Legal
BetaAcceptable Use Policy
Last updated July 26, 2026
One rule underneath all of these: do not use the gateway to do something that would be illegal, abusive, or dishonest if you did it yourself. This policy forms part of the Terms of Service.
Do not use model.cards to
Break the law
Generate, solicit or distribute content that is illegal where you or your users are — including child sexual abuse material, content that sexualises minors in any form, and material that facilitates terrorism or serious violent crime. We report CSAM to the appropriate authorities and terminate the account without notice or refund.
Harm or exploit people
Harassment, stalking, threats, doxxing, or targeted abuse of a person or group. Content designed to encourage self-harm or an eating disorder. Non-consensual sexual content, including synthetic imagery of real people. Automated decisions about someone's credit, housing, employment, insurance or legal status without human review.
Deceive at scale
Impersonating a real person, company or public authority. Generating fake reviews, fake identity documents, or fabricated news attributed to a real outlet. Political astroturfing or coordinated inauthentic behaviour. Fraud, phishing, and social-engineering material of any kind.
Send spam
Bulk unsolicited email, SMS, comments, DMs or reviews — whether you generate the content here and send it elsewhere, or drive the sending loop through our API. Generating content at volume to manipulate search rankings or recommendation systems counts.
Violate other people's rights
Reproducing copyrighted or trademarked work you have no right to use, misappropriating trade secrets, or feeding us personal data you were not allowed to collect or share. If your input contains someone else's personal data, you need a lawful basis for putting it there.
Attack the service
Probing, scanning or overloading the gateway; attempting to reach another account's keys, stored provider keys or usage; circumventing spend guardrails or rate limits; scraping the catalog in a way that degrades the service for others; or reselling access in a way that hides your users from the upstream provider's terms.
Generate weapons or malware instructions
Operational guidance for chemical, biological, radiological or nuclear weapons, or for other mass-casualty attacks. Functional malware, ransomware, or exploit code intended for unauthorised access to systems you do not own or have permission to test.
Upstream policies apply too
Every request is served by a third-party provider, and their usage policy applies to it alongside this one — some providers prohibit categories we allow, and their rules are the stricter of the two in practice. Check the policy of the labs whose models you route to. A provider blocking or refusing your request is not a fault on our side, and those requests still consume upstream capacity.
Research, security and safety work
Security research, red-teaming, content moderation, and building classifiers for the categories above are legitimate uses. If your work looks adversarial from the outside and you would rather not be interrupted, email us first at support@model.cards and we will make a note on your account.
How we enforce this
We do not read your traffic — see the Privacy Policy for what we actually store. Enforcement is driven by reports, by upstream providers telling us about a problem, and by abnormal usage patterns in the metadata we hold.
Depending on severity we may ask you to stop, disable a specific key, suspend the account, or terminate it. Where we can, we tell you what happened and give you a chance to respond first; for illegal content we act immediately. Terminating an account deletes its stored provider keys along with it.
Reporting abuse
If you believe an account is using model.cards for any of the above, email support@model.cards with whatever detail you can share. Reports about a specific piece of content are more actionable if you include when it was generated and which model produced it.