Legal

Acceptable Use Policy

Last updated: 30 July 2026

The short version. Build whatever you want, as long as it is legal, honest, and not designed to hurt people or the platform. No malware, no scams, no harassment, no sexual content involving minors, no scraping personal data, no credit farming, and no stripping the ForgeFlow badge without a Pro plan. We scan published projects automatically. Serious violations end an account immediately; smaller ones get a strike, and three strikes end it.

1.Who this applies to

This Acceptable Use Policy ("AUP") applies to everyone who uses ForgeFlow AI: account holders, workspace members and collaborators, anyone acting on their behalf, and any visitor to a site published through ForgeFlow. It covers the prompts you send, the projects you generate, the files you upload, the sites you publish, the domains you connect and the integrations you wire up.

This AUP forms part of our Terms of Service. Where the two overlap, the stricter rule applies. Terms defined in the Terms of Service have the same meaning here.

2.Core principle

ForgeFlow gives one person the power of a whole engineering team. That power is only safe if it is not pointed at other people. The single rule behind everything below: do not use ForgeFlow to build, host, distribute or automate anything designed to deceive, harm, exploit, surveil or defraud someone, and do not use it to attack the platform itself.

The lists in this policy are examples, not an exhaustive catalogue. Something can violate the spirit of this policy even if it is not spelled out word for word, and we assess intent and real-world impact, not just labels.

3.Illegal activity

You may not use ForgeFlow to plan, carry out, facilitate or promote anything unlawful in your jurisdiction, in ours, or in the jurisdiction of the people your project reaches. This includes:

  • Marketplaces or storefronts for controlled substances, prescription drugs without a licence, stolen goods, counterfeit products, forged documents or hacked accounts.
  • Money laundering, sanctions evasion, unlicensed money transmission, or services designed to conceal the origin of funds.
  • Human trafficking, forced labour, or the sale or exploitation of people in any form.
  • Unlicensed gambling, lotteries, or betting operations where a licence is required.
  • Poaching, trade in protected wildlife, or trafficking of protected cultural property.
  • Evading law enforcement, tampering with evidence, or coordinating criminal activity.

4.Fraud, scams and deception

Deceiving people for money, data or access is one of the fastest routes to permanent termination. Prohibited examples:

  • Phishing pages, credential-harvesting forms, or clones of banks, exchanges, wallets, government portals, delivery services, or any login screen you do not own.
  • Fake stores that take payment without shipping, fake charity or disaster-relief appeals, or fake job and recruitment funnels.
  • Investment scams, Ponzi and pyramid schemes, pump-and-dump coordination, guaranteed-return offers, romance-scam infrastructure, or crypto "airdrop" and wallet-drainer front-ends.
  • Fake reviews, fabricated testimonials, forged certifications, invented trust badges or made-up press coverage.
  • Dark patterns designed to trick people into subscriptions, hidden charges, or consent they did not knowingly give.
  • Deceptive AI presentation: claiming an AI conversation is a specific real person, or hiding automation where the law requires disclosure.

5.Malware, hacking and security abuse

You may not build, host, distribute or operate offensive security tooling against systems you do not own and have not been authorised in writing to test. Prohibited examples:

  • Viruses, worms, trojans, ransomware, keyloggers, spyware, stalkerware, cryptominers installed without consent, or droppers and loaders for any of these.
  • Botnet command-and-control, DDoS or stress-testing services, or infrastructure that coordinates attacks.
  • Credential stuffing, brute-force tooling, password-cracking services, OTP/2FA bypass or SIM-swap tooling, or CAPTCHA-solving services aimed at other platforms.
  • Exploit kits, malicious browser extensions, or tools designed to defeat DRM, licensing or paywalls.
  • Carding tooling, card testing, BIN checkers, or anything used to validate stolen payment credentials.
  • Deliberately building backdoors, hidden data exfiltration, or logic bombs into a project handed to someone else.

Security research and CTF work are welcome when the target is your own system or one you have documented permission to test.

6.Harmful and hateful content

  • Content that attacks, degrades or dehumanises people based on race, ethnicity, national origin, religion, caste, disability, disease, age, sex, gender identity, sexual orientation, or immigration or veteran status.
  • Harassment campaigns, coordinated pile-ons, doxxing sites, revenge-oriented "exposure" pages, or tools that help someone stalk or intimidate an individual.
  • Promotion or glorification of terrorism, violent extremism, mass violence, or the organisations behind them, including recruitment and fundraising material.
  • Content that encourages self-harm, suicide, disordered eating, or dangerous "challenges", including apps that coach users toward these behaviours.
  • Bullying or sexualised harassment of private individuals, including non-consensual imagery of any kind.
  • Medical, legal or financial misinformation presented as authoritative where it can foreseeably cause real harm.

