Version 1.0.2 · In force from · Ever Technologies LTD
Acceptable Use Policy
Ever — ever.co
Version 1.0.2 · In force from 2026-08-02
This Acceptable Use Policy ("AUP") sets out what may and may not be done with the Ever website and the websites, applications and application programming interfaces we make available at ever.co (together, the "Service").
It forms part of our Terms of Service and uses the words defined there. Breaking a rule in this policy is a breach of those Terms, and the enforcement section below sets out what we do about it.
We have kept it specific. A policy that only says "do not misuse the Service" tells nobody anything and protects nobody — least of all the people our software can be pointed at.
Who this policy applies to
- You, as the customer holding the Subscription.
- Your End Users — everyone you invite into your Workspace, whether an employee, a contractor, a client or a colleague. What they do in the Service counts as your act, and it is your job to make sure they know these rules.
- Anyone else who reaches the Service through you — a person you send a share link to, a person who receives a message sent through the Service, anyone using access you granted.
- Visitors to our public websites, documentation and community channels, and anyone using our public forms, endpoints or APIs.
You do not need an account for this policy to apply to you. Using the Service in any way means these rules apply to what you do with it.
What this policy does not apply to
Self-hosted deployments. Where our software is published as open source, that code is licensed to you under its own licence, and this policy imposes nothing on you as a self-hoster. It governs the hosted Service we operate and nothing else. Nothing here adds a restriction to any open-source licence — the open-source carve-out in our Terms of Service explains the split.
Lawful workplace monitoring. Some of our products exist to measure how work happens, and this policy does not prohibit using them for that. What it prohibits is doing it covertly, doing it to people who were never told, and doing it to people who are not yours to monitor. That distinction is drawn deliberately, and in detail, in the privacy and surveillance section below.
How it fits with everything else
- The product-specific section of this policy adds rules for the particular Service you use. Where a core rule and a product rule both apply, follow the stricter one.
- Where your Order, a written agreement with us, or the Documentation permits something this policy would otherwise forbid — an agreed rate limit, an authorised security test — that permission governs, for that thing only.
- The examples here are examples. They show what we mean; they are not a complete list of everything that can be done wrong. Conduct that is plainly within the spirit of a prohibition is prohibited.
We are not obliged to monitor what you do in the Service, and we do not routinely read the contents of your Workspace. We do act on what we find and on what is reported to us, and not acting on one thing never waives our right to act on another.
Illegal and harmful activity
Do not use the Service to do anything unlawful, to help someone else do it, or to conceal that it is being done. Something is out of bounds here if it is unlawful where you are, where we operate, or where the person affected by it is — you do not get to pick the most permissive of the three.
Never, under any circumstances
Some conduct has no lawful version and gets no benefit of the doubt. We terminate immediately for it, we preserve what we hold, and we report it to the authorities where the law requires that or where a person is at risk:
- child sexual abuse material, and sexualised content involving a minor in any form;
- content that grooms, solicits or endangers a child;
- non-consensual intimate imagery, and threats to publish it;
- terrorist content, and material that incites, promotes or gives instruction for terrorism or mass violence;
- credible threats of serious violence against a person or a group;
- human trafficking, forced labour, and the sale or exploitation of people.
There is no enforcement ladder for this list and no cure period.
Fraud and deception
- Fraud of any kind — payment fraud, invoice fraud, business email compromise, advance-fee schemes, pyramid and Ponzi arrangements.
- Phishing, credential harvesting, and pages or messages built to be mistaken for someone else's.
- Card testing, use of stolen or unauthorised payment instruments, chargeback abuse, money laundering, and moving the proceeds of crime.
- Impersonating a person, a company, a public body or us; using a false identity; forging message headers or sender identities.
- Fabricated reviews, testimonials, endorsements, certifications, awards or qualifications.
- Falsifying records the Service generates or holds — including tampering with a timer, tracker, activity log or timesheet to misstate work done or time worked. Where that record is evidence between you and your own employer or customer, falsifying it is fraud against them and a breach of this policy against us.
Unlawful goods, services and content
Do not use the Service to offer, advertise, arrange, broker or deliver: controlled substances and unlicensed pharmaceuticals; weapons, ammunition or their components; counterfeit goods; stolen property, stolen data or stolen credentials; unlicensed gambling; or anything else you are not licensed to provide where you provide it.
Where your business is lawful but regulated — health, finance, insurance, legal services, alcohol, tobacco, age-restricted goods — holding the right licences, giving the right disclosures and running the right verification and handover checks is yours to do. We do not check any of it and we are not your compliance function.
