ApiFlux Acceptable Use Policy
Version: v0.1
Last updated: 2026-07-16
Website: https://apiflux.ai/
Translation notice: This English version is a working translation pending professional review.
This policy applies to the ApiFlux website, accounts, console, API Keys, balances, redemption codes, model calls, routing policies, logging functions, and products or services that users provide through ApiFlux. It forms part of the Terms of Service.
1. Core principles
Users may use ApiFlux only for lawful, authorized purposes consistent with this policy, the Terms of Service, the policies of upstream model/API providers, and applicable law. Users must assess compliance based on their use case, target users, data types, and location, and are responsible for their inputs, configuration, output, and final product.
Users must not direct, assist, authorize, or allow another person to use their account or API Key for prohibited activity. Enterprise users must apply appropriate access controls and supervision to members, contractors, end users, and integrated applications.
2. Strictly prohibited activity
Users must not use or facilitate the use of ApiFlux for:
- Activity that violates applicable law, a court order, sanctions, export controls, or regulatory requirements;
- Fraud, scams, money laundering, theft, tax evasion, sham transactions, abusive chargebacks, or payment evasion;
- Sexual exploitation, grooming, or abuse of minors, or any related content;
- Human trafficking, terrorism, extremist recruitment, or violent crime;
- Actionable assistance to carry out violence, self-harm, weapons activity, explosives, illegal-drug activity, or other serious harm against a specific target;
- Malware, ransomware, phishing, credential theft, DDoS, unauthorized exploitation, intrusion, or persistent access;
- Stalking, harassment, threats, hate, humiliation, non-consensual intimate content, or harm based on a sensitive characteristic;
- Impersonation, false identity or authority, deceptive deepfakes, false advertising, or manipulation of public perception;
- Unauthorized collection, inference, purchase, sale, disclosure, or monitoring of personal information;
- Infringement of copyright, trademark, patent, trade secret, privacy, publicity, or another third-party right;
- Spam, fake reviews, bulk harassment, ranking manipulation, or other deceptive interactions;
- Circumvention of ApiFlux or upstream content-safety, authentication, permission, rate, token, regional, payment, account, or commercial-use restrictions.
3. High-impact and regulated uses
Users must not deploy ApiFlux in medical, mental-health, legal, financial, insurance, credit, employment, education, housing, immigration, law-enforcement, critical-infrastructure, or personal-safety settings without appropriate professional review, risk controls, transparent notice, human oversight, and a lawful basis.
AI output must never be the sole basis for a decision that produces a material legal or similarly significant effect on a person. Users must provide meaningful human review, correction, and appeal mechanisms and must verify accuracy, suitability, and potential bias.
ApiFlux must not be used for emergency calling, life support, nuclear facilities, weapons control, or another system whose failure could reasonably cause death, serious injury, or major property or environmental damage, unless the parties have an express written agreement and appropriate safety certification has been completed.
4. Data, privacy, and intellectual property
Users must not submit data they have no right to process. In particular, users should avoid passwords, private keys, full API Keys, card or payment credentials, government identification, children's information, health information, biometric information, precise location, private communications, trade secrets, regulated data, and third-party confidential information.
If a use case requires personal, sensitive, or regulated data, the user must:
- Establish a valid legal basis and provide required notice or obtain consent;
- Review the storage, training, retention, and cross-border arrangements of ApiFlux and the selected Upstream Service;
- Apply appropriate data minimization, de-identification, encryption, access control, and deletion measures;
- Enter into an applicable data-processing, security, or enterprise agreement with ApiFlux;
- Provide end users with a privacy notice, rights-request channel, and incident-response channel.
Users must respect third-party intellectual-property rights and must not use the service to copy protected content, circumvent technical protection, or commercialize content without the necessary rights.
5. Cybersecurity research and automation
ApiFlux may be used for lawful, defensive, and authorized security activity, such as analyzing the user's own code, generating remediation advice, or testing within an expressly authorized scope. Users must not:
- Scan, penetrate, test credentials, or access a system without the owner's express authorization;
- Deploy code that propagates, steals data, evades detection, or causes damage;
- Generate phishing content, malicious payloads, exploit chains, or attack infrastructure at scale;
- Use automation to create abnormal traffic, disrupt the service, or affect other users.
Security research directed at ApiFlux itself must first comply with the vulnerability-disclosure rules in the Payment, Supported Regions, Customer Support, and Security Notice.
6. API Keys, accounts, balances, and platform abuse
Users must not:
- Publicly expose, sell, rent, transfer, or share without authorization any account, API Key, balance, or redemption code;
- Register accounts in bulk, use false identities, or farm trials, rewards, referral credit, or promotions;
- Use a proxy, VPN, script, device spoofing, or another method to evade risk controls or regional restrictions;
- Resell ApiFlux through a technical or commercial arrangement without written authorization from NovaSpan LLC;
- Conduct unauthorized load tests, scraping, reverse engineering, scanning, attacks, or resource exhaustion against ApiFlux or an Upstream Service;
- Interfere with billing, logs, limits, routing, failover, security policy, or another user's normal use.
Users may integrate ApiFlux into their own products but must protect credentials, apply reasonable usage limits, monitor suspicious activity, and remain responsible for end-user behavior.
7. Upstream-service policies
Users must comply with the terms of service, acceptable-use policies, content policies, regional restrictions, and commercial rules of the upstream model, API, cloud platform, or channel actually called. Upstream policies may differ by model or channel.
Users must not use the unified interface, routing, or failover features of ApiFlux to evade upstream safety measures, model restrictions, rate limits, account restrictions, resale restrictions, regional restrictions, or payment requirements. ApiFlux may reject, filter, degrade, or reroute a request to meet upstream requirements.
8. Enforcement measures
We may use automated and human methods to detect possible violations, fraud, security risks, and abnormal traffic. Where we reasonably believe there is a violation or urgent risk, we may:
- Warn the user and require remediation;
- Limit models, features, rates, concurrency, regions, or payment methods;
- Reject, filter, delay, or stop relevant requests;
- Revoke or rotate an API Key or freeze, suspend, or terminate an account;
- Cancel promotions, referral rewards, redemption codes, or improperly obtained credit;
- Deny a refund, handle a chargeback, or recover loss under the payment rules;
- Preserve necessary evidence and notify an upstream provider, affected party, regulator, or law-enforcement body;
- Delete unlawful content or related data where permitted or required by law.
Measures depend on severity, repetition, intent, actual or potential harm, and remediation. To prevent evasion or protect third parties, we may be unable to disclose all investigation details.
9. Reports and appeals
- Abuse report: https://apiflux.ai/contact (start the subject or message with “Abuse”)
- Account appeal: https://apiflux.ai/contact (mark “Appeal”)
- Urgent security incident: https://apiflux.ai/contact (mark “Urgent Security”)
A report or appeal should include the account email, request ID, time, model/channel, order number, API Key prefix/suffix, relevant facts, and necessary evidence. Do not send a full API Key, password, private key, card information, or unrelated personal information.
10. Policy updates
We may update this policy for changes in law, the product, security risks, or upstream policies. Where reasonably practicable, we will notify users of material changes through the website, console, or registered email. Continued use after an update takes effect constitutes agreement to the updated policy.