Legal
Acceptable Use Policy
Effective September 23, 2026 · Kratu AI LLC
This policy is part of the Terms of Service between you and Kratu AI LLC. It applies to everyone who uses Hypothis, including anyone building, publishing or distributing a form. We may update it as new risks emerge.
1. Intellectual property
- Don't upload, collect or distribute content that infringes copyright, trademark, patent, trade-secret, publicity or privacy rights.
- Don't copy another company's proprietary surveys, research instruments or reports into Hypothis without the right to do so.
2. Security and infrastructure abuse
- No viruses, trojans, worms, logic bombs, ransomware or other malicious code.
- No unauthorized access (or attempts) to the Service, other accounts, or connected systems and networks.
- No probing, scanning or vulnerability testing without our written permission — see responsible disclosure below.
- No denial-of-service attacks, load or stress testing, or anything that degrades the Service for others.
- No circumventing authentication, rate limits, usage or credit limits, Cloudflare Turnstile, bot detection or other protections.
3. Automated access, copying and competition
- No scraping, crawling, data mining or bots, except through APIs we document for that purpose or with our written consent.
- No reverse engineering, decompiling or disassembling the Service, except to the extent the law expressly allows despite this restriction.
- Don't use the Service or its output to build a competing product, or to train or fine-tune AI models.
- Don't publish benchmarks or comparisons of the Service without our consent.
4. Fraud, phishing and deception
- Don't impersonate any person, company or brand — including building forms that pose as another organization.
- No phishing, credential harvesting, identity theft, fake giveaways, or other fraud.
- Never use forms to collect passwords, full payment-card numbers, bank log-ins, or government ID numbers (such as SSNs or passport numbers).
- Don't misrepresent who is collecting responses, why, or how they'll be used; don't disguise the origin of messages.
- No fake reviews, astroturfing, or manipulating research results you present to others as genuine.
5. Illegal and harmful content
- Zero tolerance for child sexual abuse material (CSAM). We remove it, terminate the account and report it to the National Center for Missing & Exploited Children as required by 18 U.S.C. § 2258A.
- No content that promotes terrorism or violent extremism, incites violence, or promotes self-harm.
- No hate speech, harassment, bullying, stalking, threats, doxxing or defamation.
- No content that sells or facilitates illegal goods or services.
6. Privacy and data protection
- Only collect personal data you have a lawful basis to collect, and give respondents the notices and obtain the consents that GDPR, the CCPA/CPRA and other applicable laws require.
- Don't collect sensitive data — health or medical information (PHI), biometric or genetic data, precise geolocation, financial-account data, Social Security numbers, or data revealing racial or ethnic origin, religion, sexual orientation or similar — unless the law permits it and the respondent has explicitly consented. Hypothis is not HIPAA-compliant and we don't sign Business Associate Agreements.
- Don't knowingly collect data from children under 13 (or under 16 in the EU/UK) without the parental consent the law requires.
- Don't sell respondent data you collect through Hypothis.
7. Spam and unsolicited communications
- Don't send unsolicited bulk invitations or messages, or otherwise violate CAN-SPAM, the TCPA, CASL, the EU ePrivacy rules or similar laws when distributing forms.
- Don't use purchased, rented or scraped contact lists to distribute forms.
- Only invite people by SMS or messaging apps (WhatsApp, Telegram, etc.) with their prior consent.
8. AI features
- No prompt injection, jailbreaking, or attempts to extract system prompts or other users' data.
- Don't use AI features to generate unlawful, deceptive or harmful content, including content prohibited by Google's Generative AI Prohibited Use Policy (our AI features run on Google Gemini).
- Don't present AI-generated output to respondents or others as advice from a human expert.
- Using AI features doesn't reduce your own obligations under consumer-protection law — you're responsible for what you do with the output, the same as if a person had drafted it.
9. Commercial misuse and platform abuse
- No reselling, sublicensing, renting or white-labeling the Service without a written agreement with us.
- Don't share log-ins or seats between people.
- Don't create multiple accounts to obtain extra trials, credits, promotions or discount codes.
- No fraudulent chargebacks, and no evading a suspension or ban by opening a new account.
10. Compliance with law
Comply with all applicable local, state, national and international laws, including U.S. export controls and OFAC sanctions — the Service may not be used from comprehensively embargoed countries or regions or by restricted parties.
11. Your responsibility for respondents
If you publish forms, you're responsible for your respondents' notices and consents, your lawful basis for collecting their data, and honouring their privacy requests. We help as described in our Data Processing Addendum.
12. Enforcement and reporting
We may investigate suspected violations, and remove content, disable forms, or suspend or terminate accounts — immediately and without refund for serious or unlawful violations (see Terms §8A). We may preserve and disclose information to law enforcement where required or to protect people.
- Report a form, account or content: hypothis.ai/report-abuse or [email protected].
- Responsible disclosure of security issues: [email protected]. Give us reasonable time to fix before disclosure, don't access others' data, and don't degrade the Service; we won't pursue good-faith research that follows these rules.