Acceptable Use Policy
Last updated: 8 August 2026
This policy covers everything you do with Poly — chat, agents, code execution, mail, research, wallets and anything you publish. It forms part of the Terms of Service.
The short version: do not use Poly to harm people, and do not use automation to do it at a scale a person could not.
You are responsible for your agents
An agent acts as your delegate. It runs on your credits, under your account, with the permissions you gave it, and — the whole point of an agent — while you are not watching.
Everything in this policy applies to what your agents do, exactly as if you had done it yourself. “The agent decided to” is not a defence. If you cannot supervise it, scope it: give it a budget it cannot exceed, withhold tools it does not need, and put an approval step in front of anything irreversible.
Do not
- Harm people. Threaten, harass, stalk, defame or incite violence against anyone. Sexual content involving minors ends an account immediately and is reported.
- Deceive. Impersonate a person or organisation, including Poly and its staff. Generate material designed to defraud, phish, or pass as an authentic document, identity or endorsement. Present model output as human-authored where that matters to whoever is reading it.
- Attack systems. Break into anything, scan or test systems you do not own or have written permission to test, distribute malware, or use the sandbox as a foothold. Circumvent our rate limits, quotas, credit accounting or safety systems.
- Send unsolicited messages. Poly Mail is for correspondence you have a reason to send. Bulk unsolicited mail, list-scraping and automated outreach without a lawful basis are out.
- Harvest data. Scrape personal data at scale, build profiles of people without a lawful basis, or infer sensitive characteristics — health, beliefs, sexuality, immigration status — about people who did not ask you to.
- Use psychological tooling on people who did not consent.Psyche is for the person taking the assessment. Running it over someone else's writing to profile them, and using it in employment decisions, are both prohibited.
- Make consequential decisions about people by machine alone. Employment, credit, housing, insurance, education and legal outcomes need a human who is accountable and genuinely able to reach a different answer.
- Give regulated advice as if from a professional. Medical, legal and financial output from a model is not advice from a doctor, lawyer or adviser, and must not be presented to anyone as though it were.
- Infringe. Reproduce work you have no right to, or strip attribution.
- Break sanctions or export law, or use Poly from a place where you are prohibited from doing so.
- Resell accessin a way that hides Poly's involvement, or serve many end users through one account without telling us.
Trading and wallets
Poly's wallet is non-custodial and its trading tools execute what you tell them to. Do not use them for market manipulation, wash trading, or to move the proceeds of crime. We cannot reverse a transaction, and neither can you.
Code execution
The sandbox is ephemeral and has no network. Do not attempt to escape it, mine cryptocurrency in it, or use it to reach anything outside it. Attempting is a breach whether or not it works.
Security research
Testing Poly itself is welcome under a few conditions: do not access other people's data, do not degrade the service, do not run automated scanning at volume, and tell us before you publish. Send findings to security@poly.inc. We will not pursue you for good faith research within those limits.
Reporting a breach of this policy
Send it to abuse@poly.inc with what you saw and where — a link, an agent name, a message. A description of the behaviour is far more actionable than an assertion that something is bad.
What we do not yet offer: a structured in-product reporting mechanism, an automatic acknowledgement of your report, or a notification telling you what we decided. A platform of this kind is expected to provide all three. Today a report is an email that a human reads, and that is the whole of it.
What happens if you breach it
Depending on what happened, we may:
- ask you to stop;
- restrict a feature, an agent, or an API key;
- unpublish something you have published;
- suspend the account;
- terminate it.
We aim to use the smallest of those that resolves the problem, and to tell you which one and why. Where there is imminent harm or a legal obligation we may act first and explain afterwards — and occasionally a legal obligation stops us explaining at all.
Your wallet is not ours to touch. Suspending an account does not affect funds: the keys are yours, the recovery phrase works in any Solana wallet, and nothing we do can freeze or move them.
Disagreeing with us
Write to legal@poly.inc. A human will read it and can reverse the decision.
That is less than you are entitled to, and we would rather say so than imply otherwise. We do not currently issue a statement of reasons in the form the law expects, keep a decision record you can point at, or run an internal complaint-handling system with defined timescales. Those are on the list; they are not built. Until they are, an appeal is an email — and nothing here takes away any right you have to complain to a regulator or go to court.
Changes
We will post changes here and update the date above. If a change materially restricts what you may do, we will give notice before it takes effect.