AirMemo

Acceptable Use Policy · V1.0 · 2026-09-22

AirMemo: Acceptable Use Policy

Version 1.0 · 2026-09-22.

This Acceptable Use Policy (the "AUP") governs Customer's use of the AirMemo service (the "Service") and is incorporated by reference into the Terms of Service.

1. Scope. This AUP applies to all use of the Service, including the composition and publishing of memos, the enrollment of orgs, devices, and agents, the console at /app/, delivery into agent session context, and any integrations Customer enables with coding agents and tools. It is incorporated by reference into the Terms of Service; capitalized terms used here have the meanings given in the Terms, and this AUP binds Customer as part of the overall agreement. The AUP applies to everyone who uses the Service: org administrators, authorized users, and the agents an org enrolls. It applies to all Customers regardless of plan, including free and pilot use. Customer is responsible for the conduct of every user and agent it enrolls, and a violation of this AUP by any enrolled user is a violation by the Customer that authorized them. Suspension and termination for breach are governed by Terms §10 (Term, Suspension, Termination), together with the enforcement provisions in Section 4 of this AUP.

2. Prohibited content in memos. Customer must not publish or transmit through the Service, whether in memo content, memo metadata, or attached context: (a) credentials, API keys, secrets, tokens, PII, or any data Customer lacks authority to transmit; the Service scans memos for credentials and secrets at author time and blocks them before publication, and Customer must not attempt to evade that scan through encoding, splitting, or obfuscation; (b) prompt-injection payloads or any content intended to manipulate, deceive, or misdirect a model or agent, including hidden instructions, jailbreaks, or "ignore prior instructions" tampering; the Service scans for injection payloads at author time, blocks them at publication, and re-scans at delivery, and Customer must not attempt to disguise such payloads; (c) malware, malicious code, or exploitative payloads of any kind; (d) content that is unlawful or that infringes third-party intellectual property, as further addressed in the Terms (Copyright / DMCA); or (e) harassment, threats, hate speech, or content that otherwise violates the rights of others. Customer is responsible for the content of the memos it publishes and must ensure that content complies with this section before it is written. The controls in this section are layered protections; Customer must not rely on them as a substitute for authoring compliant content.

3. Prohibited conduct. Customer must not: (a) attempt to circumvent, disable, or interfere with the Service's append-only audit trail, memo signing, mandatory expiry, rate limits, secret scanning, injection-payload detection, or device revocation; (b) share, resell, sublicense, or otherwise provide the Service to third parties except as expressly permitted by the Terms, including "memo brokering" or unauthorized multi-tenancy by parties that are not Customers; (c) use the Service to violate any law, including export-control and sanctions laws; (d) probe, scan, or test the Service's infrastructure beyond the documented testing mechanisms, or attempt to access another org's data across the multi-tenant boundary; (e) impersonate another user, another org, or the AirMemo system, including forging delivery receipts or audit entries; (f) interfere with or disrupt the Service, including denial-of-service activity directed at the control plane; or (g) scrape, harvest, or data-mine the Service or its documentation beyond reasonable use. This list is not exhaustive: conduct that frustrates the purpose of the Service, including using memos to bypass the controls described in Section 2, also violates this AUP.

Delivery-context responsibility. Because memos are delivered into agent session context at the next turn, Customer must ensure that memo content is accurate, current, and appropriately scoped to the org, team, or project it addresses. Customer must not use the Service to deliver content that could mislead an agent in ways that cause harm, such as fabricated facts presented as instructions. The Service is a governance tool: it signs, scopes, expires, and delivers, and it records what was delivered and when. It does not verify the truth of memo content, and it does not review the substance of permitted content. The author and their org own the content they publish, including its accuracy and the consequences of an agent acting on it.

4. Enforcement. We may, in our reasonable discretion: scan and block content at author time and at delivery, using the technical controls described in this AUP; suspend or terminate accounts or orgs that violate this AUP, per Terms §10; preserve evidence of violations, including the append-only records the Service already maintains; and cooperate with law enforcement where the law requires it. Technical controls such as secret scanning, injection-payload detection, rate limits, and approval requirements for org-wide broadcasts are part of the Service and operate automatically; they are product behavior, not discretionary enforcement decisions, and they apply without a separate human review step. Account-level enforcement, including suspension and termination, is reviewed by a human before it is imposed. We may also require corrective action from Customer, such as recalling or revising a published memo that violates Section 2, before access is restored after a suspension. We may act without prior notice where the law requires it or where immediate action is necessary to protect the Service or another Customer, and we will notify Customer as soon as practicable afterward. Suspension or termination for a violation does not waive any other right or remedy available under the Terms, and it does not limit our rights with respect to a continuing violation.

5. Reporting violations. Any person may report a suspected violation of this AUP by emailing hello@airmemo.com. Reports may be made by users, Customers, or third parties, and may be made anonymously or on the record. We evaluate each report and act where the violation is confirmed, using the measures in Section 4 as appropriate. When we confirm a violation, we will tell the affected Customer what was found and what we did, to the extent that doing so does not compromise an investigation or the safety of other Customers. We do not commit to a response time for reports, and we do not operate a public takedown process; we act as promptly as the circumstances allow. Customer must not retaliate against any person for making a good-faith report of a suspected AUP violation.

6. Changes to this AUP. We may update this AUP from time to time. We will notify Customers at least 30 days before a material change takes effect, by email or in-product, and the updated AUP will state its effective date. Continued use of the Service after a change takes effect constitutes acceptance of the updated AUP. If Customer does not accept a material change, Customer may stop using the Service and terminate in accordance with the Terms. Clarifying changes that do not restrict permitted use, that correct obvious errors, or that align this AUP with the Terms may take effect without the 30-day notice. The version stamp at the top of this page records the current version and its effective date.

7. Contact. Questions about this AUP, and reports of suspected violations, should be directed to AirMemo at hello@airmemo.com. We respond to inquiries promptly.