Zagvo
Legal

Acceptable Use Policy

This policy sets out what you may and may not do with Zagvo. It exists to keep the Service safe, available and lawful for everyone using it. It forms part of the Terms of Service, and breaching it can cost you access to your Account.

Effective date:
9 August 2026
Last updated:
9 August 2026

1. Scope and interpretation

This Acceptable Use Policy (the Policy) applies to everyone who accesses Zagvo, to all Customer Content and Output, and to any use of our APIs or automated interfaces. It uses the definitions given in the Terms of Service.

The lists below are illustrative, not exhaustive. Conduct that is not named but is clearly within the spirit of a prohibition is prohibited. Where this Policy is stricter than a general statement elsewhere in our documents, this Policy governs conduct.

You are responsible for the conduct of anyone acting under your Account, and for ensuring that people you invite in future collaboration features comply with this Policy.

2. Permitted uses

Zagvo is built for legitimate product and software development work, including:

  • exploring and specifying a product idea through guided discovery;
  • generating documentation such as product briefs, PRDs, technical specifications, database schemas, API specifications, UX flows, QA checklists, security reviews and launch checklists;
  • breaking work into phases and tasks and tracking progress toward launch;
  • using the AI mentor for guidance on scope, sequencing and product decisions;
  • storing project knowledge and uploading files that provide context for your own product;
  • exporting documents and taking generated prompts to an AI builder or development team; and
  • evaluating the Service for your organisation, subject to Section 4.9 on competitive use.

You must have the rights to any material you submit, and you must use the Service in compliance with the laws that apply to you.

3. Prohibited content and conduct

3.1 Illegal content and activity

Do not use the Service to plan, facilitate or carry out unlawful activity, or to store or generate content that is unlawful where you or we operate. This includes trafficking in controlled substances, weapons or stolen data, money laundering, evading sanctions, and unlicensed regulated activity.

3.2 Child safety

Zero tolerance

Any content that sexualises, exploits or endangers a minor is absolutely prohibited. We remove it, terminate the Account immediately and without warning, preserve evidence, and report to the relevant authorities and hotlines. There is no appeal on the merits for confirmed cases.

3.3 Harassment, hate and threats

Do not use the Service to harass, bully, stalk, threaten or intimidate anyone, to incite violence, to dox or reveal private information about a person, or to generate content that demeans or dehumanises people on the basis of a protected characteristic.

3.4 Violent extremism and terrorism

Do not use the Service to promote, glorify, coordinate or provide material support for terrorism or violent extremism, to recruit for a violent organisation, or to plan attacks on people, property or infrastructure. Do not use it to design weapons, explosives, or chemical, biological, radiological or nuclear capability.

3.5 Malware and malicious code

Do not use the Service to write, refine, obfuscate, test or distribute malware, ransomware, spyware, keyloggers, botnets, cryptominers deployed without consent, or exploit code intended for unauthorised access. Legitimate security work on systems you own or are authorised to test is permitted; see Section 4.4.

3.6 Phishing, fraud and identity theft

Do not use the Service to build or draft phishing pages, credential-harvesting flows, fake storefronts, deceptive payment pages, scam scripts, or fraudulent financial schemes. Do not impersonate another person or organisation, misrepresent your affiliation, or use another person's identity documents or personal data without authorisation.

3.7 Spam and unsolicited messaging

Do not use the Service to generate or manage bulk unsolicited messaging, to build systems whose purpose is evading spam filters or consent requirements, or to produce mass low-quality content intended to manipulate search rankings or platform recommendations.

3.8 Intellectual property abuse

Do not upload, generate or distribute material that infringes copyright, trademark, patent or trade secret rights, and do not use the Service to remove watermarks, strip attribution, circumvent technical protection measures, or launder proprietary code or content whose licence you cannot comply with.