7.Sexual content and child safety

Child sexual abuse material (CSAM) and any sexualisation of minors — real, drawn, described, edited or AI-generated — is absolutely prohibited. There is no warning, no strike and no appeal path for this: the account and every workspace it controls are terminated immediately, content is preserved as required, and the matter is reported to the relevant authorities.

Also prohibited:

  • Non-consensual intimate imagery, "nudify" tools, or deepfake sexual content of any real person.
  • Sex trafficking, escort-service coordination where prohibited by law, or infrastructure for commercial sexual exploitation.
  • Adult content presented without age verification, or served to audiences where it is unlawful.
  • Bestiality, incest content, or sexual content combined with violence or coercion.

8.Violence, weapons and dangerous goods

  • Instructions or design assistance for weapons, explosives, chemical, biological, radiological or nuclear materials, or untraceable firearms.
  • Marketplaces for firearms, firearm parts, ammunition or accessories that circumvent licensing and background-check requirements.
  • Content that incites, coordinates or funds violence against people, groups or property.
  • Graphic violence published for shock value, or content celebrating real-world attacks and their perpetrators.

9.Privacy and personal data

If your project touches other people's data, you are the one responsible for handling it lawfully.

  • No scraping, aggregating, reselling or republishing personal data without a lawful basis and, where required, consent.
  • No people-search, background-check, or "find anyone" directories built from harvested data.
  • No covert tracking, undisclosed session recording, fingerprinting designed to defeat privacy controls, or location tracking of individuals without consent.
  • No collecting sensitive categories — health records, biometrics, precise location, financial account data, government IDs, sexual orientation, religious or political affiliation — unless you have a lawful basis, appropriate safeguards and a privacy notice that says so.
  • No uploading data you are contractually or legally barred from processing on third-party infrastructure.
  • You must publish accurate privacy information on any site you launch that collects personal data, and honour deletion and access requests from your own users.

See our Privacy Policy for how ForgeFlow itself handles data.

10.Intellectual property and impersonation

  • Do not upload, generate or publish material that infringes copyright, trademark, patent, trade secret or publicity rights.
  • Do not clone another company's branding, product UI or marketing copy in a way that misleads people about who they are dealing with.
  • Do not impersonate a person, business, government body or ForgeFlow itself, including via lookalike domains or spoofed sender addresses.
  • Do not distribute pirated software, cracked licences, stolen course content, leaked datasets or paywalled media.
  • Do not misrepresent AI-generated output as the work of a named real person without their permission.

Rights holders can send takedown notices to abuse@forge-flow.live. We remove infringing content and apply strikes to repeat infringers.

11.Spam, bulk messaging and SEO abuse

  • No bulk unsolicited email, SMS or DM infrastructure, list-blasting tools, or systems that send to addresses obtained without consent.
  • No mail relays or sending flows that forge headers, hide the real sender, or omit an unsubscribe path where one is legally required.
  • No doorway pages, cloaking, link farms, private blog networks, scraped-content mills or auto-generated pages built purely to manipulate rankings.
  • No comment-spam bots, review-bombing tools, or engagement-farming automation against other platforms.
  • No traffic-inflation services, ad-fraud infrastructure, or click farms.

12.Regulated and high-risk industries

You may build in regulated spaces — health, finance, insurance, education, legal, hiring — but you carry the compliance burden, including HIPAA, PCI-DSS, GDPR, CCPA, financial licensing and local equivalents. ForgeFlow is general-purpose software and is not certified for any of these regimes on your behalf.

You may not use ForgeFlow to build systems that make consequential automated decisions about people without human review, including:

  • Automated credit, insurance, housing, benefits or employment decisions delivered without a human in the loop.
  • Clinical diagnosis, treatment or dosing tools presented as a substitute for a qualified professional.
  • Legal advice generators presented as a substitute for a lawyer.
  • Biometric identification, emotion inference, predictive policing or social scoring systems applied to individuals.
  • Safety-critical control systems for vehicles, aviation, medical devices, industrial plant or critical infrastructure.

13.Platform and infrastructure abuse

  • No probing, load-testing, penetration-testing or reverse-engineering of ForgeFlow's own systems without written authorisation.
  • No attempts to bypass rate limits, credit checks, seat caps, device limits, VPN/proxy restrictions, workspace locks or verification challenges — including via multiple accounts, shared devices, automation or residential proxies.
  • No automated scripting of the builder, headless-browser farms, or resale of ForgeFlow capacity as your own AI or hosting product.
  • No mining cryptocurrency, running general-purpose compute, or using project hosting as file storage, a CDN for unrelated content, a proxy, or a VPN exit.
  • No hosting of content unrelated to a genuine application, and no using preview or published environments to relay traffic to third parties.
  • No interfering with other customers' projects, workspaces, credits or data.

Genuine vulnerability reports are welcome — see our Security page.

