QuirkSphere Logo
QuirkSphere*
Legal

Acceptable Use Policy

Version 1.0 · Last updated 27 July 2026

Status

This document is version 1.0, dated 27 July 2026. It is currently under legal review and has not been finalised. Some entity details in this document are still to be confirmed.

Table of contents

Acceptable Use Policy

Plain-language executive summary

This policy says what a client, or anyone using something we built, is not allowed to do, and what we will not do even if asked. It exists because a lot of what we sell (AI-generated creative, cold outbound email, ad accounts, hosting access) can be misused in ways that create real legal risk for the client, for the people on the receiving end, and for us. Breaking it can get an engagement suspended or ended, and in the worst cases means the client has to cover our losses.

The headline rules: don't use anything we deliver for anything unlawful. Don't make claims in ads we build, especially about health, money, supplements, gambling, or crypto, that you can't back up before you run them. Don't strip the AI-generation labels or watermarks off AI creative, and don't use AI to fake a real person's face, voice, or endorsement without a signed release from that person. Don't impersonate a real person or company. Don't use anything we build to send marketing that breaks the rules where it lands, and understand that Canada and Germany are genuinely hard: both require the recipient's opt-in consent before you send, not just an opt-out after, and the burden of proving that consent sits with the sender. Don't scrape or buy contact lists without a lawful basis to use them, and don't target advertising at children: doing so is heading toward being flatly illegal in India, and is already restricted or dangerous everywhere else we operate. Don't use bots, fake engagement, or click fraud. Don't resell our internal frameworks, prompt systems, or pipelines, and don't try to reverse-engineer them. Don't test our systems' security without asking us first in writing. Don't misuse or share the credentials we hand each other.

If any of this happens, we can suspend the affected work, and in serious or repeated cases end the engagement, without that being a breach on our side. Depending on what happened, the client may owe us for the resulting loss, and in some cases we are legally required to report what happened to a regulator whether the client likes it or not.

We have also written down, plainly, the handful of things we will simply refuse to build, so a salesperson can point at this document on a call instead of improvising an answer.


AUP-1. Purpose and relationship to other documents

AUP-1.1 This Acceptable Use Policy ("this Policy") applies to every Client and every person the Client permits to use a Deliverable, an Agency-operated account, or Agency Materials. It sits alongside the Master Services Agreement ("MSA"), the applicable Statement of Work ("SOW"), the Data Processing Addendum ("DPA"), and the AI Delivery Rider ("AI Rider"), and does not replace anything in those documents. Where this Policy and any of those documents conflict, the order of precedence set out in the MSA and in DRAFTING-SPEC.md section 4 governs: SOW, then DPA, then AI Rider, then MSA, then this Policy and the Terms of Service.

AUP-1.2 House definitions in DRAFTING-SPEC.md section 5 apply throughout this Policy, including "Deliverable", "AI Output", "AI Tools", "Model Provider", "Agency Materials", "Client Materials", and "Third-Party Services". This Policy does not introduce new defined terms for concepts already defined there.

AUP-1.3 A breach of this Policy is a breach of the MSA and, where an SOW is in place, of that SOW.


AUP-2. Unlawful use

AUP-2.1 The Client will not use, and will not instruct or permit anyone else to use, a Deliverable, an Agency-operated account, or Agency Materials for any purpose that is unlawful in the jurisdiction where the use occurs or where its effects are felt, including the jurisdiction of any recipient, viewer, or data subject.

AUP-2.2 Agency is not the Client's lawyer and does not review deliverables for legal compliance before publication; see the MSA's "no legal advice" clause and AUP-4.4 below. This Policy names specific prohibited categories precisely because a general "comply with the law" clause is not enough protection for either party on its own.


AUP-3. Advertising and marketing claims

AUP-3.1 The Client will not instruct Agency to create, and will not itself publish, any advertising or marketing claim that is false, misleading, or deceptive, or that lacks a reasonable basis for substantiation at the time the claim is first disseminated. This mirrors the US FTC Act section 5 substantiation doctrine (substantiation must exist before dissemination, not be assembled afterward if challenged) and India's Consumer Protection Act 2019 section 2(47) definition of an unfair trade practice, both of which treat an unsubstantiated claim as unlawful regardless of whether it later turns out to be true.

AUP-3.2 The Client will not instruct Agency to write, buy, sell, or fabricate reviews or testimonials (including AI-generated reviews attributed to a non-existent person), buy followers, likes, views, shares, or comments, use an undisclosed personal or family relationship in an endorsement, or run a fake independent review site, mirroring the US FTC's rules on fake and manipulated reviews (16 C.F.R. Part 465).