Sanctions, export controls and embargoes
You must not use the Service, or allow it to be used, in breach of applicable sanctions or export-control law, or for or on behalf of a person or organisation subject to them. The compliance, export and sanctions section of our Terms of Service sets out what that means for your Subscription.
Interfering with the law
Do not use the Service to obstruct a lawful investigation, evade a court order, conceal or destroy material you are required to keep, or defeat a removal, blocking or suppression obligation that applies to you.
Content that infringes someone else's rights
You need the right to put something into the Service before you put it there. That applies to files, images, text, code, datasets, brand names, and anything an integration brings in on your behalf.
What is prohibited
- Uploading, storing, publishing, sharing or distributing anything that infringes another person's copyright, trade marks, design rights, database rights, patents or trade secrets.
- Importing or republishing datasets, catalogues, curated lists or harvested collections you have no right to use. An openly licensed source is not an unconditional one — attribution, share-alike and non-commercial conditions travel with the content, and honouring them is your job, not ours.
- Using someone else's trade mark in a workspace name, project name, URL slug, custom domain or sending domain in a way that suggests a connection you do not have. That includes typosquats and look-alike domains.
- Putting another party's confidential information into the Service where you have no right to disclose it: material under a non-disclosure agreement, another company's customer data, privileged or otherwise protected work.
- Removing, obscuring or altering a copyright notice, licence text, attribution or provenance metadata.
Our own software and brand
Where a product is published as open source, its licence governs what you may do with the code — but do not strip its licence headers or attribution, do not present a fork or a self-hosted deployment as a service we operate, do not redistribute a paid edition, and do not circumvent the limits of the tier you bought. What you may do with our names, logos and other brand features is dealt with in the intellectual property section of our Terms of Service.
Reporting infringement
If something on the Service infringes your rights, tell us at [email protected]. We handle these as notice-and-action complaints under the rules that apply to us as a hosting service in the European Union, and a notice needs to give us:
- what the right is and why you hold it, or your authority to act for the person who does;
- exactly where the material is — a URL, share link, workspace or file path, precise enough that we can find it without guessing;
- what the material infringes, and how;
- a statement that you believe in good faith the use is not authorised by the rights holder, an agent or the law; and
- how to reach you.
What happens next
We assess notices on their content, not on their volume or their tone.
Where a notice is well founded we remove or disable access to the material, and we tell the affected customer what we did and why, unless the law prevents us. Where the customer tells us the notice is wrong, we pass that back to the complainant and we may restore the material. We are not the venue for deciding who owns what — a genuine ownership dispute belongs in a court, not in our inbox.
We terminate accounts that infringe repeatedly. What counts as repeat is a judgement about the pattern and the customer's response to it, not a fixed count we publish for people to stay just underneath.
Harassment, hate and abusive content
Most of what goes into the Service is private business content in your own Workspace, and we are not the manners police for it. These rules still apply to it, and they apply with real force to anything you publish through the Service, send to another person through it, or point a share link at.
Prohibited
- Harassment and bullying — a course of conduct directed at a person that is intended to, or is reasonably likely to, intimidate, humiliate or distress them, including conduct continued after they have asked for it to stop.
- Threats of violence, and content that celebrates or wishes serious harm on identifiable people.
- Stalking — using the Service to follow, locate, contact or observe a person against their wishes. Where that involves our capture, recording or tracking features, the privacy and surveillance section below governs it and we treat it as the most serious category of breach we handle.
- Hate speech — attacking or demeaning people because of race, ethnicity, national origin, religion, disability, age, sex, sexual orientation, gender identity or another protected characteristic.
- Doxxing — publishing or sharing a person's private information without their agreement, or assembling it so that someone else can act on it. Home addresses, personal contact details, identity documents, location, medical and financial details all count.
- Sexual content involving a person who has not agreed to it being shared, and any sexual content involving a minor. That second category is dealt with absolutely in the illegal activity section above.
- Adult content on public-facing surfaces we host for you, unless we have agreed it in writing and it is lawful and age-gated where it is served.
- Abuse of our own people. Threatening, abusive or discriminatory conduct towards our staff in support tickets, chat, calls, issue trackers or community channels. We will end the conversation, and if it continues we will end the relationship.
Content you publish for other people to see
Where the Service lets you publish something publicly — a page, a directory, a profile, a shared recording, a public team — you are the publisher of it, not us. Keep other people's personal data out of it unless they know and you have a basis for holding it there, provide a way for people to complain about what you have published, and act on a reasoned objection rather than ignoring it. You must not republish content that a person has already had removed.
Where you run something on our infrastructure that accepts contributions from the public, moderating it is your obligation. Our tools do not discharge it and our policy is not your policy.