3.9 Privacy and unlawful data use

Do not upload personal data you have no lawful basis to process, scraped datasets assembled in breach of another platform's terms, biometric identifiers, or special-category data. Do not use the Service to build tools for covert surveillance, unlawful tracking, or facial recognition of people without consent.

4. Platform integrity and technical abuse

4.1 Reverse engineering

Do not reverse engineer, decompile or disassemble the Service, attempt to extract our source code, system prompts, manifests, planning logic or model configuration, or copy the Service to create a substantially similar product. This restriction does not apply where it is prohibited by applicable law.

4.2 Unauthorised access

Do not attempt to access an Account, Project, dataset, API or system you are not authorised to access; probe or bypass authentication or authorisation controls; interfere with another user's use of the Service; or interfere with our logging and monitoring.

4.3 Resource abuse and denial of service

Do not place a disproportionate load on the Service, run stress or load tests against it, open excessive concurrent sessions, or participate in a denial-of-service attack. Do not use the Service to run workloads unrelated to specifying and planning your own product, for example general-purpose bulk text generation.

4.4 Security testing

Do not conduct penetration testing, vulnerability scanning, fuzzing or automated exploitation against Zagvo or our providers without our prior written permission.

We welcome good-faith security research. Report suspected vulnerabilities privately to legal@zagvo.com, give us reasonable time to fix before disclosure, do not access or exfiltrate other users' data, and do not degrade the Service. Research conducted on those terms will not be treated as a Policy violation.

4.5 Automated abuse

Do not use bots, scrapers, headless browsers or scripted clients to interact with the Service other than through interfaces we document for that purpose. Do not create Accounts automatically, evade bot protection, or solve or bypass challenges programmatically.

4.6 Credential sharing and account misuse

Accounts are for one person. Do not share credentials, sell, rent or transfer an Account, use another person's Account, or operate multiple Accounts to obtain additional Credits, extend a trial, or evade an enforcement action.

4.7 API use and rate limits

Where we make an interface available, use it within the documented limits, identify your client honestly, cache responsibly, and back off when asked to. Do not attempt to raise your effective throughput by rotating Accounts, IP addresses or keys, and do not resell access to our AI capability.

4.8 Circumventing metering and billing

Do not tamper with Credit metering, replay or forge requests to obtain uncharged AI usage, manipulate subscription state, or abuse refunds, promotional codes or beta access to obtain service you have not paid for.

4.9 Competitive and benchmarking use

Do not use the Service to build a competing product, to systematically extract our prompts, manifests or planning behaviour for replication, or to publish benchmarks or comparisons derived from such extraction without our written consent.

5. AI misuse

5.1 Circumventing safety measures

Do not attempt to bypass, disable or trick the safety measures of the Service or of the models behind it, including jailbreaking, encoding prohibited requests to evade filters, using role-play to elicit prohibited output, or chaining requests so that each step appears benign.

5.2 Prompt injection and manipulation

Do not embed instructions in uploaded files, project text or shared content that are intended to manipulate the Service, another user's session, or our systems into acting outside their intended behaviour, exposing data, or ignoring their instructions. Do not attempt to extract system prompts or internal configuration.

5.3 Generating malicious code

Do not ask the Service to produce exploit chains, credential stealers, ransomware payloads, backdoors, or code designed to evade detection or gain unauthorised access. Defensive work, secure-coding guidance and analysis of your own systems remain permitted.

5.4 Deepfakes and synthetic misrepresentation

Do not use the Service to plan or produce content that impersonates a real person or organisation in a deceptive way, fabricates statements or events attributed to real people, creates non-consensual intimate imagery, or misleads people about elections, public health or emergencies.

5.5 High-risk and prohibited applications

Do not use the Service to design systems that make consequential decisions about people without meaningful human review, including credit, insurance, employment, housing, education, benefits, immigration or criminal-justice decisions, and do not use it to build social-scoring systems or applications prohibited under applicable AI regulation. Do not represent Output as reviewed professional advice; the Terms of Service explain why it is not.