AUP-3.3 Where a Deliverable involves an influencer or endorser, the Client is responsible for that person's disclosure of any material connection to the Client, and for approving any disclosure Agency applies to whitelisted or repurposed creative before it runs in paid placement.


AUP-4. Regulated-sector claims

AUP-4.1 Health, financial services, dietary supplements, gambling, and crypto-asset advertising carry a substantiation duty above the general standard in AUP-3, and heightened regulatory attention in every jurisdiction covered by this suite.

AUP-4.2 Before Agency creates any deliverable making a claim in one of these sectors (a health or efficacy claim, a financial return or earnings claim, a supplement claim, a gambling promotion, or a crypto-asset claim), the Client must provide the underlying substantiation in writing and sign off on the specific claim wording. Agency may refuse to proceed, or may pause work, until that sign-off is given.

AUP-4.3 The Client warrants that every claim it supplies or approves in these sectors is accurate, current, and substantiated, and indemnifies Agency for a third-party or regulatory claim arising from a breach of this warranty, as set out in the MSA's indemnity clause.

AUP-4.4 This Policy does not, and cannot, tell the Client whether a specific claim is lawful in a specific market; that determination requires the Client's own regulatory or legal advice. Agency's role is limited to refusing to publish a claim it reasonably believes is false, unsubstantiated, or unlawful, under AUP-16.


AUP-5. AI Output and Model Provider terms

AUP-5.1 The Client will not instruct Agency to use, and will not itself use, any AI Output in a way that breaches the terms of service of the Model Provider whose AI Tool produced it, including (without limitation) using AI Output for political campaigning, election-related content, or lobbying; directing an AI Tool to generate content for an audience the Model Provider's terms restrict to adults; or posting Client creative to a Model Provider's public community feed, contest, or showcase, which typically grants the Model Provider and other users promotional or remix rights over that material.

AUP-5.2 The current list of AI Tools and Model Providers in use changes and is maintained separately at quirksphereagency.com/ai-tools (or the internal equivalent); this Policy does not name a fixed list because doing so would go stale within a month of signature.

AUP-5.3 Agency may refuse a brief, or withdraw a delivered creative, that Agency reasonably believes would breach a Model Provider's terms, without that refusal or withdrawal being a breach of the MSA or the applicable SOW.


AUP-6. Provenance, watermarks, and disclosure integrity

AUP-6.1 The Client will not remove, suppress, obscure, alter, or instruct Agency to remove, suppress, obscure, or alter, any AI-generation label, watermark, C2PA or Content Credentials provenance signal, or other synthetic-content marking applied to a Deliverable, whether applied by Agency or by a Model Provider.

AUP-6.2 Agency's warranties and indemnities under the MSA and the AI Rider cease to apply to any Deliverable altered in breach of AUP-6.1. This mirrors the flow-down obligation several Model Providers impose on Agency directly (for example Higgsfield's terms prohibiting tampering with provenance markings) and India's IT (Intermediary Guidelines) Amendment Rules 2026 labelling regime.

AUP-6.3 Where a Deliverable is both AI-generated content and an advertisement under Indian law, the Client acknowledges both an SGI (synthetically generated information) label and any applicable advertising-disclosure label (for example an ASCI-style material-connection disclosure) may be required, and that one label does not substitute for the other.

AUP-6.4 For engagements reaching the European Union from 2 August 2026, the Client acknowledges that someone must carry the AI Act Article 50(4) deployer disclosure obligation for any deep-fake Deliverable, that the applicable SOW records who that is, and that the Client will not remove or disable a disclosure Agency applies for that purpose.


AUP-7. Deepfakes, likeness, and voice cloning

AUP-7.1 The Client will not supply, and will not instruct Agency to generate, any depiction of an identifiable real person's face, body, voice, or manner, whether by AI generation, voice cloning, or any other synthetic means, without first providing Agency a documented, written release from that person specific to the synthetic use. This applies equally to the Client's own founders, employees, and customers.

AUP-7.2 Without a documented written release meeting AUP-7.1, and regardless of any instruction the Client gives, Agency will not create:

  1. Synthetic intimate or sexualised imagery of any identifiable person. This is a criminal offence in the United States under the TAKE IT DOWN Act (47 U.S.C. section 223(h)) and prohibited outright, not merely subject to a labelling duty, under India's IT (Intermediary Guidelines) Amendment Rules 2026 (Rule 3(3)(a)(i) category).
  2. A synthetic endorsement, testimonial, or spokesperson appearance using a real, identifiable person's likeness or voice.
  3. A synthetic depiction presenting a real-world event as having occurred when it did not.
  4. A synthetic official document, certificate, or record.
  5. Any election, political campaign, or lobbying content generated or substantially assisted by an AI Tool.