Community and contribution channels
Our public repositories, issue trackers, documentation sites and chat channels carry these rules plus any code of conduct published with them. Spam, off-topic promotion, brigading and abuse there are breaches of this policy and we deal with them the same way.
Privacy and unlawful surveillance
This is the strictest section in this policy, and it is strict because of what our software can do.
Some of our products measure how work happens. Depending on the product and the settings your administrators choose, they can capture screenshots, webcam stills, audio, screen recordings, keyboard and mouse activity rates, the applications and websites in use, location, and how long each of those lasted. Selling software that can do that places a duty on us that a project-management tool does not carry, and this section is how we discharge it.
Lawful, disclosed monitoring of your own personnel is a legitimate use of the Service. Covert monitoring is not, and never will be. Everything below follows from that one line.
Monitoring that is never permitted
You must not use the Service, or configure it, to do any of the following.
- Covert or secret monitoring of any person. If the person being measured does not know it is happening, it is prohibited — whatever your reason, wherever you are, and whether or not you believe you have a lawful basis for the underlying processing.
- Monitoring anyone who has not been informed in the way their local law requires, before capture starts. Telling someone afterwards is not notice. A line in a handbook they have never seen is not notice either, where their law demands more.
- Monitoring outside working hours, during breaks, on personal time, or on a person's own device, without a lawful basis and their knowledge. Capture follows the work. It does not follow the person.
- Enabling screen capture, webcam stills, audio capture or screen recording where local law prohibits it, restricts it to purposes you are not pursuing, or conditions it on a process you have not completed.
- Deploying a configuration the monitored person cannot see, pause, stop or exit. Combining continuous or randomised capture with settings that stop a person closing the agent, logging out, or seeing that capture is running produces covert monitoring by construction, and we treat it as covert monitoring however it was arrived at.
- Monitoring anyone other than your own personnel in the course of their work. The Service may be used to measure your employees, contractors and workers while they work for you. It may not be pointed at a partner, a family member, a housemate, a child, a customer, a competitor, a journalist, or any other person who is not yours to monitor. Using our software as stalkerware is an immediate-termination breach and we will treat it as one.
- Installing the desktop agent, browser extension or tracker on a device you do not own or control, without the informed agreement of the person who does.
- Using captured data for a purpose the monitored person was not told about. If they were told capture was for billing accuracy, it is not then available for discipline, performance ranking or redundancy selection. Purpose creep is a breach of this policy, not only of your own notice.
- Capturing where capture predictably exposes other people's confidential or special-category data — clinical settings, legally privileged work, HR investigations, child-facing services, or a home where other people are visible or audible — unless capture is switched off for the people concerned.
- Defeating the controls that exist to protect people. Do not work around a per-person or per-team disable, a blur setting, a retention limit, an excluded-application list or a capture-frequency limit in order to observe someone whose monitoring is meant to be off or reduced.
Other people's privacy, whatever product you use
These apply across the Service, not only to the products that measure work.
- Recording a call, meeting, screen or conversation without the notice or consent the law requires from everyone involved. Several jurisdictions require every party to agree, and where participants are in different places the strictest rule among them is the one that governs.
- Capturing another person's screen, device, session or account without their authorisation.
- Using a browser extension's access to reach pages the person never intended to expose — personal banking, health portals, private messaging, personal webmail.
- Harvesting personal data at scale, from us or from anywhere else, including collecting it in breach of another platform's terms, its rate limits or its technical protections.
- Building biometric profiles, or inferring sensitive characteristics about people — health, beliefs, sexual orientation, union membership, immigration status — from anything the Service captures or holds.
- Entering another person's personal data into our forms, or subscribing an address you do not control.
- Putting special-category data into the Service without a lawful basis for it, or where your product annex states that the Service is not built to hold it.
What you promise us when you switch monitoring on
By enabling any capture or activity-measurement feature for a person, you represent to us that:
- you are the controller of that processing, you have identified a valid lawful basis for it, and you understand that consent is generally not a valid basis in an employment relationship, because of the imbalance between the person asking and the person consenting;
- you have given that person the information their law requires — what is captured, how often, why, who sees it, how long it is kept, and how to object — before capture began;
- you have carried out a data protection impact assessment where one is required, and consulted your supervisory authority where the residual risk requires that;
- you have completed any works council, trade union or employee-representative process required where that person works. These are not formalities. Co-determination in Germany, works council consent in Austria, works council approval in the Netherlands, prior union agreement or labour-inspectorate authorisation in Italy, and co-operation negotiations in Finland can each make a deployment unlawful, and the data it produced unusable, if they were skipped;
- you will not enable capture for anyone in a jurisdiction that prohibits it. Some do. Supervision of performance by remote technical means is close to prohibited outright in Portugal, and keystroke and continuous-capture tooling has been held unlawful elsewhere on proportionality grounds; and
- you are not using the Service to monitor covertly, or to monitor anyone outside a lawful monitoring programme of your own.
