Legal & Trust Center
Acceptable Use Policy
Version 1.0 describes how Ethen works today. It has not yet taken effect: passages shown in italics are still being decided, and the document will show an effective date once it is final. Earlier text is listed in the version history.
This Acceptable Use Policy sets out what you may not do with Ethen, and how Upcube enforces those rules. It applies to everyone who uses Ethen Chat, Ethen Studio, Ethen Platform or any other Ethen product, and to anything done through an Ethen Account, whether by a person, a script or an AI agent acting on that Account's behalf. It covers Prompts, files, Outputs, generated media, voice, connected apps and automated actions. It forms part of the Terms of Service. For guidance on relying on AI output responsibly, see the AI Use Policy.
On this page
- How this policy works
- Illegal activity and serious harm
- Fraud, deception and impersonation
- Abuse, harassment and hateful conduct
- Privacy and personal data
- Synthetic media, likeness and voices
- Intellectual property
- Malicious code and security
- Circumventing safeguards
- Connected apps and actions on your behalf
- Automation and platform abuse
- High-stakes uses
- Minors
- How we enforce this policy
- Reporting misuse
- Changes to this policy
- Related policies
- Contact
- Version history
How this policy works
Most uses of Ethen are ordinary work: writing, research, analysis, coding, design and creative projects. This policy is about the uses that cause harm. The rules apply to what you ask Ethen to do, what you do with what it produces, and what you direct it to do in other services on your behalf.
Some rules depend on authorization and context. Security testing, for example, is legitimate when you are authorized to test the system and harmful when you are not. Where context matters, this policy says so.
Model Providers that power Ethen may also refuse requests under their own usage policies. A request a provider allows is not automatically permitted here, and the reverse is also true.
Illegal activity and serious harm
Do not use Ethen to:
- plan, promote or carry out illegal activity, or to violate the rights of others;
- produce or distribute content that sexually exploits or endangers children, or that sexualizes minors in any way (this content is reported to the relevant authorities where the law requires);
- facilitate human trafficking, sexual exploitation or forced labor;
- help develop, acquire or use biological, chemical, nuclear or radiological weapons, or other weapons capable of mass casualties;
- plan or incite violence, terrorism or violent extremism, or praise or support such acts;
- encourage or give instructions for self-harm or suicide (if you are struggling, please contact local emergency services or a crisis line).
Fraud, deception and impersonation
Do not use Ethen to:
- commit or facilitate fraud, scams, phishing or financial deception;
- impersonate a real person, company or authority in a way that could mislead people, including by creating messages, documents, images, video or voices that appear to come from them;
- create fake reviews, testimonials, credentials or official documents;
- generate or distribute disinformation intended to deceive people about elections, public health, emergencies or other matters of public importance;
- present AI-generated content as human-created, or as the authentic words or actions of a real person, when that would mislead people in a way that matters.
Abuse, harassment and hateful conduct
Do not use Ethen to:
- harass, threaten, bully or intimidate anyone;
- target people with abuse because of a protected characteristic, such as race, ethnicity, nationality, religion, disability, sex, gender identity or sexual orientation;
- dox people, or encourage others to harass them;
- create content that degrades or dehumanizes people based on those characteristics.
Privacy and personal data
Do not use Ethen to:
- collect, compile or infer sensitive information about people without a lawful basis, including health, sexual orientation, religion, political views, biometric data or precise location;
- surveil, track or monitor people without their knowledge and a lawful basis;
- build profiles of individuals by aggregating personal data from multiple sources for purposes they would not reasonably expect;
- process other people's personal data in ways that violate privacy law;
- use facial or voice recognition to identify people without their consent where the law requires it.
Synthetic media, likeness and voices
Ethen Studio and voice features can create convincing images, video and audio. Do not use them to:
- create sexual or intimate content depicting a real, identifiable person without their explicit consent, or any such content involving a minor;
- depict a real person saying or doing something they did not say or do, where that could deceive people or harm the person;
- create a synthetic version of someone's voice without the rights and consent required by the Voice Cloning Policy policy;
- create content depicting public figures in deceptive or sexual scenarios, or that could be mistaken for authentic statements by them;
- remove or alter disclosures that identify content as AI-generated, where such disclosures exist or are required.
The Ethen Studio Media, Likeness & Generated Content policy has the full rules for uploads, likeness and consent.
Intellectual property
Do not use Ethen to:
- infringe or misappropriate copyrights, trademarks, trade secrets or other intellectual property rights;
- upload content you do not have the right to use;
- generate content designed to pass off goods or services as someone else's;
- remove copyright notices, watermarks or other rights-management information without permission.
If you believe content created with Ethen infringes your rights, use the reporting route in Reporting misuse.
