This policy forms part of the Terms of Service and applies to everyone who uses Turtle AI Coworker, including every user you invite and every agent you configure.
You are responsible for what your agents do. An agent acting badly is not a defence — you chose its instructions, its tools, and whether a human approves its actions.
1. Do not break the law
Do not use the Service to do anything unlawful under Indian law or the law that applies to you, including:
- Committing or facilitating fraud, money laundering, or financing of terrorism.
- Infringing copyright, trade marks, patents or trade secrets.
- Violating privacy or data protection law, including processing personal data you have no lawful basis to process.
- Breaching export controls or sanctions, or providing the Service to a sanctioned party.
- Violating the Information Technology Act, 2000 or rules made under it.
2. Do not attack other systems
Agents can reach external systems. That capability must be pointed only at systems you are authorised to use. Do not:
- Access any account, network or system without authorisation, or attempt to.
- Scan, probe or test the vulnerability of systems you do not own or have written permission to test.
- Circumvent authentication, rate limits, paywalls, robots directives, or CAPTCHA and other bot-detection measures.
- Scrape a service in breach of its terms, or at a volume that degrades it.
- Distribute malware, ransomware, or build command-and-control infrastructure.
- Conduct denial-of-service attacks, or generate load intended to exhaust a third party’s capacity.
3. Do not abuse messaging
The Service can send email and messages at scale. This is where autonomous agents most easily cause harm, so the rules are strict. Do not:
- Send unsolicited bulk email or messages, to purchased, scraped or harvested lists.
- Send to recipients who have not consented where consent is legally required, or who have opted out.
- Omit a working unsubscribe mechanism from marketing messages, or fail to honour opt-outs.
- Forge headers, spoof a sender, or misrepresent who a message is from.
- Impersonate a real person or organisation, or present an agent as a human where the recipient would reasonably believe they are speaking to one.
- Send messages designed to phish credentials, payment details or personal information.
4. Do not generate prohibited content
Do not use the Service to produce, store or distribute:
- Child sexual abuse material. This results in immediate termination and a report to the authorities, without notice.
- Content that incites violence, terrorism, or self-harm.
- Harassment, threats, hate speech targeting protected characteristics, or content intended to demean an individual.
- Non-consensual sexual content, or sexual content involving minors in any form.
- Deliberate disinformation, synthetic media impersonating real people, or content designed to manipulate an election.
- Instructions for making weapons, explosives, or biological, chemical, radiological or nuclear agents.
5. High-risk uses require a human
Do not deploy agents to make final, unreviewed decisions that materially affect a person’s rights, safety, livelihood or access to services. This includes:
- Hiring, promotion, discipline or termination decisions.
- Credit, lending, insurance underwriting or claims denial.
- Medical diagnosis, treatment, or triage.
- Legal advice to a third party, or filings made without review by a qualified professional.
- Eligibility for housing, education or public benefits.
- Anything where an error could cause physical harm.
Agents may assist with these — draft, summarise, screen, prepare — provided a competent human reviews and makes the decision. The Service has approval gates for exactly this purpose. Use them.
6. Do not abuse the platform
- Do not resell, sublicense or white-label the Service without a written agreement.
- Do not reverse engineer, decompile, or attempt to extract our source code, prompts or model configuration.
- Do not use the Service to build a competing product, or to benchmark it for a competitor without our consent.
- Do not share credentials between people, or evade plan limits by creating multiple accounts.
- Do not use the Service to mine cryptocurrency or to run workloads unrelated to its purpose.
- Do not deliberately extract another customer’s data, or test tenancy isolation without written authorisation.
7. Security research
We welcome it, within limits. Test only against your own workspace, do not access other customers’ data, do not degrade the Service, and report what you find to security@turtleaicoworker.com before disclosing it publicly. Research conducted in good faith within these limits will not be treated as a breach of this policy.
8. Fair use of capacity
Plans with generous or unmetered limits assume normal business use. We may contact you about usage that is disproportionate enough to affect other customers, and work out a fair arrangement. We will talk to you before we act.
9. How we enforce this
We do not monitor the content of your workspace. We act on reports, on abuse signals from our providers, and on automated safety and security signals.
Depending on severity, we may:
- Contact you and ask you to fix it — the usual first step.
- Disable a specific agent, tool or integration.
- Suspend the account.
- Terminate the account and, where the law requires it, report to the authorities.
For anything that is not an emergency, we will tell you what the problem is and give you a chance to fix it. For content or conduct causing immediate harm or legal exposure — CSAM, an active attack, a live phishing campaign — we act first and explain afterwards. Termination for breach of this policy does not entitle you to a refund.
10. Reporting abuse
To report misuse of the Service, write to security@turtleaicoworker.com with the detail you have. We investigate every report.
11. Changes
We will update this policy as new capabilities and new failure modes appear. Material changes are notified in the same way as changes to the Terms of Service.
Questions about this document? Write to legal@turtleaicoworker.com.