Purpose and scope
This Acceptable Use Policy (the “AUP”) sets out the conduct that is, and is not, permitted when you use the Appsanic service (the “Service”). The Service is operated by Encode Digital Software Solutions Pty Ltd (ACN 690 774 719), a company registered in New South Wales, Australia (“we”, “us”, “our”). Appsanic is an agentic AI mobile-app builder: you describe an app in natural language and an AI agent plans, writes, and helps you launch a real React Native application, generating source code and connecting, only at your direction, to third-party services.
This AUP forms part of, and is incorporated by reference into, our Terms of Service. Capitalised terms that are not defined here have the meaning given to them in the Terms. Where this AUP and the Terms appear to conflict, the Terms prevail.
This AUP applies to two distinct things:
- Your use of the Service itself - the prompts you send, the projects and content you create, the credentials you connect, and the way you interact with our systems and the AI agent; and
- The apps you build and distribute with the Service - the source code, configurations, and applications you generate, export, publish, or release to other people, whether or not they are hosted by us.
You are responsible for everyone who uses the Service through your account, including anyone you grant access. If you use the Service on behalf of an organisation, that organisation is bound by this AUP and you confirm you are authorised to accept it for them.
In short: use the Service lawfully, do not use it (or its AI output) to harm people or other systems, and take responsibility for the apps you build with it. The detailed rules below explain what that means and how we enforce it.
No illegal activity
You must not use the Service, and must not build, distribute, or operate any app using the Service, to do anything that is unlawful under Australian law or under the laws of any other jurisdiction that applies to you, to us, or to the people who will use what you build. This prohibition includes, without limitation, activity regulated or prohibited by:
- the Criminal Code Act 1995 (Cth) - including offences relating to child abuse material, terrorism, fraud, and interference with computers and data;
- the Privacy Act 1988 (Cth) and the Australian Privacy Principles - including the unlawful collection, use, or disclosure of personal information;
- the Spam Act 2003 (Cth) - the sending of unsolicited commercial electronic messages;
- the Online Safety Act 2021 (Cth) - including the Basic Online Safety Expectations and the prohibitions on class 1 and class 2 material; and
- any applicable consumer-protection, anti-money-laundering, sanctions, export-control, gambling, financial-services, health-regulation, or intellectual-property law.
You must not use the Service to plan, promote, facilitate, or carry out any criminal offence, nor to help any other person do so.
No infringement of others’ rights
You must not use the Service in any way that infringes the legal rights of another person or organisation. In particular, you must not:
- build, distribute, modify, or operate content or applications that infringe someone else’s copyright, trademark, patent, design, trade secret, or other intellectual-property right, or that misappropriate their confidential information;
- impersonate any person or organisation, or falsely state or imply an affiliation, sponsorship, partnership, or endorsement that does not exist;
- publish content that is defamatory, or that you know or ought reasonably to know is false and damaging to another person’s reputation;
- harass, bully, stalk, intimidate, or threaten any person, or encourage others to do so;
- breach an obligation of confidence or a contractual restriction you owe to a third party; or
- collect, scrape, or use another person’s data, name, image, or likeness without the lawful basis or consent required to do so.
AI output can resemble existing material, and connecting a third-party service does not transfer any licence to you. You are responsible for confirming that what you build and publish does not infringe anyone else’s rights. See the AI-output section of our Terms of Service for more detail.
No harmful content
You must not use the Service to generate, request, host, store, distribute, or build apps that produce or distribute any of the following. Some of this content triggers immediate, zero-tolerance enforcement and mandatory reporting, as described in the Enforcement section.
- Child sexual abuse material and child sexualisation. Any content that depicts, describes, sexualises, or exploits a child, including computer-generated or AI-generated material, or any content intended to groom or endanger a child. There is no exception to this rule and no warning is given before we act.
- Terrorism and violent extremism. Content that incites, instructs, glorifies, or provides material support for terrorism, genocide, mass violence, or violent extremist organisations.
- Weapons of mass harm. Content that facilitates the development, acquisition, or deployment of weapons capable of mass harm, including biological, chemical, radiological, nuclear, or high-yield explosive (CBRN) weapons, or that provides operational guidance for attacks on critical infrastructure.
- Non-consensual intimate imagery.Intimate or sexual images of a person produced, shared, or threatened to be shared without that person’s consent, including “deepfake” intimate imagery.
- Deceptive deepfakes and fraud. Synthetic media that impersonates a real person or organisation in order to deceive, defraud, manipulate an election, or cause harm, and any content designed to facilitate fraud or scams.
