Flatrouter

Acceptable Use Policy

Version v0.1Last updated August 25, 2026Effective August 25, 2026

This policy sets out what Flatrouter may and may not be used for. By using Flatrouter you agree to follow it, along with the terms of service, the privacy policy, and the policies of the upstream models and providers your requests pass through.

01

Permitted use

So long as you stay within the law, the terms of service, and upstream policy, you may use Flatrouter to:

  • build, test, and run lawful software, websites, and automation;
  • generate, summarise, translate, classify, assist with code, and analyse data;
  • evaluate models, build prototypes, and do internal productivity work;
  • add AI features to your own lawful product, within the resale and key-management rules below.

02

Prohibited unlawful and harmful use

You must not use Flatrouter to:

  • break any applicable law, regulation, court order, or regulatory requirement;
  • commit fraud, theft, extortion, money laundering, phishing, or identity impersonation;
  • create or distribute malware, trojans, ransomware, or attack code;
  • scan, break into, damage, or interfere with systems, networks, or accounts without authorisation;
  • send spam, bulk harassment, malicious marketing, or unsolicited automated messages;
  • infringe copyright, trademarks, trade secrets, privacy rights, or other third-party rights;
  • generate or spread explicit threats, incitement to violence, or hateful content targeting protected groups;
  • deceptively manipulate elections, financial markets, public services, or other critical systems.

03

Personal and sensitive data

Unless you have sufficient authorisation, a lawful basis, and the necessary safeguards, you must not submit or process:

  • another person's passwords, private keys, full API keys, or payment credentials;
  • identity documents, card numbers, CVVs, or account passwords;
  • unauthorised health, financial, biometric, or precise location data;
  • sensitive information about minors;
  • customer, employee, or third-party data you have no right to process.

Flatrouter is not a dedicated medical, financial, identity verification, or high-risk decision system. You must not rely on model output alone to make medical, credit, insurance, hiring, education, housing, legal, or other high-impact decisions about a person.

04

Accounts, API keys, and access control

You must not:

  • share, sell, rent, or publicly post a Flatrouter account or API key;
  • register accounts in bulk, create false identities, or use someone else's payment method;
  • use proxies, VPNs, device rotation, or any other means to evade risk controls, regional limits, rate limits, or account limits;
  • reverse-engineer, crack, or bypass the authentication, billing, rate-limiting, or security mechanisms of Flatrouter;
  • probe, stuff credentials against, or otherwise attempt other people's accounts and keys through automation;
  • run Flatrouter as a shared key pool, a credential marketplace, or an anonymous forwarding service.

05

Upstream provider policies

Flatrouter requests may pass through third-party models, cloud platforms, or API providers. You must also follow the upstream policies that apply to the model, account, region, and request content you chose.

You must not use Flatrouter to:

  • evade an upstream provider’s safety policy, content limits, or account limits;
  • get around quota, payment, or review requirements through multiple accounts, account pools, or route switching;
  • mislead an upstream provider, fabricate company information, or submit false documentation;
  • use suspended, stolen, or unauthorised upstream credentials.

06

Resale and embedded use

You may use Flatrouter inside your own lawful product, provided you:

  • apply appropriate account, usage, and abuse controls to your end users;
  • never expose a Flatrouter or upstream API key to an end user;
  • never claim to be an official agent of Flatrouter, NovaSpan LLC, or an upstream provider;
  • never run Flatrouter as an unauthorised public shared relay;
  • give your end users the applicable privacy and data handling information;
  • follow any additional written commercial agreement.

Without written authorisation from NovaSpan LLC, you must not sell Flatrouter accounts, credit, keys, or access under your own brand.

07

Monitoring and enforcement

To protect the service and its users, we may monitor usage, request metadata, errors, anomalous behaviour, and security signals. We do not undertake to review every request by hand, nor to give notice before acting.

Where we reasonably believe there is a violation, fraud, an attack, a credential leak, a payment risk, or an upstream policy risk, we may:

  • limit rates, models, regions, or quota;
  • suspend or revoke an API key;
  • suspend an account or freeze the related balance;
  • remove unlawful or clearly infringing content;
  • disclose what is necessary to the affected providers or to law enforcement;
  • take other measures to protect users, the platform, or the public.

08

Reporting a violation

If you find account abuse, a leaked key, an attack, fraud, or any other breach of this policy, contact hello@flatrouter.com, ideally with the subject Abuse Report or Security Report.

Please do not include a full API key, a password, a private key, or a payment credential in the email.

09

Changes to this policy

We may update this policy as the law, upstream policies, product features, and security risks change. The updated version is published on this site with a new update date.