Acceptable Use Policy

    Preliminary version under legal review

    Version 0.9.0

    Table of contents

    1. Scope and how this Policy works
    2. Illegal content and activity
    3. Protection of children
    4. Intimate images and sexual content
    5. Harassment, threats, hate and violence
    6. Real people: voice, likeness, deepfakes and impersonation
    7. Elections and political content
    8. Spam and unsolicited messaging
    9. Abuse of our Services: scraping, bots, overload and limits
    10. Security testing, malware and unauthorized access
    11. Prohibited and high-risk uses of AI
    12. Sensitive data and people's privacy
    13. Product-specific rules
    14. Sanctions and restricted persons
    15. Enforcement ladder
    16. Statements of reasons and appeals
    17. How to report a breach
    18. Changes to this Policy

    1. Scope and how this Policy works

    1.1 Who it applies to. This Policy forms part of the Terms of Service. Capitalized terms have the meaning given there. It applies to:

    • every use of the Services;
    • Customer Data and User Content;
    • messages sent through our AI agents;
    • AI outputs that you request.

    1.2 Organizations answer for their users. An Organization must make sure that its Authorized Users, and the AI agents it deploys, follow this Policy.

    1.3 Examples, not a complete list. The examples in this Policy illustrate the rules. They are not a complete list of what is prohibited. A use that is illegal, or that causes similar harm, breaks this Policy even if it is not listed.

    1.4 Relation to law. This Policy does not replace the law. Where the law of the place where you are, or the law of Brazil, is stricter than this Policy, the law applies.

    2. Illegal content and activity

    You may not use the Services to:

    2.1 store, share, generate or promote content that is illegal in Brazil or in the place where it is accessed;

    2.2 commit or facilitate fraud, scams, phishing, identity theft, money laundering, illegal gambling or any other crime. This includes voice-clone scams and fake invoices or receipts;

    2.3 sell or promote illegal goods or services, including drugs, weapons, counterfeit goods and stolen data;

    2.4 carry out illegal lending or usury, or collect debts through threats, public exposure or harassment (see Section 13.3);

    2.5 infringe someone else's copyright, trademark, trade secret or other intellectual property. The Copyright and Content Removal Policy explains how rights holders can report this;

    2.6 promote or incite terrorism, violent extremism, anti-democratic acts, or trafficking in persons.

    3. Protection of children

    3.1 Zero tolerance. You may not create, upload, store, request, generate or share:

    • (a) child sexual abuse material (CSAM), in any form, whether real, drawn or AI-generated;
    • (b) sexualized content involving minors, or content that sexualizes minors;
    • (c) content or conduct aimed at grooming, sexual exploitation or trafficking of minors.

    3.2 Our response. When we become aware of such content, we:

    • remove it or disable access to it;
    • close the account involved;
    • preserve the evidence that the law requires or allows us to keep;
    • report the case to the competent authorities. In Brazil, these include the Federal Police reporting center created by Decreto 12.882/2026 and the SaferNet hotline. Elsewhere, we report to the competent national bodies.

    We do not warn the account holder before reporting, and we do not give an appeal that would restore the content.

    3.3 Other risks to minors. You may not:

    • (a) use the Services to contact minors for purposes unrelated to the educational service for which their school uses Verita;
    • (b) profile minors for advertising, or target advertising at them;
    • (c) add paid random items (loot boxes) to any product aimed at, or likely to be accessed by, minors;
    • (d) create accounts for minors outside the cases the Children and Student Data Addendum (Verita) allows.

    4. Intimate images and sexual content

    4.1 Non-consensual intimate images (NCII). You may not upload, share, generate, or threaten to share intimate images, video or audio of a person without that person's consent. This applies whether the content is real or created or altered with AI. Examples are sexual deepfakes, "nudified" images and synthetic intimate audio.

    4.2 48-hour removal. If the person depicted, or someone authorized to act for them, sends a valid removal request, we remove the content within 48 hours. We also make reasonable efforts to find and remove identical copies on our Services. The Copyright and Content Removal Policy explains how to send a request. This process follows:

    • the US TAKE IT DOWN Act;
    • the Marco Civil da Internet, art. 21;
    • the Digital Services Act for users in the EU.

    4.3 AI tools. You may not use any SonhoLab AI feature to generate sexual or intimate content depicting a real, identifiable person. We apply safety filters to block this.

