KChat — Acceptable Use Policy
Effective Date: 8 September 2026 · Version: 1.0 (public beta edition)
This Policy forms part of the Terms of Service. It is kept separate so we can update it as new abuse patterns emerge without asking you to re-accept the Terms. Material changes are notified as set out in Terms §23.
It applies to everything you do with the Service — prompts, uploaded files, memories, web searches, the code sandbox, and what you do with the output.
1. The principle
Use KChat to get work done. Do not use it to break the law, hurt people, deceive them, take others' work, or attack our systems.
Your chats live on your own computer, and we cannot see them. That is a feature, not a loophole: this Policy applies to what you send through our gateway and to how you use what comes back.
2. Do not use the Service to
2.1 Break the law
- Anything illegal under the law that applies to you or to us.
- Fraud, scams, phishing, or financial deception.
- Facilitating money laundering, sanctions evasion, or terrorist financing.
- Violating export control or sanctions law.
2.2 Create harmful or abusive content
- Child sexual abuse material. Any such content is reported to the authorities and the account is terminated immediately and permanently.
- Content that sexualises minors in any way.
- Content promoting or instructing on violence, self-harm, suicide, or eating disorders.
- Content inciting hatred, harassment, or discrimination against people on the basis of a protected characteristic.
- Threats, stalking, doxxing, or targeted harassment of an individual.
- Instructions for weapons, explosives, or biological, chemical, radiological, or nuclear harm.
- Malware, exploits, or code intended to damage or gain unauthorised access to any system.
2.3 Deceive people
- Impersonating a person, business, or public institution.
- Political disinformation, fabricated news, or fake official communications.
- Passing AI-generated content off as human-authored where that deception would cause harm or is prohibited by law — including the EU AI Act.
- Fake reviews, testimonials, credentials, or endorsements.
- Fabricated data, research results, financial figures, or medical claims.
2.4 Take other people's work
- Infringing anyone's copyright, trademark, design right, patent, or trade secret.
- Uploading documents you have no right to process — someone else's confidential files, pirated books, leaked material.
- Using the Service to systematically reproduce a competitor's or another author's protected work.
- Violating someone's privacy, publicity, or likeness rights.
2.5 Misuse personal data
- Submitting personal data about others that you have no lawful basis to process.
- Submitting government identifiers, payment card numbers, or children's data in a request.
- Submitting special category data — health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, trade union membership — unless you have a lawful basis and it is necessary for your task. Remember that request content reaches the model provider, under zero retention, and that web search terms reach public engines.
- Using web search to locate, track, or profile an individual.
2.6 Attack or overload the Service
- Unauthorised access to the Service, other users' accounts, or our infrastructure.
- Probing, scanning, or testing our security without our prior written permission. (Responsible disclosure is welcome — see §6.)
- Denial-of-service or spam.
- Extracting, copying, or sharing your device key, or using it from anything other than the KChat app.
- Reverse-engineering, decompiling, or attempting to extract our prompts, model configuration, gateway architecture, or the identity of the underlying model, except as an applicable open-source licence permits.
- Automated access, scripted use, or driving the app or gateway from another program beyond ordinary human use.
- Circumventing the allowance, the hard stop, rate limits, per-request caps, or the web-search privacy filter — including by creating multiple accounts or sharing one account between people.
- Using the web-search hop as a general-purpose proxy, scraper, or crawler.
- Attempting to escape the code sandbox's isolation.
- Anything that degrades the Service for other users.
2.7 Compete unfairly
- Using the Service or its output to train, fine-tune, evaluate, or benchmark a competing AI model or product.
- Reselling, sublicensing, or redistributing access to the Service, or seats on your account, without our written consent.
- Systematically extracting output to build a competing dataset or product.
3. What happens on your computer
Content on your computer is yours and we cannot see or remove it. But the Service is not a safe harbour for anything in §2. If we learn — from a report, a legal demand, or the pattern of your usage — that you are using the Service in breach of this Policy, we act on the account, as set out in §5. Your local data stays with you either way.
4. Your responsibility for AI output
The AI can produce content that breaches this Policy even from an innocuous prompt. You are responsible for what you do with the output — what you send, publish, file, or act on. Review output before you use it. If the AI generates something that breaches this Policy, delete it and — if it seems like a systematic problem — tell us at support@the-karya.com.
Attempting to jailbreak, prompt-inject, or otherwise manipulate the AI into producing prohibited content is itself a breach of this Policy.
5. What we do about breaches
We investigate reports and signals proportionately. We have no access to your content, so we act on what we can see — usage patterns, reports, and what you tell us. Depending on severity and history, we may:
| Response | When |
|---|---|
| Warning | First, minor, likely inadvertent |
| Restrict a feature | Targeted abuse of one feature, such as web search |
| Revoke device keys | Key misuse or account sharing |
| Suspend the account | Serious or repeated breach |
| Terminate permanently, without refund | Severe breach, or repeat after suspension |
| Report to law enforcement | CSAM, credible threats, serious crime |
We act immediately and without prior notice where there is CSAM, a credible threat to someone's safety, an active attack on our systems, or a binding legal demand.
Appeals. If you think we got it wrong, write to support@the-karya.com with your account email and what happened. A human reviews it. We aim to respond within 10 business days.
6. Reporting
| What | Where |
|---|---|
| Abuse or a policy breach | support@the-karya.com |
| Copyright or trademark concern | support@the-karya.com — see the Copyright & Intellectual Property Policy |
| Security vulnerability | support@the-karya.com |
| Child safety | support@the-karya.com, marked URGENT |
Responsible disclosure. Report a vulnerability privately, give us reasonable time to fix it, and do not access other users' accounts or degrade the Service while testing. Testing the app on your own computer is fine; testing our gateway beyond your own account is not, without permission. We will not pursue legal action against good-faith research that follows these rules.