This Usage Policy describes what you may and may not do with the Melaya platform, including the visual pipeline builder, the assistant, agents, tools and connectors, retrieval features, Device Control, the Melaya Engine, and all related services (collectively, the "Services"). It applies to every use of the Services, including every action taken by an agent, pipeline, connector, model, or paired device operating under your account, and it forms part of, and should be read together with, our Terms of Service. If you do not comply with this Policy, we may suspend or terminate your access.
1. Scope, Who This Policy Applies To, and Relationship to the Terms of Service
This Policy applies to you and to anyone you permit to access or use the Services through your account, workspace, credentials, API keys, runners, or paired devices, including collaborators, clients, end users of anything you build on Melaya, and any automated system you connect. You are responsible for ensuring that all such persons and systems comply with this Policy, and a violation by any of them is treated as a violation by you.
Because Melaya agents can take real actions, everything your agents do is attributed to you. An instruction you give a pipeline, an action an agent performs through a connector with your credentials, and a tap or keystroke an agent executes on your paired phone are all your use of the Services for purposes of this Policy. "I did not know what the agent would do" is not a defense: you are responsible for configuring, scoping, supervising, and stopping your agents.
This Policy is incorporated into and governed by our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service. If this Policy conflicts with the Terms of Service, the Terms of Service control, except that the stricter provision controls with respect to what conduct is permitted on the Services.
2. Eligibility, Export Controls, and Sanctions Compliance
You may not access or use the Services if you are located in, organized under the laws of, or ordinarily resident in any country or territory subject to comprehensive sanctions or embargoes of the United States, the European Union, or the United Nations, or if you are listed on, or owned or controlled by any person listed on, any applicable sanctions or denied-parties list, including the U.S. Treasury OFAC Specially Designated Nationals List. You represent that you are not such a person and will not permit any such person to use the Services through your account, workspace, API keys, runners, or paired devices.
The Services, including client software, runner software, and the Device Control application, and any outputs, may be subject to export control laws. You may not export, re-export, or transfer them in violation of those laws, and you may not use the Services to facilitate sanctions evasion by any person.
3. Universal Prohibitions
You may not use the Services, and may not permit or configure any agent, pipeline, connector, model, or paired device to be used, to do any of the following, whether directly, through an intermediary, or by generating content or instructions that enable someone else to do so:
- Violate any applicable law or regulation, or facilitate, promote, or conceal illegal activity, including money laundering, terrorism financing, sanctions evasion, human trafficking, or the sale of illegal goods and services.
- Create, request, distribute, or facilitate access to child sexual abuse material or any content that sexualizes, exploits, grooms, or abuses minors, whether real, fictional, or AI-generated. We report apparent violations to relevant authorities, including the National Center for Missing and Exploited Children where applicable.
- Plan, incite, glorify, or facilitate violence, terrorism, or violent extremism, or provide material support to terrorist or violent extremist organizations.
- Develop, design, acquire, produce, or facilitate the use of weapons, including conventional weapons where unlawful and chemical, biological, radiological, nuclear, or high-yield explosive weapons, their precursors, or their delivery systems.
- Harass, threaten, intimidate, stalk, bully, or abuse any person, or generate content that demeans or promotes hatred against people on the basis of protected characteristics.
- Create, distribute, or deploy malware, ransomware, spyware, or other malicious code; gain or attempt to gain unauthorized access to any system, account, network, or data; or disrupt, degrade, or overload any service, including the Services themselves.
- Conduct credential stuffing, password spraying, brute-force attempts, session-token or cookie theft or replay, account takeover, or any other attempt to gain access to accounts or systems using credentials you were not issued or authorized to use.
- Develop, generate, host, or operate offensive security tooling, including exploits, exploit kits, vulnerability scanners aimed at third-party systems, command-and-control infrastructure, phishing kits, or automated intrusion or lateral-movement tooling, except for legitimate security research, testing, or defense that you are expressly authorized in writing to perform against the specific target and that complies with applicable law.
- Engage in fraud, scams, phishing, pyramid or Ponzi schemes, academic dishonesty on assessments where prohibited, fake reviews, plagiarism presented as original work where disclosure is required, or any other materially deceptive practice.
- Send spam or unsolicited bulk communications, operate bot farms or fake account networks, manufacture fake engagement, or conduct coordinated inauthentic behavior on any platform.