AUP-7.3 AUP-7.2 is a scope exclusion, not a warranty subject to negotiation: Agency will decline any brief calling for it, without liability, and without prejudice to fees for work already performed on the balance of the engagement.


AUP-8. Impersonation

AUP-8.1 The Client will not use a Deliverable, or instruct Agency to create one, that impersonates a real person or organisation the Client does not represent, including by falsely suggesting affiliation, endorsement, or sponsorship.

AUP-8.2 This applies independently of AUP-7; an impersonation can occur through text, a brand mark, or a fabricated quote with no synthetic image or voice involved at all.


AUP-9. Marketing sent using our deliverables

AUP-9.1 The Client will not use a Deliverable, an Agency-operated account, or a list Agency sources or the Client supplies, to send commercial email, SMS, or make calls, that is unlawful in the jurisdiction of the recipient.

AUP-9.2 Plain statement of why Canada and Germany are hard: most jurisdictions in this suite's current or planned footprint (India, the United States) work on an opt-out model, where you can send until someone says stop. Canada and Germany do not. Canada's Anti-Spam Legislation requires the recipient's consent, express or narrowly implied, before the first message, and the sender carries the legal burden of proving that consent exists (CASL section 13); a third-party enrichment list (Apollo-style or similar) does not create implied consent under CASL, regardless of who compiled it. Germany's Act Against Unfair Competition requires prior express consent for email marketing to any recipient, business or consumer, with no B2B exemption (UWG section 7(2) no. 2); the same absence of a B2B exemption applies across the EU generally under the ePrivacy Directive. A list that is lawful to email in the United States or India is very likely unlawful to email in Canada or Germany without separate, documented opt-in consent.

AUP-9.3 The Client warrants, for any list it supplies to Agency, that it has a lawful basis to have that list used for the marketing Agency is instructed to send, including documented consent where the destination jurisdiction requires it, and indemnifies Agency for a claim arising from a breach of that warranty. Where Agency sources a list itself, AUP-10 governs.

AUP-9.4 Agency may refuse or amend any messaging copy, sending instruction, or list it reasonably believes would breach CAN-SPAM, the US TCPA or a state mini-TCPA, CASL, an EU or UK marketing-consent rule, or FTC Act section 5, without that refusal being a breach.

AUP-9.5 The Client will not instruct Agency to designate an exclusive opt-out channel, to spoof a sending domain or sender identity, to use a deceptive "Re:" or "Fwd:" style subject line, or to falsely claim personalisation where none exists.


AUP-10. Scraping and list acquisition

AUP-10.1 Where Agency sources a contact list or business data on the Client's behalf using an enrichment tool (Apollo-style or similar), the Client acknowledges that such tools generally state they have not provided notices or obtained consent on the user's behalf, and that Agency does not represent that any such list was lawfully collected under the data protection law of any recipient's jurisdiction.

AUP-10.2 The Client will not scrape, and will not instruct Agency to scrape, a website, app, or platform for contact or personal data without a documented lawful basis to do so, and will not combine or resell an enrichment vendor's data beyond what that vendor's own terms permit.

AUP-10.3 Agency structures cold-outbound work as campaign execution rather than as a data supply product for this reason: enrichment vendors typically restrict distributing or reselling the data they generate, and can require Agency to stop using it, including data already in the Client's hands, on a suspected breach.


AUP-11. Children's data and targeting minors

AUP-11.1 The Client will not use a Deliverable, or instruct Agency, to direct behavioural advertising, tracking, or targeted marketing at anyone under 18.

AUP-11.2 In India, this will become an absolute prohibition, with no advertising or marketing exemption, once section 9(3) of the Digital Personal Data Protection Act, 2023 comes into force. The commencement date is expected to be 13 or 14 May 2027; the gazette notification itself is internally inconsistent on the exact date, so this Policy deliberately does not hardcode one and instead ties the obligation to the date the provision actually commences.

AUP-11.3 In the United States, the Client warrants it will notify Agency in writing if any audience for a Deliverable is, or becomes, directed to children under 13 or is likely to attract them, so Agency can assess obligations under the Children's Online Privacy Protection Act. Behavioural advertising to a known or reasonably knowable under-18 audience is separately prohibited under state laws including Maryland's.

AUP-11.4 Agency will suspend third-party advertising and analytics tags on any property where Agency discovers under-13 users are present, pending the Client's written instruction, and will notify the Client of that discovery within 2 business days.


AUP-12. Malware, bots, click fraud, and platform manipulation

AUP-12.1 The Client will not use, and will not instruct Agency to use, malware, bots, click-fraud techniques, fake engagement, or any technique designed to manipulate an advertising platform's delivery, measurement, or ranking systems.

