Acceptable Use Policy
Pure Grace AI, LLC — AI Privacy Center
Version: 1.0 · Effective Date: July 1, 2026
This Acceptable Use Policy (“AUP”) governs Customer’s and its Authorized Users’ access to and use of the Services. By accessing or using the Services, Customer agrees to this AUP. This AUP is incorporated into and forms part of the Terms of Service or Master Services Agreement between Customer and Company (the “Agreement”), and is governed by and subject to it. Capitalized terms not defined here have the meaning given in the Agreement. This AUP supplements, and does not limit, the Agreement; to the extent of any conflict regarding permitted use, the more restrictive provision controls. The Agreement’s limitation-of-liability provisions and the California Civil Code Section 1668 savings clause apply to this AUP. Nothing in this AUP expands Company’s liability or waives any non-waivable right of Customer or any other person under applicable law.
1. Responsibility for Use and Accounts
Customer is responsible for all activity under its account and for its Authorized Users’ compliance with this AUP and the Agreement, except to the extent caused by Company’s breach of the Agreement, violation of law, fraud, willful misconduct, or other liability that cannot be limited or waived under applicable law. Customer will keep account credentials confidential, will not share credentials or permit access by anyone other than its Authorized Users, and will promptly notify Company of any suspected unauthorized access or use. Customer is responsible for ensuring its Authorized Users are of legal age to provide any consents required in their jurisdiction.
2. General Prohibited Conduct
Customer and its Authorized Users must not, and must not authorize or enable any third party to:
(a) use the Services in violation of any applicable law, regulation, or third-party right;
(b) upload, store, transmit, or distribute content that is unlawful, infringing, defamatory, harmful, deceptive, or that violates intellectual property, privacy, publicity, or other rights;
(c) send spam or other unsolicited or unlawful communications, including unlawful email, SMS, robocalls, or similar electronic marketing where applicable;
(d) upload or transmit any virus, malware, worm, Trojan horse, or other harmful code, or any link that redirects to such code;
(e) attempt to gain unauthorized access to, or disrupt the integrity, security, or performance of, the Services or related systems, networks, or data;
(f) reverse engineer, decompile, disassemble, or attempt to derive source code from, or circumvent any technical limitation, rate limit, plan limit, or protection mechanism of, the Services, except to the extent this restriction is prohibited by applicable law;
(g) access or use the Services to build or benefit a competing product or service, or for benchmarking without Company’s prior written consent;
(h) resell, sublicense, or otherwise make the Services available to third parties except as expressly permitted by the Agreement;
(i) load-test, stress-test, or probe the Services without Company’s prior written approval; or
(j) misuse the Services in any manner that imposes an unreasonable or disproportionate load on Company’s infrastructure or degrades the Services for others.
3. Site Scanning — Authorized Targets Only
The Services include functionality that loads and scans websites Customer designates. Customer must not scan, or direct the Services to scan, any domain, website, or property that Customer does not own or is not otherwise authorized to scan. Customer is responsible for verifying ownership or authorization of any target (including via the platform’s domain-verification mechanism where required) and for ensuring its scanning is permitted by the target’s terms and applicable law. Customer must not use the scanning functionality to probe, map, or attack infrastructure, to attempt to reach internal or non-public systems, or to circumvent the platform’s scanning safeguards.
4. Writes to Customer Property (CMS Writes)
Customer must only enable, authorize, or direct a CMS Write to Customer Property that Customer owns or is authorized to modify, and must hold all necessary rights, credentials, and approvals. Customer must not use the CMS Write functionality to publish content to, or modify, any property it does not control or is not authorized to change. Customer is responsible for reviewing and approving content before it is written, for maintaining backups (see Terms of Service, “Customer Backup Responsibility”), and for the consequences of writes it authorizes (see Terms of Service, “Customer Authorization for CMS Writes and Site Changes”).
5. Consent Records and Audit Logs
Customer must not store, submit, or cause the Services to record false, fabricated, simulated, or otherwise inaccurate consent records, and must not tamper with, alter, forge, or attempt to defeat the integrity of the consent records, the tamper-evident consent audit log, or any other audit or compliance log maintained by the Services. Customer must ensure that consent and preference data submitted through the Services reflects genuine end-user interactions.
6. AI-Generated Content
The Services may generate draft privacy policies, disclosures, and data-subject-request responses using automated and AI-assisted tools. Customer must not represent AI-generated output as legal advice, must independently review, edit, and approve such output before relying on or publishing it, and remains solely responsible for its accuracy and legal sufficiency (see Terms of Service, “No Legal Advice; Customer Compliance Responsibility” and “Customer Responsibility for Privacy Notices”). Customer must not use the Services’ generation features to produce unlawful, infringing, or deceptive content.
7. Data-Subject-Request Intake
Customer must not use the data-subject-request (DSR) intake and fulfillment features to submit fraudulent, harassing, or abusive requests, to impersonate another person, or to obtain or disclose personal information without authority. Customer, as the controller of its data, is responsible for verifying the identity and authority of requestors and for fulfilling DSRs in accordance with applicable law; the Services provide assistance only.
8. Privacy- and Compliance-Consistent Use
Customer must not implement or configure the Services in a manner that is inconsistent with the privacy, consumer-protection, or data-protection laws applicable to Customer’s website visitors or end users. Customer is responsible for providing all required notices, obtaining all required consents, honoring opt-outs, and otherwise complying with applicable law in connection with its use of the Services, its Customer Property, and its data, marketing, advertising, and subscription practices.
9. Monitoring, Suspension, and Enforcement
Company may, but is not obligated to, monitor use of the Services for compliance with this AUP. Company may investigate suspected violations and may, with notice where practicable, suspend or restrict access to the Services to address a violation of this AUP, a security risk, abusive activity that degrades the Services for others, or a legal requirement. Company may suspend immediately and without prior notice where it reasonably believes immediate action is necessary to prevent harm, a security incident, or a violation of law. If a violation is not reasonably cured within the period stated in the Terms of Service after notice, Company may terminate the Agreement as provided there. Company may respond to lawful requests, subpoenas, court orders, emergency requests, or other valid legal process, and may cooperate with law enforcement, in each case only as permitted or required by applicable law and consistent with Company’s Privacy Notice. Company’s rights under this Section are in addition to its other rights and remedies and do not limit them.
10. Reporting Abuse
To report suspected abuse, security issues, or violations of this AUP, contact abuse@puregraceai.com.
11. Changes to This AUP
Company may update this AUP from time to time. Material changes will be handled in accordance with the “Updated Terms; Re-Acceptance” section of the Terms of Service, and Customer’s continued use of the Services after an update’s effective date constitutes acceptance of the updated AUP, to the extent permitted by applicable law. Updates to this AUP do not modify pricing, renewal terms, subscription term length, or cancellation rights unless those changes are separately made in accordance with the Agreement and applicable law.