Viro AI API Acceptable Use Policy

Effective August 1, 2026

1. Scope

This Acceptable Use Policy ("Policy") governs your access to and use of:

  • the Viro AI API;
  • the Viro developer console;
  • Viro model routers;
  • Viro-operated tools;
  • model Output generated through the Service; and
  • any application, product, or service you build using the Service,

collectively, the "Service."

This Policy forms part of the Viro AI API Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.

You must comply with this Policy and ensure that your employees, contractors, agents, Customer Applications, and End Users comply with it.

A violation of this Policy may result in rejected requests, restricted features, suspension, or termination of your account.

2. General Rule

You may not use the Service to engage in, facilitate, materially assist, encourage, conceal, or automate conduct that is illegal, abusive, deceptive, exploitative, or likely to cause serious harm.

A use is prohibited when the Service is a meaningful part of carrying out the prohibited activity, even if the activity occurs outside the Service.

Attempting a prohibited activity is itself a violation, whether or not the attempt succeeds.

3. Child Sexual Exploitation and Abuse

Viro has zero tolerance for child sexual exploitation or abuse.

You may not use the Service to:

  • generate, transform, describe for exploitative purposes, distribute, solicit, obtain, or facilitate child sexual abuse material ("CSAM");
  • sexualize a person known or reasonably suspected to be under 18;
  • create sexual content depicting an actual or fictional minor;
  • create sexualized images of an adult portrayed as a minor;
  • groom, entice, extort, threaten, or exploit a minor for sexual purposes;
  • facilitate child sex trafficking or sexual contact with a minor;
  • identify, locate, or target a minor for sexual exploitation;
  • evade systems intended to detect or prevent child exploitation; or
  • provide instructions intended to enable any of the above.

This prohibition includes photorealistic, illustrated, animated, digitally altered, and AI-generated content.

Viro may immediately suspend or terminate accounts associated with suspected child sexual exploitation. We may preserve relevant information and report apparent violations to the National Center for Missing & Exploited Children, law enforcement, Providers, or other authorities where required or permitted by law.

Legitimate child-safety, law-enforcement, legal, or academic work must be authorized, handled securely, and must not submit or generate CSAM through the Service.

4. Sexual Exploitation and Non-Consensual Content

You may not use the Service to:

  • create or distribute non-consensual intimate imagery;
  • digitally undress a real person;
  • create sexual deepfakes of an identifiable person without that person's consent;
  • facilitate sexual extortion, coercion, trafficking, or exploitation;
  • advertise or solicit non-consensual sexual services;
  • generate sexual content involving coercion or an inability to consent;
  • expose or threaten to expose intimate information to control or harm a person; or
  • facilitate sexual violence.

You are responsible for obtaining all legally required consent before creating or modifying intimate or sexual content involving an identifiable adult.

5. Illegal Activity, Fraud, and Deception

You may not use the Service to plan, commit, facilitate, conceal, or evade detection of illegal activity.

Prohibited conduct includes:

  • fraud, theft, embezzlement, or money laundering;
  • phishing or impersonation intended to obtain money, credentials, or sensitive information;
  • creating or altering counterfeit identification, licenses, credentials, certificates, invoices, prescriptions, financial records, or government documents;
  • facilitating tax evasion or sanctions evasion;
  • operating scams, pyramid schemes, or deceptive investment schemes;
  • knowingly making materially false representations in commerce;
  • evading law enforcement or regulatory requirements;
  • trafficking prohibited or unlawfully obtained goods;
  • facilitating unauthorized gambling or wagering;
  • providing customized assistance intended to commit a crime; or
  • concealing the proceeds or evidence of unlawful conduct.

This section does not prohibit general legal information, fictional content, fraud-prevention work, compliance testing, or discussion of unlawful conduct that does not meaningfully facilitate wrongdoing.