- Violate the privacy of others, including unlawful tracking, monitoring, or surveillance of individuals; scraping, collecting, or processing personal data without a lawful basis; facial recognition or biometric identification without required consent; or building dossiers on people who have not consented where consent is required.
- Attempt to re-identify, or facilitate the re-identification of, individuals from data that has been anonymized, de-identified, pseudonymized, or aggregated, including by correlating data across connectors, retrieval sources, or datasets, except where expressly permitted by law for security testing of your own data.
- Infringe, misappropriate, or facilitate the infringement of intellectual property rights or trade secrets of any party, or remove or falsify rights-management information.
- Create or distribute non-consensual intimate imagery, sexual deepfakes of real people, or any sexual content involving minors under any circumstance.
- Encourage, glorify, or provide instructions for suicide, self-harm, or disordered eating, or exploit a person in crisis.
4. Child Safety and Minors
We maintain zero tolerance for child sexual abuse material and child exploitation. This prohibition applies to all inputs, outputs, retrieval sources, connected accounts, generated media, and any content an agent encounters, produces, stores, or transmits, and it applies regardless of whether the material is real, synthetic, drawn, or described in text. You may not use the Services to sexualize minors, to groom or solicit minors, to arrange harm to a minor, or to locate, produce, or trade exploitative content. We remove such content, terminate the accounts involved, preserve evidence where legally appropriate, and report to law enforcement and child-protection authorities.
The Services are not directed to children and may not be used by anyone under the age of eighteen (18), or the higher age of digital consent in your jurisdiction. In addition, you may not use the Services to knowingly collect personal data from children unlawfully, to profile or target children with advertising in violation of applicable law, to build products directed at children without the protections the law requires, or to contact, monitor, or influence a child without lawful parental or institutional authority.
5. Agents, Automation, and Acting Through Third-Party Services
Melaya's core capability, agents that act across real systems using your credentials, carries specific obligations. When an agent operates a connected service, whether email, a CRM such as Odoo, LinkedIn, Stripe, Shopify, a messaging platform, or any other tool or connector, you must comply with that service's terms of use, developer policies, automation rules, and technical limits, exactly as if you were performing each action yourself. Melaya provides the mechanism; the authorization must come from you and from the third-party service.
Melaya may provide operating playbooks, templates, or built-in knowledge that help agents navigate specific third-party apps and services. The availability of a playbook, template, or connector for a service is not a representation that the service permits automation, and it does not grant you any authorization from that service. You remain solely responsible for confirming that your use of any third-party app or service through the Services complies with its terms and applicable law.
You must keep meaningful human oversight over your agents in proportion to the consequences of their actions. Actions that publish content, contact people, move money, modify or delete production data, or enter into commitments must be reviewed by a human or governed by a control you have deliberately configured, such as approval gates, allowlists, spend limits, or dry-run modes. Do not remove or bypass human-approval controls that the Services apply to consequential actions.
Where this Policy or the Services require human review or approval of an action, that review must be performed by a natural person with actual authority over the action and a genuine opportunity to reject it. You may not satisfy a human-approval requirement by routing the decision to another agent, model, script, auto-approval rule, or pre-recorded consent, and you may not configure approval prompts to be accepted automatically or by default.
Agents can act imperfectly, and outputs and actions may be inaccurate, incomplete, or unintended. You assume the risks of deploying agents against real accounts, real funds, real recipients, and real devices, and you are responsible for validating consequential actions before permitting them. The Services are provided without warranties to the extent stated in the Terms of Service, and your indemnification obligations for claims arising from your use of the Services, including actions taken by your agents and on your paired devices, are set out in the Terms of Service.
Agent and model outputs can be inaccurate, incomplete, outdated, or fabricated even when they appear confident. Before you rely on an output, publish it, send it to another person, or allow it to trigger a consequential action, you must review it with the care the situation demands. You remain fully accountable for outputs you use or distribute, and the involvement of an agent does not reduce your professional, contractual, or legal responsibility for the result.
- Do not use agents, connectors, or Device Control to evade rate limits, bans, suspensions, CAPTCHAs, bot-detection measures, geographic restrictions, paywalls, or any other technical or policy control of a third-party service.
- Do not run mass or automated outreach, posting, messaging, connection requests, follows, likes, reviews, or other engagement in volumes or patterns that violate the target platform's rules or applicable anti-spam and telemarketing laws.
