Frayme Acceptable Use Policy
Last updated: 17 September 2026
This Acceptable Use Policy ("AUP") forms part of the Frayme Terms of Service and applies to all use of the Service. Capitalised terms have the meaning given in the Terms. You accepted this AUP when you accepted the Terms, and it applies to every request you make to the Service. If your End Users misuse a Customer Application in a way that causes a breach of this AUP through your account, that use is attributed to you, so design your Customer Applications with appropriate safeguards. In deciding what action to take, Frayme will take into account the safeguards you had in place and how quickly you acted once you became aware of the misuse.
Frayme's Service composes user interfaces. Because interfaces shape what people see, trust and click, this AUP pays particular attention to deceptive interface design.
1. No illegal use
You must not use the Service to violate any applicable law or regulation, or to facilitate, promote or instruct others in illegal activity, including fraud, money laundering, unlawful gambling, trafficking, or the sale of illegal goods or services.
Sanctions and export control. You must comply with the export-control and sanctions laws that apply to you, including those of the United Kingdom, the European Union and the United Nations and, to the extent they apply to you or to your use of the Service, those of the United States. The Service is provided using infrastructure in the United States, so United States controls are relevant to how it is delivered. You must not use the Service, and must not knowingly make a Customer Application that relies on the Service available:
- in or from any country or region that is subject to comprehensive UK, EU or US sanctions; or
- to, or for the benefit of, any person or entity that is listed on, or that is 50% or more owned or otherwise controlled by a person listed on, the UK Sanctions List maintained under the Sanctions and Anti-Money Laundering Act 2018, the EU consolidated list of persons subject to financial sanctions, the United Nations Security Council Consolidated List, or the US Specially Designated Nationals and Blocked Persons List or other restricted-party lists maintained by the Office of Foreign Assets Control or the Bureau of Industry and Security.
Nothing in this section requires you to act, or to refrain from acting, in a way that would breach Council Regulation (EC) No 2271/96 as it applies in the European Union, or that Regulation as it forms part of assimilated law in the United Kingdom, the Protection of Trading Interests Act 1980, or any equivalent blocking or anti-boycott law that applies to you. Clause 23.7 of the Terms contains your related warranty.
2. No deceptive or harmful interfaces
You must not use the Service to generate, or render Outputs as, interfaces that are designed to deceive or harm, including:
- Phishing and credential harvesting: interfaces that imitate a login, payment or verification flow of another organisation, or that collect credentials, payment details or personal data under false pretences.
- Impersonation: interfaces that misrepresent their operator, or imitate another company's product, branding or official communications in a way likely to mislead.
- Counterfeit commerce: fake checkout flows, fabricated order confirmations, receipts, invoices or account statements presented as genuine.
- Scareware and tech-support scams: fake system warnings, virus alerts or urgency screens designed to panic users into an action.
- Dark patterns: interfaces engineered to trick users into decisions they did not intend, such as hidden costs revealed only at the last step, disguised advertisements, consent flows designed to mislead, subscription traps, or cancellation flows deliberately made obstructive.
- Malware delivery: interfaces that distribute or link to malicious software, or that exploit vulnerabilities in renderers or browsers.
- Spam and unlawful messaging: interfaces used to send, or to support the sending of, bulk or unsolicited electronic communications in breach of applicable direct-marketing and electronic-communications law (for example the Privacy and Electronic Communications (EC Directive) Regulations 2003, the ePrivacy Directive and its national implementations, CAN-SPAM, the TCPA or CASL), or to harvest contact details for that purpose.
3. Prohibited content
You must not submit Customer Content to, or generate interfaces through, the Service that:
- constitutes or promotes child sexual abuse or exploitation material in any form (Frayme applies zero tolerance: it will suspend access immediately under clause 16 of the Terms, terminate the Agreement in accordance with clause 17 of the Terms, and report the matter to the relevant authorities, for example the Internet Watch Foundation or the National Crime Agency, where required or permitted by law);
- promotes terrorism or violent extremism, or incites violence or hatred against people on the basis of protected characteristics;
- harasses, threatens or defames any person, or exposes a person's private information without authorisation (doxxing), including by using information obtained from or through the Service;
- infringes intellectual property or other proprietary rights (rights holders can report suspected infringement under the IP and Content Complaints Policy);
- consists of intimate or sexually explicit images of a real person made or shared without that person's consent, including synthetic or manipulated ("deepfake") images; or
- is otherwise unlawful in the jurisdictions where your Customer Application is offered.