6. Violence, Weapons, and Physical Harm

You may not use the Service to:

  • plan, threaten, encourage, or facilitate violence against a person or group;
  • identify or track a person for the purpose of harming them;
  • meaningfully assist the construction, acquisition, modification, deployment, or concealment of a weapon intended to harm people;
  • develop or deploy chemical, biological, radiological, or nuclear weapons;
  • meaningfully increase the destructive capability of a weapon;
  • facilitate terrorism, violent extremism, assassination, kidnapping, or hostage-taking;
  • praise or promote a violent extremist organization in a manner intended to recruit, radicalize, or support operations;
  • provide operational instructions for committing violent acts; or
  • evade safeguards designed to prevent physical harm.

This section does not prohibit high-level information about weapons, legitimate safety training, historical analysis, fictional writing, lawful sporting use, defensive security, emergency preparedness, or authorized research that does not meaningfully facilitate harm.

7. Cybersecurity and Malicious Software

You may not use the Service to compromise, disrupt, damage, surveil, or obtain unauthorized access to a system, account, device, network, or dataset.

Prohibited uses include:

  • deploying malware, ransomware, spyware, credential stealers, botnets, destructive code, or unauthorized cryptominers;
  • generating or adapting exploit code for unauthorized use;
  • stealing passwords, session tokens, API keys, or authentication credentials;
  • phishing, credential stuffing, or account takeover;
  • evading endpoint protection, monitoring, authentication, or access controls for malicious purposes;
  • conducting denial-of-service or resource-exhaustion attacks;
  • exfiltrating or destroying data without authorization;
  • establishing unauthorized persistence;
  • probing or scanning systems without permission;
  • purchasing, selling, or distributing stolen credentials or access; or
  • concealing the source, control infrastructure, or proceeds of a cyberattack.

Legitimate cybersecurity uses are permitted when appropriately authorized and reasonably designed to prevent or mitigate harm. Examples include:

  • defensive security analysis;
  • vulnerability remediation;
  • secure-code review;
  • malware classification;
  • threat-intelligence research;
  • authorized penetration testing;
  • capture-the-flag exercises;
  • sandboxed demonstrations; and
  • academic security research.

You are responsible for obtaining authorization before testing or interacting with systems you do not own.

8. Harassment, Threats, and Abuse

You may not use the Service to:

  • threaten, intimidate, stalk, or harass a person;
  • encourage others to target or abuse a person;
  • coordinate persistent or large-scale harassment;
  • disclose or facilitate the disclosure of private identifying information with the intent to harm;
  • generate false allegations about an identifiable person while presenting them as fact;
  • impersonate a real person in a materially deceptive or harmful manner;
  • shame, blackmail, or coerce a person;
  • target a person based on a protected characteristic in a manner likely to cause harm; or
  • create content intended to incite imminent violence or discrimination.

This does not prohibit criticism, satire, parody, opinion, public-interest reporting, or discussion of public figures, provided it is not used for unlawful harassment, deception, or harm.

9. Hate and Violent Extremism

You may not use the Service to:

  • advocate hatred or violence against people based on a protected characteristic;
  • dehumanize or promote the exclusion or subjugation of a protected class;
  • recruit for, materially support, or coordinate a violent extremist organization;
  • create propaganda intended to radicalize people into violence;
  • praise violent attacks in a manner intended to inspire further violence; or
  • identify or target people for violence based on a protected characteristic.

Protected characteristics include race, color, ethnicity, national origin, religion, caste, sex, gender, gender identity, sexual orientation, disability, and other characteristics protected by applicable law.

This section does not prohibit counterspeech, academic research, journalism, historical analysis, moderation, or efforts to identify and prevent hateful or extremist activity.

10. Self-Harm and Dangerous Conduct

You may not use the Service to:

  • encourage, glorify, or pressure a person to engage in suicide or serious self-harm;
  • provide personalized instructions intended to help a person seriously injure or kill themselves;
  • operate a service that promotes eating disorders or other self-destructive behavior;
  • target a vulnerable person with content intended to worsen a crisis; or
  • facilitate a suicide pact, challenge, or competition.

Supportive conversations, prevention resources, clinical research, education, and content intended to reduce harm are permitted.

You may not represent model Output as a substitute for emergency services or qualified medical care.

