Acceptable Use Policy
What you can and can't build with MaximusDev. Plain rules. We're a one-person operation; please don't make us play whack-a-mole with abuse.
Contents
1. What this covers
This policy applies to everything you do with MaximusDev: prompts you send, apps you build, files you upload, content your apps host, and traffic you push through our infrastructure. It applies whether you're on the free tier, a paid tier, or using your own OpenRouter API key (BYOK) — you're still on our platform.
It sits alongside the Terms of Service (the contract) and the Privacy Policy (the data side). Where they overlap, all three apply.
2. Don't break the law
Don't use MaximusDev to build, host, or do anything illegal under UK law, EU law, or the law of the country you're operating in. We don't try to enumerate every offence — assume the obvious things (fraud, theft, money laundering, tax evasion, regulated-financial-services without authorisation, regulated-medical-claims without authorisation) are not allowed.
If you're operating in a regulated sector (financial services, healthcare, gambling, alcohol, tobacco, firearms, legal services), you are responsible for your own compliance. We don't pre-vet your app for sectoral rules.
3. Don't build things that harm people
Specifically, no:
- Child sexual abuse material (CSAM), including AI-generated
- Content depicting non-consensual sexual acts, or sexual content involving real people without their consent
- Content that promotes or facilitates self-harm or suicide
- Material that incites violence or hatred against people based on race, religion, gender, sexuality, disability, nationality, or any other protected characteristic
- Terrorism or violent extremism content, recruitment, or coordination
- Stalkerware, doxxing tools, or content designed to track or expose private individuals against their will
- Content that exploits vulnerable people (e.g. predatory loans, deceptive medical pseudoscience aimed at the seriously ill)
CSAM and terrorism content trigger immediate, no-warning suspension and reporting to the Internet Watch Foundation, the National Crime Agency, or whichever authority is relevant. There is no "I didn't realise" defence here.
4. AI-specific rules
When you use MaximusDev, your prompts are routed through OpenRouter to model providers — currently Anthropic, OpenAI, and MiniMax. Their usage policies apply to your prompts, in addition to ours. Don't:
- Generate or distribute malware, phishing pages, or fraud kits
- Use the AI to produce disinformation that's intended to be passed off as authentic news, government communications, or independent expert opinion
- Generate synthetic media (deepfakes) of real people without their consent — especially for political, sexual, or defamatory purposes
- Try to circumvent the model providers' safety mechanisms via prompt injection, system-prompt extraction attacks, or jailbreaking — including indirectly, by building an app that accepts user prompts and forwards them unguarded
- Use the AI to grade, score, or make consequential decisions about people (employment, credit, insurance, immigration, education, criminal justice) without meaningful human review and a clear lawful basis
The model providers' policies are linked from our documentation. Read theirs too — your obligations under their policies pass through to you when you use their models via us.
If you build a customer-facing app that uses our AI, you're responsible for what your end-users prompt. We expect reasonable safeguards (input filtering on obvious prohibited content, rate limits, abuse reporting) — not perfection.
5. Impersonation and brand abuse
Don't impersonate real people, real organisations, or real public bodies — including by mimicking branding, faces, voices, or domain names — without permission. Don't pass off a MaximusDev-built app as the official product of a company that didn't make it. Don't use someone else's trade marks, logos, or copyrighted material in a way they haven't authorised.
Parody and commentary that's clearly identifiable as such is fine — that's what fair dealing is for.
6. Spam and bulk messaging
Don't use MaximusDev to send unsolicited bulk email, SMS, push notifications, or any other mass communication. If you build a tool that sends messages on a user's behalf, you must:
- Comply with PECR, UK GDPR, CAN-SPAM, and any other rule that applies in the recipient's jurisdiction
- Have a lawful basis for the messaging (consent or legitimate interests, not "we hope they'll like it")
- Include a working unsubscribe link or equivalent opt-out mechanism in every message
- Honour opt-outs immediately — across all your apps, not just the one that sent the message
Cold outreach that is genuinely targeted, B2B, and PECR/GDPR-compliant is not spam and is fine.
7. Security and abuse of our infrastructure
Don't:
- Probe, scan, penetration-test, or attack our infrastructure or other users' apps without our written permission
- Try to escape your tenant boundary or access another tenant's data
- Run cryptocurrency miners, distributed compute jobs, or other workloads that aren't building or running an app
- Use MaximusDev as free CDN, file-share, or pirate-content host
- Generate or distribute traffic-amplification, DDoS, or credential-stuffing tools
- Re-sell raw access to our AI routing or compute as a "wrapper" SaaS — building a product that uses AI is fine; reselling our infrastructure as your own is not (see also section 8)
If you find a security issue, please report it responsibly to hello@maximusdev.cloud with "SECURITY" in the subject. We'll respond within 24 hours.
8. No-reselling rule
You can charge your end-users for the apps you build with MaximusDev. That's the point.
What you can't do is package up our AI routing and resell it as a generic API or a "ChatGPT competitor". The line is whether you're shipping a product (a real app that does a real thing for real users) or a thin wrapper that just exposes our infrastructure with a different logo. If you're not sure where your idea sits, email us before building it.
9. Sanctions and export control
You must not use MaximusDev if you, your organisation, or your end-users are subject to UK, EU, or US sanctions, or located in a country subject to comprehensive sanctions (currently including, but not limited to, Russia, Belarus, Iran, North Korea, Syria, Cuba, and the contested territories of Ukraine).
You must not use MaximusDev to build technology that is subject to UK or EU export-control regimes (e.g. dual-use cryptography or surveillance tools) without the appropriate licences.
10. How we enforce this
We don't pre-screen prompts, content, or apps. We respond to reports, automated abuse signals (e.g. provider safety flags fired by your prompts), and discoveries we make ourselves.
Three escalation levels:
- Warning + fix window — for fixable, non-severe issues (e.g. an outdated unsubscribe footer, a borderline prompt). We email you, give you a reasonable window to fix it, and only escalate if it isn't fixed.
- Suspension — for serious or repeated breaches. Your account is locked; your apps may be paused. We email you the reason. You can appeal by reply.
- Immediate termination + reporting — for CSAM, terrorism content, active attacks against our infrastructure, or active fraud. We don't warn first. We do report to the relevant authority.
If we terminate your account for breach, the 30-day data grace described in the Terms doesn't apply — your data may be deleted immediately, except where we're legally required to preserve it (e.g. for criminal investigation).
11. Reporting abuse
If you've spotted something on MaximusDev — a hosted app, a public-facing endpoint, generated content — that breaks this policy, please tell us at hello@maximusdev.cloud with "Abuse" in the subject. Include:
- The URL or app name
- What you saw and when
- A screenshot if it helps and isn't itself sensitive content
We aim to acknowledge abuse reports within 24 hours and act on them within a few working days. CSAM reports get priority routing — same email, same subject, but we'll move within hours.
If the abuse is on a hosted MaximusDev-built app and the operator of that app refuses to act, you can also escalate directly via the relevant authority (Internet Watch Foundation for CSAM, Action Fraud for fraud, ICO for data-protection breaches).
12. Contact
Email: hello@maximusdev.cloud
Subject prefixes: "Abuse" for reports, "SECURITY" for vulnerabilities, "Appeal" for suspension reviews.
Operator: Tim Harfield, trading as MaximusDev. United Kingdom.