4. Prohibited data
Unless separately agreed with Frayme in writing, you must not submit Prohibited Data to the Service (including in DATA blocks), and you must design your Customer Applications so that they do not routinely pass Prohibited Data to the Service.
Prohibited Data has the meaning given in clause 8.3 of the Terms, namely: special categories of personal data (including health, biometric or genetic data), personal data relating to criminal convictions or offences, full payment card numbers or financial account credentials, government-issued identification numbers, or personal data of children (for this purpose, anyone under 16). The DPA applies the same prohibition and adds any other category of sensitive personal data or sensitive personal information defined in an applicable data protection law. For clarity, "special categories of personal data" means the categories listed in Article 9 of the UK GDPR and the EU GDPR, and "full payment card numbers" means primary account numbers (PANs).
If Prohibited Data reaches the Service incidentally despite reasonable safeguards, that is not by itself a breach of this AUP, provided you stop the source promptly once you become aware of it. You may ask Frayme at support@frayme.ai to delete the affected Request Content before the end of the retention period described in section 7 of this AUP, the DPA and the Privacy Policy. See clause 8.3 of the Terms and the DPA.
5. High-risk and restricted uses
5.1 Safety-critical uses. The Service is not designed for, and you must not use it in, any application where a failure, delay or error in an interface, or in the content it presents, could reasonably be expected to lead to death, personal injury, or severe physical, environmental or financial harm (including medical diagnosis, treatment or emergency response; aviation, rail, maritime or other transport control; autonomous vehicles; weapons or military targeting systems; and the operation or control of critical infrastructure).
5.2 High-risk AI systems. You must not deploy the Service as part of an AI system that is high-risk under Article 6 and Annex III of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), as and when those obligations apply, or under an equivalent law, without Frayme's prior written agreement under clause 5.5 of the Terms. In summary, Annex III covers: biometric identification, categorisation and emotion recognition; the management and operation of critical infrastructure; determining access to, or evaluating people in, education and vocational training; recruitment, selection, promotion, termination, task allocation and the monitoring of workers; deciding eligibility for, or the terms of, essential private or public services, including credit scoring and the pricing of life and health insurance; law enforcement; migration, asylum and border control; and the administration of justice and democratic processes. If your Customer Application operates in any of these areas, write to support@frayme.ai before you go live; the parties will then agree the information and cooperation terms described in clause 5.5 of the Terms.
5.3 Prohibited AI practices. You must not use the Service in any practice prohibited by Article 5 of the EU Artificial Intelligence Act or an equivalent law, including interfaces that use subliminal, manipulative or deceptive techniques to materially distort a person's behaviour in a way that causes or is likely to cause significant harm, that exploit a person's vulnerability arising from age, disability or a social or economic situation, or that implement social scoring.
5.4 Automated decisions. Outputs are presentation, not decisions. You must not present content composed through the Service as the sole basis for a decision producing legal or similarly significant effects on an individual unless you provide the human involvement, information and right to contest that applicable data protection law requires (for example under Article 22 of the UK GDPR or the EU GDPR).
6. Platform integrity
You must not:
- share, sell, sublicense or publish API keys, or allow your account or keys to be used by anyone other than your personnel and the contractors and service providers who work on your Customer Applications under your direction and under written confidentiality obligations (for whom you remain responsible under clause 3.3 of the Terms);
- create multiple accounts or workspaces to stack Free-plan allowances or evade limits, suspensions or terminations;
- circumvent or attempt to circumvent usage allowances, rate limits, validation, metering or security controls;
- access, or attempt to access, any account, workspace, API key, Customer Content or Output that is not yours, or test whether you can, except as authorised by the Vulnerability Disclosure Policy;
- probe, scan or test the vulnerability of the Service, or conduct any penetration testing, except as authorised by the Vulnerability Disclosure Policy. Testing that stays within that policy is authorised by Frayme for the purposes of this section, of clause 7.2(b) of the Terms and of section 1 of the Computer Misuse Act 1990, and Frayme will not treat it as a breach of the Agreement; testing outside that policy is not authorised;
- reverse engineer, decompile or disassemble the Service, or attempt to extract or reconstruct Frayme's models, weights, system prompts or training data, including by prompt-injection or model-extraction techniques, except to the extent a restriction is not permitted by applicable law (see clause 7.2(c) of the Terms);
- use the Service, or systematically use Outputs, to build, train or improve a competing natural-language interface-composition product or model;
- scrape, crawl or bulk-extract the dashboard or the Documentation by automated means, other than ordinary search-engine indexing of public pages or use of a documented export feature or API;
- frame, mirror or otherwise simulate the appearance or function of the Service or the dashboard, or remove or obscure any proprietary, copyright or attribution notice in the Service, the component catalogue or the Documentation; or
- interfere with the Service's operation or other customers' use, including by imposing an unreasonable load outside your Plan's documented rate limits. Load or performance testing within those limits, for your own internal purposes, is permitted under clause 7.2(h) of the Terms.
