Winthos AI

ACCOUNT POLICY

Acceptable Use Policy

Draft dated September 24, 2026. This policy requires legal and security review before account registration, subscriptions, or API access begin.

The Winthos website does not yet issue API keys or run hosted models. When those features launch, the account flow must present this policy and obtain explicit acceptance with the final Terms before access begins.

1. Follow the law and respect others

Do not use Winthos to violate applicable law, infringe rights, harass or threaten people, exploit minors, distribute nonconsensual intimate material, commit fraud, or process information you have no right to use. Do not misrepresent AI output as a verified professional judgment or conceal material AI involvement where disclosure is required.

2. Authorized cybersecurity work only

Security analysis, vulnerability research, and penetration testing are allowed only for systems you own or have explicit permission to test. Stay within written scope, time limits, and rules of engagement. Do not use Winthos for unauthorized access, credential theft, persistence, malware deployment, ransomware, destructive exploitation, evasion, denial of service, or exfiltration of data. Do not target third parties because a model suggested doing so.

3. Review code and operational changes

Test generated code, scripts, configuration, and security recommendations in an appropriate environment before deployment. A qualified person must review changes that affect production systems, privacy, safety, financial outcomes, or other consequential interests. Maintain backups and rollback procedures. You remain responsible for deployments and the effects of your instructions.

4. Health, legal, and emergency boundaries

Do not use model output as the sole basis for diagnosis, treatment, legal strategy, emergency action, or decisions that significantly affect a person. Seek qualified professional review and follow applicable professional obligations. Do not submit protected health information, client confidences, or other sensitive data to a hosted service until its final privacy and data-processing terms support that use.

5. Accounts, keys, and service integrity

Do not share, resell, publish, or expose API keys. Do not bypass quotas, billing, access controls, or safety measures, or attempt to disrupt the service. Use reasonable controls to prevent unauthorized use of your account. Report suspected compromise and revoke affected keys promptly. Automated use must respect published rate and usage limits.

6. Enforcement and reporting

We may investigate credible abuse reports and limit, suspend, or terminate access for a material violation, suspected compromise, or urgent risk, subject to applicable law and the final Terms. When reasonable, we will provide notice and an opportunity to correct a non-urgent issue. We may preserve records or report conduct when required by law. The final service launch must provide a contact route for abuse reports and appeals.

Read the Terms and liability limits ยท Return to Winthos AI