11. Privacy, Surveillance, and Personal Data

You may not use the Service to:

  • obtain, infer, expose, or distribute highly sensitive personal information without a lawful basis;
  • identify an anonymous person for the purpose of harassment, punishment, discrimination, or harm;
  • create or maintain unlawfully obtained databases of personal information;
  • conduct unlawful surveillance or tracking;
  • intercept private communications without authorization;
  • determine a person's precise location for a harmful purpose;
  • infer highly sensitive traits for unlawful discrimination or manipulation;
  • perform face recognition or biometric identification where prohibited by law;
  • impersonate a person to bypass identity-verification systems;
  • facilitate stalking or domestic abuse; or
  • violate another person's privacy, confidentiality, publicity, or data-protection rights.

You must have all necessary rights, permissions, notices, and lawful bases before submitting personal information to the Service.

12. High-Impact Decisions

You may not use the Service as the sole basis for making a decision that determines a person's eligibility, selection, or access in a high-impact area, including:

  • employment;
  • housing;
  • credit or lending;
  • insurance;
  • health care;
  • education;
  • legal services;
  • essential utilities;
  • government benefits; or
  • similarly significant services or opportunities.

Uses in these areas must comply with applicable law and include appropriate:

  • human oversight;
  • testing and validation;
  • documentation;
  • transparency;
  • bias and discrimination controls;
  • security safeguards;
  • opportunities for correction or appeal; and
  • professional judgment.

You may not use the Service to discriminate unlawfully or circumvent protections against discrimination.

13. Medical, Legal, Financial, and Safety-Critical Uses

You may use the Service to assist qualified professionals, provide general information, organize information, or support administrative tasks.

You may not:

  • falsely represent Output as professional advice from a qualified person;
  • conceal that consequential content was generated by AI where disclosure is legally required;
  • rely on Output without appropriate review in a safety-critical context;
  • provide a diagnosis, prescription, legal determination, or individualized investment instruction through a fully automated system where prohibited by law;
  • use Output to replace legally required professional judgment; or
  • deploy the Service in a manner that creates an unreasonable risk of death, injury, financial loss, or deprivation of legal rights.

You are responsible for evaluating Output and implementing appropriate human review.

14. Deception, Impersonation, and Synthetic Media

You may not use the Service to create or distribute deceptive content that is reasonably likely to cause material harm.

Prohibited uses include:

  • impersonating a person or organization to defraud or deceive;
  • fabricating evidence for a legal, employment, insurance, financial, or disciplinary proceeding;
  • falsely representing AI-generated content as an authentic recording of an identifiable person where doing so is likely to cause harm;
  • removing or altering provenance labels or watermarks where prohibited by law or Provider policy;
  • generating fake endorsements or testimonials presented as genuine;
  • operating deceptive customer-support or government-service impersonation schemes; or
  • creating synthetic media intended to suppress voting, incite violence, or defraud the public.

Satire, parody, fiction, artistic expression, and authorized simulations are permitted when they are not used to cause unlawful or material deception.

15. Political Activity and Public Opinion

The Service may be used for ordinary political discussion, journalism, research, voter education, policy analysis, advocacy, and lawful campaign communications.

You may not use the Service to:

  • conduct coordinated inauthentic influence operations;
  • operate networks of deceptive accounts that conceal their common control;
  • impersonate candidates, election officials, government agencies, or news organizations in a materially deceptive manner;
  • knowingly provide false information about when, where, or how to vote;
  • intimidate or discourage legally eligible people from voting;
  • generate deceptive synthetic media intended to materially interfere with an election;
  • target political messages using unlawfully obtained sensitive personal information;
  • conceal foreign sponsorship or coordination where disclosure is legally required; or
  • automate political manipulation, astroturfing, or engagement fraud at scale.

You are responsible for complying with election, campaign-finance, advertising, disclosure, lobbying, and communications laws applicable to your use.