We make no claim that any configuration of the Service is lawful in any country. This law differs sharply from one jurisdiction to the next and is still moving. We build the controls, publish what each one does, and give you the material to run your own assessment. The decision to switch monitoring on is yours, and so is the liability that comes with it. Your indemnity in our Terms of Service covers claims that arise from breaking the representations above.
We act on credible reports of covert monitoring
Anyone can report suspected covert or unlawful monitoring to [email protected] — you do not have to be our customer. A monitored worker, a works council, an employee representative, a family member or a regulator can all use that address. We would far rather receive a report that turns out to be a misunderstanding than not receive one at all.
When we receive a credible report:
- we treat the reporter's identity as confidential. We do not pass it to the customer without their agreement unless the law compels us. We know that the person best placed to report covert monitoring is usually the person with the most to lose by reporting it;
- we may require the customer to evidence the notice it gave, the lawful basis it relies on, and the consultations it completed. "Trust us" is not evidence, and a customer that cannot produce any is treated as a customer that has none;
- we may switch off specific capture features for that Workspace while we look, suspend the account, or terminate it, depending on what we find and how serious it is; and
- we will not take a customer's assurance over a credible report from the person being monitored.
Retaliating against someone because they reported to us — dismissing them, disciplining them, withdrawing their work — is itself a breach of this policy, and we will act on it against the customer that does it.
Security violations
The Service is shared infrastructure. The rules below protect other customers at least as much as they protect us.
Do not
- Access anything you were not given access to — another customer's Workspace or data, another user's account, our internal systems, or any part of the Service behind a boundary you were not invited past.
- Probe, scan or test the Service, our networks or our infrastructure for vulnerabilities without our prior written permission, except within the coordinated disclosure route below.
- Attack accounts — credential stuffing, password spraying, brute forcing, or enumerating accounts and email addresses through sign-in, recovery or invitation endpoints.
- Enumerate or guess identifiers. Share links, object ids, invitation tokens and export URLs are meant to be given to you, not discovered by you.
- Circumvent controls — authentication, authorisation, session handling, tenant isolation, rate limits, quotas, access gates, licence-tier limits, or any technical protection measure.
- Interfere with the Service — denial-of-service traffic, load designed or reasonably likely to degrade the Service for others, or any attempt to cross the isolation between one Workspace and another.
- Reverse engineer, decompile or disassemble the Service, except to the extent an applicable open-source licence or a law that cannot be excluded permits it.
- Turn the Service into infrastructure for something else — an open relay or proxy, an anonymisation or VPN service, a command-and-control endpoint, a port scanner, a password-cracking rig, or a staging point for an attack on a third party.
Credentials and access
- Accounts are for one person. Do not share a login, and do not hand an account from one person to the next as staff change — create and remove accounts instead.
- Do not share API keys, tokens or seats outside the Workspace they were issued for, and do not leave them anywhere others can read them.
- Do not give us credentials you are not entitled to use — a colleague's, a former employer's, a shared mailbox you do not control, or an access token, key or configuration file belonging to someone else.
- Do not use the Service to store, distribute or trade credentials obtained from anyone else.
- Keep your own credentials secure, turn on multi-factor authentication where we offer it, and tell us at [email protected] as soon as you suspect an account has been compromised. Delay there costs other people, not only you.
Security research
We want to hear from researchers, and we will not pursue anyone who acts in good faith.
Your testing is in scope if you work only against your own account and your own data; do not access, modify or retain another customer's data; stop at the point that demonstrates the issue rather than pushing further; avoid degrading the Service or causing a privacy impact; do not run automated scanning at volume; and report to us promptly and privately at [email protected] before disclosing anywhere else.
Testing against another customer's Workspace or data is never in scope, whatever your intent. How we handle reports, and what we commit to in return, is set out on our Security page.
Resource abuse
You share compute, storage, bandwidth and outbound sending reputation with every other customer. Use your share.
Do not
- Mine cryptocurrency, run distributed computing, or use the Service for processing that has nothing to do with what the Service is for.
- Use our storage or bandwidth as a general-purpose content delivery network, a file-distribution service, a backup target for unrelated data, or a home for media we had no part in producing — including hot-linking files held with us into other sites.
