Brylee Acceptable Use Policy
Version: v0.6 Effective date: October 6, 2026 Part of: the Brylee Terms of Service
1. Who this applies to
This policy applies to everyone who uses Brylee, every user in every workspace, whether you use Brylee for a business or for yourself. You must be at least 18 years old to use Brylee. If you own a workspace, you are also responsible for making sure the people you invite into it follow this policy.
2. The basics: lawful use
Don't use Brylee to:
- violate any law or regulation, or help anyone else do so;
- infringe anyone's intellectual property, privacy, or other rights;
- store or distribute malware, or phish, defraud, deceive, or harass anyone;
- process data you don't have the right to process.
3. Prohibited data
- No protected health information (PHI). Brylee is not HIPAA compliant and does not sign BAAs. Do not store or process PHI, or any data that would make Brisco a "business associate" under HIPAA. This includes collecting health information through your Brylee forms.
- No data whose processing would be illegal for you or for us.
- Use good judgment with other high-sensitivity data (government IDs, full financial account numbers). Brylee encrypts stored data, but our compliance posture is stated honestly in the Terms (no SOC 2 certification yet). Decide with open eyes what belongs here.
4. Messaging and anti-spam
Brylee automations send email and messages through your own connected accounts (for example, your own Gmail), not from Brylee's addresses. That means:
- You must comply with the laws that apply to your messages (such as CAN-SPAM and, where applicable, telemarketing/texting laws like the TCPA) and with the terms of the service you send through.
- Only send to people who have a real relationship with you or have agreed to hear from you. No purchased lists, no unsolicited bulk messaging, no misleading senders or subject lines.
- Brylee is an automation tool, not a bulk-mailing service. If your goal is mass cold outreach, Brylee is the wrong tool, and using it that way violates this policy.
5. Connectors, credentials, and other people's systems
- Only use credentials you're authorized to use. Connect only accounts and API keys that belong to you or your business, or that you have explicit permission to use.
- Only point Brylee at systems you're authorized to access. When you supply an API specification or a destination hostname, you are telling us you have the right to use that API and access that system. Don't use Brylee to probe, scrape, or extract data from systems you don't have permission to access, or in violation of the API provider's terms.
- No impersonation. Don't submit connectors that use another company's name or branding to point somewhere that company doesn't control. (Brylee automatically refuses connectors that collide with apps it already supports but point elsewhere. Don't try to get around this.)
- No capture-and-exfiltrate destinations. Don't direct connectors or credentials at request-capture, tunnel, or throwaway shared-hosting endpoints to intercept traffic or harvest keys. Brylee routes suspicious destination types to staff review; attempting to evade that review violates this policy.
- Don't use Brylee to launder access, for example, using a connector to fetch data on behalf of someone who is not entitled to it.
6. Platform integrity
Don't:
- probe, scan, or test the vulnerability of the Service without our prior written permission;
- attempt to access another customer's workspace or data, or test the boundaries of tenant isolation. If you find a security issue, report it to us at support@bryleeai.com and we will thank you for it;
- interfere with the Service, evade rate limits or plan limits (including by creating multiple free workspaces to dodge them), or impose unreasonable load;
- resell, white-label, or offer the Service to third parties as a service bureau without a written agreement with us;
- copy the Service or use access to it to build a lookalike product using our non-public information;
- use another person's account or share credentials to evade per-user or per-workspace limits.
7. AI features
Don't use Brylee's AI features to:
- generate or spread content that is illegal, or that is designed to deceive (impersonation of real people or organizations, fraud, disinformation);
- attempt to extract other customers' data, Brylee's internal prompts or credentials, or otherwise bypass the assistant's safety and permission boundaries;
- produce output you then present as professional advice (legal, medical, financial) without a qualified human reviewing it.
8. High-stakes use
Brylee has no SLA today (see the Terms, Section 12). Do not use it for anything where a delay, outage, or automation error could endanger life, health, or safety, for example emergency dispatch, medical devices, or safety-critical industrial control.
9. How we enforce this
- We may investigate suspected violations and may remove or disable the offending Task, connector, form, or content.
- We may refuse, disable, or remove any user-submitted connector at any time (see the Terms, Section 8.3), and certain connector destinations always go to staff review.
- For serious or repeated violations, or where required by law or to protect other customers, we may suspend or terminate workspaces or accounts, following the process in the Terms, Section 13. Where practical and lawful, we'll warn you first and give you a chance to fix it.
- We may report unlawful activity to law enforcement where appropriate.
10. Reporting abuse
If you see spam, fraud, or abuse involving Brylee, or believe a Brylee-built form or automation is being used against you, report it to support@bryleeai.com.
11. Changes
We may update this policy as the product and the world evolve. Material changes will be announced the same way as changes to the Terms.