16. Spam and Platform Manipulation

You may not use the Service to:

  • generate or distribute unsolicited bulk communications in violation of applicable law or platform rules;
  • automate spam campaigns;
  • create deceptive reviews, ratings, referrals, clicks, impressions, followers, or engagement;
  • evade anti-spam systems or platform enforcement;
  • operate fake accounts at scale;
  • manipulate search, marketplace, advertising, or recommendation systems through deceptive activity;
  • distribute chain letters, scams, or malicious links; or
  • generate content for lists obtained without appropriate permission.

Legitimate marketing and customer communications are permitted when sent with appropriate authorization, disclosures, and opt-out mechanisms.

17. Intellectual Property and Other Rights

You may not use the Service to:

  • infringe or misappropriate intellectual-property rights;
  • distribute pirated or unlawfully obtained material;
  • remove copyright-management information for an unlawful purpose;
  • falsely claim ownership or authorship;
  • misuse another party's trademark or brand to deceive;
  • extract protected content from a system without authorization; or
  • violate confidentiality, contractual, publicity, or personality rights.

You are responsible for determining whether you have the right to submit Input and use or distribute Output.

18. Model Extraction and Competing Models

Unless expressly permitted by Viro and the applicable Provider or model license, you may not use the Service to:

  • reverse engineer an underlying proprietary model;
  • discover, reconstruct, extract, or replicate model weights;
  • systematically extract model behavior or training data;
  • bypass technical measures intended to prevent model extraction;
  • use automated queries primarily to create an unauthorized substitute for a proprietary model; or
  • violate an applicable model license or Provider restriction concerning competitive model development.

This section does not prohibit ordinary evaluation, benchmarking, interoperability testing, or research that complies with applicable Provider terms and law.

19. Web Search, Web Retrieval, and Tools

When using viro:web_search, viro:web_fetch, function calling, or another tool, you may not:

  • access a system or resource without authorization;
  • retrieve private, internal, loopback, link-local, or otherwise restricted network resources;
  • bypass authentication, paywalls, access controls, robots restrictions, or technical safeguards unlawfully;
  • scrape or retrieve content at abusive volume;
  • overload a website or third-party service;
  • probe for vulnerabilities without permission;
  • retrieve or distribute unlawfully obtained personal information;
  • use retrieved content to facilitate malware, fraud, harassment, or another prohibited activity;
  • instruct a tool to take an irreversible or consequential action without appropriate authorization and safeguards; or
  • violate applicable website terms, intellectual-property rights, privacy rights, or law.

Infrastructure-level blocks do not eliminate your responsibility to use tools lawfully and responsibly.

You are responsible for validating tool inputs and outputs and protecting your application against malicious content, prompt injection, and unintended tool execution.

20. Service Integrity and Technical Restrictions

You may not:

  • interfere with or degrade the Service;
  • deliberately overload Viro or Provider infrastructure;
  • bypass rate, spend, concurrency, model, geographic, or account limits;
  • create or use multiple accounts to evade a restriction, suspension, or Credit limitation;
  • conceal the source of abusive traffic;
  • falsify request metadata;
  • access another customer's account or data;
  • test Viro systems for vulnerabilities without written permission;
  • reverse engineer Viro software except where the restriction is prohibited by law;
  • use stolen, shared, or unauthorized API keys;
  • fraudulently obtain promotional Credits;
  • resell or provide raw access to the Service contrary to the Terms of Service; or
  • assist another person in doing any of the above.
21. Customer Applications and End Users

If you provide a Customer Application to End Users, you must implement safeguards appropriate to the nature and risk of your application.

Depending on the use case, safeguards may include:

  • authentication and account controls;
  • rate and spend limits;
  • moderation and abuse detection;
  • user reporting systems;
  • human review;
  • age-appropriate design;
  • parental consent where required;
  • notices that users are interacting with AI;
  • testing for harmful or discriminatory behavior;
  • tool confirmations;
  • audit records;
  • escalation procedures; and
  • suspension or removal of abusive End Users.

You may not knowingly permit End Users to violate this Policy.

You must promptly investigate credible reports of abuse occurring through your Customer Application and take reasonable corrective action.