- Run automated bulk extraction against the Service, our websites, our documentation or our APIs. Issued API credentials used within their documented scope and rate limits are exactly what they exist for; scraping the interface, or driving an API past its published limits, is not.
- Run unbounded or pathological workloads — agent or job loops with no termination condition, retry storms, runaway automation, or deliberately expensive requests repeated to see what happens.
- Hold sessions, connections or reserved capacity open purely to keep hold of them.
- Evade a limit rather than raise it: extra accounts to farm a free allowance, disposable addresses, referral or credit gaming, seat sharing, or a second Workspace created because the first one hit its ceiling.
Free plans and trials
Free and trial access exists so that you can evaluate the Service and so that small teams can use it. It is not anonymous infrastructure. Limits on free plans are tighter, are enforced at our discretion, and can change without notice. We may reclaim idle free resources, and we may decline to keep providing a free plan to an account whose consumption is out of proportion to what free access is for.
How we handle it
Sustained load that is normal for your plan is fine. Bursting is fine. What we act on is load that degrades the Service for other people, load that is not really use of the product at all, and load that keeps growing after we have asked about it.
Our first step is normally to contact you, not to cut you off. We would rather move you onto a plan or a limit that fits than lose you over a number. We throttle before we suspend, and we suspend without warning only where the platform or other customers are at risk.
If your usage above a published limit is a genuine business need rather than abuse, write to [email protected] and we will look at raising it. The numbers themselves are in the fair use section below, in your plan or Order, and in the Documentation.
Spam and unsolicited messaging
The Service sends mail, invitations, notifications and, in some products, text messages — sometimes from our own sending domains and on our own reputation. That makes messaging abuse everybody's problem here: one customer's cold-outreach campaign is what gets every other customer's invoices and password resets filtered.
Do not
- Send unsolicited bulk email, SMS or messages of any kind through the Service, or use it to prepare, host or support a campaign that someone else sends.
- Mail a list you cannot stand behind. You must be able to show us, on request, how each recipient came to be on it. Purchased, rented, swapped, harvested and scraped lists are prohibited, and so are address guessing, permutation and dictionary attacks.
- Spoof or falsify a sender identity, a header, a reply path or a domain, or send from a domain you do not control. Where you send through the Service, configure SPF, DKIM and DMARC for your own domain, respect any warm-up schedule and sending rate we set, and keep a working reply path that a human reads.
- Strip, hide, disable or visually suppress an unsubscribe link, a
List-Unsubscribeheader, a required postal address, or any compliance footer the Service adds. Making the opt-out hard to find is the same breach as not having one. - Ignore an opt-out. Suppression must be honoured promptly and permanently. No re-importing a suppressed person, no refreshing them from another source, no moving them into a second Workspace or account to escape the suppression list, and no treating an unsubscribe click as an engagement signal.
- Repurpose our transactional messages as a marketing channel. Invitations, verification mails, share notifications, estimates, invoices and system notices exist to carry their own content — not to carry an offer to someone who never asked for one.
- Use invitations to reach people who will not be working in your Workspace. The invitation flow is a foreseeable spam vector and we watch it.
- Abuse our own public endpoints — automated submissions to our contact, newsletter or support forms, repeated submissions used to bomb a third party's mailbox through them, or link injection into free-text fields.
The law applies to you, and we do not check it for you
Electronic marketing to individuals is regulated separately from data protection. Depending on where your recipients are you may need prior opt-in, and the existing-customer exception is much narrower than most senders assume. Working out which rule covers which recipient is yours to do. Nothing the Service does — including any compliance footer it adds for you — makes a message lawful that would not otherwise be.
Deliverability is an enforcement trigger
We monitor bounce rates, spam complaints, blocklist entries and mailbox-provider feedback for traffic sent through the Service. Where a sender's numbers put shared reputation at risk we act immediately and without notice — pausing a campaign, throttling or suspending sending, revoking a sending domain, or suspending the account. We do the same on a credible complaint from a recipient, a mailbox provider or a blocklist operator.
If you received a message from someone using the Service and you did not ask for it, report it to [email protected] with the full headers if you have them.
Malware and hostile files
Do not upload, store, link to or distribute
- Malware of any kind — viruses, worms, trojans, ransomware, rootkits, keyloggers, spyware and stalkerware.
- Exploit code, exploit kits, cracking and credential-stuffing tools, and payloads intended to establish or keep unauthorised access to anything.
- Files built to attack whatever opens them — decompression bombs, entity-expansion payloads, deliberately malformed documents, and uploads crafted to break a parser, a preview renderer or a downstream viewer.
