Acceptable Use Policy
Version 2.0 · Effective August 2, 2026
This Acceptable Use Policy sets out what you may not do on Veloris (the “Platform”). It forms part of the Terms of Service, and breaching it is a breach of those Terms.
The list is specific rather than general on purpose. A policy that says only “do not misuse the service” gives nobody — user or reviewer — a usable standard.
1. Account integrity and credential fraud
Access to this Platform is gated on being a verified medical professional. You must not:
- submit false, altered or forged credential documents, or credentials belonging to another person;
- misrepresent your identity, qualifications, institution, licence status, or date of birth;
- share your account credentials, or let anyone else use your account — including colleagues, classmates and study groups;
- sell, rent, lend or otherwise transfer access to your account, or pool a subscription among several people;
- create multiple accounts to extend free-tier limits, evade a suspension, or obtain a second verification decision;
- register on behalf of someone else without our written agreement.
Credential fraud and account sharing are treated as the most serious breaches of this policy. They are not billing irregularities: verification exists so that clinically detailed content is only available to people trained to interpret it, and sharing an account hands that access to someone who was never verified.
2. Clinical misuse
You must not:
- submit information about a real, identifiable patient in any form;
- use the Platform for diagnosis, treatment planning, prescribing, triage or any other clinical decision, for any real person including yourself;
- use the Platform, or any output from it, within a clinical workflow or at the point of care;
- present output as clinically validated, or as reviewed or endorsed by us or by any clinician.
The Medical Disclaimer explains why these boundaries exist.
3. Bypassing safety mechanisms
You must not attempt to defeat any protection on the Platform, including by:
- circumventing or attempting to circumvent the AI safety classifier — by rephrasing a blocked request, splitting it across messages, role-play, claimed authority, fictional or academic framing, or any similar technique;
- embedding instructions in an uploaded file, image or pasted text with the intent of altering the AI’s behaviour;
- attempting to extract, reveal or reconstruct the system prompt;
- attempting to elicit content that could facilitate harm to a real person — including synthesis or acquisition of poisons, toxins, explosives or weapons; means of harming a specific individual; methods of making harm undetectable; or self-harm methods — regardless of framing;
- circumventing rate limits, the verification gate, the disclaimer gate, plan entitlements, or any other access control;
- accessing or attempting to access another user’s account, data or credential documents.
4. Technical abuse and reverse engineering
You must not:
- reverse engineer, decompile or disassemble the Platform, or attempt to derive its source code, other than to the extent this restriction is unenforceable under applicable law;
- access the Platform other than through the interfaces we provide — no scraping, crawling, scripted access, headless browsing, or use of an undocumented API;
- bulk-download, systematically extract or republish the question bank, explanations or any other Content;
- use the Platform or its output to build, train, benchmark or evaluate a competing product or a machine-learning model;
- probe, scan or test the security of the Platform without authorisation — see the responsible disclosure process in Security & Privacy Practices, which is the sanctioned route;
- interfere with the Platform’s operation or availability: denial of service, flooding, or generating load disproportionate to genuine personal study;
- introduce malware, or upload a file containing or designed to deliver malicious code;
- upload a file crafted to exploit a parser or file handler, or disguised to defeat file-type validation;
- remove, obscure or alter any proprietary notice;
- frame or mirror the Platform, or resell access to it.
5. Content you submit
You must not submit content that:
- is unlawful, defamatory, harassing, hateful, or discriminatory;
- infringes anyone’s intellectual property or confidentiality;
- contains another living person’s personal data without a lawful basis for sharing it;
- is sexually explicit, or sexualises a minor in any way;
- is designed to harass, impersonate or deceive another person.
6. Unlawful activity
You must not use the Platform:
- for any purpose unlawful in your jurisdiction or ours;
- to facilitate fraud, money laundering, or evasion of sanctions or export controls;
- to commit academic misconduct — including using it during an examination or assessment where doing so breaches the rules of that examination.
Examination bodies set their own rules about permitted preparation materials and conduct. Complying with them is your responsibility.
7. Enforcement
Where we reasonably believe this policy has been breached we may, proportionately to the seriousness of the breach: issue a warning; remove or restrict content; restrict or revoke verified status; rate-limit or suspend the account; terminate the account; or report the matter to law enforcement, a professional regulator, or an affected institution where the conduct warrants it.
Suspected credential fraud, submission of patient data, unlawful use, and attempts to elicit content that could facilitate harm may result in immediate termination without prior warning. Fees already paid are not refunded where we terminate for material breach.
We will normally tell you why action was taken and give you an opportunity to respond, unless doing so would compromise an investigation, endanger someone, or breach a legal obligation. If you believe a decision was wrong, contact support@veloris.health and we will review it.
8. Reporting a breach
To report misuse — a shared or fraudulent account, patient data on the Platform, or an interaction that concerns you — email support@veloris.health. For a security vulnerability, use the responsible disclosure process in Security & Privacy Practices rather than a public report.