7. Enforcement
Frayme does not routinely review Customer Content and, as described in the Terms, acts as a presentation layer for material you supply. Frayme stores Request Content (your prompt, the DATA block, each model output for that request and the returned interface specification) in its database in the European Union for up to 60 days, and one of the purposes of that storage is the investigation of suspected abuse, fraud and security incidents and the protection of the Service, its customers and third parties. At the end of that period the content is irreversibly deleted from the record, as described in clause 8.5 of the Terms, the DPA and the Privacy Policy.
Where Frayme has a reasonable basis to suspect a breach of this AUP (from an abuse report, from technical signals such as validation failures or rate-limit or key-sharing patterns, or from a legal notice), it may inspect the retained Request Content and records relating to the requests, API keys or workspace concerned, to the extent necessary for that investigation, and may in its reasonable judgement:
- issue a warning and require remediation;
- throttle, suspend or restrict access, or revoke API keys (see clauses 6.2 and 16 of the Terms);
- block or rate-limit specific requests, request patterns, API keys, workspaces or Customer Applications identified as the source of the abuse (Frayme cannot edit or take down content inside your own applications);
- terminate the Agreement in accordance with clause 17.3 of the Terms, where the material breach is not remedied within 14 days of written notice; this does not affect Frayme's right to suspend immediately under clause 16 of the Terms, or its rights at law where a breach is repudiatory; and
- where required or permitted by law, refer matters to law enforcement or regulators, and preserve records relevant to the matter as described below.
Preservation. Where Frayme is investigating a suspected breach, has taken enforcement action, has referred a matter to law enforcement or a regulator, or is required to preserve material by law, it may retain the Request Content and records relevant to that matter beyond the retention periods described in the DPA and the Privacy Policy, for as long as the matter (including any resulting claim or proceeding) requires, and will then delete them.
Where lawful and practicable, Frayme will notify you of the suspected breach and the action it proposes, tell you the reason, and give you a reasonable opportunity to remediate before acting, except where immediate action is needed to prevent serious harm, illegality or a security risk, in which case Frayme will notify you as soon as practicable afterwards.
Review. If you believe an enforcement decision was wrong, write to support@frayme.ai within 30 days of the decision, identifying the decision, why you believe it was wrong and any remediation you have carried out. Frayme will acknowledge within 5 working days (Monday to Friday, excluding public holidays in England) and give you its decision, with reasons, within 10 working days of receiving your complete request, or tell you within that period if it needs longer and why. Frayme will lift or reduce any action that is no longer justified. This review does not affect your rights under clause 23.1 of the Terms. Subject to clause 21.1 of the Terms, Frayme is not liable to you for enforcement action taken reasonably and in good faith under this section; clause 16.2 of the Terms governs Fees during a suspension.
8. Reporting abuse
Report suspected misuse of the Service (including deceptive interfaces you believe were composed through Frayme) to support@frayme.ai. Intellectual-property complaints have their own route and required contents: see the IP and Content Complaints Policy. Security vulnerabilities have their own route: see the Vulnerability Disclosure Policy. Include the material, where you found it, and why you believe it breaches this AUP. Frayme reviews reports promptly and treats reporter identities as confidential where lawful.
9. Changes
Frayme may update this AUP as the Service and the ways it can be misused evolve. Material changes are notified in accordance with clause 22 of the Terms. Where a change is needed urgently to address a new form of abuse, a security risk or a change in law, it may take effect on posting; Frayme will notify you as soon as reasonably practicable, and if the change materially restricts your existing lawful use of the Service, clause 22.2 of the Terms applies.