    4.4 Sexual content in general. Our Services are not designed for pornography or sexually explicit content. You may not publish such content in any area visible to other users. Product addenda may set stricter rules.

    5. Harassment, threats, hate and violence

    You may not use the Services to:

    5.1 harass, bully, stalk, intimidate or threaten any person, including through repeated unwanted messages;

    5.2 publish someone's private information to expose, intimidate or harm them ("doxxing");

    5.3 attack or demean people because of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability, age, serious illness or similar characteristics, or incite discrimination or violence against them;

    5.4 incite or glorify violence, including violence against women;

    5.5 encourage or give instructions for suicide or self-harm. Our AI products follow a crisis protocol: when they detect signs of risk, they stop role-play and show crisis resources.

    6. Real people: voice, likeness, deepfakes and impersonation

    6.1 Voices and likeness need consent. You may not clone, synthesize or imitate the voice, face, image or likeness of a real person unless that person has given explicit consent. For a deceased person, you must meet the rules of the Hades Addendum: Voice, Biometrics, Memorials and Companion AI. A checkbox by the uploader is not a substitute for the consent of the voice owner.

    6.2 Deepfakes. You may not create or share synthetic or manipulated audio, images or video that realistically depict a real person saying or doing something they did not say or do, unless:

    • the person has consented; and
    • the content is clearly labeled as AI-generated.

    You may never create such content to deceive, defraud, defame, harass or sexualize anyone.

    6.3 Public figures, politicians and candidates. You may not use our Services to simulate, clone or imitate the voice or likeness of public figures, politicians, public officials or electoral candidates. This applies even for satire, because our voice and companion products are not designed to distinguish satire safely.

    6.4 Impersonation. You may not impersonate any person, company, public authority or SonhoLab. You may not falsely claim an affiliation, or create accounts, slugs, domains or AI agents designed to mislead people about who they are dealing with.

    6.5 AI must not pretend to be human. You may not configure or instruct an AI agent to deny being an AI, or to claim to be a human, a specific real person or a deceased person. You may not remove or hide the AI disclosure that our agents give at the start of each conversation, or the labels on synthetic content.

    6.6 Removal within 48 hours. When a person, or their legitimate representative or heir, reports an unauthorized use of their voice or likeness, we remove it within 48 hours of a valid request. See the Copyright and Content Removal Policy.

    7. Elections and political content

    7.1 You may not use the Services to:

    • (a) create or spread deepfakes of candidates, parties, public officials or electoral authorities. Under Brazilian electoral rules, this includes the image or voice of a living, deceased or fictional person;
    • (b) spread false information about when, where or how to vote, or about eligibility to vote;
    • (c) run AI agents or automated messaging for electoral propaganda. This includes mass messaging to voters and bots that simulate supporters;
    • (d) intimidate voters, electoral officials or candidates.

    7.2 In Brazil, you must also comply with the rules of the Superior Electoral Court (TSE) on artificial intelligence in electoral propaganda. These include TSE Resolution 23.610/2019, art. 9º-B, as amended by Resolution 23.755/2026.

    7.3 During election periods we may apply additional restrictions to protect the integrity of elections.

    8. Spam and unsolicited messaging

    8.1 No spam. You may not use the Services, including our AI agents, messaging integrations, email and forms, to send unsolicited bulk or commercial messages.

    8.2 Consent before marketing. Before you send marketing messages, you must obtain every consent the law requires. You must keep a record of it and honor opt-outs promptly. In particular:

    • (a) United States. You may not send automated or AI-generated marketing messages, texts or WhatsApp messages to US numbers without the recipient's prior express written consent (Telephone Consumer Protection Act and state laws, including those of Florida and Oklahoma). You must:

      • honor revocation of consent made by any reasonable means;
      • respect quiet hours;
      • identify the sender;
      • check the National Do Not Call Registry where the law requires it.
    • (b) Email. Commercial email must meet CAN-SPAM and the equivalent laws where the recipients live. That means:

      • no false or misleading headers or subject lines;
      • a clear identification that the message is an advertisement, where the law requires it;
      • a valid postal address;
      • a working unsubscribe link, honored within 10 business days.
    • (c) Brazil. Marketing must have a valid legal basis under the LGPD, respect the data subject's right to object, and not use data collected for another purpose.
    • (d) EU/EEA and UK. Electronic marketing needs prior consent, except for the limited "soft opt-in" for existing customers where the law allows it. Every message must offer a simple opt-out.