5.6 Misrepresenting AI involvement

Do not present AI-generated Output as human-authored where doing so would deceive someone to their detriment, or where a law, employer, client or academic institution requires disclosure.

6. Enforcement

6.1 How we detect issues

We rely on automated signals such as rate-limit and abuse detection, provider notifications, and reports from users and third parties. We do not routinely review Customer Content; we access it to investigate a specific report, a suspected serious violation, or a security incident, as described in the Privacy Policy.

6.2 Warning process

For a first, non-serious violation our usual response is a warning: we explain what we found, what needs to change, and by when. Most matters end here. We may also restrict a specific feature, remove offending content, or apply tighter rate limits while the issue is resolved.

6.3 Suspension

Where a violation is serious, repeated, or ongoing, we may suspend the Account or specific features. Suspension is normally preceded by notice, except where immediate action is needed to protect users, the Service or a third party. Suspension for cause does not entitle you to a refund for the suspended period.

6.4 Termination

We may terminate an Account for a material or repeated violation that is not remedied, or immediately and without prior notice for the most serious categories:

  • child sexual abuse material or child endangerment;
  • credible threats of violence, terrorism or material support for it;
  • distribution of malware or active attacks on systems;
  • large-scale fraud, phishing or identity theft; or
  • conduct that exposes us or our providers to legal liability or regulatory action.

On termination, remaining Credits are forfeited and no refund is due for the terminated period. Export your work before an enforcement deadline passes where you have been given one.

6.5 Proportionality

We aim to match the response to the conduct, considering severity, intent, harm caused, whether it was repeated, and how you engaged with us. Honest mistakes are treated as mistakes.

6.6 Legal and regulatory referral

Where the law requires it, or where there is a risk of serious harm, we may preserve evidence and report conduct to law enforcement or a regulator, and cooperate with lawful requests.

7. Appeals

If you believe an enforcement decision was wrong, you can appeal. Email legal@zagvo.com from the address on the Account within 30 days, referencing the notice you received and explaining what you think we got wrong, with any evidence.

Appeals are reviewed by a person who was not responsible for the original decision. We aim to respond within 10 business days. We may uphold, reduce or reverse the action, and we will tell you the outcome and the reason. Where an action is reversed, we restore access and, where a paid period was affected, apply a service credit or refund in line with the Refund Policy.

Appeals are not available on the merits for confirmed child-safety violations, and we may decline to review repeat appeals that raise no new information.

8. Reporting abuse

If you become aware of conduct on Zagvo that breaches this Policy, tell us. Email legal@zagvo.com and include what you observed, where, when, and any material that helps us verify it. Report suspected security vulnerabilities to legal@zagvo.com instead, following Section 4.4.

We acknowledge reports, investigate proportionately, and take action where a violation is confirmed. We protect the identity of reporters as far as we can, and we do not retaliate against good-faith reports. Knowingly false or abusive reports are themselves a violation of this Policy.

If you believe content on the Service infringes your intellectual property, include enough detail to identify the material and your rights, and a statement that you are authorised to act.

9. Changes to this policy

We may revise this document from time to time to reflect changes in the Service, our providers, or applicable law. When we make material changes we will update the “Last updated” date, publish the revised document on this page, and (where the change materially reduces your rights or materially expands your obligations) notify account holders by email or in-product notice before the change takes effect. Changes are effective on the stated effective date. Continued use of the Service after that date constitutes acceptance of the revised document. Prior versions are available on request.

Because abuse patterns and AI capability both change quickly, we may add prohibitions to address a new harm with immediate effect. Where we do, we will publish the change and explain it.

10. Contact

  • Abuse reports and appeals: legal@zagvo.com
  • Security disclosures: legal@zagvo.com
  • General support: help@zagvo.com, or the contact page on this website

Your next product starts with an idea.

Describe what you're building and let Zagvo create your roadmap, organise your work and guide you from your first prompt to launch.