- Values crafted to execute somewhere else. Text you put into a field that is later exported — a name, a translation string, a note, a description — must not be built to run as a formula, a script or a command in whatever opens the export.
- Phishing and credential-harvesting pages, fake sign-in screens, and deceptive destinations of any kind. A link on our domain lends our credibility to whatever it points at, which is exactly why share links attract this and exactly why we move fast on it.
We scan, and we are telling you so
We may scan, sandbox, quarantine, refuse, disable or delete files, links and messages that we reasonably believe are hostile, and we may do it without prior notice.
We are stating this openly because scanning your uploads is itself a processing activity, and undisclosed processing is not something we are willing to do. What it means for personal data is set out in our Privacy Policy.
Automated detection is imperfect in both directions. If we have quarantined something wrongly, tell us at [email protected] and we will look again.
Security work with a legitimate need
If your work genuinely involves handling malware samples — you run a security team, or you research this for a living — do not do it in the Service without asking us first. Write to [email protected], tell us what you need and how it will be contained, and we will either agree it in writing or tell you no. Doing it without that agreement is a breach, however good the reason.
Your own hygiene
Keep the devices and networks you use to reach the Service reasonably secure and up to date, and tell us at [email protected] if you believe a device with access to your Workspace has been compromised.
AI features, assistants and agents
These rules apply wherever the Service uses a model on your behalf — an assistant, a generated document, an autonomous agent, a connected tool endpoint, or a feature you drive with your own provider key. They sit on top of everything else in this policy, and alongside the AI terms in our Terms of Service.
Anything an agent does under your credentials is your act. Automating a decision does not move responsibility for it.
Do not generate unlawful, deceptive or infringing content
- Content that is unlawful, defamatory, harassing or discriminatory. The rest of this policy applies to generated output exactly as it applies to text you typed yourself.
- Fraud material — phishing text, fake invoices, scam messages, or anything designed to deceive a person into parting with money, credentials or access.
- Impersonation of a real person or organisation, including synthetic voice, image or video of a real person without their agreement, and content presented as authentic when it is not.
- Fabricated facts about a named person or business: reviews, testimonials, endorsements, qualifications, awards, or claims about their conduct, finances or history.
- Content that infringes someone else's rights, and output presented as original where it is not.
- Bulk low-value content produced to manipulate search rankings — doorway pages, mirror sites, near-duplicate sites generated at scale, cloaking and link schemes.
- Removing or falsifying provenance metadata or watermarks that mark content as machine-generated, and passing model output off as human-created where doing so misleads someone whose decision depends on it.
Do not make consequential decisions about people without human review
Model output is an input to a decision. It is never the decision.
Where a decision materially affects a person — hiring, promotion, discipline, dismissal, pay, credit, insurance, tenancy, education, benefits, access to essential services, or legal and immigration status — you must not treat a score, ranking, band, signal, summary or recommendation produced through the Service as the sole or determinative basis for it. A human being with authority and real discretion must consider the case and be able to reach a different answer.
That applies with particular force to anything derived from monitoring. An activity percentage, a productivity score, a screenshot summary or an attention metric is not a finding about a person's performance, and treating it as one is both a breach of this policy and, in many places, a breach of the law.
You must not use these features to discriminate on a protected characteristic, directly or through a proxy for one. Where we find a customer doing this, we may switch the feature off for that Workspace.
Do not present output as professional advice
Do not use the Service to give medical diagnosis or treatment decisions, clinical decision support, legal advice, or financial and investment advice in a way that a recipient would reasonably take as coming from a qualified professional. Do not use it in the design or development of weapons.
Do not attack the models or the pipeline
- No attempts to extract training data, model weights, system prompts, tool definitions, configuration, or another customer's data or prompts.
- No prompt injection. Do not place instructions in content, files, profile fields, repositories, tickets, commits or messages that are designed to make an assistant ignore its policies, act outside its permissions, operate on another party's data, call a tool it was not authorised to call, or disclose secrets.
- No circumventing safety measures — content filters, approval gates, human-in-the-loop confirmations, usage limits or policy checks. That includes automating a confirmation so an action is taken without a real human decision behind it. The approval gates are load-bearing. Defeating one is a severe breach and we may block access immediately.
- No using our AI endpoints as a general-purpose relay: proxying traffic, reaching internal or arbitrary hosts, or pushing work unrelated to your use of the Service through us to a provider.
- No supplying provider credentials you are not entitled to use, and no sending a provider content you have no right to send it. Where you bring your own key, that provider's terms bind you as well as ours do.
