Version 1.0 · Effective 29/08/2026 · The Vietnamese text is the binding version; this English text is a reference translation
This policy is an inseparable part of the Terms of Service. Breaching this policy is a breach of contract.
This applies to you, to every user in your organisation, to every API key your organisation issues, and to every end user of an application you build on TexAPI. That last point is an obligation that flows down from TexAPI’s infrastructure supplier: their policy applies to anyone who can send data into the service, including through an agent or relayed access. If you build a product for end users, you must pass the obligations in sections 3 and 4 down into your own terms.
You are responsible for everything you send and for everything you do with what you get back. The fact that content passed the automated filter does not mean that content is permitted.
Unlawful activity — fraud, deception, misappropriation of property; money laundering, terrorist financing, tax evasion; unlawful gambling; trading in prohibited goods, narcotics or weapons; human trafficking; violating state secrets.
Weapons and dangerous substances — producing instructions, designs or assistance for making weapons, explosives, or chemical, biological, radiological or nuclear material is prohibited. That the information can be found elsewhere, or that you state a research purpose, does not change this.
Cybersecurity — creating or distributing malware, ransomware, spyware or botnets; denial-of-service attacks; phishing and website spoofing; stealing or testing credentials at scale; unauthorised access to other people’s systems, data or accounts; scanning for and exploiting vulnerabilities in systems you do not own or for which you have no written authorisation; bypassing or disabling security controls.
Permitted, and welcome: security work on systems you own or are clearly authorised to test — contracted penetration testing, CTF competitions, research on your own code, building defensive tooling, and teaching. The line is ownership and authorisation, not the technique involved.
Infringing other people’s rights — copyright, trademarks, trade secrets; privacy, including processing another person’s personal data without a legal basis for doing so; mass surveillance, tracking individuals without consent, profiling on the basis of legally protected characteristics; facial or biometric identification of private individuals; impersonation and generating content that poses as a real person without their consent; harassment, threats, defamation, extortion; content that incites hatred or discrimination.
Sexual and violent content — generating pornography, sexually exploitative content and gratuitous violence is prohibited. Professional discussion in a professional context — building a content-moderation system, for instance — is permitted.
Spam and abuse at scale — spam email and messaging, manipulating engagement metrics, polls or rankings; automated account creation at scale on other platforms; coordinating inauthentic behaviour on social networks; scraping websites in breach of the scraped site’s terms.
Evading a model’s safety measures — deliberately working to make a model produce content this policy prohibits, whether by jailbreak, prompt injection, encoding the content, or any other technique.
In these domains: legal; medicine and health; insurance; finance and credit; recruitment, employment and housing; examinations, accreditation and admissions; journalism and professional media content — if TexAPI is used to give advice or a recommendation, or takes part in a judgement-based decision that directly affects an individual, then a person qualified in that domain must review it before it is published or finalised.
TexAPI does not prohibit you from working in these domains. TexAPI requires you to have human review and to disclose. That is an important difference.
If you find a billing bug in your favour, tell support. TexAPI does not penalise anyone for reporting one honestly; TexAPI acts against people who exploit one systematically.
The automated filter extracts at most 40,000 characters of text that you wrote from each request, ignoring the system prompt and anything the model generated, and matches it against keyword expressions entirely inside the TexAPI process — your content is not sent to anyone for analysis.
If a request is not flagged, nothing is recorded. If it is flagged: the request is blocked and not charged, and an excerpt of at most 500 characters is kept for 24 months as evidence.
TexAPI also computes some operational signals, such as one key appearing from several addresses or several countries. These signals lead to no automatic action; they are only a lead for a human operator to look at. TexAPI currently does not block by IP address and does not restrict by country.
TexAPI escalates in steps and in proportion to the conduct: warning → blocking the offending request → reducing limits → restricting models → revoking the API key → suspending the account → terminating the account → reporting to the competent authority where the law requires it. For a child-safety breach, TexAPI goes straight to the last step.
Only one mechanism leads to suspension automatically: when the number of exact matches reaches 3, the account is locked automatically. Every other step is decided by a person, with an unalterable audit record and a written reason.
TexAPI commits to: notifying you when it applies step 3 or beyond, naming which term was breached and the specific basis for it — no generic reasons; giving you a chance to explain before termination, except for a child-safety breach or where there is a risk of immediate harm; never using suspension as a way to hold on to your money; restoring the account and the violation counter when something turns out to be a false positive; and not reading the content of your requests beyond the 500-character excerpt kept when there is a breach — TexAPI does not have the full content to read, because it does not store it.
Appeals: email support with the subject [KHIẾU NẠI]. TexAPI replies within 7 working days, and the review is done by someone other than the person who made the original decision. Your right to complain under the law is not limited by this document.
Suspension or termination does not cost you your balance, except for a serious breach and then only in proportion to the actual loss, with a written explanation.
If you find someone using TexAPI in breach of this policy: email support with the subject [LẠM DỤNG]. TexAPI acknowledges receipt within 2 working days, investigates and replies within 10 working days, keeps the reporter’s identity confidential, and takes no adverse action against anyone who reports in good faith. For content relating to child safety, TexAPI acts within 24 hours.
One limitation worth stating up front: TexAPI does not store the content of requests and responses, so TexAPI cannot find or take down a specific piece of content a customer has generated. So far as it is able, TexAPI acts at the account level.
TexAPI complies with lawful requests, checks that a request is lawful and what it covers, and does not hand over more than its scope. TexAPI notifies you when there is a request concerning your data, unless the law forbids notifying you.
TexAPI does not have the content of your requests and responses to hand over. What TexAPI has is usage metadata, account information, payment history, and a moderation excerpt where there has been a breach.
A change that widens what is prohibited is announced 30 days in advance. A change that clarifies, or that brings this policy into line with a legal requirement or a requirement from the infrastructure supplier, can take effect immediately — in which case TexAPI states the reason.