profusia ai
Draft for attorney review — not yet in force.

Part of the legal pack — see also: Terms of Service · Privacy Policy · Data Processing Addendum · Refund Policy. The in-force privacy page this product operates under today is /privacy, unaffected by this draft.

Profusia AI — Acceptable Use Policy

Effective date: [DATE]

This Acceptable Use Policy ("AUP") is part of the Profusia AI Terms of Service. It applies to you, to everyone you invite into your workspace, to every assistant you connect, and to anyone who uses a link you hand out. If you let someone use the Service through you, their conduct is your responsibility.

The short version: Profusia hosts documents that businesses send to their clients. Do not use it to host or send anything that is illegal, harmful, deceptive, or somebody else's.


1. Do not break the law or harm people

You may not use the Service to store, publish, share, or transmit content, or to do anything, that:

  • violates any applicable law or regulation, or facilitates doing so;
  • infringes a patent, copyright, trademark, trade secret, publicity, or other right;
  • sexually exploits or endangers a minor, or contains child sexual abuse material — we report this to the appropriate authorities and terminate immediately, without notice or cure;
  • is non-consensual intimate imagery;
  • threatens, harasses, defames, or incites violence against a person or group;
  • promotes terrorism or violent extremism;
  • facilitates human trafficking, illegal weapons or drug sales, or the exploitation of vulnerable people;
  • violates export control or sanctions law, or is accessed from an embargoed jurisdiction or by a restricted party.

2. Do not deceive

You may not use the Service for phishing, credential harvesting, fraud, pyramid or Ponzi schemes, fake invoices, counterfeit goods, impersonation of a person or organization you are not, or any page designed to make a reader believe it comes from someone else.

Published pages are served from addresses that carry our name. Content designed to abuse that trust is the specific harm this section exists to stop.

3. Do not put regulated or hazardous data in the Service

The Service is not designed, certified, or sold for:

  • protected health information subject to HIPAA — we will not sign a Business Associate Agreement;
  • payment card data subject to PCI DSS (card numbers, CVVs, magnetic stripe data);
  • government-classified or export-controlled technical data;
  • children's personal information subject to COPPA;
  • biometric identifiers, or financial account credentials;
  • data whose handling requires a certification we do not hold. We hold none (see /trust).

You may not use the Service in circumstances where its failure could lead to death, personal injury, or severe environmental damage — including aircraft or vehicle control, life support, nuclear facilities, or emergency dispatch.

4. Do not attack the Service

You may not:

  • attempt to access another workspace's data, another customer's account, or any system, credential, or address you were not given;
  • probe, scan, or test the vulnerability of the Service except under our vulnerability disclosure process (/.well-known/security.txt) — good-faith research reported responsibly is welcome and we will not pursue you for it;
  • circumvent or interfere with authentication, rate limits, spending caps, entitlements, or audit logging;
  • introduce malware, ransomware, cryptominers, or destructive code — including inside a document you publish;
  • overload the Service with automated traffic beyond documented limits, or use it as a denial-of-service origin;
  • reverse engineer, decompile, or attempt to derive source code, except where law expressly permits and only to that extent;
  • scrape, mirror, or resell the Service, or build a competing product from it;
  • share a single workspace across organizations to avoid member or size limits, or resell workspace access without a written reseller agreement from us.

5. Do not misuse the AI features

You may not use in-app AI to:

  • generate content prohibited by any other section of this AUP;
  • generate content designed to deceive a reader about whether it was machine-generated where doing so would be unlawful or misleading in context;
  • circumvent, extract, or interfere with a model provider's safety systems, or attempt to extract model weights or system prompts;
  • automate bulk requests with the purpose of exhausting an allowance, degrading service for others, or reselling model access;
  • produce legal, medical, financial, or safety-critical advice that you then present to others as reviewed when it was not. AI output may be wrong; you are responsible for reviewing it before relying on it.

6. Do not misuse email or sharing

  • Do not use notification email to send unsolicited bulk mail. The Service sends mail only to people in your own workspace who asked to hear about mentions; using it any other way is a violation.
  • Do not mint share links, portals, or embeds for content you do not have the right to distribute.
  • Every link the Service mints is a bearer link. Hand them out accordingly — a link forwarded is a link that works. Do not use a password on a share link, a handling notice, or a document state label as a substitute for a control that actually restricts access. They inform; they do not enforce, and the product says so.

7. Respect the connected-service boundaries

  • The optional Google Drive sync writes only into files Profusia creates, in an account you connected. Do not attempt to widen its scope or use it to move content you have no right to move.
  • An assistant you connect over MCP acts as your workspace. Do not connect an assistant you do not control, and do not hand a workspace access key to a third party.

8. Enforcement

What we will do. Where we believe this AUP has been violated, we may remove or disable specific content, revoke a specific link, suspend a user or a workspace, or terminate the Agreement.

Notice and cure. Where the violation does not present an ongoing risk of harm, we will give you notice and a reasonable opportunity to cure before suspending or terminating. Where it does — CSAM, an active attack, an active phishing campaign, a legal order — we act first and tell you as soon as we can.

Proportionality. We prefer the narrowest action that stops the harm. Revoking one link is better than suspending a workspace, and we will reach for it first where it works.

No monitoring obligation. We do not review Customer Content as a matter of course, and nothing in this AUP creates an obligation to monitor. Acting on one report does not oblige us to act on any other.

Refunds. Fees are not refunded for a suspension or termination caused by your violation of this AUP.

Your content on termination for cause. Even where we terminate for a violation, you keep the 30-day export window in the Terms, unless retaining or returning the content would itself be unlawful.

9. Reporting a violation

  • Abuse, illegal content, or a violation of this policy: legal@evadaroo.com
  • Security vulnerabilities: security@profusia.ai and /.well-known/security.txt
  • Copyright (DMCA): legal@evadaroo.com, addressed to the Copyright Agent, Evadaroo & Company, LLC, [REGISTERED OFFICE ADDRESS]. Include the elements required by 17 U.S.C. § 512(c)(3): your signature, identification of the work, identification of the material and where it is, your contact details, a statement of good-faith belief, and a statement under penalty of perjury that the notice is accurate and you are authorized to act. We honor counter-notices under § 512(g) and terminate repeat infringers.

10. Changes

We may update this AUP. Material changes get 30 days' notice to workspace owners, except where a change is required immediately by law or to stop an active harm.


Evadaroo & Company, LLC · [REGISTERED OFFICE ADDRESS] · Pennsylvania, USA · legal@evadaroo.com