- Do not create, operate, or coordinate networks of fake or misattributed accounts, and do not use agents to simulate grassroots activity or independent voices that are in fact centrally controlled.
- Do not impersonate any person or organization, misrepresent an agent's identity or affiliation, or present an agent as a human where the recipient would reasonably want or is legally entitled to know they are interacting with an automated system.
- Where a platform, jurisdiction, or context requires disclosure that content is AI-generated, you must provide that disclosure.
- Do not use agents, connectors, or Device Control to harvest, bulk-export, or systematically extract data from any service, account, or website beyond the scope you are authorized to access or in excess of that service's terms and technical limits, and do not use the Services to exfiltrate data from a connected system for a purpose the data owner did not authorize.
- Do not chain agents, schedule triggers, or configure autonomous loops in a way that removes your practical ability to monitor, correct, or stop what your agents are doing.
- Do not configure agents to expand their own capabilities or footprint beyond what you have explicitly granted, including creating additional agents, accounts, API keys, or credentials without your direction; acquiring computing resources or spending funds outside limits you have set; copying themselves or their instructions to systems outside your workspace; or taking any action designed to evade suspension, monitoring, or shutdown by you or by Melaya. Every agent you run must remain subject to immediate stop and credential revocation at all times.
- You are fully responsible for every action your agents take with your credentials, your accounts, your data, and your devices, including unintended actions resulting from your configuration.
6. Device Control
Device Control lets an agent operate the visible interface of a paired Android phone within the apps you have approved, including opening apps, reading the screen, tapping, typing, and swiping. You may pair and operate only devices that you own or are expressly authorized to control, and you are responsible for every action performed on a paired device during a run.
App permissions are deny-by-default and publishing actions require on-device human approval. You must not attempt to defeat, automate away, or socially engineer around these safeguards, and you must not use Device Control to operate apps you have not approved for the workflow. Approve an app for agent access only if you accept that the agent may read what that app displays.
You are responsible for the physical and account security of any paired device. Pair only devices under your control, protect them with a screen lock and up-to-date software, do not leave a controlled session unattended in a way that exposes it to others, and immediately revoke the pairing and rotate affected credentials if the device is lost, stolen, shared, or compromised.
Do not use Device Control to monitor, track, or act on behalf of another person without their knowledge and lawful authority; to surveil an intimate partner, employee, child, or any other person unlawfully; to access another person's accounts or messages; to bypass device or app security intended for a human user; or to perform on a phone any activity prohibited elsewhere in this Policy. Screen mirroring can expose whatever is visible on the display, so do not open unrelated sensitive apps or other people's information during a controlled session.
Content visible on a paired device may include communications and personal data of people other than you, such as the other participants in a conversation. You must not use Device Control to record, intercept, extract, or systematically store the communications or personal data of other individuals in violation of interception, recording-consent, or confidentiality laws, and you must limit what an agent reads, retains, and forwards from the screen to what the approved workflow legitimately requires.
You may not use Device Control to operate a device farm or to make automated activity appear human at scale. This includes pairing one or more devices to create, warm, or operate multiple social media, messaging, marketplace, or review accounts; to mass-produce posts, votes, reviews, follows, likes, or other engagement; to register accounts in bulk; or to conduct coordinated influence operations through a handset in order to evade platform bot detection that would block the same activity performed through an API or script.
7. Deception, Impersonation, and Content Authenticity
You may not use the Services to deceive people in ways that cause or are likely to cause harm. This includes generating or spreading disinformation; fabricating evidence, credentials, reviews, or endorsements; creating deepfakes of real people without consent and clear disclosure where lawful at all; misrepresenting the origin, sponsorship, or authorship of content; and using agents to manipulate individuals through exploitation of vulnerabilities, undue pressure, or dark patterns.
Regardless of whether disclosure is required in a given context, you may not remove, obscure, alter, or defeat watermarks, content credentials, provenance metadata, or other signals that identify media as AI-generated or that attest to its origin, whether the media was produced through the Services or obtained elsewhere, and you may not use the Services to build or operate tools whose purpose is to strip such signals.
If you deploy Melaya-built agents or content to third parties, you are responsible for honest representation of what your product does, for required AI-interaction and synthetic-media disclosures in the jurisdictions where you operate, and for handling complaints from the people your agents interact with. Additional obligations for products built on the Services are set out in Section 14.