22. Upstream Provider and Model Policies

Requests may be routed to third-party model and infrastructure Providers.

Your use of a model is also subject to:

  • the applicable Provider's usage or acceptable-use policies;
  • model-specific licenses;
  • geographic or industry restrictions;
  • safety requirements; and
  • other restrictions identified in Viro's documentation.

If an applicable Provider policy is stricter than this Policy, the stricter rule governs your use of that Provider or model.

A use being permitted under this Policy does not guarantee that every Provider will accept the request. Providers may reject, filter, restrict, or investigate requests under their own systems and policies.

Viro may reject or reroute a request when necessary to comply with an applicable Provider requirement.

23. No Circumvention

You may not attempt to evade this Policy by:

  • using coded, misspelled, translated, obfuscated, or indirect instructions;
  • splitting a prohibited task across multiple requests;
  • using multiple models, tools, accounts, or Providers;
  • asking for fictional, hypothetical, academic, or role-play content when the actual purpose is prohibited;
  • using Output from one request as Input to facilitate a prohibited activity; or
  • causing another person or automated system to perform the prohibited activity for you.

We evaluate the reasonably apparent purpose and effect of a use, not merely how a request is phrased.

24. Enforcement

Viro may investigate suspected violations using information reasonably available to us, including:

  • usage and security metadata;
  • automated abuse or risk signals;
  • Provider reports or enforcement actions;
  • customer or third-party reports;
  • payment and account activity;
  • support communications; and
  • information required or permitted by law.

Viro does not promise to monitor or review every request or piece of Output.

Depending on the nature, severity, frequency, and credibility of a suspected violation, we may:

  • reject or block a request;
  • restrict a model, Provider, tool, or feature;
  • reduce rate or spend limits;
  • require additional verification;
  • revoke an API key;
  • preserve relevant records;
  • request corrective action;
  • suspend or terminate an account;
  • withhold or invalidate promotional Credits;
  • notify an affected Provider or third party;
  • report activity to an appropriate authority where required or permitted by law; or
  • take other reasonable measures to prevent harm.

For less serious or apparently accidental violations, we may provide notice and an opportunity to correct the issue.

We may act immediately and without advance notice where we reasonably believe activity involves:

  • child sexual exploitation;
  • an active cyberattack;
  • an imminent threat of physical harm;
  • significant fraud;
  • account compromise;
  • evasion of an existing suspension;
  • material risk to Viro, a Provider, or another customer; or
  • a legal requirement that prevents notice.

Enforcement decisions may be based on the information reasonably available at the time and may occasionally be incorrect.

25. Appeals

You may appeal a suspension, restriction, or termination by contacting nick@viro.app.

Your appeal should include:

  • your account email address;
  • the affected API key prefix, if applicable;
  • the date and approximate time of the relevant activity;
  • an explanation of your use case;
  • why you believe the action was incorrect; and
  • any corrective measures you have implemented.

Submitting an appeal does not guarantee reinstatement. We may decline to provide details that would expose security systems, confidential Provider information, investigations, or legally restricted information.

26. Reporting Abuse and Security Issues

To report suspected misuse of the Service, contact:
nick@viro.app

Include enough information for us to identify and investigate the issue, but do not email CSAM or other illegal content. Instead, provide non-content identifiers such as:

  • account or organization information;
  • API key prefix;
  • request identifier;
  • timestamp;
  • relevant URL; or
  • a description of the suspected conduct.

Security vulnerabilities should be reported privately to nick@viro.app before public disclosure.

27. Changes to This Policy

Viro may update this Policy to address:

  • new models, tools, or features;
  • changes in law;
  • new safety or security risks;
  • Provider requirements;
  • enforcement experience; or
  • changes to the Service.

We will update the effective date when this Policy changes.

Material changes will be communicated through email, the developer console, the Service, or another reasonable method.

Changes necessary to address urgent abuse, security, Provider, or legal risks may take effect immediately.

28. Contact

Questions about this Policy may be sent to:
Viro Climate Action, Inc.
Email: nick@viro.app