    8.3 Messaging platform rules. You must comply with WhatsApp's business and commerce policies. These include:

    • obtaining opt-in before business-initiated messages;
    • using approved message templates;
    • honoring opt-outs.

    Our AI agents always honor the opt-out keyword.

    8.4 Purchased lists. You may not message people whose contacts you bought, scraped or obtained without their consent. You may not use the Services to build or sell contact lists.

    8.5 Deceptive messages. You may not send messages that hide the sender's identity, simulate personal messages for mass campaigns, or use misleading urgency to get payments or data.

    9. Abuse of our Services: scraping, bots, overload and limits

    You may not:

    9.1 scrape, crawl, spider or harvest data from the Services, or from other customers' pages, by automated means. The only exceptions are through an API we offer for that purpose, within its documented limits, or where the law expressly allows it despite this restriction;

    9.2 create accounts by automated means, create multiple accounts to avoid Plan limits or enforcement measures, or sell or transfer accounts;

    9.3 share credentials, or use one login for several people, to get around the limit of people with access to a Plan;

    9.4 get around rate limits, quotas, usage caps, paywalls, age checks, geo-restrictions or other technical limits;

    9.5 overload or disrupt the Services. Examples are sending excessive requests, running denial-of-service attacks, or running loads that degrade performance for others;

    9.6 resell, sublicense or rebrand access to the Services without a written agreement with us;

    9.7 use the Services, or their outputs, to copy our software, content or datasets systematically in order to build a competing service;

    9.8 use our free tools or APIs to process content that you have no right to process.

    10. Security testing, malware and unauthorized access

    10.1 No unauthorized access. You may not access, or try to access:

    • another customer's data or account;
    • our internal systems;
    • any part of the Services you are not authorized to use.

    This applies even if you find a way to do it. If you find a vulnerability, do not exploit it. Report it to us.

    10.2 Security research needs permission. You may not probe, scan, penetration-test or stress-test the Services without our prior written permission. Write to security@sonholab.com with a description of the planned tests. We will agree scope, timing and rules with you. If you find a vulnerability in good faith, report it privately at the same address and give us reasonable time to fix it before any disclosure. We will not pursue good-faith research that stays within the agreed rules. Our security contact is also published at https://sonholab.com/.well-known/security.txt, and Security and Incident Response (08-security-and-incidents.md) describes how we handle reports.

    10.3 No malware. You may not upload, store, distribute or run malware, including:

    • viruses, worms, trojans, ransomware and spyware;
    • cryptominers;
    • droppers, or code that runs automatically when a file or project is opened.

    10.4 No circumvention of security. You may not disable, bypass or interfere with authentication, encryption, logging, tenant separation or other security controls.

    10.5 No interception. You may not intercept or monitor communications or data that are not addressed to you.

    11. Prohibited and high-risk uses of AI

    11.1 Uses prohibited by the EU AI Act, art. 5. You may not use any SonhoLab AI feature, anywhere in the world, to:

    • (a) deploy subliminal, manipulative or deceptive techniques that materially distort a person's behavior and cause, or are likely to cause, significant harm;
    • (b) exploit vulnerabilities of a person or group due to age, disability or social or economic situation, in a way that causes or is likely to cause significant harm. This includes bereaved people using memorial features;
    • (c) evaluate or classify people over time based on their social behavior or personal traits, where the resulting "social score" leads to unjustified or disproportionate detrimental treatment;
    • (d) assess or predict the risk that a person will commit a crime based solely on profiling or personality traits;
    • (e) create or expand facial recognition databases through untargeted scraping of facial images from the internet or from CCTV footage;
    • (f) infer the emotions of people in workplaces or educational institutions, except for medical or safety reasons;
    • (g) categorize people based on their biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation;
    • (h) carry out real-time remote biometric identification in publicly accessible spaces for law enforcement;
    • (i) generate non-consensual intimate imagery of real persons, or child sexual abuse material. Sections 3 and 4 already prohibit this.

