15% off all models 🎉 Every model at 85% of the maker's official list price.Browse models →

ApiFlux Acceptable Use Policy

Version: v0.2
Last updated: 2026-08-19
Website: https://apiflux.ai/

Important: This Policy forms part of the ApiFlux Terms of Service. It is not legal advice. Users remain responsible for their use case, data, users, outputs, and compliance with applicable law and upstream provider requirements.

This Acceptable Use Policy applies to the ApiFlux website, accounts, console, API Keys, balances, credits, redemption codes, model calls, routing policies, logging functions, integrations, and products or services that users provide through ApiFlux.

1. Core principles

Users may use ApiFlux only for lawful, authorized, and responsible purposes consistent with this Policy, the Terms of Service, the Privacy Policy, the Payment Notice, the policies of the Upstream Service actually used, and applicable law.

Users must assess compliance based on their use case, target users, data types, jurisdictions, model channels, and downstream impact. Users are responsible for their inputs, configurations, outputs, decisions, end products, and end-user behavior.

Users must not direct, assist, authorize, or allow another person to use their account or API Key for prohibited activity. Enterprise users must apply appropriate access controls, supervision, monitoring, and incident response for employees, contractors, end users, and integrated applications.

2. Strictly prohibited activity

Users must not use or facilitate the use of ApiFlux for:

  • Activity that violates applicable law, court orders, sanctions, export controls, or regulatory requirements;
  • Fraud, scams, money laundering, theft, tax evasion, sham transactions, payment evasion, or abusive chargebacks;
  • Sexual exploitation, grooming, or abuse of minors, or related content;
  • Human trafficking, terrorism, extremist recruitment, or violent crime;
  • Actionable assistance to carry out violence, self-harm, weapons activity, explosives, illegal-drug activity, or other serious harm against a specific target;
  • Malware, ransomware, phishing, credential theft, DDoS, unauthorized exploitation, intrusion, persistence, or unauthorized access;
  • Stalking, harassment, threats, hate, humiliation, non-consensual intimate content, or harm based on a sensitive characteristic;
  • Impersonation, false identity or authority, deceptive deepfakes, false advertising, or manipulation of public perception;
  • Unauthorized collection, inference, purchase, sale, disclosure, or monitoring of personal information;
  • Infringement of copyright, trademark, patent, trade secret, privacy, publicity, or another third-party right;
  • Spam, fake reviews, bulk harassment, ranking manipulation, or other deceptive interactions;
  • Circumvention of ApiFlux or an Upstream Service's content-safety, authentication, permission, rate, token, regional, payment, account, or commercial restrictions.

3. High-impact and regulated uses

Users must not deploy ApiFlux in medical, mental-health, legal, financial, insurance, credit, employment, education, housing, immigration, law-enforcement, critical-infrastructure, or personal-safety settings without appropriate professional review, risk controls, transparent notice, meaningful human oversight, and a lawful basis.

AI output must never be the sole basis for a decision that produces a material legal or similarly significant effect on a person. Users must provide meaningful human review, correction, and appeal mechanisms and must verify accuracy, suitability, and potential bias.

ApiFlux must not be used for emergency calling, life support, nuclear facilities, weapons control, or another system whose failure could reasonably cause death, serious injury, or major property or environmental damage, unless the parties have an express written agreement and appropriate safety certification has been completed.

4. Data, privacy, and intellectual property

Users must not submit data they have no right to process. In particular, users should not submit passwords, private keys, full API Keys, card or payment credentials, government identification, children's information, health information, biometric information, precise location, private communications, trade secrets, regulated data, or third-party confidential information unless they have a lawful right and have completed the necessary privacy and security review.

If a use case requires personal, sensitive, or regulated data, the user must:

  • Establish a valid legal basis and provide required notice or obtain consent;
  • Review the storage, training, retention, security, and cross-border arrangements of ApiFlux and the selected Upstream Service;
  • Apply data minimization, de-identification, encryption, access control, and deletion measures;
  • Enter into an applicable data-processing, security, or enterprise agreement where required;
  • Provide end users with a privacy notice, rights-request channel, and incident-response channel;
  • Verify that the selected model channel is permitted for the data and use case.

