Acceptable use policy
The plain-language version: use Orama lawfully, only with data you have the right to use, keep people in charge of consequential decisions, and do not attack the Services or use them to harm anyone.
Last updated September 14, 2026
Who this policy applies to
This policy applies to everyone who uses the Orama website, Metis, Orama Studio, Zetta, our hosted services, APIs, and related services (the “Services”), including the people a customer allows to use its account. It is part of our terms of service. If you are a customer, you are responsible for making sure your users follow it.
The examples below are not a complete list. We may treat any use that is similar in purpose or effect as a violation.
Unlawful and harmful activity
Do not use the Services to:
- Break any law or regulation, or help anyone else do so.
- Create, store, or share child sexual abuse material, or any content that sexualizes minors.
- Promote or incite violence, terrorism, or violent extremism, or threaten, harass, stalk, or intimidate anyone.
- Commit fraud, run scams or phishing, impersonate a person or organization, or misrepresent where content comes from.
- Send spam or other unsolicited bulk messages.
- Infringe or misappropriate intellectual property, trade secrets, or other proprietary rights.
- Develop, produce, or acquire biological, chemical, nuclear, or radiological weapons, or other weapons intended to cause mass harm.
- Distribute malware, or create content designed to deceive people about elections or civic processes.
Data you connect to the Services
- Only connect, upload, or process data you have the legal right and any required authorization to use in the Services.
- When the data includes personal information, have a lawful basis for processing it, give any notices and obtain any consents the law requires, and honor the rights of the people it describes.
- Do not process special categories of personal data, such as health, biometric, genetic, or financial account data, or government identifiers, unless the law allows it and your agreement with Orama expressly covers it.
- Do not collect data by scraping or other automated means in violation of a website’s terms or applicable law, and do not use the Services to access data you are not authorized to access.
AI and automated decisions
- Do not use outputs to make decisions that have legal or similarly significant effects on people, such as decisions about employment, credit, housing, insurance, education, healthcare, or access to essential services, without meaningful human review and compliance with the laws that apply to those decisions.
- Do not use the Services for unlawful surveillance or tracking of individuals, or to identify people from biometric data without a lawful basis.
- Do not use the Services to discriminate unlawfully against anyone based on a protected characteristic.
- Do not present outputs as human-made where the law requires disclosure that they were generated by AI, and do not use the Services to create deceptive impersonations of real people.
- Do not attempt to bypass the safeguards built into the Services or the models they use.
Security and integrity of the Services
Do not:
- Access, or attempt to access, the Services, other accounts, or Orama systems without authorization, or probe, scan, or test their vulnerabilities, except under our coordinated disclosure process below.
- Circumvent authentication, access controls, usage limits, or billing.
- Interfere with or disrupt the Services, including by overloading them or launching denial-of-service attacks.
- Use the Services to attack, probe, or gain unauthorized access to any other system or network.
- Share credentials, or resell or provide access to the Services, except as your agreement with Orama allows.
- Reverse engineer any part of the Services that is not open source, except where the law expressly permits it.
What happens on a violation
Violations can lead to content removal, suspension, or termination of the account, depending on severity. Where the situation allows it, we contact you before acting. Unlawful activity may be reported to the relevant authorities.
We may investigate a suspected violation, and we may remove or disable access to content that violates this policy. You agree to cooperate with a reasonable investigation.
Reporting abuse and security issues
Report abuse, security issues, or content that violates this policy to [email protected].
If you find a security vulnerability, tell us before disclosing it publicly and give us a reasonable time to fix it. Please do not access or change data that is not yours, degrade the Services, or keep any data you encounter while testing. We will not pursue legal action against good-faith research that follows these rules.
Changes to this policy
We may update this policy as the Services and the law change. We will post the updated version on this page and change the date at the top.
