InterviewerAI — Acceptable Use Policy (AUP)
DRAFT — NOT LEGAL ADVICE. Prepared 2026-07-04 for counsel review. Do not publish
or rely on this document until it has been reviewed and approved by a qualified lawyer.
Incorporated into the Terms of Service. Violations are grounds
for suspension or termination under ToS §§8–9.
**The platform is not offered as a HIPAA-covered service and no BAA is available
today; see the Trust Page.**
This policy protects three groups: respondents who trust the surveys they take,
customers who share the platform, and the platform itself. Customer is
responsible for its users' and agents' compliance (including AI agents operating the
platform via API/MCP on Customer's behalf).
1. Prohibited survey content and use
You may not create, field, or distribute surveys or stimuli that:
- are unlawful, or are used for an unlawful purpose, in any jurisdiction where the
survey is fielded;
- harass, threaten, defame, or incite violence or hatred, or target protected groups
for exclusionary or discriminatory harm (screening for legitimate research sampling
criteria is permitted; targeting to harm is not);
- contain or link to malware, phishing, or credential-harvesting content, or
impersonate another organization;
- infringe third-party intellectual-property or publicity rights (including in
uploaded stimuli);
- are directed at children. Customer may not knowingly collect personal data of
children under 13 (or the applicable higher age of digital consent) on the
self-serve service; research involving minors requires an enterprise agreement with
appropriate safeguards, and Customer is responsible for GDPR Art. 8 / COPPA
compliance for any lawfully permitted research;
- disguise marketing, selling, lead generation, or fundraising as research
("sugging"/"frugging"), or misrepresent the research sponsor where disclosure is
legally required.
2. Prohibited data collection
You may not use surveys to collect:
- **protected health information (PHI) or special-category health data, except under
an explicitly contracted healthcare/HIPAA engagement** with the platform's HIPAA
mode enabled, a signed BAA where required, and an approved DPIA. Outside such an
engagement, health-related special-category collection is prohibited — the platform
is not offered for it (see DPA Annex I and TRUST_PAGE.md);
- government identification numbers, full payment-card numbers, passwords, or other
credentials;
- special-category / sensitive personal data (racial or ethnic origin, political
opinions, religious beliefs, sexual orientation, biometrics for identification) —
prohibited on the self-serve service; such collection is permitted only under an
enterprise or BAA agreement that expressly contracts for it (see DPA
Annex I).
3. Respondent protection
You may not:
- deanonymize or attempt to re-identify respondents — including voice matching,
cross-referencing responses against other datasets, device fingerprinting, or
soliciting identifying details to link a "anonymous" response to a person — except
where identification is disclosed to the respondent and lawfully consented;
- misrepresent survey length, purpose, or reward;
- offer deceptive incentives: advertised rewards must be real, funded, and
delivered as described; prize draws must disclose material terms (odds/selection
method) and comply with applicable sweepstakes/lottery law (see
Panel & Incentive Disclaimers);
- retarget, contact, or build marketing profiles on respondents from survey data
without a disclosed lawful basis;
- coerce participation or exploit a dependency relationship (e.g., employer-employee)
without appropriate disclosures.
4. AI / LLM misuse
The platform embeds LLM and voice-AI capacity for one purpose: running your surveys.
You may not:
- prompt-inject, jailbreak, or otherwise manipulate the AI interviewer, probing
engine, or authoring agents to produce content unrelated to the survey, to reveal
system prompts, other customers' data, or platform IP, or to bypass safety and
usage controls;
- use platform AI capacity as a general-purpose AI gateway — reselling access,
routing non-survey workloads through probes/translations/imports, or synthetic
traffic designed to farm metered LLM/voice usage;
- use the AI interviewer to generate or elicit content that would violate Section 1
if authored directly;
- systematically scrape or extract AI outputs to train or improve a competing
product;
- field AI "respondents" or bots as if they were human participants, or otherwise
fabricate respondent data (fraud detection may flag and reject such sessions);
- use AI-generated survey instruments or AI-coded analyses unreviewed in clinical,
safety-critical, or regulated-decision research — such research requires human
review and approval of the instrument and the analysis before reliance (see ToS
§10.3).
5. Platform integrity
You may not:
- probe, scan, or test the security of the platform without prior written
authorization (responsible disclosure: security@interviewerai.app );
- attempt to bypass organization isolation, authentication, usage caps, metering, or
billing;
- interfere with service operation (excessive automated load outside documented API
use, denial-of-service, abuse of test endpoints);
- share, sell, or transfer accounts or API keys outside your organization;
- use another customer's or respondent's credentials or session identifiers.
6. Enforcement
- Graduated response. Depending on severity: warning with cure period →
feature/project suspension → organization suspension → termination (ToS §§8–9).
Egregious cases (fraud, security attacks, illegal content, respondent harm) may be
suspended immediately without notice.
- In-flight respondents. Where reasonably safe, respondent sessions in progress
are allowed to complete before enforcement takes effect.
- Reporting. Suspected violations can be reported to
abuse@interviewerai.app . A "Report this survey" link on the respondent
surface is planned .
- Cooperation. We may preserve and disclose information about violations where
required by law, and will notify affected customers (as controllers) of respondent-
impacting incidents per the DPA.