8. High-Risk Uses Requiring Qualified Human Oversight
Some domains carry elevated risk of harm when automated. You may build workflows that touch these domains only if a qualified professional or accountable human reviews outputs and decisions before they affect a real person, you provide the disclosures required in your jurisdiction, and you comply with the sector-specific laws that apply. Agent output in these domains is informational input to a human decision, never the decision itself.
- Legal, medical, health, psychological, financial, tax, or accounting advice or services, where outputs must be reviewed by an appropriately qualified professional before being relied upon or delivered to a client or patient.
- Consequential automated decisions about individuals, including employment and recruiting, housing, credit and lending, insurance underwriting and claims, education admission or eligibility, and access to essential government or private services, where you must ensure human review, non-discrimination, required notices, and contestability.
- Political campaigning, lobbying, and election-related content, where you must not generate or distribute misinformation about voting procedures, eligibility, or results, must not suppress or deter lawful voting, and must comply with disclosure and disclaimer requirements for political communications.
- Operation of, or interference with, critical infrastructure, including energy, water, transportation, communications, financial market infrastructure, and healthcare systems, and any safety-critical control system where failure could cause physical harm.
- Law-enforcement, immigration, and judicial contexts, where use must remain lawful, proportionate, and subject to human authority.
9. Trading and Financial Markets
The Services include an optional trading capability through which the Melaya Engine can place orders on supported venues using API keys you provide. Melaya is not a broker-dealer, exchange, investment adviser, commodity trading advisor, money transmitter, or financial institution of any kind. Nothing produced by the Services, including agent output, strategy analytics, backtests, simulations, and signals, constitutes investment, financial, legal, or tax advice or a recommendation to buy or sell any instrument. You bear all trading risk, including the risk of total loss.
You must not use the trading capability for market manipulation of any kind, including wash trading, spoofing, layering, pump and dump schemes, front-running, or trading on material non-public information; to operate an unregistered regulated financial business; to trade on behalf of third parties without the licenses and authority required; or to access markets or products that are restricted or prohibited for you under applicable law. You are responsible for determining that your trading activity is lawful in your jurisdiction and compliant with the rules of every venue you connect.
10. Data Protection, Privacy, and the Rights of Others
Connect only accounts, credentials, API keys, and data sources that you own or are expressly authorized to use, and grant your agents only the scopes and permissions their tasks require. Using someone else's credentials without authority, exceeding the authorization you were given, or retaining access after authorization ends is prohibited.
When your agents collect, retrieve, store, or process personal data about other people, whether through uploads, RAG sources, connectors, scraping, or a device screen, you are the party responsible for that processing. You must have a lawful basis, provide required notices, honor data-subject rights such as access and deletion, respect confidentiality and professional-secrecy obligations, and refrain from processing sensitive categories of data without the safeguards the law requires. Do not upload or index content you have no right to use, and do not use the Services to launder data obtained in violation of a source's terms or the law.
For personal data that you or your agents submit to or process through the Services, including data reaching Melaya through uploads, connectors, RAG sources, agent memories, run logs, and paired device screens, you are the data controller (or business) and Melaya acts as your processor (or service provider) solely to provide the Services, as further governed by our Data Processing Addendum, which applies whenever you process personal data subject to data-protection law. You must not use the Services to process personal data of third parties unless the Data Processing Addendum is in place where required and you have the authority, lawful basis, and notices needed for Melaya to process that data on your behalf.
You represent and warrant that you have all rights, licenses, consents, and authority necessary for the content, data, credentials, accounts, and instructions you provide to the Services and for the activities you configure your agents to perform, including any professional, regulatory, or business licenses required for your use case, and that your use of the Services does not violate any agreement you have with a third party.
- Cross-border transfers. When you configure the Services to send personal data to a destination you select, including a third-party model provider under your own API key, a connector endpoint, a runner, or a workspace region, you are responsible for ensuring that any resulting cross-border transfer of personal data complies with applicable transfer rules, including implementing standard contractual clauses, adequacy findings, or other valid transfer mechanisms where required, and for informing data subjects of such transfers where the law requires.
