Legal

Acceptable Use Policy

What you must not connect to Brain, and what you must not do with it. Forms part of the Terms of Service.

Effective Version 1.0

This policy forms part of the Terms of Service. Breaking it is grounds for suspension.

1. Content you must not connect

Do not point Brain at sources containing:

  • Credentials, private keys, API tokens or other secrets.
  • Special category personal data under UK GDPR — health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation.
  • Children's personal data.
  • Payment card data, or data subject to PCI DSS.
  • Material subject to legal privilege, or under a confidentiality obligation that forbids processing by a third party.
  • Content you are not entitled to share with a third-party language model provider outside the UK.

Brain does not automatically redact personal data before sending content for processing. This list is not a filter we enforce — it is a boundary you must respect. See the Privacy Policy.

2. Things you must not do

  • Use Brain unlawfully, or to infringe anyone's rights.
  • Attempt to access another workspace's data, or probe, scan or test our systems except as permitted by our security disclosure process.
  • Reverse engineer, decompile or attempt to extract the platform's source, or use Brain to build a competing product.
  • Circumvent access controls, rate limits or quotas.
  • Resell or provide Brain to a third party as a service without our written agreement.
  • Misrepresent generated Skills as human-authored guidance where accuracy is safety-critical.

3. Agent and MCP access

Workspace access tokens grant an agent the ability to read your Skills and to write observations back into your workspace, which feed later distillation runs. You are responsible for what agents holding your tokens do.

  • Do not share workspace tokens outside your organisation, or embed them in client-side code or public repositories.
  • Do not use automated capture to write bulk, synthetic or junk content — it degrades your own Skills and consumes model capacity.
  • Do not use Brain's interfaces in a way that places disproportionate load on the platform. There are no hard rate limits on capture today; we ask you not to make them necessary.

If a token is exposed, revoke it in the console and tell us at hello@brayn.tech.

4. Reporting

Report abuse or a suspected compromise to hello@brayn.tech.

5. Enforcement

We may suspend or terminate a workspace that breaches this policy. Where the breach is not serious or unlawful, we will give notice and an opportunity to fix it first.