Acceptable Use Policy
Last updated: August 26, 2026
Effective date: August 26, 2026
This Acceptable Use Policy (“AUP”) governs use of the Service. It binds two groups directly:
- People who use the Casola consumer service. It forms part of your Terms of Service.
- API customers. It forms part of your Developer & API Terms, and you must flow its prohibitions down to your own end users and enforce them.
Casola is a non-explicit service; sexual or pornographic generation is not permitted. Violations may result in suspension, termination, and reporting to authorities where required.
1. Absolute Prohibitions
You must not use the Service to create, request, solicit, store, or distribute, and if you operate a product on the API you must contractually prohibit and technically prevent your end users from creating, requesting, soliciting, storing, or distributing:
- Any sexual or sexualized content depicting a minor (real or AI-generated), including age-regression, “child-coded” characters, or any avatar configured to appear underage in a sexual context. This applies to synthetic output, which is unlawful in most jurisdictions even when fully generated.
- Any sexualization of minors, or content that facilitates the grooming, secrecy, or isolation of a minor.
- Non-consensual intimate imagery (NCII) or sexual deepfakes of a real, identifiable person.
This content is never permitted under any framing. We screen for it, block it, preserve evidence, and report it to NCMEC and/or other authorities (see Section 5). Detected use leads to immediate termination.
2. Other Prohibited Uses
You must not use the Service to:
- Generate sexual, pornographic, or sexually explicit content. Casola is non-explicit.
- Create the likeness of a real, identifiable person without their express, written consent, or any deceptive or defamatory likeness.
- Produce or promote violent-extremist or terrorist content, or incitement to violence.
- Harass, stalk, threaten, defame, or impersonate any individual.
- Generate content that encourages self-harm, suicide, or disordered eating.
- Present an avatar as a human being, or strip out an AI disclosure we provide. See the AI Disclosure.
- Present an avatar as a licensed professional, or use its output as medical, mental-health, legal, or financial advice.
- Develop or deploy weapons (biological, chemical, nuclear, radiological) or other instruments designed to cause serious harm.
- Create malware, exploits, or phishing material, or conduct unauthorized access or fraud.
- Record a conversation with another person present without the consent their jurisdiction requires.
- Infringe IP or privacy rights, or otherwise violate applicable law.
Good-faith security research is carved out of the unauthorized-access prohibition above. Testing that stays inside the scope and rules of our Vulnerability Disclosure Policy is authorized, and we will not suspend or terminate an account over it. That policy is the only route to the carve-out: a report sent afterwards does not make earlier testing authorized.
3. Avatar and Character Rules
- No character configured with childlike features, ages, or descriptors in a sexualized context.
- No avatar depicting a real, identifiable person without that person’s verified consent.
4. Self-Harm and Crisis
The avatars are not a crisis service and cannot help in an emergency. If you are in danger or thinking about harming yourself, contact your local emergency number. In the US, call or text 988. In the UK, call 116 123. International helplines are listed at findahelpline.com.
You must not use the Service to encourage, plan, or assist self-harm or suicide, for yourself or anyone else.
Do not rely on the Service as a crisis or emergency service, and do not let anyone using a product you build on it rely on it that way either. For API customers, running a crisis protocol in your deployment is your obligation under Section 6.
5. How We Enforce Safety
Independent of any controls you run, we apply the following to what the Service generates, and by using the Service you acknowledge them:
- Input screening, on submitted script content. Text you save as a script is matched against a maintained list of patterns for prohibited content, including markers of child sexual abuse material, credible threats, and incitement. Matches are blocked and logged. One limit worth stating plainly: it does not run on live conversation, which reaches the model without passing through it.
- Generation guardrails. The models refuse prohibited depictions, including any sexual depiction of a youthful or minor-coded character.
- Reporting and preservation. Suspected child sexual abuse material is reported to the NCMEC CyberTipline (US-based reporting under 18 U.S.C. §2258A) and/or the relevant authority, with evidence preserved.
These are our own obligations. For an API customer they do not replace the controls you must run at your own layer (Section 6).
6. Deployment Requirements for API Customers
This section applies to API customers, not to consumer users.
Because you operate the consumer experience, you must, as a condition of use:
- Bind your end users to terms and an acceptable-use policy at least as strict as this AUP, with rights to suspend and report.
- Provide a clear, conspicuous “you are interacting with AI” disclosure and any required extended-session reminders. See the AI Disclosure.
- Maintain a self-harm and crisis protocol that refers at-risk end users to crisis resources (e.g., 988 in the US) and prevents self-harm-encouraging content.
- Perform end-user age assurance appropriate to the risk (not a self-attested checkbox alone). As a default you must exclude end users under 18; if your lawful, documented use case serves minors, you must first notify us and implement minor-specific safeguards (age-appropriate experience, the disclosures and reminders above, and stricter content limits) and comply with applicable child-protection law. You may not rely on Casola to age-gate your end users.
- If you switch on session capture, disclose the recording to your end users and collect whatever consent their jurisdiction requires.
- Not market the avatars as a substitute for therapy, professional care, or human relationships.
7. Monitoring and Enforcement
We may verify identity and business details, monitor usage, and at our discretion warn, suspend, or terminate access, apply key-level blocks, and report to authorities. Section 1 violations skip any warning ladder and result in termination and reporting. API customers must cooperate with our investigations and provide end-user information where it is lawfully required for a safety matter.
Every enforcement decision comes with a reason and a way to challenge it. We tell you what we acted on and whether a person or an automated check flagged it, and you can appeal to legal@casola.ai. We reinstate what we got wrong. The exception is material we have reported to an authority under Section 5, which stays down. Consumer users: Section 10 of the Terms of Service sets out the same process for you.
8. Reporting
Report suspected violations to safety@casola.ai. Suspected child sexual abuse material may also be reported to the NCMEC CyberTipline at report.cybertip.org (US) or your national hotline.