- Data-subject requests. When you receive a valid data-subject request, including a request for access, deletion, correction, objection, or restriction, you are responsible for actioning it across every location within your control on the Services where the personal data resides, including uploaded documents, knowledge bases and retrieval indices, agent memories, pipeline configurations, outputs, and run histories, and for not re-ingesting the same personal data from a connector or retrieval source after you have deleted it in response to such a request.
- Indirect collection. If your agents collect or compile personal data about individuals from sources other than the individuals themselves, for example from public profiles, connected services, or scraped pages, you must provide those individuals with the privacy notices required by applicable law within the required time, honor their objections, and refrain from contacting them in violation of anti-spam, telemarketing, or electronic-communications rules. You may not use the Services to build or enrich marketing, recruiting, or investigative profiles of individuals where you cannot meet these obligations.
- Sensitive inference. Do not use the Services to infer, derive, or categorize individuals by special or sensitive categories of personal data, including health or disability status, sexual orientation or sex life, racial or ethnic origin, religious or philosophical beliefs, trade union membership, immigration status, biometric identifiers, or precise geolocation, except where you have an explicit legal basis and any required consent. Do not use the Services for emotion recognition or biometric categorization of individuals in employment, education, or other contexts where such use is restricted or prohibited by applicable law.
- Retention. Retain personal data on the Services, including in knowledge bases, retrieval indices, agent memories, and stored outputs, only for as long as you have a lawful purpose for keeping it, and delete or de-identify it when that purpose ends. Configure scheduled and triggered pipelines that collect personal data so that they do not accumulate personal data beyond what their purpose requires.
11. API Keys, Runners, Teams, and Account Security
You must keep all access credentials issued by or stored with Melaya secure and confidential, including account credentials, platform API keys, session tokens, local runner tokens, connector credentials, and device pairing codes. You may not sell, share, or transfer platform API keys outside your workspace, embed them in publicly accessible client-side code or public repositories, or use another user's keys, and you may not allow a third party to use your keys in place of obtaining their own access. Programmatic access is subject to this Policy in full, including all documented rate limits, and you may not misrepresent request origin, rotate keys or accounts to evade limits or enforcement, or use the API to recreate restricted or suspended access. If you believe your account, keys, runner, or paired device has been compromised, revoke or rotate the affected credentials immediately and notify us promptly at [email protected]. All activity performed with your credentials is attributed to you until you revoke them.
You are responsible for securing any local runner you deploy and the environment it runs in. Do not use a runner as a bridge, proxy, or pivot to reach systems, networks, or data that the account holder is not authorized to access, and do not connect a runner to a network in a manner that violates the network owner's policies. Keep the runner host patched, restrict its file-system and network access to what your workflows require, and revoke its credentials promptly if it is lost, shared, or compromised.
When you store a credential, API key, or connector at project or team scope, every member of that project with sufficient role can act through it. Store a credential at shared scope only if you have the authority to let each of those members act on the underlying account, and remove the credential or the member when that authority ends. Project owners and administrators are responsible for who they invite, for the roles they assign, for the workflows their members run against shared credentials and paired devices, and for promptly revoking access for departed or untrusted members. Inviting a member does not transfer your responsibility under this Policy.
12. Bring Your Own Model and Provider Terms
Melaya lets you route pipelines through third-party model providers with your own API keys, or through models running on your own hardware. When you bring a provider or key, you must comply with that provider's terms of service, usage policies, and rate limits in addition to this Policy, and you are responsible for the data you send to it. Running a model locally does not exempt you from this Policy: all use of the Services, whatever model powers it, remains subject to these rules. You may not use provider arbitrage, key rotation, or local execution to accomplish something this Policy prohibits.
If you route pipelines that process personal data of third parties through a model provider under your own API key, you are appointing that provider as your own processor or recipient. You must ensure that appropriate data-processing terms are in place with that provider, that the provider does not use the personal data to train its models unless you have a lawful basis and any required consent for that use, and that data subjects are informed of the disclosure where the law requires. The same duties apply to models you host yourself when other people access their outputs.
13. Templates and Shared Workflows
When you save a template or workflow and share it with a team or publish it to the community catalog, you are distributing content that other users may run against their own credentials, connectors, and devices, and additional rules apply.
