Version 2
Effective date September 10, 2026
This Acceptable Use Policy applies to Trampoline Cloud Services, including Workflows built with Avalanche, Predict RLM workloads, model calls, tools, connectors, schedules, and automated external actions. It is incorporated into the Trampoline Cloud Services Terms.
The policy is designed for a platform where software can reason, branch, call tools, transform data, and act in connected systems. Customers must match permissions, testing, approvals, and oversight to the consequences of each Workflow.
1 Customer Accountability
Customer is responsible for its Authorized Users, Customer Content, Customer Code, Workflows, connected systems, provider choices, and use of Customer Output. Customer must have lawful authority to access every source and destination and must provide notices, consents, and review required for the use case.
Customer must test Workflows before production, use representative data where lawful, define success and failure criteria, monitor material changes, investigate unexpected behavior, and keep a person accountable for each production Workflow.
2 Illegal Harmful and Abusive Use
You may not use the Cloud Services to create, facilitate, coordinate, or materially assist:
- Activity that violates law, sanctions, export controls, a court order, or the rights of another person.
- Child sexual abuse material, sexual exploitation of minors, human trafficking, or grooming.
- Credible threats, targeted harassment, stalking, non-consensual intimate imagery, or incitement to violence or hatred.
- Fraud, impersonation, deceptive schemes, phishing, spam, credential theft, or material misrepresentation.
- Malware, ransomware, destructive payloads, botnets, unauthorized surveillance, service disruption, or evasion of security controls.
- Unauthorized collection, reidentification, sale, disclosure, or exfiltration of personal, confidential, or proprietary information.
- Infringement or misappropriation of intellectual property, privacy, publicity, confidentiality, or trade-secret rights.
- Development or deployment of weapons, or instructions intended to cause physical harm, where prohibited by law or provider policy.
3 Access Data and Credentials
You may process only data and systems that you are authorized to use. Do not scrape, query, monitor, or connect to a source in violation of law, contract, robots or access controls, or a binding platform rule. Do not use a Workflow to circumvent authentication, rate limits, network boundaries, paywalls, or technical restrictions.
Use managed secrets or supported credential controls. Do not place passwords, private keys, access tokens, or similar secrets in ordinary prompts, logs, test fixtures, or Customer Output. Grant least privilege, separate production from testing, rotate exposed credentials, and revoke access promptly when no longer needed.
4 Sensitive and Regulated Data
Confidential business information and trade secrets may be processed where you have authority and use appropriate security settings. The following categories require an Order or Documentation that expressly supports the use, along with any required supplemental agreement and safeguards:
- Protected health information or other regulated health data, which requires a signed business associate agreement where applicable.
- Full payment card data, financial account credentials, or authentication secrets. Use tokenized or purpose-built payment systems instead.
- Biometric identifiers used to identify a person, precise location histories, genetic data, or similarly sensitive profiling data.
- Government identification numbers, criminal records, children's data, student records, or information subject to professional secrecy.
- Classified, controlled-unclassified, defence, export-controlled, or other government-restricted information.
Even where supported, collect and disclose only what is necessary, apply retention limits, restrict access, and document the lawful purpose. Do not infer sensitive traits about a person unless the inference is lawful, necessary, transparent where required, and expressly supported.
5 High Impact and Regulated Decisions
You may not use Customer Output as the sole basis for a decision that produces legal or similarly significant effects in employment, worker management, credit, lending, insurance, housing, education admissions, healthcare, legal services, essential utilities, public benefits, immigration, law enforcement, or another high-impact domain unless Trampoline has approved the use in writing and the Workflow is designed and operated in compliance with applicable law.
Approved high-impact uses must include, as appropriate:
- A documented purpose, lawful basis, risk assessment, accountable owner, and defined population.
- Qualified human review with real authority to disagree, obtain more information, and change the result.
- Testing for accuracy, reliability, bias, disparate impact, foreseeable misuse, and material changes before and during deployment.
- Meaningful notice and explanation, a way to correct relevant data, and a way to contest or appeal the result where required.
- Access controls, data minimization, retention limits, logs, version records, incident response, and periodic review.