Do not compete with what you are using
Do not use the Service, its output or its features to develop, train, fine-tune, distil or benchmark a competing model or product, and do not resell, sublicense or transfer model access obtained through us.
Fair use and published limits
Every plan has limits. We publish them, rather than leaving "fair use" to mean whatever we decide later.
Where the numbers are
The limits that apply to you are in your plan description or Order, in the Documentation for the Service, and in the product-specific section of this policy. Where the same limit appears in more than one of those, the one in your Order wins.
Depending on the product, they cover:
- API request rate, and the burst allowance above it;
- concurrent connections — streaming, websocket, agent and tool endpoints;
- total stored data per Workspace, and the size of any single upload;
- capture and media volume, where the product records screenshots, recordings or other media;
- outbound message volume and sending rate;
- agent, job or build run time; and
- seats, Workspaces and connected integrations.
What "unlimited" means when we say it
Where a plan is described as unlimited, or as fair use, it means unlimited normal use of the product as it is sold — not permission to use us as generic storage, generic compute or a content delivery network. When your usage stops resembling use of the product, it stops being covered by the word.
How limits are applied
Rate limits are enforced technically: over the limit you get an error and a retry signal, not a surprise invoice. We do not bill overage that was not in your Order.
Where a storage or volume ceiling is exceeded, we contact you first and give you a reasonable period to reduce usage or move to a plan that fits before we restrict anything. Free and trial plans are the exception, and the resource abuse section above says how.
When limits change
We may change published limits. Where a change materially reduces what you can do on a plan you are paying for, we give you notice in the way the changes section of our Terms of Service requires, and you may cancel before it takes effect. Increases, and changes to free-plan limits, take effect when we publish them.
If you have a genuine need above a published limit, ask us at [email protected]. We would much rather agree a higher limit with you in advance than discover the traffic.
Reporting abuse
[email protected] — one address, read by people, for anything on this page.
You do not have to be our customer to use it. We publish it for the person with no other route: a worker who believes they are being monitored covertly, someone who received a message they never asked for, a rights holder, a researcher, a works council, a parent, a regulator. Reports from people who are not customers get the same handling as reports from people who are.
What to tell us
The more of this you can give us, the faster we can act. Send what you have — an incomplete report is still worth sending.
- What happened, in your own words.
- Where — the URL, share link, workspace, sending address, message headers, or the name of the application or agent involved. Precise enough that we can find it without guessing.
- When, with dates, times and the time zone you are quoting.
- Who is affected, if you can say, including whether that is you.
- Evidence — headers, message ids, screenshots, links. Attach it where you can, rather than describing it.
- What you are asking for — content removed, messages stopped, monitoring investigated, information.
- How to reach you, if you want an answer. You may report anonymously, but we then cannot come back to you for the detail that often decides a case.
Some reports have a better route. A request about your own personal data goes to [email protected]. A security vulnerability goes through the coordinated disclosure route in the security violations section above. An intellectual property complaint needs the specific details listed in the infringing content section.
If you are reporting suspected covert monitoring, say so in the first line. Those go to the front of the queue.
What we do with it
- We acknowledge within two business days.
- We give you a substantive answer, or a real status update, within ten business days. Investigations that involve a customer's own workforce sometimes take longer than that. Where they do we will tell you where it has got to rather than going quiet on you.
- Where a person is at immediate risk, we act first and correspond afterwards.
- We keep the reporter's identity confidential. We do not pass it to the customer without your agreement unless the law compels us, and where that happens we will tell you if we are permitted to.
- We tell you the outcome in general terms. We will not hand you another party's account details, internal correspondence or personal data, however much you would like us to. The same protection applies to you.
What we are not
We are not a court and we are not an arbitrator. Where a report is really a commercial or contractual dispute between you and someone else, we will say so and decline to take a side. We enforce our own rules against our own customers — that is the whole of our jurisdiction.
Deliberately false reports, and automated or mass reporting used as a weapon, are themselves a breach of this policy. Being wrong in good faith is not. We would far rather read a hundred honest reports that come to nothing than miss the one that mattered.
Enforcement
How we decide
We aim to be proportionate: the smallest action that actually stops the problem, applied to the narrowest part of the account that will do it. We weigh how serious the conduct is, whether anyone is being harmed right now, whether it looks deliberate, whether it is still going on, and what you did when we raised it.
We also judge you by what you do about abuse by the people using the Service under your Subscription. A customer whose End Users cause a problem and who moves quickly to stop it is in a very different position from one who cannot or will not.
Investigation
We may look into a report, or into something we detect ourselves. That can include reviewing account and configuration metadata, logs, message headers, sending records, public-facing content, and content you have made available to us — and asking you for evidence: the notice you gave your monitored personnel, your opt-in records, your right to use content, your authority for an integration.
