Acceptable Use Policy

Effective

1. Who this policy applies to

1.1 This policy is issued by DeepRed LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States. It applies to everyone who uses DeepRed Connect, the Connect API, the developer console, the CLI, the MCP server or Creator Studio ("you"). Tenants also answer for their users, staff, contractors and anyone they share Platform Data with.

1.2 Capitalised words have the meanings in the API Terms.

2. General rules

You must not use the Service to:

2.1 break any law, including privacy, consumer-protection, anti-spam, intellectual-property, sanctions and export laws;

2.2 collect data about people who have not personally connected their own account through Connect, or look up, search for or monitor accounts that aren't connected. The proxy blocks lookup and search endpoints for this reason;

2.3 ask anyone for a platform password, or log in to a platform as someone else;

2.4 scrape platforms, call private or undocumented platform endpoints, or get around any platform's rate limits, quotas, reviews, account-type restrictions or bans;

2.5 rotate keys, accounts, IP addresses or apps to get around our limits or a platform's;

2.6 buy, sell or exchange followers, likes, comments, views or other engagement, or pay people to engage;

2.7 send spam, or automate likes, follows, reposts, replies, mentions or direct messages;

2.8 publish anything on a creator's account that the creator hasn't seen and expressly approved;

2.9 publish content that infringes rights, is illegal or breaks a platform's rules, or add your own branding or watermark to content posted to TikTok;

2.10 probe, scan or test the Service's security without our written permission (use the disclosure route at https://connect.deepred.app/security), or reach another Tenant's or user's data;

2.11 misrepresent who you are, or imply that any platform endorses, sponsors or partners with you or with us;

2.12 build or use anything that monitors or benchmarks a platform's availability, performance or usage.

3. Prohibited uses of platform data (all platforms)

You must not use Platform Data, or anything derived from it:

3.1 to make eligibility decisions about anyone, including for housing, employment, insurance, education, credit, lending, government benefits or immigration status;

3.2 to discriminate against people based on race, ethnicity, colour, national origin, religion, age, sex, sexual orientation, gender identity, family status, disability, medical or genetic condition, or any other protected attribute;

3.3 for surveillance, intelligence gathering, law-enforcement or national-security purposes, background checks or vetting, to monitor protests, rallies or other sensitive events, or to track individuals;

3.4 to sell, license, rent or buy it, or give it to data brokers, information resellers or advertising networks, or to a country of concern or covered person under 28 CFR part 202;

3.5 to build or enrich profiles of people without their valid consent, or to build databases of creators or other people across Connections or Tenants, including for creator discovery, ranking or matching;

3.6 to target, segment, profile or draw inferences about individuals by sensitive characteristics (health, financial hardship, politics, race or ethnicity, religion, sex life or orientation, union membership, alleged crimes);

3.7 to re-identify anonymised or aggregated data;

3.8 to serve or target advertising outside the platform the data came from, or to train or fine-tune AI models;

3.9 for anything other than the Approved Use Cases listed in the console for that platform (managed mode) or your own platform-approved use case (BYOA mode);

3.10 to collect data from children under 13, or sensitive data the platform's terms don't allow.

4. Platform display and sharing rules (Tenants)

4.1 One creator at a time. Keep each Connection's data separate. Show it only to the creator it belongs to, and to others only where §4.2 to §4.8 and the Distribution Policy allow.

4.2 Meta. Use each permission's data only for Meta's allowed usage. Show Threads posts, insights and replies only to the creator who made them. Don't use Instagram data just to display, import or back up content. Make sure Page managers accept Meta's Terms of Service, including Meta's Advertising Standards, and never reveal a Page's administrators. Managed-mode Tenants receive opaque IDs, never Meta user IDs or tokens.

4.3 YouTube. Show YouTube data obtained with a creator's authorisation only to that creator or to agents the creator expressly approved. Show YouTube branding wherever you display YouTube content. Don't aggregate YouTube data across different content owners, and don't build rankings, leaderboards or benchmarks across creators from it. Don't create derived YouTube metrics (scores, estimates, embeddings); simple arithmetic on one channel's API figures is allowed. Label any non-YouTube figure shown next to YouTube figures as yours. If your users use YouTube features, your terms must bind them to the YouTube Terms of Service. Don't re-offer YouTube data or functionality through any API, CLI, MCP tool or feed.

