Binding policy. Violation may lead to site suspension, OAuth revocation, reporting to authorities/platforms, and liability. Operators are responsible for their users' compliance on self-hosted instances. When in doubt — don't do it, or seek legal advice first.
1. General Principles
- Comply with all applicable laws (Kuwait, your residence, and where you deploy): criminal, privacy, IP, consumer, export/sanctions, and platform terms of service.
- Respect human oversight: keep HITL gates on for consequential actions in production.
- Be transparent about AI (EU AI Act Art. 50): disclose AI interaction and label synthetic content.
- Least privilege: only connect data/scopes you have rights to and need.
2. Prohibited Content & Conduct (Never)
- Illegal activity: crime, fraud, illicit finance, sanctions evasion, child sexual abuse material, sexual exploitation, human trafficking, harassment, stalking, threats, defamation.
- EU AI Act prohibited practices (Art. 5) — banned: social scoring; manipulative/subliminal techniques materially distorting behavior; exploiting vulnerabilities (age, disability, socio-economic); non-consensual real-time remote biometric identification for law enforcement (except narrow statutory exceptions); workplace/education emotion inference; untargeted facial scraping; predictive policing based solely on profiling.
- Deception: disinformation, deepfakes and non-consensual intimate imagery, impersonation, astroturfing, fake reviews, undisclosed AI personas where disclosure is required.
- Spam/abuse of messaging & mail: bulk unsolicited commercial mail/messages via Gmail/Telegram/Discord/Slack/X; circumventing filters, quotas, or abuse controls; using multiple accounts to evade limits.
- Security abuse: unauthorized access, malware/ransomware, intrusion, credential theft, bypassing authentication/HITL/checksums, distributing malicious skills or MCP tools, crypto-mining on others' resources, DDoS.
- IP abuse: copyright circumvention (paywalls/DRM), large-scale reproduction of copyrighted text/code/media without rights, trademark counterfeiting, Drive-as-CDN copyright dissemination.
- Privacy abuse: connecting accounts/data without consent; exfiltrating others' mailbox/Drive/chat contents; re-identifying anonymized data; stalking or surveillance.
- High-risk safety abuse: weapons (including CBRN and cyber-weapons), attacks on critical infrastructure, instructions facilitating imminent violence or wrongdoing, unsupervised control of vehicles/medical/industrial safety systems.
3. Restricted / High-Care Uses (Allowed Only With Safeguards + Counsel)
- Employment, education, credit, housing, insurance, immigration, law-enforcement, judicial, democratic-process, or safety-component contexts (EU Annex III high-risk analogues): require documented risk assessment, logging, human review, bias testing, and legal sign-off.
- Legal/medical/financial communications sent on your behalf: licensed-professional review required.
- Children's data: guardian consent + data minimization; no targeting.
- Health/financial/biometric data: explicit consent, purpose limitation, heightened encryption and retention controls.
- Web automation/browsing: respect robots.txt, terms of service, and rate limits; no credential stuffing or deceptive scraping.
4. Platform-Specific Duties
- Google: only approved use cases (email clients, backup, productivity, reporting); least-privilege scopes; no ads/generalized-training on Restricted data; honor Limited Use; complete verification/assessment for your OAuth client.
- X (Twitter): posting and automation must use the official X API v2 through the Kazma publisher with human-in-the-loop approval; respect X's developer agreement, automation rules, and rate limits; no bulk-following, engagement farming, or undisclosed bot personas; label AI-generated content where X rules or law require.
- Telegram/Discord/Slack: comply with each platform's API terms, bot policies, and user-consent rules; honor opt-outs promptly.
- LLM providers & MCP: comply with provider usage policies; classify MCP tools by risk; untrusted tools stay HITL-gated in production; verify skill checksums (fail-closed on mismatch).
5. Operational Safety Rules for Kazma Operators
- Keep
KAZMA_PRODUCTION=1, strong secrets, vault key, RBAC/OIDC for multi-user, Postgres for multi-replica (never share SQLite across replicas). - Do not expose the Web UI or gateways publicly without authentication, TLS, trusted-proxy configuration, and rate limits.
- Test backups and restores; maintain audit logs/snapshots for incident review.
- Report vulnerabilities privately (admin@kazma.ai); do not weaponize or publicly disclose before a coordinated fix.
6. Enforcement & Reporting
We may investigate, suspend site access, remove content, revoke integrations, or report to platforms/authorities for violations. Self-host operators must enforce against their users and cooperate with lawful requests. To report abuse: admin@kazma.ai with logs, timestamps, and impact. Security issues: admin@kazma.ai (see SECURITY.md).
7. Changes
We may update this AUP as laws (notably EU AI Act guidance/Codes of Practice, Google policies) evolve. Material changes get prominent notice; continued use constitutes acceptance.
Related: Privacy Policy · Terms of Use · AI Disclaimer