    11.2 No solely automated high-impact decisions. Our AI features are decision-support tools. You may not use them to take decisions based solely on automated processing that produce legal or similarly significant effects on a person, without meaningful human review. This applies in particular to:

    • (a) admission, grading, discipline or evaluation of students, or monitoring students during tests;
    • (b) recruitment, selection, promotion, task allocation, performance evaluation or dismissal of workers or drivers;
    • (c) creditworthiness, credit scoring, debt collection priority or access to essential services;
    • (d) housing, rental or property valuation decisions that bind a person;
    • (e) access to health care or clinical decisions.

    The person affected must be able to obtain human review, express their view and contest the decision.

    11.3 No misleading AI claims. You may not tell your customers or the public that an AI feature is more accurate or capable than it is. Examples are "replaces your doctor", "guaranteed valuation" and "100% accurate".

    11.4 Deployer duties. If your Organization deploys an AI agent to talk to other people, you must meet the duties in the Terms of Service, Section 12.5, and in the AI Agents and Messaging Addendum. These include AI disclosure, human handoff, opt-out and consent. The AI Transparency Notice explains how our AI features work.

    11.5 No jailbreaking. You may not try to bypass the safety filters, disclosures or limits of our AI features, or get them to produce content this Policy prohibits.

    12. Sensitive data and people's privacy

    You may not:

    12.1 collect, upload or process personal data without a lawful basis, or without giving the notices and obtaining the consents the law requires;

    12.2 upload health data, biometric data, children's data, identity documents or precise location to a System that is not designed for that category of data. Health data belongs in Clinics, and student data in Verita. Each System's product addendum describes the data it is designed for;

    12.3 use location, photos or activity data to monitor workers secretly, outside working hours, or beyond what employment law allows. See the Workforce, Farm and Site Monitoring Addendum;

    12.4 use location features to stalk or track a person without their knowledge, or to locate people near health facilities for purposes unrelated to the service;

    12.5 use the Services to sell, rent or trade personal data, or to build profiles of people for purposes unrelated to your service to them;

    12.6 use data obtained through the Services to discriminate unlawfully, or to make decisions on employment, credit, insurance or housing in breach of the law;

    12.7 use health data for economic advantage in breach of the LGPD, art. 11, §4, or share it with third parties without a lawful basis;

    12.8 re-identify, or try to re-identify, people in data that has been anonymized or pseudonymized.

    13. Product-specific rules

    Product addenda add rules for their Systems. Some key rules:

    13.1 Hades. Hades is for adults only. Voices are cloned only with the explicit, separate consent of the voice owner, or under the rules for deceased persons. No public figures, politicians or candidates. The shared voice library is opt-in only. See the Hades Addendum: Voice, Biometrics, Memorials and Companion AI.

    13.2 Games. Virtual items have no cash value. You may not sell, trade, transfer or redeem chips or virtual items for money or anything of value, or use bots, collusion or multiple accounts. Poker is for adults only and is not available in Washington State. See the Games and Virtual Items Terms.

    13.3 CobraDia (collections). You must not:

    • threaten debtors or expose them to ridicule or public embarrassment;
    • contact their family, employer or references about the debt;
    • publish lists of debtors;
    • collect amounts that are not due;
    • use the System for illegal lending.

    See the Debt Collection Addendum (CobraDia).

    13.4 Speed and Passayum. You must not use location data for purposes other than the trip or delivery. See the Location and Mobility Addendum (Speed, Passayum).

    13.5 Job Portal. You must not post fake jobs, charge candidates fees to apply, or collect candidates' data for unrelated purposes. See the Recruiting and Job Portal Addendum.

    13.6 Developer APIs and the LLM gateway. You must keep API keys secret, and must not share keys or use them to serve end users in breach of this Policy. See the Developer and API Terms (Brain SaaS, LLM gateway).

    13.7 Free tools and content services. Only process files you have the right to process. See the Free Tools and Content Services Terms.

    14. Sanctions and restricted persons

    You may not use the Services if you are located, organized or ordinarily resident in a country or region subject to comprehensive sanctions. You may not use them if you are, or are owned or controlled by, a person on a sanctions or restricted-party list maintained by Brazil, the United Nations, the European Union, the United Kingdom or the United States. You may not use the Services on behalf of such a person, or for any end use that those laws prohibit. See the Terms of Service, Section 25.

    15. Enforcement ladder

    15.1 Proportionate response. When we learn of a possible breach, we assess:

    • how serious it is and the harm it causes or could cause;
    • whether it was intentional;
    • whether it has happened before;
    • the rights and interests of everyone involved.

    We then apply the least restrictive measure that effectively stops the harm.