A Workflow may assist a qualified professional, but it must not impersonate one or represent generated output as professional advice without appropriate review and authorization.
6 Prohibited AI Practices
Regardless of whether a jurisdiction labels a system as high risk, you may not use the Cloud Services for:
- Subliminal, manipulative, or deceptive techniques intended to materially distort a person's behavior and cause significant harm.
- Exploitation of vulnerability based on age, disability, or a person's social or economic situation in a manner likely to cause significant harm.
- Governmental or private social scoring that leads to unjustified or disproportionate treatment unrelated to the context in which data was collected.
- Biometric categorization that infers sensitive traits, or untargeted scraping of facial images to build or expand recognition databases.
- Emotion recognition in workplaces or educational institutions except where lawful and strictly necessary for a medical or safety purpose.
- Predicting that a person will commit a crime based solely on profiling, personality traits, or characteristics, without objective and verifiable facts linked to criminal activity.
- Real-time remote biometric identification in publicly accessible spaces unless the use is expressly lawful, authorized, and supported under a specific agreement.
7 Agentic Execution and External Actions
A Workflow that can act outside its execution environment must be configured so that authority is explicit, limited, reviewable, and reversible where reasonably possible. Use human approval or an equivalent control before an agent:
- Deletes, overwrites, publishes, transmits, or materially changes data.
- Sends a message in a person's or organization's name, makes a public statement, or contacts an individual.
- Commits funds, changes a price, accepts terms, signs or purports to sign an agreement, or creates another legal or financial obligation.
- Creates, disables, or changes identities, permissions, security controls, infrastructure, or production deployments.
- Takes an action affecting employment, access to a service, a claim, a benefit, a legal position, safety, or another material interest.
Design retries and parallel Runs to avoid duplicate effects. Use idempotency controls where available, set time and spending limits, validate destinations, log approvals and material actions, and provide a tested stop or rollback path. Do not instruct an agent to conceal its actions, defeat review, or falsely claim that a human performed them.
8 Accuracy Transparency and Human Review
Do not present generated output as verified fact when it has not been checked. Disclose AI assistance where required by law, professional duty, contract, or context. Preserve source links, provenance, and uncertainty when they are material to the recipient's decision.
Do not fabricate evidence, citations, identities, approvals, records, test results, or professional credentials. Do not use the Cloud Services to create deceptive synthetic media or impersonation intended to mislead a reasonable person about a material fact.
9 Security Testing and Open Source Use
You may conduct good-faith security testing on systems you own or are authorized to test, within Trampoline's published rules and without accessing another customer's data, degrading the service, or exploiting a finding beyond what is necessary to demonstrate it. Report suspected vulnerabilities promptly to security@trampoline.ai.
This policy does not restrict rights granted by an applicable open-source licence. You may inspect, benchmark, modify, self-host, and distribute Open Source Components where the licence permits. Restrictions that protect the hosted Cloud Services, customer data, credentials, non-public systems, and rate limits continue to apply.
10 Service Integrity and Resource Use
Do not use the Cloud Services to mine cryptocurrency, create unreasonable load, bypass purchased limits, resell access except as permitted by an Order, or interfere with monitoring, metering, safety, or abuse-prevention controls. Do not probe or access another tenant, account, model credential, Run, log, or Customer Content.
11 Enforcement
Trampoline may investigate suspected violations and may require information reasonably necessary to assess risk. Where practicable, Trampoline will request correction before suspension. Trampoline may immediately limit or suspend affected access when reasonably necessary to prevent material harm, protect data or service integrity, comply with law, or respond to a serious or repeated violation.
Trampoline will scope enforcement to the affected account, Workflow, connector, feature, or data where reasonably possible. Customer may ask Trampoline to review an enforcement decision by writing to legal@trampoline.ai. The Cloud Services Terms govern termination, remedies, and liability.
12 Reporting and Questions
Report abuse, unsafe behavior, or policy questions to legal@trampoline.ai. Report suspected security vulnerabilities to security@trampoline.ai. Include enough information to identify the affected account or Workflow without sending unnecessary personal data or secrets.
Trampoline may update this policy as described in the Cloud Services Terms. Material changes will be notified in accordance with the Agreement.