Skip to content
Acceptable Use Policy

The rules for people and for agents

Falrow gives people and AI agents write access to the same records. This policy sets out what neither may do with it. It forms part of the Terms of Service.

Version 1.0 · Effective 6 October 2026

In plain words
  • Use Falrow for lawful work. Do not store illegal content in it or use it to harm anyone.
  • Your coding agents act under your account. What an agent does through your token is treated as what you did.
  • Do not attack, overload, scrape or reverse engineer the service, and do not test its security without our written permission.
  • Report abuse or a vulnerability to bas@falrow.com.

This summary helps you read the document. It is not part of it: where they differ, the sections below apply.

1.Who this applies to

This policy applies to every Customer and every User of Falrow, and to every automated client that connects on their behalf, including coding agents using the MCP server, scripts using the REST API, and bots installed through integrations such as Slack. Capitalised terms have the meaning given in the Terms of Service.

The Customer is responsible for making sure its Users and its agents follow this policy. An action taken with a Customer's token, OAuth grant or session is treated as an action of that Customer.

2.Content you may not put in Falrow

  • Content that is illegal where you or the people it concerns are, including child sexual abuse material, which we report to the relevant authorities.
  • Content that infringes someone else's copyright, trademark, trade secret or other rights, or that you have no right to share with us.
  • Malware, ransomware, exploit code aimed at systems you are not authorised to test, or anything designed to damage or gain unauthorised access to a system.
  • Personal data you have no lawful basis to process, including meeting recordings or transcripts made without the consent the law requires from the people recorded.
  • Special categories of personal data (health, biometric, genetic data, data about racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation), criminal records, government identification numbers, full payment card numbers, or bank credentials, unless we have agreed it in writing. Falrow is not designed to hold these and does not carry the controls they need.
  • Data subject to sector rules Falrow does not support, such as protected health information under HIPAA, payment card data under PCI DSS, or classified or export-controlled technical data.

3.Things you may not do

  • Harass, threaten, defraud or impersonate anyone, or use Falrow to send unsolicited bulk messages.
  • Probe, scan or test the vulnerability of Falrow, or bypass authentication, rate limits, role checks or version checks, except under our vulnerability disclosure terms.
  • Overload the service, including by running agents or scripts in loops that make requests faster than the documented limits, or by uploading files designed to exhaust resources.
  • Scrape, copy or resell the service, or use it to build a competing product, or reverse engineer it except where the law allows this despite a contractual restriction.
  • Share accounts or tokens between people, or give access to someone who is not an authorised User.
  • Use Falrow in a way that violates US export controls or sanctions, or from a country or region subject to comprehensive US sanctions.
  • Use Falrow, or any AI feature in it, for a practice the EU AI Act prohibits, or to make decisions that produce legal or similarly significant effects on a person without meaningful human review.

4.Extra rules for AI agents and automation

Agents are powerful because they can write. These rules keep that safe for everyone sharing a workspace and a server:

  • Connect agents with the narrowest scope that works. Use read scope where the agent only needs to plan.
  • Do not disable or work around version checks, workflow rules or role checks to force a write.
  • Do not instruct an agent to put content into Falrow that this policy prohibits, or to copy Customer Data from a workspace you are not entitled to see.
  • Keep a person accountable for each agent connection. The workspace owner must be able to identify who connected it and revoke it.
  • Do not present agent output to a client or anyone else as reviewed human work if no one reviewed it, where that would mislead them.

5.What we do if this policy is broken

We do not monitor the content of workspaces. We act on reports, on signals from our security tooling, and on orders from authorities. When we learn of a likely violation we may, proportionately to the harm:

  • ask the Customer to fix it;
  • remove or disable access to the specific content;
  • revoke a token, an OAuth grant or an integration;
  • suspend a User or the workspace, in line with the Terms of Service; or
  • report illegal content to the authorities where the law requires it.

We will tell the Customer what we did and why, with the facts we relied on, unless the law or an authority forbids it or telling them would create a security risk. You can ask us to reconsider by replying to that notice; a person who was not involved in the original decision will review it.

6.Reporting a violation

Send reports of abuse or illegal content to bas@falrow.com, with the location of the content (a link or ticket key), why you believe it is illegal or violates this policy, and your name and email address. The Legal Notices page explains what a complete notice contains and how we handle it. Security vulnerabilities go to the same address.

Who you contract with
Spring Digital Commerce LLC2810 North Church Street
Wilmington, DE 19802
United States
EIN 35-2886201bas@falrow.com
This versionVersion 1.0, effective 6 October 2026. Earlier versions are available on request from bas@falrow.com.All legal documents