1. Why this policy exists
The platform finds, reads and reasons over public information about people, companies and narratives, and lets you build your own agents, workflows and connectors to do it. That capability is useful for due diligence, research, risk and reputation work, and it is harmful in the wrong hands. We do not review what you build before it runs, so the line has to be written down. This is the line.
2. Never allowed
These uses are prohibited for every account, plan and engagement, with no exception:
People
- Surveillance, tracking or profiling of a private individual without a lawful basis; locating a person’s home, family, movements or private contacts; “find everything about this person”; doxxing and doxxing-style aggregation.
- Stalking, harassment, intimidation, blackmail or extortion, or building material for them — including running a result about a person and then using it to demand money, silence, a favour or any other action from them.
- Feeding the platform false, forged or manipulated material about a person or organisation to obtain a result that damages them, or editing a result after it was produced and presenting it as the platform’s output.
- Covert monitoring of employees, partners, journalists, activists, lawyers or political opponents beyond what the law expressly allows.
- Collecting, inferring or disclosing special-category data (health, biometrics, sexual orientation, religion, political opinion, union membership, criminal history) about identified people without a legal basis.
- Discrimination or unlawful profiling on protected characteristics; fully automated decisions with legal or similarly significant effects on a person without meaningful human review.
- Any child-safety violation. Any sexual content involving minors.
Data collection
- Bulk extraction of personal e-mail addresses, phone numbers or contact data; people enrichment for unsolicited outreach; building marketing or lead lists of private individuals.
- Scraping or accessing a site or platform in breach of its terms, its access controls, its rate limits or a login wall; using a connector to reach content the source does not make public.
- Bringing data to the platform that you obtained unlawfully, or that you have no right to process.
Deception and harm to the public sphere
- Disinformation, coordinated inauthentic behaviour, fake reviews, astroturfing, smear or “black PR” campaigns, defamation.
- Impersonating a person or organisation; deceptive synthetic media of real people; misrepresenting an AI-assisted result as human verification or as a finding of fact.
- Presenting a result as an audit, certification, investigation report or finding of Tuluko Group OÜor of any AA Group direction. A result is your analysis on our infrastructure; we issue no reports about third parties on a user’s behalf.
- Suppressing, burying or deterring lawful public-interest journalism or reporting. Reputation work on the platform addresses well-founded falsehoods and privacy violations, never accurate reporting.
- Interfering with elections or democratic processes; targeting voters with deception.
Crime, security and safety
- Evading sanctions, export controls, embargoes or anti-money-laundering obligations; facilitating fraud, bribery, corruption, money laundering or tax evasion.
- Weapons of mass destruction; targeting for conventional weapons; attacks on critical infrastructure; violent extremism or terrorism.
- Malware, credential harvesting, phishing, unauthorised access to systems, accounts or data; any attack on the platform or on another user’s tenant.
3. High-risk uses: allowed with safeguards
The platform supports the following uses as decision support only. In each of them a person can be seriously affected by a wrong result, so you are the accountable decision-maker and you must keep these safeguards in place:
- Human review. A qualified person reviews the result and the cited sources before any decision or action; the result is never the sole basis.
- Lawful basis and purpose. You have a documented legal basis for processing the data of the people involved and a purpose the law recognises.
- Transparency. Where the law requires it, the person affected is told that AI-assisted analysis was used and can contest the outcome.
- Records.You keep the result, its sources and the reviewer’s decision, so that the decision can be explained.
- Proportionality. You collect no more than the decision needs, from public scope only.
The uses this applies to include:
- employment screening, onboarding and offboarding;
- credit, tenancy, insurance and other eligibility decisions;
- KYC, AML, sanctions and counterparty due diligence workflows;
- litigation support, evidence preparation and investigations;
- journalism and publication about identifiable people;
- reputation assessment and remediation;
- political, electoral and public-opinion analysis;
- security, defence and law-enforcement support.
The platform does not provide KYC approval, AML or sanctions clearance, fraud or authenticity verdicts, legal or compliance determinations, complete background checks, private-data access, or continuous surveillance, and no result may be represented as any of these.
4. Sources and connectors
- Connectors reach third-party services under those services’ terms. Switching one on is your decision to use that service under its terms; you may not use a connector to do what the source forbids.
- Lookups in court and legal registries by a private individual’s name pass through the platform’s human gate, and you must have a lawful purpose for them. Lookups by company do not need the gate.
- Do not build assets whose purpose is to aggregate a private individual’s life across sources, to extract contact data, or to defeat a source’s protections.
- Do not present alpha, partial or unverified sources as authoritative in a result; keep the platform’s confidence labels and source links on what you publish.
5. Sharing and publication
- You are the publisher of what you share, inside or outside the platform, including toward the people named in it. Sharing a result that breaches Section 2 is a breach by you.
- Do not share an asset that would run another person’s private content, credentials or connector secrets on the recipient’s account.
- Keep the output notice on results you share or export; do not remove the AI, sources and confidence statements, and do not attach a person’s name to a result as its author unless they chose it.
- Do not re-publish a result another user shared with you beyond what the sharer allowed.
- Remember that a Public artifact is visible to every signed-in user of the platform: do not make Public an artifact that contains another person’s personal data, confidential material or credentials, and do not share a chat whose prompts contain them.
- Do not place in an artifact code that tracks, fingerprints or attacks the people who open it, or that loads resources for any purpose other than displaying the artifact.
6. Platform integrity
- No circumventing credits, rate limits, schedule limits, human gates or safety controls; no bypassing billing; no chargeback abuse.
- No automated mass or commercial use beyond the plan you are on without our written permission; no reselling access without an agreement.
- No extracting our prompts, routes, methodology parameters or model outputs at scale; no reverse engineering; no using results to build a competing service.
- No uploading malware; no probing, scanning or attacking the platform or another tenant; no sharing credentials between accounts.
- No interfering with another user’s assets, shares or runs.
7. Reporting and enforcement
If you see a use of the platform that breaks this policy, or if you are the subject of one — for example you received a “report” about yourself with a demand attached — write to [email protected]. Every exported or shared result carries a result identifier; send it to us and we will confirm whether the result was produced on the platform, by which solution and when, whether it has been altered since, and which parts came from public sources and which from material the user supplied. We do not confirm the identity of the user without a legal basis, but we act on the account. On a reasonable belief of a breach we may suspend a run, a share, an asset or an account, restrict connectors or limits, preserve evidence, and cooperate with law enforcement and supervisory authorities. Where the law allows we tell you what was found and why. Repeated or serious breaches end the account; credits consumed in breach are not refunded.
8. Changes and contact
We update this policy as the platform, the law and our understanding of misuse change; the new version is posted here with a new “Last updated” date and, for material changes, announced in the application. Questions: [email protected]. Tuluko Group OÜ, registry code 14335661, Tuukri tn 19-315, 10120 Tallinn, Estonia.