Short version. Use Chantro to run your business. Don't use it to break the law, harm people, steal data, disrupt the service, or mislead others — especially with AI. Customers are responsible for the actions of their users.
1. Scope & responsibility
This Acceptable Use Policy (“AUP”) governs your access to and use of Chantro. It applies to every Customer, workspace, User, guest, API consumer, and integration. Customers are responsible for all activity in their workspaces, including the conduct of their Users and any third parties they authorize to access the Service. A violation of this AUP is a violation of the Terms of Service.
2. Prohibited content
You must not upload, generate, store, link to, or transmit any content that:
- is illegal in a jurisdiction that applies to you, the content, or its recipients;
- infringes another party's intellectual-property, publicity, or privacy rights, or breaches a confidentiality obligation you owe a third party;
- sexually exploits, abuses, or endangers minors — or depicts minors in sexualized contexts in any form;
- incites or praises violence, terrorism, genocide, self-harm, suicide, or the targeted harassment of an individual or group;
- is defamatory, fraudulent, or materially misleading in a way that could harm others;
- contains malware, exploit code, ransomware, phishing kits, or credential dumps;
- solicits or facilitates the purchase or trafficking of weapons, controlled substances, or other items illegal in the relevant jurisdiction;
- is intentionally racist, sexist, or otherwise targeted at protected classes in a harassing or threatening way.
3. Prohibited conduct
You and your Users must not:
- attempt to bypass authentication, tenant isolation, rate limits, entitlements, or content filters;
- probe, scan, or penetration-test the Service without our prior written consent (an authorized disclosure program is the only acceptable channel);
- reverse-engineer, decompile, or disassemble the Service, or extract model weights;
- scrape, crawl, or otherwise harvest data from the Service (including AI outputs) except via documented APIs;
- use the Service to build a competing product or to benchmark the Service without our prior written consent;
- misrepresent your identity, affiliation, authority, or the origin of content;
- impersonate a Chantro employee, another User, or a third party, including in AI-generated content;
- sell, sublicense, or resell access to the Service or to AI Output you obtain through the Service;
- interfere with another User's use of the Service, including by submitting requests designed to exhaust shared resources.
4. AI misuse
You must not use AI features to:
- create content intended to deceive, defraud, or manipulate (including deepfakes of real people without clear, lawful, and documented consent);
- generate content that sexualizes minors, depicts non-consensual sexual acts, or is otherwise “CSAM-adjacent”;
- produce content that promotes self-harm, terrorism, violent extremism, or discriminatory harassment;
- automate decisions that materially affect individuals (for example, hiring, firing, credit) without meaningful human review;
- generate detailed instructions for the creation of weapons, malware, or hazardous materials;
- circumvent safety filters of the Service or any underlying model provider, including through jailbreak prompts, tool abuse, or prompt smuggling;
- present AI Output as advice from a licensed professional (lawyer, accountant, engineer, doctor) when it is not.
5. Restricted data categories
Do not upload or otherwise process the following categories of data in Chantro unless we have agreed in writing to support that use case:
- full payment card numbers, CVVs, or bank account numbers (outside of our approved payment processors);
- government-issued identifiers such as full Social Security or national ID numbers (last four digits are acceptable when necessary for payroll workflows);
- protected health information (PHI) as defined under HIPAA — Chantro is not a HIPAA business associate;
- data subject to ITAR, EAR Export Administration Regulations, or other classified export-control regimes;
- precise geolocation data beyond what is needed for a feature you intentionally use;
- data obtained unlawfully or in breach of contract with a third party.
6. Security & integrity
You will:
- use strong, unique credentials and enable multi-factor authentication for every account that has access to sensitive workspace data;
- promptly revoke access for departing Users and rotate API keys that may have been exposed;
- report suspected security vulnerabilities to security@chantro.com rather than exploiting, demonstrating, or disclosing them;
- not share session cookies, API tokens, or other authenticators outside your workspace; and
- not attempt to interfere with logging, monitoring, rate limiting, or fraud-prevention systems.
7. Fair use & rate limits
We publish rate limits for our APIs and AI features. You will not design workloads to deliberately exceed those limits or pool multiple workspaces to evade per-workspace quotas. Automated workloads must back off on 429 responses and respect documented guidance. We may throttle, queue, or refuse requests that threaten the stability of the Service.
8. Outbound messaging & email
Chantro lets Customers send transactional messages (for example, proposals, invitations, and schedule notices) to third parties they have a legitimate business relationship with. You will:
- send only to recipients who have a reasonable expectation of hearing from you;
- honor opt-outs and unsubscribe requests without delay;
- not use Chantro for unsolicited bulk email (spam), cold outreach lists you do not own, pretexting, or phishing;
- comply with applicable anti-spam and messaging laws (CAN-SPAM, CASL, PECR, GDPR, TCPA, and their successors).
9. Integrations & API use
When you connect a third-party integration or use our APIs, you will:
- only authorize integrations you control or trust, and revoke them when no longer needed;
- comply with the terms of the connected services (for example, Google's API Services User Data Policy where Google Workspace is connected);
- not use integrations to exfiltrate data outside the scope your Customer has authorized;
- not develop applications that compete with Chantro using our APIs.
10. Reporting abuse
If you believe a workspace, User, or content on the Service is violating this policy, contact us at trust@chantro.com. Please include URLs, screenshots, and as much detail as you can share. For alleged copyright infringement, follow our DMCA Policy. For suspected security issues, email security@chantro.com.
11. Enforcement
When we believe this policy has been violated, we may, at our discretion and proportionate to the severity and risk: remove or disable the offending content; issue warnings; suspend affected Users, API keys, or integrations; rate-limit a workspace; terminate a subscription; or notify law enforcement where required or appropriate. Where practical and lawful, we notify the Workspace Owner in advance or contemporaneously with action. Egregious violations — including illegal content, credential theft, attacks on the Service, or risk of imminent harm — may be enforced immediately without notice.
12. Changes to this policy
We may update this AUP to respond to new risks, new product capabilities, and new legal requirements. The current version is always posted at chantro.com/legal/acceptable-use.