- Build what you like, as long as it is lawful, honest and does not harm other people.
- Do not use Florgin to generate malware, run scams, impersonate people, or produce material that sexualises children.
- Never put real patient records, card numbers or government ID data into Florgin. Build against test data and connect the real source yourself.
- Do not attack the platform, resell it as your own, or use it to train a competing model.
- Report abuse to us and we will investigate.
1. Scope
This Acceptable Use Policy applies to everything you do with Florgin: the prompts you submit, the products you generate, the content you host, and anything you deploy or distribute using the Services. It applies to you and to everyone in your workspace. Breaching it is a material breach of the User Agreement.
The examples below are illustrative, not exhaustive. If something is clearly harmful but not listed, assume it is not permitted.
2. Prohibited content and purposes
You may not use the Services to create, host, distribute or facilitate:
- Child sexual abuse material, or any content that sexualises a minor. We report this to the relevant authorities without notice to the account holder.
- Content that promotes, incites or facilitates terrorism, violent extremism, or violence against a person or group.
- Harassment, stalking, doxxing, threats, or targeted abuse of an individual.
- Content that promotes self-harm, suicide or disordered eating.
- Non-consensual intimate imagery, or sexual content depicting a real person without their consent.
- Content that unlawfully discriminates against, or incites hatred towards, a person or group on the basis of a protected characteristic.
- Material that infringes copyright, trademark, patent, trade secret, publicity or privacy rights.
- Content that is defamatory, or that you know to be false and that is likely to cause harm.
3. Prohibited conduct
You may not use the Services to:
- Develop, distribute or operate malware, ransomware, spyware, keyloggers, credential harvesters, botnets or other malicious code.
- Build phishing sites, fake login pages, or anything designed to obtain credentials, payment details or personal information under false pretences.
- Run fraudulent schemes, including fake stores, deceptive subscription traps, investment fraud, pyramid or Ponzi structures, or fake reviews and testimonials.
- Impersonate a real person, company, government body or brand, or create fabricated records, receipts, credentials or documents presented as genuine.
- Send unsolicited bulk messages, spam, or bulk automated outreach in breach of anti-spam law.
- Conduct unauthorised security testing, scanning, penetration testing or denial-of-service activity against systems you do not own or have written permission to test.
- Circumvent authentication, paywalls, DRM, rate limits or access controls of any system, including ours.
- Scrape or harvest personal data at scale, or build facial recognition or biometric identification databases from scraped material.
- Operate high-risk applications — medical diagnosis or treatment, legal or financial advice presented as professional advice, critical infrastructure control, weapons systems, or automated decisions with legal or similarly significant effects on people — without qualified human review and any licence the law requires.
- Violate export control, sanctions, anti-money-laundering or other applicable trade laws.
4. Data you must not submit
Florgin is a general-purpose software generation tool. It is not certified, audited or contractually structured to handle regulated data. Your Input is stored in your project history and sent to third-party model providers so that a build can run, which means anything you paste into a prompt leaves systems we alone control. You must not submit the categories below, and you must not use the Services to store, process or transmit them.
- Protected health information, or any individually identifiable health, medical, mental health, prescription or insurance claim data — including patient records, clinical notes, diagnoses, test results and appointment histories.
- Special category data under Article 9 of the EU or UK GDPR: health, genetic data, biometric data used to identify a person, sex life or sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership.
- Full payment card numbers, card verification values, magnetic stripe or chip data, or any other cardholder data governed by PCI DSS.
- Government-issued identifiers, including national identity, social security, passport, driving licence and tax identification numbers.
- Financial account numbers together with their access credentials, and consumer report data governed by the Fair Credit Reporting Act or an equivalent credit reporting law.
- Personal information of children below the age of digital consent, where it is subject to COPPA or an equivalent children's privacy law.
- Classified, export-controlled or otherwise government-restricted material, including material subject to ITAR or the EAR.
- Credentials belonging to another person, and any data you do not have the right to disclose to us.
We check for part of this automatically. Payment card numbers and national identity numbers can be recognised from their check digits, and text containing one is refused at submission — before it is stored in your project history and before it is sent to a model provider. The check is a pattern match on the text you submit, not a review of your content: no person reads it, and nothing is kept from a refused submission. It catches the common cases, not every case, so keeping regulated data out of the Services remains your responsibility rather than ours.
If regulated data reaches the Services in breach of this section, you remain its controller and are responsible for the consequences, including any notification your own regulator requires. Tell us as soon as you become aware. We may remove the affected content, project or account without notice, and removal may take surrounding project content with it. We cannot confirm erasure of data that has already been transmitted to a third-party provider on your instruction.
5. Protecting the platform
You may not:
- Attempt to gain unauthorised access to the Services, other workspaces, or any account that is not yours.
- Interfere with, overload or disrupt the Services or the infrastructure they run on.
- Circumvent usage limits, quotas or billing, including by creating multiple accounts to obtain additional free capacity.
- Resell, sublicense or provide the Services to a third party as a standalone offering, or operate a competing code-generation product on top of them.
- Use Output or the Services to train, fine-tune or evaluate a competing foundation model or code-generation system.
- Scrape, crawl or bulk-extract the Services, or use automated means to access them other than through documented interfaces.
- Probe model safety systems in an attempt to make them produce content this Policy prohibits.
- Remove, obscure or alter any proprietary notice, or misrepresent the origin of Output.
6. Responsibility for what you deploy
If you deploy a product built with Florgin and it serves other people, you are the operator of that product. You are responsible for reviewing the code before it goes live, for its security, for the accuracy of what it tells your users, for its own privacy notice and legal terms, and for complying with the law wherever your users are.
Automatically generated code can contain security defects. Review authentication, authorisation, input validation, secret handling and data exposure before you put anything into production. Florgin's automated verification gates reduce risk; they do not replace your review.
7. How we enforce this Policy
We investigate credible reports and signals of abuse. Depending on severity, we may: ask you to fix the problem; remove or disable specific content; block a build; restrict a feature; suspend the account; terminate the account; or report the matter to law enforcement.
Where practical and lawful, we tell you what happened and give you a chance to respond before we act, and we aim to take the least restrictive measure that resolves the problem. We act immediately and without notice where there is a risk of serious harm, legal liability, or where notice would prejudice an investigation.
If you believe we acted in error, reply to the enforcement notice or email 1florginai@gmail.com within 30 days. A different reviewer will look at the decision, and we will respond in writing.
8. Reporting abuse
- Abuse and policy violations: 1florginai@gmail.com
- Security vulnerabilities: 1florginai@gmail.com — we will not pursue legal action against good-faith research that respects user privacy and does not degrade the service.
- Copyright complaints: 1florginai@gmail.com
- Everything else: 1florginai@gmail.com
Please include a link or identifier, a description of the problem, and how to reproduce it. We acknowledge reports within 2 business days.
This document is published in English. Any translation provided for convenience is not an official version, and the English text controls except where mandatory local law requires otherwise.