- Content that promotes self-harm or serious violence against people or animals, or that incites others to commit such harm.
AI-specific misuse
The Service is driven by an autonomous AI agent powered by commercial Claude models provided by Anthropic. You must not use the agent, its tools, or its output to do, build, or assist any of the following:
- Malware and intrusion tools. Create, modify, or distribute viruses, ransomware, spyware, keyloggers, rootkits, exploit kits, or any code whose primary purpose is to damage, disrupt, or gain unauthorised access to a system or its data.
- Phishing and credential harvesting. Build pages, apps, emails, or tooling designed to deceive people into revealing passwords, payment details, multi-factor codes, or other credentials, or that impersonate a legitimate brand or login.
- Fraud and scam apps. Build applications that facilitate fraud, deceptive schemes, fake stores, investment or cryptocurrency scams, or other arrangements designed to obtain money or data by deception.
- Spam and bulk-abuse tooling. Build systems for sending unsolicited messages at scale, for evading anti-spam controls, or for generating large volumes of deceptive content.
- Disinformation campaigns. Generate or operate coordinated inauthentic content intended to mislead the public, manipulate civic or political processes, or impersonate news sources.
- Stalkerware and covert surveillance. Build apps that track, monitor, or record a person without their knowledge and consent, or that are marketed or designed for covert surveillance of partners, family members, or employees.
- Safety-system evasion.Attempt to jailbreak, trick, or otherwise circumvent the agent’s safety guidelines, content filters, or the safety systems of the underlying model provider, including by obfuscating a prohibited request.
AI output is probabilistic and can be wrong, incomplete, or unsafe. You must not present output from the Service as professional advice in a regulated field - including health, legal, financial, tax, or safety-critical contexts - without review and sign-off by a suitably qualified person. You remain responsible for reviewing, testing, and validating all output before you rely on it or release it, as set out in our Terms of Service.
How we keep your secrets out of the model. The AI agent never receives your decrypted connector secrets. Connector credentials are encrypted at rest, are decrypted only on our ephemeral worker for the duration of a direct API call, and a redaction layer strips secret-like fields from tool results before they reach the model. You should still never paste passwords, API keys, or other secrets directly into a prompt.
No abuse of the Service or its security
You must respect the integrity, security, and availability of the Service and the systems it runs on. You must not:
- probe, scan, or test the vulnerability of the Service, or breach or attempt to breach its security or authentication measures, except strictly within the scope of responsible disclosure under our Security Policy;
- circumvent, disable, or interfere with authentication, session controls, Row Level Security, rate limits, credit metering, billing, or any other access control or usage measure;
- access, or attempt to access, accounts, projects, or data that do not belong to you, or use the Service to facilitate such access by others;
- upload, generate, or transmit malware, malicious code, or content designed to harm our infrastructure, our sub-processors, or other users;
- launch a denial-of-service attack, flood the Service with automated requests, or otherwise disrupt or overload our systems or those of our sub-processors;
- scrape, crawl, or harvest the Service at rates or in ways beyond ordinary interactive use, or use automated means to extract data in breach of these rules; or
- reverse engineer, decompile, or disassemble any part of the Service except to the extent that restriction is prohibited by applicable law.
Rate limits apply to sensitive actions such as sign-in, sign-up, password reset, account deletion, and data export. Treating those limits as a target to defeat, rather than a guardrail, is a breach of this AUP.
No training competing AI systems
You must not use the Service, its outputs, its responses, or any data derived from it to train, fine-tune, benchmark for competitive purposes, evaluate, or develop a machine-learning model, foundation model, or AI product or service that competes with the Service. This restriction is in addition to, and does not limit, any restriction in our Terms of Service. We do not use your prompts or generated code to train any AI model, and we expect the same restraint from you in respect of the Service itself.
No resale or unauthorised sublicensing
You must not resell, rent, lease, sublicense, time-share, or otherwise make the Service available to any third party as a service, except as expressly permitted by your plan or by a separate written agreement with us. You may build and distribute the apps you create with the Service - that is the point of Appsanic - but you may not repackage access to the Service or its AI agent as your own product, or operate the Service on behalf of others, without our prior written consent. Plan entitlements, including member and collaboration features, are described on our pricing page.
