Tore

Legal

Acceptable Use Policy

What you may and may not do with Tore.

Draft, not yet reviewed by a lawyer

This document is published so its structure and facts can be checked. It has not been through legal review and should not be relied upon as a binding agreement until this banner is gone.

Last updated: 4 August 2026

This policy is part of the Terms of Service and is incorporated into them by reference. Breaking it is a breach of that agreement.

Who this applies to

It applies to everyone using Tore on any plan, including a free trial and the Free plan: you, the people you invite into your workspace, anyone using your API keys, and the customers who reach you through a widget, help center, feedback board, portal or support address we host for you.

You are responsible for all of them. If someone you invited, or someone writing into a surface you operate through Tore, breaks this policy, we treat it as your breach and we deal with you. Make sure your team knows these rules, and moderate what appears in public under your name.

Do not

  • Break the law, or use the Service to help someone else break it.
  • Upload or transmit malware, or use the Service to attack anything.
  • Try to gain access to another organization’s data, or to parts of the Service you have not been granted. Probing tenant isolation without a written agreement with us is not permitted; see below for how to test properly.
  • Connect a code repository you are not authorized to grant access to.
  • Send unsolicited bulk email through the Service, or use it to distribute spam, phishing or fraudulent content.
  • Upload content you have no right to upload, or that infringes someone else’s rights.
  • Deliberately capture sensitive categories of personal data you do not need, health, biometric, financial account credentials, government identifiers, through the bug capture tool. Configure the tool to exclude them.
  • Use the Service to build a competing product, or to benchmark it for publication, without our written agreement.
  • Circumvent limits, quotas or billing, including by creating accounts to obtain repeated free trials.
  • Resell or provide the Service to a third party except under an agency arrangement we have agreed in writing.
  • Use automated means to place unreasonable load on the Service, or to scrape it.
  • Use the Service where US export control or sanctions law prohibits it, as described in the Terms of Service.

Data you must not put into Tore

Some categories of data need protections or agreements we do not have yet, and putting them in creates risk for the people they describe. Do not use the Service to store or process:

  • Protected health information. We do not sign HIPAA business associate agreements.
  • Payment card numbers, CVVs or full bank credentials. Take payment details in a system built for them, not in a support conversation or a session recording.
  • Government identifiers such as social security, passport or national ID numbers, unless you genuinely need them and have told us.
  • Special category data under UK or EU data protection law including health, biometric, genetic, racial or ethnic origin, political opinions, religious belief, trade union membership and sexual orientation, without an agreement with us that covers it.
  • Data about children where the Service is not an appropriate place to hold it.
  • Anything classified, or subject to a regulatory regime we have not agreed to in writing.

If a customer of yours volunteers one of these in a conversation, that is not a breach by you. Deliberately routing them into Tore is.

Bug capture

Bug capture is the most sensitive thing Tore handles. A capture can include a session replay, console output, a network trail, and details of the device, browser and release.

  • Tell the people whose sessions you are recording, before you record them, and obtain consent where the law where they live requires it.
  • Configure the capture tool to exclude what it must never see. Mask password and payment fields, exclude the screens where sensitive data appears, and turn off network body capture where it would carry credentials or tokens.
  • Do not use capture to monitor your own staff, or to observe a person for a purpose they have not been told about.
  • Do not deliberately capture a third party’s site or application that you do not operate.

Our redaction runs as a background job after an artifact has been stored, and quarantines anything that fails rather than passing it on. That is a backstop, not a filter in front of storage, and it is never perfect. Configuring the tool properly is your job and it comes first.

Email you send through Tore

Tore sends and receives email on your behalf, so what you send affects the deliverability of everyone on the platform. When you use it:

  • Send only to people who contacted you, bought from you, or otherwise agreed to hear from you. No purchased or scraped lists.
  • Comply with CAN-SPAM, CASL, the UK and EU rules on electronic marketing, and any other law that applies where your recipients are.
  • Do not forge headers, disguise the origin of a message, or send from a domain you do not control.
  • Honor unsubscribe and stop requests promptly, and keep bounce and complaint rates within normal industry limits. We may throttle or stop sending for an account whose rates put the platform at risk.
  • Do not use the Service for bulk marketing campaigns. It is a support product, not an outbound sending platform.

Your public surfaces

If you run a help center, feedback board, roadmap or portal through Tore, it is published under your name and you are responsible for what is on it. Do not publish unlawful, infringing, deceptive or harassing content, and moderate what your own users post there. We may remove content from a surface we host if it breaches this policy or the law, and we will tell you when we do.

Code repositories

  • Connect only repositories you own or are authorized to grant access to. If you are an agency, get the client’s authorization first.
  • Do not use the Service to work on code whose license or a confidentiality obligation prohibits sending it to a third-party service.
  • Do not use it to produce or distribute malware, exploit code aimed at systems you do not own, or a circumvention of someone else’s technical protection.
  • Review every proposed change before merging it. Nothing is merged without a person on your side, and that person is responsible for the merge.

AI-specific rules

  • Do not attempt to make the Service produce content that is illegal, or that would harm someone.
  • Do not use prompt injection or similar techniques against the Service’s AI to make it act outside its permissions. Content taken from a bug report, a web page or a third-party ticket is treated as evidence, never as instructions, attempting to defeat that is a breach of this policy.
  • Do not present AI-generated replies as the statement of a named human who did not review them.
  • Do not use a connected AI provider key that you are not entitled to use.
  • Do not use AI Output to make a decision with a legal or similarly significant effect on a person without meaningful human review.
  • Do not use the Service to generate content that impersonates a real person or organization, or to produce material designed to deceive.
  • Do not use the Service, or its output, to train a competing model, and do not extract its prompts, weights or configuration.

API and automated access

Use documented endpoints, respect rate limits and the response headers that describe them, keep your API keys secret, and rotate a key you think has leaked. Do not share keys outside your organization, run traffic that degrades the Service for other customers, or use automation to evade a plan limit. If you need a higher limit, ask us.

Security testing

We welcome security research. Test against your own organization only, do not access anyone else’s data, do not degrade the Service for others, and report what you find to security@codaslabs.com before disclosing it publicly. Research conducted that way will not be treated as a breach of this policy.

Denial of service testing, social engineering of our staff or our providers, and physical testing are out of scope and are never authorized. We do not currently run a paid bounty program.

If something goes wrong

If we believe this policy has been breached we may remove content, restrict a feature, suspend an account, or terminate it. Except where the risk is urgent or the law requires otherwise, we will tell you first and give you a chance to put it right. We keep any action no broader and no longer than the problem requires, and restore access once it is resolved. Suspension for a breach does not entitle you to a refund, and it does not cancel fees you already owe.

Reporting abuse

If you believe someone is using Tore in breach of this policy, tell us at abuse@codaslabs.com with enough detail for us to investigate: what you saw, where, and when. If it is a security vulnerability rather than abuse, use security@codaslabs.com instead. We acknowledge reports and will tell the reporter the outcome where we can do so without breaching someone else’s confidentiality.

Changes to this policy

We may update this policy as the product changes. For material changes we will give at least 30 days’ notice by email or in the product, except where a change is needed for legal or security reasons and cannot wait. The date at the top of this page shows when it last changed.