You must not publish, share, or distribute pipeline templates, agent configurations, tools, connectors, prompts, model files, or other artifacts that contain malicious code, concealed data-exfiltration behavior, deceptive instructions, or hidden calls to attacker-controlled endpoints, or that are designed to compromise the accounts, credentials, data, or devices of users who install or run them. You must not tamper with, backdoor, or misrepresent shared artifacts, and you must accurately describe what any artifact you distribute does.
You must not share or publish any template that is designed to violate this Policy or a third-party service's terms; that contains hidden, obfuscated, or misleading instructions, including steps that exfiltrate the data, credentials, or device access of the user who runs it; that embeds credentials, API keys, tokens, or other secrets; or that carries a name, description, or category that materially misrepresents what it does. You must not represent a template as validated, endorsed, or published by Melaya unless it carries that status in the catalog. We may review, decline, remove, demote, or modify the visibility of any shared or community template at any time, and repeated publication of violating templates is grounds for suspension of sharing privileges or of your account.
14. Building Products on Melaya: Deployers, End Users, and Resale
If you build a product or service on the Services, including through platform API keys, the SDKs, or agents you operate for clients, you must:
You remain responsible to us for all end-user activity that reaches the Services through your keys, agents, or infrastructure.
You may not resell, rent, lease, sublicense, or otherwise provide third parties with direct access to the Services, including through shared logins, shared API keys, or white-labeled access to your workspace, except as expressly permitted by your plan or a separate written agreement with us. Offering your own products and services that are built on the Services is permitted, provided that you remain the account holder, you do not represent your product as being provided by Melaya, and your end users' activity complies with this Policy.
- Impose use restrictions on your end users at least as protective as this Policy and enforce them.
- Not allow your product to be used as a way for end users to accomplish anything this Policy prohibits, whether or not you intended that use.
- Use reasonable technical and procedural measures to detect and stop misuse of your deployment, in proportion to its capabilities and audience.
- Give your end users a working channel to report abuse, and forward to us reports that indicate a violation of this Policy involving the Services.
15. Platform Security and Integrity
You may not probe, scan, or attack the Services; attempt to access other tenants' data, pipelines, indices, credentials, or devices; interfere with or place excessive load on our infrastructure; circumvent authentication, authorization, quota, billing, tier, or safety controls; or misuse free tiers or trials through duplicate accounts. Good-faith security research is welcome only within the scope and rules of engagement of the Responsible Disclosure program described in our Security Overview.
You may not attempt to extract, jailbreak, or manipulate models, agents, or safety systems in order to produce prohibited outputs, and you may not build datasets of Melaya safety behavior for the purpose of defeating it. In addition:
- Prompt injection. You may not craft, plant, upload, or distribute content, including in web pages, emails, documents, retrieval sources, connector payloads, or text displayed on a screen, that is designed to covertly instruct, hijack, or subvert an agent or AI system, whether operated by Melaya, by another Melaya user, or by a third party, a technique commonly known as indirect prompt injection. You may not use hidden text, metadata, encoded payloads, or similar methods to cause an agent to ignore its instructions, exfiltrate data, escalate its permissions, invoke tools without authorization, or take any action the account holder did not intend.
- Your own trust boundaries. Because your own agents process content from sources you do not control, you are responsible for the trust boundaries of your agents, including scoping their tool permissions, credentials, and approval requirements with that risk in mind and validating and constraining untrusted content that your pipelines ingest before it can influence a consequential action.
- Internal networks and metadata endpoints. Do not direct connectors, HTTP or web-fetch tools, retrieval crawlers, or the local runner to access resources you are not authorized to reach, including loopback and link-local addresses, private or internal network ranges, cloud instance metadata endpoints, container or orchestration control planes, and other internal-only services. You may not use the Services to perform server-side request forgery, port scanning, service enumeration, or network reconnaissance against any system without the owner's explicit authorization.
- Software tampering. You may not modify, patch, recompile, fork, or otherwise alter the Melaya runner, client applications, or the paired-device application in order to disable, weaken, or bypass approval gates, deny-by-default app permissions, rate limits, safety checks, or logging and audit functions, and you may not run altered versions of that software against the Services. Disabling or falsifying run logs and audit trails to conceal agent activity is itself a violation of this Policy.
- Reverse engineering. Except to the extent this restriction is prohibited by applicable law, you may not reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, underlying models, algorithms, prompts, or non-public architecture of the Services, including the web client, the local runner software, and the Device Control application, and you may not remove, alter, or obscure any proprietary notices in them.
