1. Scope
This Acceptable Use Policy applies to all ReplyRoot accounts, organizations, uploaded files, knowledge bases, prompts, widget installations, conversations, agent actions, integrations, APIs, and related use of the service.
You are responsible for the conduct of your organization's users and for how your website visitors are invited to use the widget. You must promptly address misuse that occurs through your workspace.
2. Unlawful, harmful, or abusive use
You must not use ReplyRoot to:
- Violate applicable law, regulation, court order, sanctions, export controls, or another person's legal rights.
- Facilitate violence, terrorism, exploitation, trafficking, abuse, harassment, stalking, threats, or discrimination.
- Distribute illegal goods or services, instructions intended to enable serious wrongdoing, or content that creates an unreasonable risk of harm.
- Impersonate another person or organization without authorization.
- Use a customer-support interface to conceal unlawful monitoring, profiling, or decision-making.
3. Privacy, confidential information, and sensitive data
You must not:
- Collect, upload, disclose, or process personal data without an appropriate legal basis, notice, and authority.
- Upload passwords, authentication secrets, private keys, payment-card numbers, or credentials.
- Upload unnecessary medical, biometric, genetic, criminal-record, government-identifier, precise-location, children's, or other highly sensitive data.
- Use ReplyRoot to identify, track, profile, or surveil people unlawfully.
- Expose confidential customer or employee data through a public knowledge base or customer-facing response.
Regulated or highly sensitive use requires a separate written agreement, an appropriate security and privacy review, and any safeguards required by law. Do not use ReplyRoot for such data unless that use has been expressly approved in writing.
4. Security and malicious activity
You must not:
- Upload malware, ransomware, viruses, exploit code, malicious macros, decompression bombs, or files intended to damage or evade security controls.
- Probe, scan, attack, overload, disrupt, or attempt unauthorized access to ReplyRoot, another tenant, a service provider, or any connected system.
- Bypass authentication, origin restrictions, rate limits, usage limits, authorization checks, or tenant-isolation controls.
- Reverse engineer, scrape, copy, or automatically extract the service except where expressly allowed by law or written permission.
- Conduct penetration testing or security research against production or shared systems without prior written authorization and an agreed testing scope.
- Use prompts, uploaded documents, or messages to deliberately extract system instructions, secrets, private knowledge, or another organization's data.
Good-faith security concerns should be reported through the legal contact rather than tested against live systems without permission.
5. Spam, manipulation, and deceptive behavior
You must not use ReplyRoot to:
- Send unsolicited bulk messages, spam, phishing, scams, or fraudulent offers.
- Create fake reviews, fake support records, fabricated endorsements, or misleading customer identities.
- Misrepresent an AI system as a human where disclosure is required or where the representation would materially deceive a person.
- Manipulate customers into disclosing unnecessary sensitive information.
- Use the widget in a manner that obscures which business operates it or who will receive the conversation.
6. AI and high-impact decisions
ReplyRoot is designed for customer support assistance, not as an autonomous authority for consequential decisions. You must not use AI output as the sole basis for decisions that determine a person's legal rights, medical treatment, safety, employment, housing, education, insurance, credit, financial access, law-enforcement treatment, immigration status, or another similarly significant outcome.
You must provide qualified human review, appropriate explanations, and any legally required appeal or correction process. AI responses must not be presented as medical, legal, tax, investment, or other regulated professional advice unless reviewed and delivered by an appropriately qualified professional under a use expressly supported by written agreement.
7. Content rights and accuracy
You must not:
- Upload or distribute content that infringes copyright, trademark, privacy, publicity, confidentiality, or other rights.
- Use confidential information without authority.
- Intentionally create a knowledge base containing false, deceptive, dangerous, or materially outdated business information.
- Configure the assistant to make guarantees, promises, refunds, warranties, or contractual commitments that your organization does not authorize.
You are responsible for reviewing the accuracy, currency, and public suitability of uploaded knowledge and for correcting information that becomes outdated.
8. Usage limits and service integrity
You must not avoid or manipulate message, conversation, document, storage, rate, or other service limits. You must not create duplicate accounts or organizations to evade restrictions, interfere with usage measurement, or consume resources in a way that threatens availability for others.
Automated access, load testing, high-volume ingestion, or unusual traffic requires prior written approval unless it falls within a documented product feature and configured limit.
9. Monitoring and enforcement
We may investigate suspected violations using relevant account, usage, security, error, document, or conversation information. Where reasonably necessary, we may block a file, reject a request, reduce access, preserve evidence, suspend a workspace, terminate service, or notify affected providers or authorities.
We will consider the seriousness, frequency, intent, impact, customer cooperation, and legal requirements. Urgent threats may require immediate action without advance notice. Enforcement under this policy does not limit other rights available under the Terms, a customer agreement, or law.
10. Reporting concerns
Report suspected abuse, security issues, unlawful content, or privacy concerns through the legal contact. Include enough detail to identify the affected organization, widget, conversation, document, or event, but do not send passwords, access tokens, or unnecessary sensitive data.
Contact
Questions, legal notices, and privacy requests should be sent to ReplyRoot.
Email: support@replyroot.com
Business address: Benghazi, Libya