access a workspace, account or data that is not yours, by any means.
  • Probe, scan or test platform vulnerabilities outside what section 6 allows.
  • Reverse engineer the service or attempt to extract the platform's source code.
  • Circumvent the technical or commercial limits of your plan, including by creating multiple accounts or workspaces for that purpose.
  • Compromise platform stability or degrade the experience of other users.

3. Public API Use

The public API exists so you can integrate your workspace with your own systems. Credentials belong to the workspace that issued them and are non-transferable: do not share them, do not publish them in a repository or client application, and do not embed them in a product distributed to third parties.

The following are not permitted:

  • Circumventing, masking or otherwise attempting to evade your plan's request limits.
  • Issuing or distributing credentials in parallel in order to multiply the available quota.
  • Reselling, sublicensing or offering API access as your own service, without an agreement with Workspacefy.
  • Mirroring, replicating or systematically extracting a workspace's database to build an equivalent database outside the platform.
  • Automating access in ways that harm service stability for other users.

Every call is audited per request. Treat the usage records for what they are: the history of what was done on your behalf.

4. Automation and AI Assistants

Connecting an AI assistant to a workspace grants an external system the ability to act on your behalf. Treat that decision with the same care you would use in giving access to a person.

Always grant the smallest scope that solves your case: if the assistant only needs to read, do not authorize deletion. Periodically review active connections and revoke the ones you are no longer using.

Actions performed by a connected assistant are recorded as yours and you are responsible for them, including when the outcome was not what you expected. You may not use an AI connector to bulk-extract workspace content for purposes unrelated to using the product, nor to circumvent any limit in this Policy or in your plan.

5. Data You Enter

You decide what goes into the workspace, and that decision has consequences. Do not enter data you have no legal basis to process, nor third-party content you are not authorized to store.

Sensitive categories of data, health, biometrics, data about children and adolescents, among others, call for extra care, especially before exposing them through the public API or a connected AI assistant. Once data leaves the workspace through a scope you granted, control over it also depends on whoever received it.

6. Security and Responsible Research

Security research is welcome when done responsibly. It is acceptable to test against your own workspaces and your own credentials, without affecting other users and without accessing data that is not yours.

It is not acceptable to run load or denial-of-service tests, to exploit a flaw beyond the minimum needed to demonstrate it, to access or exfiltrate third-party data, or to publicly disclose a vulnerability before giving us reasonable time to fix it.

Found something? Write to info@workspacefy.com with the technical details and reproduction steps. We treat security reports as a priority.

7. Public Forms and Third-Party Content

Public forms collect data from people who are not platform users. Whoever publishes the form is responsible for what it collects: stating the purpose, having a legal basis for the processing, and answering requests from those who responded. Do not use forms to collect data deceptively, to impersonate another organization, or to capture credentials and payment details under false pretenses.

8. Consequences

Our response is proportionate to what happened and, whenever possible, starts with a warning. Depending on severity and repetition, we may:

  • Notify you and ask for a fix, with a deadline, the standard path for misuse without bad faith.
  • Throttle request rates, when the problem is volume and affects service stability.
  • Suspend or revoke an API credential, or disable an AI assistant connection, on its own.
  • Suspend the workspace or the account, reserved for serious breaches, risk to third parties, or repetition after a warning.
  • Terminate the account and, where the law requires, report to the competent authorities.

In cases of imminent risk to platform security or to third-party data, we may act first and communicate afterwards.

9. How to Report Abuse

If you have identified misuse of the platform, abusive content or a compromised account, write to info@workspacefy.com describing what happened. We review every report and protect the identity of whoever reports it.