We do not routinely read the contents of your Workspace. Where an investigation genuinely requires looking at Customer Data, we look at the minimum needed, restrict it to staff who need it, and record that we did.
We may preserve material relevant to an investigation, and we may hold an account in a restricted state while we work.
What we can do
- Ask you to fix it, with a deadline.
- Remove, disable or de-publish specific content, a public page, a share link or a custom domain.
- Restrict or switch off a specific feature for a Workspace or a user — including capture and monitoring features.
- Reduce a rate limit, throttle traffic, pause a campaign, or revoke a sending domain.
- Suspend a user, a Workspace, a project or the whole account.
- Terminate your account and these Terms.
- Decline to contract with you again.
- Recover our costs, where the law allows it.
With or without notice
Where the problem can be fixed, we tell you first and give you a chance to fix it. That is the normal path and most matters end there.
We act immediately, without prior notice, where waiting would be irresponsible — including:
- anything in the never-permitted list in the illegal activity section;
- covert or unlawful monitoring of a person;
- malware, phishing, or a live security incident;
- conduct putting shared infrastructure, other customers or sending reputation at risk;
- a court order, a regulator's direction, a law-enforcement requirement or a takedown obligation; and
- abuse that continues after we have already raised it with you.
Where we act without notice we tell you as soon as we reasonably can — what we did, why, and what would have to change for us to undo it — unless a legal obligation stops us. Suspension is also dealt with in the term, suspension and termination section of our Terms of Service, and everything there applies here.
Telling other people
Where the law requires it, we notify affected people, rights holders and authorities, and we respond to regulators, courts and law enforcement. Where someone's safety is at risk, we may notify without being required to. We may also tell a mailbox provider, a blocklist operator or a source platform what we did about a complaint they sent us.
Some legal demands prohibit us from telling you that they exist. Where that is the case, we comply with the demand.
Money
Where we terminate because you broke this policy, you get no refund.
- Fees for a period already served remain payable.
- A period during which the account was suspended for abuse is not refunded. It is still part of your paid term.
- The 30-day money-back guarantee in our Refund Policy is not available on a termination for breach of this policy.
- The export window we allow after an ordinary termination may be withheld where we terminated for cause, as our Terms of Service sets out.
Your indemnity in those Terms covers claims brought against us because of what you or your End Users did in breach of this policy.
If we get it wrong
We will sometimes get it wrong. Automated detection produces false positives, and reports are sometimes mistaken or malicious.
Write to [email protected] and we will look again — with someone who was not part of the original decision, wherever we practically can. If we were wrong we restore access, and we do not charge you for the period we took it away. Tell us anything that changes the picture: a decision made on partial information is exactly the kind we want to revisit.
Two things this section does not do
It does not oblige us to monitor. We have no general duty to review what you put into the Service, and choosing not to act on one thing never gives up our right to act on another. Acting in good faith on a report does not make us responsible for what someone else did.
It does not take away a consumer's rights. If you are dealing with us as a consumer rather than for business purposes, your mandatory statutory rights stand whatever this section says.
Changes to this policy
Abuse moves faster than contracts do, so this policy changes more often than the rest of our documents. Every version carries a number and an effective date at the top, and superseded versions stay published, so you can always establish which rules applied on a given day.
Where a change materially reduces what you are allowed to do, we give you at least thirty (30) days' notice before it takes effect — by email to your administrative contact and in the Service — and you may cancel before it applies, on the terms in the changes section of our Terms of Service.
Everything else takes effect when we publish it. That covers new examples of conduct this policy already prohibits, clarifications, corrections, and changes we make because the law, a regulator, a court, a payment provider or an infrastructure provider requires them — sometimes at no notice at all, because we are given none.
The version in force when you use the Service is the version that governs that use. Continuing to use the Service after a change has taken effect means you accept it.
How to reach us
Write to a person, not a form. These addresses are monitored and we answer them.
- Abuse, harmful content, covert monitoring, spam, or a security problem — [email protected]. Anyone may use this address, customer or not.
- Questions about this policy, or about a decision we made under it — [email protected]
- Your personal data, and any request about it — [email protected]
By post: Ever Technologies LTD, Mladost 2, bl. 211, ent. A, Sofia 1799, Bulgaria — registered in Bulgaria under company number 204599535.
We correspond in English.
This document is version 1.0.2 of the Acceptable Use Policy for ever.co, in force from 2026-08-02. It forms part of our Terms of Service, and earlier versions, with the dates they applied, are published alongside them.