No spam
You must not use the Service to send unsolicited commercial electronic messages, or to build or operate tooling that helps others do so. Any messaging functionality in an app you build with Appsanic - email, SMS, push notifications, or in-app messaging - must comply with the Spam Act 2003(Cth) and the equivalent rules in each recipient’s jurisdiction (including the CAN-SPAM Act in the United States and the ePrivacy rules in the European Union).
In practical terms, messages your app sends must:
- be sent only with the recipient’s consent (express or, where lawful, inferred);
- clearly identify the sender on whose behalf the message is sent; and
- include a functional, no-cost way to unsubscribe that you honour promptly.
Respect personal data
If an app you build with the Service collects, stores, or otherwise handles personal information, you are the entity responsible for that data to the people it relates to. You must:
- have a lawful basis to collect and process the data under each applicable privacy law (for example, the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and, where relevant, the GDPR or CPRA);
- provide users with a clear, accurate, and accessible privacy notice that explains what you collect, why, and how it is used and shared;
- protect the data with safeguards appropriate to its sensitivity, and collect only what you genuinely need;
- honour the data-subject rights that apply - including access, correction, deletion, and portability - within the time limits the law requires; and
- notify affected individuals and the relevant regulator when an eligible data breach occurs, in accordance with the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988 (Cth)) and any other breach-notification law that applies to you.
How we handle the data you give us is described in our Privacy Policy, our Cookie Policy, and our list of sub-processors.
Responsibility for the apps you build and distribute
You are solely responsible for the legal and policy compliance of everything you build, publish, distribute, or operate using the Service, whether you host it yourself or distribute it through a third-party platform you connect (such as GitHub, Expo Application Services, the Apple App Store, or Google Play). That responsibility includes:
- complying with all laws that apply to your app, its users, its content, and the data it handles;
- complying with the developer agreements, content policies, and review guidelines of any store or platform you publish to;
- obtaining any licences, approvals, or professional reviews your industry requires before you go live; and
- providing your own users with the terms, privacy notices, age restrictions, and support that the law and the relevant platform require.
We do not review, approve, or endorse the apps you create, and we are not a party to the relationship between you and your users. Connecting a distribution provider does not make us responsible for what you publish through it. The applicable third-party platforms process your data only at your direction and under their own terms.
Enforcement
We monitor for, and respond to reports of, breaches of this AUP. Where we detect or are notified of a breach, we will respond proportionately to its seriousness and to the risk it poses to other people and to the Service. Depending on the circumstances, we may take one or more of the following steps, in roughly escalating order:
| Step | What it means |
|---|---|
| Warn | Notify you of the issue and ask you to stop or remediate, often with a deadline. |
| Quarantine or disable | Remove, restrict, or make private the offending content, project, or app while the matter is reviewed. |
| Suspend | Temporarily suspend access to the Service or to specific features while a serious or repeated breach is investigated. |
| Terminate | Close the account and end access to the Service for a material or persistent breach, in accordance with the Terms. |
| Report | Refer the matter, and preserve and disclose relevant records, to law enforcement or the relevant regulator where the law requires or permits it. |
We do not have to move through these steps in order. The step we take depends on the severity of the breach, the risk to other people, your history, and our legal obligations. Where a breach is capable of being cured and does not pose an immediate risk, we will generally give you a reasonable opportunity to cure it first.
Zero tolerance. For child-safety content and credible threats of serious harm we act immediately and without prior warning. We will disable the content and account, preserve the relevant records, and report the matter to the appropriate authorities, including specialist child-safety bodies, as required by law.
Reporting abuse and vulnerabilities
If you believe someone is using the Service or an app built with it in breach of this AUP, please tell us. Email contact@appsanic.com with as much detail as you can provide - links, identifiers, dates, and a description of the conduct. We aim to acknowledge abuse reports within one business day. For child-safety or credible-harm reports, mark the subject line clearly so we can prioritise.
If you have found a security vulnerability in the Service, please follow the responsible-disclosure guidance in our Security Policy. We acknowledge security reports within 48 hours. Do not test, exploit, or access other people’s data while investigating - good-faith disclosure within the scope of that policy is welcome, but it is the only authorised form of security testing on the Service.
Changes to this policy
We may update this Acceptable Use Policy from time to time to keep pace with new threats, new product features, and changes in the law. The “Last updated” date at the top of this page reflects the current version. Where a change materially affects your rights or obligations, we will give you reasonable notice by email or through a prominent notice in the Service before it takes effect. Your continued use of the Service after a change takes effect means you accept the updated AUP. For any question about this policy, email contact@appsanic.com; a postal address is available on request.