AUP-12.2 This includes the fabricated-engagement conduct already excluded under AUP-3.2 (fake followers, likes, views, shares, and comments) and extends it to any automated or deceptive interaction with an advertising or analytics platform, whether or not the interaction touches a public-facing review.


AUP-13. Agency Materials: no resale, sublicensing, or reverse engineering

AUP-13.1 Agency Materials, including Agency's pre-existing frameworks, boilerplate, component libraries, design systems, internal skills, prompt systems, generation pipelines, scripts, and know-how, are not part of the Deliverables assigned to the Client under the MSA. The Client receives the right to use Agency Materials only as embedded in a Deliverable it has accepted.

AUP-13.2 The Client will not resell, sublicense, distribute, or otherwise make Agency Materials available to a third party independent of an accepted Deliverable, and will not reverse-engineer, decompile, or attempt to extract Agency's prompts, prompt chains, or generation pipelines from a Deliverable or from Agency-operated tooling.


AUP-14. Security testing of our systems

AUP-14.1 Nobody, including the Client, its personnel, or a third party the Client engages, may conduct security testing, vulnerability scanning, or penetration testing of any system, account, or credential vault operated by Agency, without Agency's prior written authorisation naming the specific systems and testing window.

AUP-14.2 This clause governs Agency's own infrastructure. Penetration testing Agency performs on a Client's systems as a purchased service is governed by the separate SOW for that engagement, not by this clause.


AUP-15. Credentials

AUP-15.1 Neither party will disclose to the other any password, passphrase, API key, session token, or other authentication credential for any account. Access will be granted through each platform's delegated-access mechanism (for example, Meta Business Manager partner access, Google Ads MCC linking, a Shopify collaborator account, or a Vercel team invite) wherever the platform supports one.

AUP-15.2 Either party may refuse, and will promptly destroy, any credential disclosed to it in breach of AUP-15.1, and will notify the other party that this happened.

AUP-15.3 The Client will not use a credential or delegated access Agency provides for any purpose outside the engagement it was granted for, will not share it with anyone not named in the applicable SOW's personnel list, and will revoke Agency's access within 5 working days of the engagement ending. Agency will revoke a departing team member's access within the same period.


AUP-16. Consequences

AUP-16.1 On a breach, or a reasonably suspected breach, of this Policy, Agency may, without that action being a breach of the MSA or the applicable SOW:

  1. Suspend the specific Deliverable, account access, or activity affected, with notice to the Client where practicable;
  2. Refuse to create, or withdraw, a specific creative or piece of copy under AUP-3, AUP-4, AUP-7, or AUP-9;
  3. Terminate the affected SOW, or the MSA, on written notice, where the breach is serious, repeated, or not cured within a reasonable period after notice.

AUP-16.2 Where a breach of this Policy causes Agency loss, including a third-party claim, a regulatory fine, or an upstream Model Provider or platform sanction, the Client indemnifies Agency for that loss on the terms set out in the MSA's indemnity clause.

AUP-16.3 Agency's confidentiality obligations to the Client do not override, and are expressly subject to, any legal duty Agency has to report an incident to a regulator, including its duty to report a cyber incident to India's CERT-In within 6 hours of the incident under the CERT-In Directions of 28 April 2022. This is not something the Client can contract Agency out of, and this Policy does not create that impression.


AUP-17. What we will refuse to do

A short list, for use in sales conversations, of what a client cannot buy from us regardless of budget or urgency:

  1. Synthetic intimate or sexualised imagery of an identifiable person.
  2. A synthetic endorsement, testimonial, or spokesperson using a real person's face or voice without their own signed release.
  3. Fabricated reviews, testimonials, followers, likes, views, shares, or comments, or a fake independent review site.
  4. Advertising targeted at, or behavioural tracking of, children or anyone under 18.
  5. Election, political campaign, or lobbying content.
  6. Cold email or SMS sent into Germany, Austria, Italy, or Spain (and, pending confirmation, the Netherlands, Belgium, and Poland) without a separately scoped, opt-in-consent-based engagement; see AUP-9.2.
  7. Removal of an AI-generation label, watermark, or provenance marking from a deliverable.
  8. Any claim in a regulated sector (health, financial, supplements, gambling, crypto) without the Client's prior written substantiation and sign-off.
  9. Security testing of Agency's own systems without prior written authorisation.
  10. Guaranteed return-on-ad-spend, ranking, conversion, or revenue figures as a contract term.

AUP-18. Amendment

Agency may update this Policy on notice to the Client, effective for new engagements from the notice date and for existing engagements from [30] days after notice, except that a change narrowing what is prohibited requires the Client's written agreement to take effect for an in-progress SOW.

Cookie settings

We use cookies to run the site and, only with your permission, to measure traffic and ad performance. Read our Cookie Policy for detail.