Acceptable Use Policy
What you can and can't do with the Rōmy Service
This Acceptable Use Policy ("AUP") sets out what you can and can't do with the Rōmy Service. It is part of our Terms of Service. Violations may result in suspension, termination, and legal action.
1. You must not use the Service to
1.1 Break the law
- Violate any applicable law or regulation, including privacy, consumer-protection, anti-discrimination, anti-spam (e.g. CAN-SPAM, CASL, GDPR e-privacy), or sanctions law (e.g. OFAC).
- Process personal data without a lawful basis under applicable privacy law.
- Infringe intellectual property, trade secret, publicity, or contractual rights.
1.2 Process restricted data
You agree not to upload to or process via the Service:
- Protected Health Information (PHI) under HIPAA. We are not a Business Associate and do not sign BAAs.
- Payment card data (PAN, CVV/CVC, full track data, PIN). Use our billing processor's hosted forms only.
- Government identifiers (SSN, passport, driver's licence) unless explicitly required by a feature.
- Children's data (data about individuals under 16 as a research subject).
- Special-category data under GDPR Art. 9 unless you have explicit lawful basis and notify us in advance.
- Information obtained unlawfully (e.g., via account takeover, scraped behind logins, leaked data, breached databases).
1.3 Harm individuals
- Harass, stalk, or surveil specific individuals.
- Use the Service to target individuals based on protected characteristics (race, ethnicity, religion, sexual orientation, gender identity, disability, etc.) for unlawful discrimination.
- Profile individuals in connection with credit, insurance, employment, housing, or other decisions covered by FCRA, ECOA, FHA, or equivalent laws — Rōmy is not a consumer reporting agency and outputs may not be used for these purposes.
- Use Rōmy outputs as the sole basis for any decision producing legal or similarly significant effects on a person.
1.4 Abuse the infrastructure
- Reverse-engineer, decompile, or attempt to extract our models or training data.
- Bypass rate limits, authentication, throttling, or access controls.
- Send spam, junk, phishing, or malicious content via the Service.
- Distribute malware, ransomware, or other harmful code.
- Conduct security testing, penetration testing, or vulnerability scanning without prior written permission (see §3 Vulnerability disclosure).
- Interfere with other users' use of the Service or with the Service itself.
- Create fake accounts, evade bans, or impersonate others.
- Resell, redistribute, or operate the Service as an unauthorised third-party service.
1.5 Misuse AI outputs
- Present AI-generated outputs as verified facts without independent review.
- Train competing AI models on Rōmy outputs.
- Use Rōmy to generate disinformation, deepfakes, fraudulent communications, or content designed to deceive.
2. Specific to prospect research
The Service is intended for lawful donor research by nonprofit organisations and authorised fundraising professionals.
You agree to:
- Have a lawful basis (typically legitimate interests under GDPR, or equivalent under US state privacy laws) for researching each Prospect.
- Provide any required transparency notice to data subjects under your jurisdiction.
- Honour data-subject rights requests (access, erasure, objection) when contacted, with our reasonable assistance.
- Apply data-minimisation: only research individuals you reasonably believe may be relevant donors for your specific cause; no speculative mass-profiling.
- Not use Prospect data for purposes other than donor cultivation by your organisation, unless you have a separate lawful basis and notice.
- Not share Prospect outputs publicly or with third parties except in confidence and under equivalent obligations.
3. Vulnerability disclosure
We welcome good-faith security research. If you find a vulnerability, email solomon@getromy.app with details and reproduction steps before disclosing publicly. Do not:
- Access or modify data that is not yours
- Disrupt the Service for other users
- Demand payment as a condition of disclosure
We will acknowledge receipt within 5 business days and aim to remediate within 90 days. We do not currently run a paid bug bounty.
4. Reporting abuse
If you believe someone is misusing the Service, email howard@getromy.app. Include URLs, account identifiers if known, and a description.
If you believe a Rōmy-generated profile contains material errors about you, email howard@getromy.app.
5. Enforcement
We may at our discretion investigate suspected violations. Enforcement may include:
- Warning
- Removing the offending content
- Suspending the account
- Terminating the account
- Reporting to authorities
We may take action without notice for severe violations, including upload of Restricted Data, fraud, or threats to other users.
6. Changes
We may update this AUP from time to time. The current version is always the one published at intel.getromy.app/aup.
Published at intel.getromy.app/aup.