Users must respect third-party intellectual-property rights and must not use ApiFlux to copy protected content, circumvent technical protection, or commercialize content without the necessary rights.

5. Cybersecurity research and automation

ApiFlux may be used for lawful, defensive, and authorized security activity, such as analyzing the user's own code, generating remediation advice, or testing within an expressly authorized scope.

Users must not:

  • Scan, penetrate, test credentials, or access a system without the owner's express authorization;
  • Deploy code that propagates, steals data, evades detection, or causes damage;
  • Generate phishing content, malicious payloads, exploit chains, or attack infrastructure at scale;
  • Use automation to create abnormal traffic, disrupt ApiFlux or an Upstream Service, or affect another user's normal use;
  • Continue testing after ApiFlux or the system owner requests that testing stop.

Security research directed at ApiFlux must follow Section 9 of the Payment, Supported Regions, Customer Support, and Security Notice.

6. API Keys, accounts, balances, and platform abuse

Users must not:

  • Publicly expose, sell, rent, transfer, or share without authorization any account, API Key, balance, or redemption code;
  • Register accounts in bulk, use false identities, or farm trials, rewards, referral credit, affiliate commission, or promotions;
  • Use a proxy, VPN, script, device spoofing, false address, or another method to evade risk controls or regional restrictions;
  • Resell ApiFlux through a technical or commercial arrangement without written authorization from NovaSpan LLC;
  • Conduct unauthorized load tests, scraping, reverse engineering, scanning, attacks, or resource exhaustion against ApiFlux or an Upstream Service;
  • Interfere with billing, logs, limits, routing, failover, security policy, or another user's normal use;
  • Use another person's payment method, account, identity, or credentials without authorization.

Users may integrate ApiFlux into their own products, but they must protect credentials, apply reasonable usage limits, monitor suspicious activity, comply with upstream rules, and remain responsible for their end-user behavior.

7. Upstream-service policies

Users must comply with the terms of service, licenses, acceptable-use policies, content policies, regional restrictions, and commercial rules of the upstream model, API, cloud platform, or channel actually called. Upstream policies may differ by model, account, route, and region.

Users must not use the unified interface, routing, failover, or model-switching features of ApiFlux to evade upstream safety measures, model restrictions, rate limits, account restrictions, resale restrictions, regional restrictions, payment requirements, or commercial-use requirements.

ApiFlux may reject, filter, delay, stop, limit, or reroute a request to meet an upstream requirement or protect the platform.

8. Enforcement measures

We may use automated and human methods to detect possible violations, fraud, security risks, abnormal traffic, credential exposure, and abuse. Where we reasonably believe there is a violation or urgent risk, we may:

  • Warn the user and require remediation;
  • Limit models, features, rates, concurrency, regions, payment methods, balances, or credits;
  • Reject, filter, delay, stop, or reroute relevant requests;
  • Revoke or rotate an API Key, or freeze, suspend, or terminate an account;
  • Cancel promotions, referral rewards, affiliate commissions, redemption codes, or improperly obtained credit;
  • Deny or adjust a refund, handle a chargeback, or recover loss under the Payment Notice;
  • Preserve necessary evidence and notify an Upstream Service, affected party, regulator, or law-enforcement body where appropriate;
  • Delete unlawful content or related data where permitted or required by law.

Measures depend on severity, repetition, intent, actual or potential harm, security risk, upstream requirements, and remediation. To prevent evasion or protect third parties, we may be unable to disclose all investigation details.

9. Reports and appeals

Use the following email routes. Do not send a full API Key, password, private key, card information, or unrelated personal information.

A report or appeal should include, where relevant:

  • Account email or organization identifier;
  • Request ID and approximate time;
  • Model, protocol, and provider channel if known;
  • Order number or billing reference if relevant;
  • API Key prefix or suffix only, never the full key;
  • Relevant facts, reproduction steps, and necessary evidence;
  • A safe way to contact the reporter.

10. Policy updates

We may update this Policy for changes in law, the product, security risks, or Upstream Service policies. We will state the update date on the page. Where reasonably practicable, we will notify users of material changes through the website, console, or registered email address. Continued use after an update takes effect constitutes agreement where permitted by law.


Copyright 2026 NovaSpan LLC. All rights reserved.

Enterprise AI Gateway for routing, securing, and observing every model call.