Legal
Acceptable use policy
This covers both directions: how you may use our services and this site, and what we will decline to build. The second half is the more interesting one.
Last updated 1 July 2026 · Exinary Technologies Private Limited
Using this website
You may not:
- Attempt to circumvent rate limits, or automate form or assistant submissions
- Probe, scan or test our infrastructure without prior written authorisation — except good-faith vulnerability research reported to [email protected], which we welcome
- Scrape content at volume or republish it as your own
- Use the assistant to attempt extraction of its instructions, or to generate content unrelated to our services
- Submit anyone else’s personal data without their consent
Using systems we build for you
Systems we deliver must not be used to break the law, infringe rights, or process data you have no right to process. Specifically, you must not repurpose a system we built for one stated purpose to a materially different one without telling us — particularly where that would breach the purpose limitation the design assumed under the DPDP Act.
Where we build a system with human review in the design, removing that review is a material change. We will help you assess the risk; we will not certify a configuration we consider unsafe.
What we will not build
We decline this work regardless of fee. This is not a negotiating position.
- Autonomous decisions in regulated domains. Credit and lending decisions, clinical diagnosis or treatment, hiring rejections, insurance denials, or anything else where an accountable human is required. We build decision support; the decision stays with a person.
- Surveillance of individuals. Emotion recognition, biometric categorisation, social scoring, or covert monitoring of employees or the public.
- Deception at scale. Systems designed to impersonate real people, generate synthetic media of identifiable individuals without consent, or run coordinated inauthentic behaviour.
- Dark patterns. Automation whose purpose is to make cancellation, refunds or consent withdrawal harder.
- Bulk unsolicited outreach. We will build research and drafting support for outbound sales. We will not build a system whose function is sending unsolicited messages at volume.
- Circumventing another party’s controls. Scraping in breach of terms, defeating rate limits or bypassing access controls on systems you do not own.
- Weapons, and offensive cyber capability.
Where we ask questions first
Some work is legitimate but carries enough risk that we want the oversight design agreed in writing before we start:
- Anything affecting an individual’s access to a service, employment or money
- Automation touching children’s data or other sensitive categories
- Content moderation at scale, where both false positives and false negatives cause real harm
- Systems intended to operate without any human in the loop, in any domain
In these cases the governance work is not optional — it is part of the engagement.
Reporting and enforcement
If you believe a system we built is being misused, tell us at [email protected]. We investigate every report.
Where a client breaches this policy we will raise it, ask for it to be remedied, and — if it is not — suspend the engagement. We reserve the right to terminate immediately for serious breaches, including any use that puts individuals at risk.
Questions?
Email [email protected] for anything about data or these policies, or [email protected] for security matters. See also our security page.