- Competitive use and benchmarking. You may not use the Services, or any output, template, prompt, workflow, or other material obtained from the Services, to develop, train, improve, or benchmark a product or service that competes with Melaya, including any model, agent framework, or automation platform, and you may not systematically extract or harvest the Services' templates, prompts, tool definitions, connector logic, or agent behaviors for that purpose. Publishing performance comparisons or benchmarks of the Services is permitted only if they are accurate, reproducible, and disclose the configuration used.
- Referral and promotional abuse. You may not abuse referral, promotional, discount, or credit programs, including by referring yourself or accounts you control, creating or coordinating accounts to generate referral rewards, misrepresenting eligibility, or buying, selling, or transferring referral benefits contrary to program terms. We may reverse rewards and credits obtained in violation of this rule in addition to any other enforcement action.
16. Beta and Preview Features
We may designate certain features, including new connectors, tools, models, or agent capabilities, as beta, preview, experimental, or early access. Such features are provided for evaluation, may be modified, restricted, or withdrawn at any time without notice, may be subject to additional terms or reduced availability, and should not be relied on for production or consequential workloads. Your use of a beta or preview feature is at your own risk and remains subject to this Policy in full.
17. Reporting Violations and Incidents
If you become aware of a violation of this Policy, of content or activity on the Services that you believe is unlawful, or of an agent behaving in a harmful or unintended way, report it to [email protected] with enough detail for us to locate the account, pipeline, run, or content at issue. If your own agent takes a harmful action you did not intend, stop the run, revoke the relevant credentials or device pairing, and notify us promptly; self-reporting made in good faith is taken into account in enforcement decisions. To report security vulnerabilities, use the responsible disclosure channel in our Security Overview.
If an agent, pipeline, connector, or paired device operating under your account causes unauthorized access to, disclosure of, or loss of personal data, you are responsible for your obligations as controller, including assessing the incident and notifying supervisory authorities and affected individuals where required by law. You must also notify us without undue delay at [email protected] when the incident involves the Services, so that we can meet our own legal obligations and assist you where the Data Processing Addendum requires.
18. Enforcement
We may investigate suspected violations of this Policy using account records, run logs, audit trails, and reports we receive, consistent with our Privacy Policy. Depending on severity, we may issue a warning, require changes to a workflow, throttle or restrict features such as connectors, triggers, trading, or Device Control, remove or disable content, suspend an account or workspace, or terminate access entirely, with or without prior notice where the circumstances require immediate action. We may also preserve and disclose information to law enforcement and other authorities where we believe in good faith that disclosure is required by law or necessary to prevent serious harm, and we report child sexual abuse material to relevant authorities.
Enforcement is proportionate but not negotiable: we consider intent, harm, and history, and we reserve all remedies available under the Terms of Service and applicable law. Fees are not refunded for periods of suspension or termination caused by your violation.
If you believe an enforcement action was taken in error, you may appeal by contacting [email protected] within thirty (30) days of the action, and we will review the appeal and respond, although we are not obligated to reinstate access.
Upon suspension or termination we may disable execution of your pipelines, triggers, trading activity, and device pairings immediately. Unless prohibited by law or by the nature of the violation, we will provide a reasonable opportunity to export your workspace data in accordance with the Terms of Service and our Privacy Policy, after which we may delete it in line with our retention practices. We may retain records relating to the violation as needed for legal compliance, security, and enforcement.
19. Changes to This Policy
As Melaya's capabilities evolve, particularly its agentic and device features, we will update this Policy. When we make material changes we will notify you through the Services or by email at least fifteen (15) days before they take effect, except where a shorter period is necessary to address a legal requirement or an emerging risk of harm. The "Last updated" date at the top of this Policy reflects the most recent revision, and your continued use of the Services after a change takes effect constitutes acceptance of the revised Policy. If a change is unacceptable to you, stop using the Services and close your account before the effective date.
20. General
If any provision of this Policy is held unenforceable, that provision will be enforced to the maximum extent permissible and the remaining provisions will remain in full effect. Provisions that by their nature should survive, including responsibility for actions taken during your use, enforcement rights, and reporting and cooperation obligations, survive suspension, termination, or closure of your account. Our decision not to enforce a provision in one instance is not a waiver of our right to enforce it later, and the examples in this Policy are illustrative, not exhaustive.