4.4 TikTok. Make TikTok data available only to the creator it relates to, for their personal use. Don't share it with brands, agencies or other users, don't redistribute or syndicate it, and don't use it for creator discovery or ranking. Don't download TikTok videos or images.

4.5 X. If you pass X data to anyone, pass only Post IDs, Direct Message IDs and User IDs. Give no entity more than 1,500,000 Post IDs in any 30 days, and no person more than 500 public Post or User objects a day, and only by non-automated means. Recipients must first accept X's Terms of Service, Privacy Policy, Developer Agreement and Developer Policy, and sign data-protection terms at least as protective as X's. Don't make X data available to government users without our written approval.

4.6 Google Limited Use. Use Google API data, YouTube included, only for user-facing features prominent in your app. Let people read it only with the user's affirmative agreement, or for security or legal reasons.

4.7 Bluesky (if opened). Follow the Bluesky Developer Guidelines in your own app, honour logged-out visibility settings, and stop showing deleted or moderated content within 24 hours.

4.8 LinkedIn, Twitch, Pinterest, Snapchat and income sources. Closed to Tenants until the Distribution Policy says otherwise. When one opens, its rules are added to API Terms Schedule 1 first.

5. Keeping data current and deleting it (Tenants)

5.1 Act on every Deletion Event by the earlier of deletion_required_by and the deadline in API Terms S1.11. In short: X within 24 hours; YouTube within 7 calendar days; Meta and every other platform within 24 hours; everything within 30 days of your account ending, or sooner where S1.11 says so.

5.2 Refresh or delete YouTube data other than analytics at least every 30 days. Keep YouTube data fetched without the creator's authorisation for 30 days at most.

5.3 Update or delete stored X content within 24 hours when it changes, becomes protected or is deleted on X.

5.4 Delete from every copy: databases, caches, search indexes, analytics stores, exports, logs, derived data and your recipients' systems. Backups must expire within 35 days, or sooner where the platform requires, and must not be restored for use without re-applying deletions.

5.5 Keep a record of when you deleted data for each Deletion Event.

6. Publishing (Tenants and Creator Studio users)

6.1 Publish only content the creator has seen and expressly confirmed, to the account and at the time they confirmed. Send the consent object with each API publish request.

6.2 YouTube and TikTok posts, and any post requested through the MCP server, are confirmed on our hosted screen. Don't bypass it.

6.3 Don't set or change a video's privacy setting without the creator's instruction.

6.4 Don't run AI auto-reply bots or automated engagement on any platform.

6.5 Disclose paid partnerships and branded content where the platform requires it.

7. Children and minimum age

7.1 Don't use the Service to connect accounts of people below the minimum creator age in our Terms (18, or the age of majority where the creator lives if that is higher), or below the platform's own minimum age.

7.2 Don't direct your use of the Service at children. If you learn that a connected creator is below the minimum age, disconnect them through the API at once.

8. Security

8.1 Keep API keys secret and out of client-side code. Rotate them if exposed.

8.2 Verify our webhook signatures before acting on them.

8.3 Tell us immediately, and in any case within 24 hours, at security@deepred.app, about any unauthorised access to Platform Data you received from us.

9. How we enforce this policy

9.1 We monitor use of the Service for abuse: request patterns, Distribution Policy blocks, publishing volumes, deletion-event handling and platform complaints.

9.2 We may audit your compliance (API Terms §13). Platforms may audit us, and you will help us answer them.

9.3 If we believe you have broken this policy, we may act at once and without prior notice where the risk requires it: block a request, pause publishing, suspend an API key, a platform, a mode or your whole account, require you to delete data and certify deletion, and end your agreement (API Terms §14, §15). If a platform asks us to cut off your access, we will.

9.4 We may report illegal activity to the authorities and tell a platform about breaches of its terms.

10. Reporting abuse

Report suspected abuse to support@deepred.app with "Report" in the subject line. Report security issues as described at https://connect.deepred.app/security.