14.Credits, referrals and billing abuse

Credits are the platform's fuel, so manipulating them is treated as a serious violation:

  • No creating multiple accounts, workspaces or identities to collect additional free or daily credits.
  • No referral farming: self-referrals, fake signups, incentivised or purchased conversions, or coordinated rings. Referral conversions are capped on a rolling basis and exceeding the cap blocks invites for one month.
  • No purchasing beyond the published daily credit cap by splitting spend across accounts, workspaces, cards or IP addresses.
  • No chargeback abuse or refund abuse. Refunding credits you have already consumed creates an outstanding balance, locks the workspace and takes published sites offline until it is settled.
  • No reselling, transferring, trading or gifting credits outside the workspace features we provide.
  • No use of stolen, borrowed or unauthorised payment instruments.

Billing terms are covered in the Terms and the Refund Policy.

15.AI model misuse

  • Do not attempt to jailbreak, prompt-inject or otherwise coerce the models into producing content this policy prohibits.
  • Do not use ForgeFlow's models to train, distil or benchmark a competing model, or to systematically extract model outputs at scale.
  • Do not build applications that pass user prompts straight through to our models as an unmoderated general-purpose chatbot resold as your own AI service.
  • Do not deploy AI output in production without human review. Generated code can contain security flaws, and generated text can be wrong.
  • Do not use generated content to impersonate real people, fabricate evidence, or produce synthetic media intended to deceive.

16.Publishing, domains and the ForgeFlow badge

  • Published sites must accurately describe what they do and who runs them, and must not disguise their purpose from our scanners or from visitors.
  • Domains you connect must be ones you legitimately control. Lookalike or typosquatted domains targeting other brands are prohibited.
  • The "Built with ForgeFlow" badge may only be hidden on a Pro workspace. Removing, masking, overlaying or CSS-hiding it on any other plan is a violation, and doing so deliberately is treated as an abuse attempt rather than a mistake.
  • Do not serve different content to our scanners than to real visitors (cloaking), and do not gate a site to hide prohibited material.
  • You are responsible for content published under your project, including user-generated content, and must have a way to remove it when it breaks these rules.

17.Team workspaces and shared responsibility

In a team workspace, the Owner is accountable for what the workspace produces and publishes. Admins and Editors are accountable for their own actions. A violation by any member can result in action against the individual member, the workspace, or both — including credit loss, workspace lock, or deletion of the workspace and its projects in severe cases.

Owners should manage seats, roles and per-member credit limits carefully, remove members who leave, and avoid sharing credentials. Transferring a project into or out of a workspace to escape enforcement does not work: flags, strikes and locks follow the project and the people involved.

18.Automated safety scanning

We run automated safety checks on projects and published sites on a recurring basis, and we may review a project manually when a scan, a report or a payment signal warrants it. Scanning looks at project content, published output and metadata — not at the private contents of your personal messages beyond what is needed to enforce this policy.

When a project is flagged, it may be taken offline immediately while we assess it, and the owner is notified with the category and reason. Where the law requires it, we preserve and report material to the appropriate authorities. Attempting to defeat scanning — obfuscation, cloaking, delayed payloads, or shipping prohibited content only after a scan passes — is itself a violation and is treated as severe.

19.Enforcement and strikes

Depending on the severity, history and intent behind a violation, we may take any of the following steps, with or without prior notice:

  • Warn the account and require a change.
  • Remove or unpublish the offending content, or take the whole project offline.
  • Disable a specific capability — publishing, referrals, transfers, invites or custom domains.
  • Lock a workspace and freeze its credits.
  • Suspend the account temporarily.
  • Terminate the account and delete associated workspaces and projects.
  • Report the matter to law enforcement or affected third parties where required or clearly justified.

Most violations issue a strike. Three strikes result in termination of the account, or deletion of the workspace where the violations are workspace-wide. Severe categories — CSAM, terrorism, malware distribution, large-scale fraud and coordinated platform attacks — skip the strike system and result in immediate termination.

Credits are not refunded when an account is terminated for a violation, and terminated users may not create new accounts.

20.Reporting a violation

If you find a ForgeFlow-hosted project that breaks this policy, email abuse@forge-flow.live with the URL, what you saw, and any evidence such as screenshots or timestamps. Reports about child safety, imminent threats of violence or active phishing are prioritised and actioned as fast as we can verify them.

Please do not attack, deface or attempt to break into a site you are reporting — send us the details instead.

21.Appeals

If you believe a strike, takedown, lock or termination was a mistake, email support@forge-flow.live from the address on the account within 30 days. Include the project or workspace name, the notice you received, and an explanation of why the decision was wrong.

We review appeals with a human, aim to respond within a few business days, and will restore access and content where we got it wrong. Decisions involving child safety are final and are not appealable.

22.Changes to this policy

We update this policy as the platform, the models and the abuse landscape change. Material changes are announced in-app or by email, and the "last updated" date at the top always reflects the current version. Continuing to use ForgeFlow after a change means you accept the updated policy.

Questions about whether a project is allowed? Ask us at support@forge-flow.live before you build it — we would rather answer early than take something down later.