PromptOps — Acceptable Use Policy
Version: 1.0 Effective date: 2 August 2026 Status: in force
This policy forms part of the Terms of Service and the End User Licence Agreement.
Table of contents
- Purpose and scope
- Prohibited conduct
- Provider terms
- Security research
- What we do not restrict
- How we enforce this policy
- Reporting a violation
- Changes
- Version history
1. Purpose and scope
1.1 PromptOps is a developer tool that runs code, executes commands and orchestrates AI agents. It is powerful by design. This policy sets out the small number of things you must not do with it.
1.2 It applies to your use of the PromptOps desktop application, the web application, the mobile remote application, our APIs and our website.
1.3 This policy is deliberately specific. We do not want a rule so broad that it would let us suspend anyone for anything. Each prohibition below describes conduct that is identifiable, and section 6 sets out how enforcement works.
2. Prohibited conduct
2.1 Unlawful activity
You must not use PromptOps to carry out, plan, facilitate or conceal activity that is unlawful under the law applicable to you or to us.
2.2 Malware and harmful code
You must not use PromptOps to develop, host, distribute or operate malware, ransomware, spyware, keyloggers, botnet infrastructure, or code whose purpose is to damage or gain unauthorised control of systems belonging to others.
This does not prohibit legitimate security work — see section 4.
2.3 Unauthorised access and system compromise
You must not use PromptOps to gain or attempt to gain unauthorised access to any system, network, account or data, whether ours or a third party's. This includes exploiting vulnerabilities, escalating privileges, and bypassing authentication or authorisation controls, without authorisation from the system's owner.
2.4 Credential theft
You must not use PromptOps to harvest, steal, crack, resell or otherwise misappropriate credentials, API keys, tokens or authentication material belonging to others.
2.5 Abuse of our infrastructure
You must not:
- send requests to our services at a volume or rate designed to degrade them, or that in fact degrades them, beyond published limits;
- use our services for cryptocurrency mining, distributed computation or other workloads unrelated to the product's purpose;
- use our services as a general-purpose proxy, relay or file host for unrelated traffic;
- probe, scan or stress-test our infrastructure without authorisation (see section 4);
- interfere with other users' use of the services.
2.6 Circumventing limits and licence controls
You must not circumvent, disable or interfere with plan limits, usage limits, authentication, licence enforcement or security features; nor create multiple accounts, or use automation, to obtain benefits reserved to a plan you do not hold — for example repeatedly restarting free trials.
2.7 Account sharing
Licences are granted on a named-user basis. You must not share your account credentials, or allow more than one individual to use a single seat concurrently. Reassigning a seat within an organisation when someone changes role is permitted.
2.8 Intellectual property infringement
You must not use PromptOps to infringe copyright, trade marks, patents, trade secrets or other rights of third parties, including by distributing material you have no right to distribute.
2.9 Harming others
You must not use PromptOps to:
- harass, threaten, stalk or intimidate any person;
- produce or distribute child sexual abuse material;
- produce or distribute non-consensual intimate imagery, including synthetic imagery;
- incite violence or terrorism;
- carry out fraud, phishing, impersonation or social engineering against others;
- conduct mass unsolicited messaging.
2.10 Misuse of AI capability
You must not use the AI agents orchestrated through PromptOps to:
- generate content that is unlawful under section 2.9;
- impersonate a real person or organisation in a deceptive way;
- generate disinformation intended to deceive the public;
- circumvent the safety measures of an AI provider;
- generate output that you present as human-authored where a law or professional obligation applicable to you requires disclosure.
2.11 Interfering with the product
You must not misrepresent the origin of the software, distribute modified versions as if they were ours, or remove proprietary notices (see EULA clause 12).
3. Provider terms
3.1 When you use an AI provider or third-party tool through PromptOps, you must comply with that provider's terms and policies.
3.2 Breaching a provider's terms may cause that provider to suspend your account with them. That is a matter between you and the provider; we cannot restore access to a service we do not operate.
3.3 Where a provider notifies us that use through PromptOps is breaching their terms, we may need to act. We will tell you first where we can.
4. Security research
4.1 Legitimate security work is not prohibited by this policy. Developing exploits, analysing malware, running penetration tests and building offensive tooling are ordinary professional activities — provided you are authorised to test the target and you comply with applicable law.
4.2 If you want to test our systems, contact us first at luca.mangiacotti@shellonback.com. We will not pursue good-faith research conducted within a scope we have agreed.
4.3 Report vulnerabilities to luca.mangiacotti@shellonback.com. We aim to acknowledge within 5 working days. Please give us reasonable time to fix an issue before disclosing it publicly.
5. What we do not restrict
To be clear, because the boundary matters for a developer tool:
- You may run any code you have the right to run, including code you did not write.
- You may give agents broad permissions on your own machine. That is your risk to take (see EULA clause 18).
- You may use PromptOps commercially, within the terms of your plan.
- You may work on any subject matter, including security, cryptography and content moderation, provided it is lawful.
- We do not inspect your projects or your code. Enforcement under section 6 is based on what we can observe about use of our own services, or on reports we receive.
6. How we enforce this policy
6.1 Proportionality. Our response will be proportionate to the problem. In order of preference:
- contacting you to understand and resolve the issue;
- applying a technical limit to the specific behaviour;
- suspending a specific feature;
- suspending the account;
- terminating the account.
6.2 Notice. We will normally contact you before taking a restrictive measure, and will tell you what we believe happened and what needs to change.
6.3 Immediate action. We may act without prior notice where the conduct causes an immediate and serious risk to our services, to other users or to third parties, or where a law or binding order requires it. We will inform you as soon as possible afterwards, unless prohibited from doing so.
6.4 Review. You may contest a measure by writing to luca.mangiacotti@shellonback.com. We will review the decision, including a human review of any automated measure, and respond. We respond within 30 days.
6.5 No arbitrary suspension. We will not suspend or terminate an account except on the grounds set out in this policy, in the Terms of Service, or as required by law.
6.6 Where an account is terminated for breach, section 23 of the Terms of Service and clause 23 of the EULA govern the consequences, including data export.
7. Reporting a violation
If you believe someone is using PromptOps in breach of this policy, tell us at luca.mangiacotti@shellonback.com.
Please include what happened, when, and anything that helps us verify it. We will assess reports and act where appropriate. We will not disclose the identity of the reporter unless required by law.
8. Changes
We may update this policy. Material changes will be notified in advance in accordance with clause 26 of the Terms of Service.
9. Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | 2 August 2026 | First version. |
If you spot something in this document that looks wrong or unclear, write to us — we would rather fix it than defend it.