Malicious code and security
What is prohibited
Do not use Ethen to:
- create, distribute or operate malware, ransomware, spyware or other harmful code intended for use against systems you are not authorized to affect;
- gain unauthorized access to accounts, systems or data, including by credential theft, password spraying, session hijacking or phishing;
- develop or deploy exploits against systems you do not own and are not authorized to test;
- plan or carry out denial-of-service attacks;
- run destructive operations, such as wiping data, encrypting systems or disabling security controls, against systems you are not authorized to change;
- evade detection or attribution for unauthorized activity.
Authorized security work is allowed
Ethen can be used for legitimate defensive and authorized security work, including:
- reviewing your own code for vulnerabilities;
- analyzing malware samples in a controlled setting;
- writing detection rules;
- explaining vulnerabilities;
- security research on systems you own;
- penetration testing performed with the system owner's permission.
Keep that work within the scope of your authorization. If your use could look like an attack to a third party, be prepared to show that you were authorized.
Testing Ethen itself
Do not probe, scan, load-test or attempt to break into Ethen's own systems, or other users' accounts or data, outside a vulnerability disclosure process Upcube has published. If you find a vulnerability in Ethen, report it as described in the Enterprise Security document. Do not access more data than you need to show the problem, and never access, modify or delete other users' data.
Circumventing safeguards
Do not:
- attempt to bypass, disable or interfere with Ethen's safety measures, usage limits, rate limits, access controls or approval steps, or those of the Model Providers behind Ethen;
- use prompts designed to make models ignore their safety rules in order to obtain prohibited content (a "jailbreak");
- create multiple Accounts, rotate identities or use other techniques to evade limits, suspensions or bans;
- misrepresent who you are or why you need access in order to obtain features or limits you would not otherwise receive.
Connected apps and actions on your behalf
When connected apps become available, Ethen will be able to read from and act in services you connect, such as email and calendars. Do not use these features to:
- send spam, bulk unsolicited messages or deceptive communications;
- access accounts that are not yours, or that you are not authorized to use;
- read, copy or move other people's data in ways they have not permitted;
- take actions that violate the connected service's own terms;
- approve actions you have not reviewed in a way that harms others, such as sending messages to people who have not agreed to receive them.
You are responsible for the actions you approve. See Connected Apps & Integrations.
Automation and platform abuse
Do not:
- use scripts, bots or agents to access Ethen in ways Upcube does not provide, or at volumes that degrade the Services for others;
- scrape or extract data from Ethen, or from Ethen's model-comparison data, beyond what its license allows;
- resell or share access to your Account, or operate Ethen as a service for others without Upcube's agreement;
- interfere with the Services, introduce malicious content into them, or attempt to access non-public parts of them;
- use Ethen to distribute spam through any channel.
High-stakes uses
Some uses carry serious consequences for people. Unless you have appropriate human review, safeguards and any legally required approvals, do not use Ethen to make or substantially automate decisions about:
- a person's access to employment, credit, housing, insurance, education or essential government services;
- medical diagnosis or treatment;
- legal outcomes, including law-enforcement or immigration decisions;
- the operation of critical infrastructure or safety systems.
In every case, follow the laws that apply to your use. The AI Use Policy explains what responsible review looks like.
Minors
Do not use Ethen to:
- create, request, share or store any content that sexualizes minors;
- groom, exploit or endanger minors;
- create synthetic media depicting a real minor without the consent of a parent or guardian;
- clone a minor's voice.
The rules for who may create an Account are in the Terms of Service.
How we enforce this policy
We may review content and activity when we receive a report, detect a potential violation through automated safeguards or usage patterns, or are required to by law. Depending on the severity, history and context of a violation, we may:
- refuse or block a request;
- remove or disable content, or revoke a shared link;
- limit features or usage;
- disconnect connected apps;
- suspend or terminate an Account;
- report the activity to law enforcement or other authorities where required or appropriate.
We aim to act proportionately and, where practical and lawful, to tell you what we did and why. If you believe we made a mistake, you can ask us to review it using the contact details below. Organizations should enforce their own stricter rules where needed; doing so does not limit Upcube's ability to enforce this policy.
Reporting misuse
To report content or activity that violates this policy, including infringement, impersonation, non-consensual media or abuse of a connected service, use the contact options in the Legal & Trust Center. Include enough detail for us to find the content or activity, such as a link, a description and the date. For security vulnerabilities in Ethen, see the Enterprise Security document.
Changes to this policy
We may update this policy as Ethen and the risks around it change. We will post updates here with a new version number and date.
Contact
Dedicated contact channels for privacy, security, legal, support and abuse reports are being set up and will be listed here before Ethen's policies take effect.
Version history
| Version | Date | Status | Summary of changes |
|---|---|---|---|
| 1.0 | October 5, 2026 | Not yet in effect | Expanded rules covering connected apps, automation, synthetic media, voice cloning and minors; clarified authorized security research. |
| 0.9 | September 2026 | Superseded | Earlier public-preview text. Archived. |