Legal
Smol API Acceptable Use Policy
What you may not send to the Smol API or do with it, how to report abuse, and what we do when a report arrives.
1. Who this applies to
1.1This policy is part of the Smol API Terms of Service. It applies to everyone who uses the Smol API, and to anyone who reaches it through your product.
1.2You are responsible for your users. If your product lets other people send files to the API, you must have your own rules and your own way to deal with abuse.
2. Content you must not send
2.1Do not send, or let others send through you:
- child sexual abuse material, in any form;
- any other content that is illegal to hold, process or distribute where you operate or in the United States, including sexual images of a person shared without their consent;
- malware, or files built to exploit, crash or escape the software that processes them, such as decompression bombs;
- content you have no right to process, such as material that infringes someone’s copyright or reveals their trade secrets; or
- personal data that you have no lawful basis to send to a processor.
2.2Data that needs a specific agreement or certification is restricted by clause 10.4 of the Terms of Service.
3. Conduct that harms the service
3.1Do not:
- attack the service, try to overload it, or interfere with other customers’ use of it;
- probe or test the service for weaknesses without our agreement (the security page explains how to report a vulnerability in good faith);
- try to reach other customers’ files or records, or our internal systems;
- use an input address, an output address or a webhook address to make our servers send traffic to a system you do not control;
- get around rate limits, concurrency limits, file limits or the spend cap, for example by opening several accounts or rotating keys;
- get around billing, including by tampering with requests so that work is done without being charged;
- use test keys, or the published sample files, to avoid paying for real work;
- share or sell your keys, or let a key be used from a browser or an app you distribute; or
- resell the API, or offer it under another name as a compression or conversion API, without a written agreement with us.
3.2Building your own product on the API and charging your customers for that product is allowed. What needs our agreement is passing the API itself on to others.
4. How to report abuse
4.1Email [email protected] with “Abuse report” in the subject line. A person reads every report.
4.2Tell us:
- what the content or conduct is, and why you believe it breaks this policy or the law;
- anything that identifies it, such as a download link, a job ID or a request ID;
- when you saw it; and
- how to reach you.
4.3Do not attach the content itself. Never send us child sexual abuse material, even as evidence; describe where it is instead.
4.4For a copyright complaint, also state the work you own, that you believe in good faith the use is not authorised, and that your statement is accurate. Our designated copyright agent is [TO BE COMPLETED: designated copyright agent and address, once registered].
5. What we do when we receive a report
5.1We do not scan content. We do not look at, review or filter the files customers send, and we keep them only briefly. A file in a direct request is gone when the response has been sent. A job’s input is deleted when the job ends, and its output is deleted when it expires, which is at most 24 hours later. By the time a report reaches us, we usually no longer hold the file.
5.2We act on what we actually know. We have no general knowledge of what passes through the service. When a report, a court order or our own handling of an incident gives us actual knowledge of unlawful content or of a breach of this policy, we act on it.
5.3Depending on what we find, we may:
- delete a file that is still in our storage and disable its download link;
- revoke a key or suspend an account;
- end the agreement with the customer; and
- keep the records we hold (account and usage records, not file contents) where the law requires us to preserve them.
5.4We report where the law requires it. If we gain actual knowledge of apparent child sexual abuse material, we report it to the authority the law names (in the United States, the National Center for Missing & Exploited Children) and preserve what the law requires. We answer valid legal demands from public authorities. We can hand over only what we hold: account and usage records, and any file not yet deleted.
5.5We may tell the customer about a report unless the law forbids it or doing so could cause harm. We reply to the person who reported when we have acted or need more detail.
6. If you break this policy
6.1We may suspend your account or end the agreement under sections 7 and 8 of the Terms of Service. For a serious breach we may do so without notice.
6.2Fees for usage up to that point remain due.
7. Changes to this policy
7.1We may update this policy as set out in section 16 of the Terms of Service. The version and date at the top show which text is current.