Last updated May 13, 2026
1. Purpose
This Acceptable Use Policy (the “Policy”) describes conduct that is prohibited when using TermHarbor. It exists to protect users, workspace administrators, customer contract data, the integrity of the Service, and responsible use of AI in contract workflows.
This Policy is incorporated into the Terms of Service and applies to every account, workspace, member, and integration that touches the Service. Workspace administrators are responsible for ensuring their members understand and follow this Policy.
2. Prohibited misuse
You must not use the Service to:
- Engage in illegal activity. Violate any applicable law, regulation, sanction, or court order.
- Attempt unauthorized access. Access, probe, or interfere with accounts, workspaces, systems, or data you are not authorized to access.
- Distribute malware. Upload, transmit, or link to viruses, trojans, ransomware, or other malicious code.
- Scrape or abuse the platform. Crawl, scrape, or harvest data, content, or rate-limited resources without authorization.
- Send spam. Use the Service to send unsolicited messages, bulk email, or unwanted communications.
- Run phishing campaigns. Impersonate TermHarbor, your counterparties, or any third party for the purpose of deceiving recipients.
- Steal credentials. Collect or attempt to collect authentication credentials, session tokens, or API keys belonging to other users.
- Conduct unauthorized security testing. Run penetration tests, vulnerability scans, or load tests against the Service without prior written permission.
- Circumvent rate limits. Bypass, evade, or interfere with usage limits, quotas, anti-abuse controls, or access tiers.
- Interfere with the Service. Disrupt, degrade, or attempt to disable the Service, its infrastructure, or other users’ access.
- Upload content without rights. Submit any document, file, or data you do not have rights or authority to process through the Service.
- Misrepresent outputs. Use AI outputs to deceive others, fabricate facts, or misrepresent the source, accuracy, or authority of generated content.
- Harm others. Use the Service to plan, support, or carry out unlawful, fraudulent, or harmful business or legal conduct.
3. Contract and data misuse
- Authority to upload. Do not upload contracts, attachments, exhibits, or supporting data that you do not have authority to process under your organization’s policies and applicable law.
- Third-party confidentiality. Do not expose third-party confidential information, trade secrets, or personal data without appropriate authorization, consent, or legal basis.
- No use to evade obligations. Do not use the Service to evade contractual, regulatory, fiduciary, or legal obligations owed by your organization or its counterparties.
- No falsification. Do not falsify, backdate, or tamper with contract records, comments, approvals, audit trails, obligations, or renewal histories.
- No mass extraction. Do not extract or export workspace data in a manner that violates the rights of counterparties, members, or your own organization’s data policies.
- Sensitive content. Limit upload of sensitive content (for example, government-restricted, regulated personal data, or material non-public information) to authorized users acting under your organization’s controls.
4. AI misuse
TermHarbor uses AI to analyze contract content, extract risk signals, identify obligations, suggest review language, and generate summaries. AI outputs are review aids and should be checked by an authorized human reviewer before business or legal decisions are made.
- No autonomous legal approval. Do not configure the Service to autonomously approve, sign, or bind your organization to any legal obligation without human review.
- No final advice without review. Do not present AI outputs to internal stakeholders or counterparties as final legal advice without review by a qualified human reviewer.
- No deceptive documents. Do not use AI features to draft contracts, redlines, or correspondence intended to deceive a counterparty about material terms, identity, or authority.
- No hiding AI uncertainty. Do not strip, disable, or obscure AI confidence indicators, citations, or human-review prompts when sharing outputs with reviewers who rely on them.
- Qualified review required. Do not rely on AI outputs in contexts where qualified legal, regulatory, or financial review is required by law, policy, or professional duty.
- No prohibited prompts. Do not use the Service to generate content that promotes illegal activity, fraud, or harm to identifiable individuals.
AI outputs are review aids, not legal advice. TermHarbor is not a law firm and does not create an attorney–client relationship.
5. Email and communication abuse
- No spam. Do not use the Service or its email-sending capabilities to send unsolicited, bulk, or harassing communications.
- No unauthorized lists. Do not import, send to, or build marketing lists from contacts who have not opted in or who have unsubscribed.
- No contact-form misuse. Do not submit fake, automated, or abusive submissions through contact, sales, support, or security forms.
- Respect unsubscribes. Honor unsubscribe and email-preference requests promptly. Do not attempt to circumvent suppression lists.
- No impersonation. Do not send communications that misrepresent the sender, the source, or the relationship between sender and recipient.
6. Enforcement
We take violations of this Policy seriously. Depending on the nature and severity of the violation, we may take one or more of the following actions:
- Warning. Notify the workspace administrator and request prompt remediation.
- Suspension. Suspend access to specific features, workspaces, or accounts while we investigate.
- Content removal. Remove or quarantine content that violates this Policy or applicable law.
- Termination. Terminate accounts for material, repeated, or willful violations.
- Reporting. Report unlawful conduct to relevant authorities where required by law or appropriate to protect users.
To report suspected misuse, abuse, or security issues, contact security@termharbor.com. To appeal an enforcement action, contact legal@termharbor.com. For general questions about this Policy, contact support@termharbor.com.