    15.2 The ladder. Our measures, from least to most serious, are:

    StepMeasureTypical use
    1Notice and request to fixA minor or first breach that you can fix yourself, such as a missing opt-out in a template
    2Removal or disabling of specific contentContent that is illegal or infringes rights, after a valid notice
    3Restriction of a featureFor example, pausing an AI agent's outbound messages, limiting sharing, or lowering rate limits
    4Temporary suspension of the account or of a SystemSerious or repeated breaches; security risks; failure to fix after notice
    5Termination of the accountVery serious breaches; repeat infringement; failure to fix a serious breach within 15 days after notice
    6Report to authoritiesCSAM, threats to life or safety, and other crimes where the law requires or allows us to report

    15.3 Skipping steps. We may go directly to a higher step, including immediate suspension or termination, when:

    • the breach involves CSAM, NCII or a threat to someone's life or safety;
    • the breach creates a security risk to the Services or to other customers;
    • the law or a competent authority requires it;
    • an earlier step has already failed.

    15.4 Customer Data during enforcement. Suspension does not delete Customer Data. It stays exportable, unless the law or an order of an authority says otherwise. After termination, the export and deletion rules of the Terms of Service, Section 19, apply. Illegal content itself is not returned.

    15.5 Organizations and their users. If an Authorized User breaks this Policy, we normally act against that user and tell the Organization Owner. We may act against the Organization if it does not stop the conduct after our notice.

    15.6 Human review. A person at SonhoLab reviews every suspension and termination of an account. We do not take those measures by automated means alone. Automated tools may block a single request or output, such as a filtered AI response or a rate-limited request, while that happens.

    16. Statements of reasons and appeals

    16.1 We tell you why. When we remove or restrict your content, or suspend or terminate your account, we send you a statement of reasons. It explains:

    • what we did and its scope and duration;
    • the facts and circumstances we relied on, including whether the case started from a notice;
    • whether automated means were used to detect the issue or to decide;
    • the rule of this Policy or of the law we relied on;
    • how to appeal.

    We do not send a statement where the law forbids it, where it would hinder a criminal investigation or endanger someone, or for spam and deceptive high-volume commercial content.

    16.2 How to appeal. You can appeal free of charge within 6 months of our decision. Reply to the decision message, or write to contacto@sonholab.com with the subject "Appeal" and your account email. Explain why you think the decision was wrong and attach any evidence.

    16.3 Who decides. A person who did not take the original decision reviews your appeal. We decide without undue delay and tell you the outcome and our reasons. If the appeal shows that our decision was wrong, we reverse it without undue delay and restore your content or access.

    16.4 Other remedies. The appeal does not limit your right to go to court. In the EU, it does not limit your right to complain to the Digital Services Coordinator of your member state. In Brazil, it does not limit your right to go to consumer protection bodies. See the Terms of Service, Sections 14 and 23.

    16.5 Abuse of the reporting system. If someone frequently sends notices or complaints that are manifestly unfounded, we may, after a warning, stop processing their notices for a reasonable period.

    17. How to report a breach

    17.1 Where to report.

    • Content that infringes copyright, or that violates rights to voice, likeness or intimate images: follow the Copyright and Content Removal Policy.
    • Any other breach of this Policy: write to contacto@sonholab.com with the subject "Abuse report". Include:

      • the location of the content or conduct (a link, slug, phone number of the agent, or screenshot);
      • what rule you believe is broken and why;
      • your contact details, unless you are reporting CSAM. You may report CSAM anonymously.

    17.2 Urgent threats. If someone's life or safety is in immediate danger, contact your local emergency services first.

    17.3 Privacy. We use the information in your report only to handle it and to keep the records the law requires. We do not tell the reported person who you are, except where the law requires it or where your identity is essential to the claim (for example, in a copyright notice).

    18. Changes to this Policy

    We may update this Policy to address new risks or legal requirements. Material changes are announced in advance, as described in the Terms of Service, Section 24. Changes needed to stop an immediate risk of harm, or required by law, may take effect sooner. Each version is published at sonholab.com/{lang}/legal with its date.


    Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.

    Preliminary version under legal review

    Version 0.9.0

    SHA-256 fingerprint of this text: c9877f030fcb1106c7d0a8ef52b2f03e15ff2d84b30dbb423acc89eb92a2195d

    Back to the Legal Center