Acceptable Use Policy
Last updated 2026-09-24
This Acceptable Use Policy (the "Policy") is part of the Terms of Service between Cheetah Technologies LLC ("Cheetah Technologies", "we" or "us") and each customer of Cheetah OS (the "Service"). It applies to every customer, every User and End User (as defined in the Terms), and every demo account. Customers are responsible for making sure everyone who uses the Service under their account follows it. Capitalized terms not defined here have the meanings given in the Terms.
The Calling, Texting, Email and Recording Rules add detailed rules for outreach and recording. Where that document and this Policy both address a topic, both apply and the stricter rule controls.
1. General Rule
You may use the Service only for lawful business purposes in the commercial finance industry, in the way the Terms and our documentation describe. You must not use the Service, or help or allow anyone else to use it, to do anything that is illegal, fraudulent, deceptive, harmful, or that violates the rights of others, whether or not this Policy lists that specific conduct.
2. Illegal Lending, Funding and Collection Practices
You must not use the Service to:
- offer, arrange, broker or fund financing without every license, registration, bond or exemption the law requires;
- misrepresent the cost, terms, total repayment, factor rate, estimated APR, approval odds, funding speed, or any other material term of financing, including in business-to-business calls, texts, emails and documents;
- conceal, falsify, alter or omit any disclosure the law requires, or present a disclosure in a misleading way;
- charge or collect advance fees in violation of law, or promise a loan or funding in exchange for an upfront payment where the law prohibits it;
- evade usury, licensing or disclosure laws, including by disguising a loan as a purchase of receivables;
- use or file confessions of judgment where the law prohibits or restricts them;
- debit or attempt to debit a merchant's account without authorization, after an obligation has been satisfied, or in amounts or at times the contract does not permit;
- collect or attempt to collect amounts that are not owed, or use threats, intimidation, harassment, false statements or other abusive practices in collection, whether against a business, an owner, a guarantor or anyone else;
- conceal existing financing from a funder, or facilitate fraudulent "stacking" of financing in breach of a merchant's or funder's contract;
- offer, broker, service or collect consumer credit, consumer debt relief, debt settlement or credit repair, unless we have agreed in writing and you maintain your own compliance program for those products; or
- discriminate against any applicant on a basis prohibited by fair lending or anti-discrimination law.
3. Deceptive Practices and Identity Fraud
You must not use the Service to:
- create, alter or submit forged or falsified documents, including bank statements, tax forms, identification, applications, contracts or signatures;
- create or use synthetic, stolen or borrowed identities, or apply for financing in someone else's name without authority;
- impersonate any person, business, funder, government agency or Cheetah Technologies, or misrepresent your affiliation with any of them;
- obtain, or attempt to obtain, anyone's financial information from a financial institution or other person by false pretenses (pretexting);
- make false or unsubstantiated claims in marketing, including earnings, results, approval or "guaranteed funding" claims;
- create or publish fake reviews or testimonials, or suppress genuine ones; or
- run any scheme to defraud, including investment fraud, business opportunity fraud, or Ponzi or pyramid schemes.
4. Harassment and Harmful Conduct
You must not use the Service to harass, threaten, stalk, intimidate, bully or abuse any person; to send hateful, obscene, sexually explicit or violent content; to incite violence; to publish anyone's personal information to harm or embarrass them; or to contact anyone who has asked you to stop, except as the law permits.
5. Communications Abuse
You must not use the Service to:
- call, text, email or record anyone without the consents, disclosures and registrations the law requires, or in violation of the Calling, Texting, Email and Recording Rules;
- send spam, unsolicited bulk messages, or messages to purchased, rented, scraped, aged or shared lists that lack verifiable consent covering you;
- spoof or falsify caller ID, sender names, email headers or message origins, or present a number you are not authorized to use;
- rotate, cycle or "snowshoe" numbers, domains or sending accounts to evade carrier filtering, spam labeling, blocking or opt-outs;
- send content that carriers prohibit, including content involving sex, hate, alcohol, firearms or tobacco, or high-risk financial content that carrier rules do not permit on your registered campaign;
- ignore, delay, or work around an opt-out, a do-not-call request, or a suppression list; or
- use the Service to place calls to emergency services lines or to tie up any telephone line.
6. Data Misuse
You must not:
- access, or attempt to access, any other customer's tenant, account or data, or any data you are not authorized to access;
- upload personal information, documents or recordings that you do not have a lawful basis and all required consents and notices to collect and use;
- upload protected health information regulated by HIPAA, personal information of children under 13, or payment card numbers (except in a feature designed for them);
- use the Service to compile, sell, rent, license or share lists or profiles of merchants, owners, guarantors or other individuals, or to act as a data broker;
- use the Service as, or to operate, a consumer reporting agency, or to obtain, use or share consumer reports without a permissible purpose under the Fair Credit Reporting Act;
- share any merchant's, owner's or guarantor's information with another business through the Service to evaluate that person's creditworthiness or eligibility, except as the law allows and with any required consent;
- display, transmit or export Social Security numbers, taxpayer identification numbers or bank account numbers in a way that violates applicable law or bypasses the Service's masking and access controls;
- collect biometric identifiers (such as face geometry or voiceprints) through the Service without the notices, written consents and retention policies the law requires; or
- use data obtained through the Service for any purpose other than your legitimate business relationship with the person it concerns.
7. AI Misuse
You must not use the Service's AI features, or any content they produce, to:
- create deepfakes or any synthetic audio, image, video or document that depicts or imitates a real person, or that could be mistaken for a genuine document, without that person's written consent and a clear disclosure;
- clone or imitate the voice of any real person without that person's written consent;
- impersonate any person, or present AI-generated calls, messages or chats as coming from a human when you are asked, or where the law requires you to disclose the use of AI;
- generate fake or altered bank statements, pay stubs, tax documents, identification, reviews or other evidence;
- make, or be the sole basis for, a decision about credit, funding, employment or any other matter with a legal or similarly significant effect on a person, without review by a qualified person;
- consider or infer race, color, religion, national origin, sex, marital status, age, receipt of public assistance, or any other protected characteristic, or a proxy for one, in any credit decision;
- evaluate the creditworthiness of, or produce a credit score for, natural persons located in the European Union;
- attempt to extract system prompts, model instructions, other customers' data or confidential information through prompt injection, jailbreaking or similar techniques;
- generate content that is unlawful, defamatory, infringing, sexually explicit, or that promotes violence or self-harm; or
- use outputs to develop or train a competing AI model or product.
8. Securities and Investment Misuse
You must not use the Service, including the investor and syndication module, to:
- publish or distribute any offering of securities, participations or investments to the public, or engage in general solicitation where your exemption does not permit it;
- solicit or accept investments from anyone you do not have a lawful basis to contact;
- pay, or enable anyone to receive, transaction-based compensation for selling securities unless that person is properly registered or exempt;
- make false or misleading statements to investors about returns, risks, use of funds, defaults or performance; or
- conceal losses, misallocate distributions, or operate any scheme in which returns to earlier investors are paid from later investors' money.
9. Security and Integrity
9.1 Prohibited conduct
You must not:
- probe, scan, test or attempt to breach the security of the Service, or bypass any authentication, multi-factor authentication, rate limit, bot protection (including Cloudflare Turnstile), tenant isolation, access control or usage limit;
- attempt credential stuffing, password spraying, session hijacking or any account takeover;
- interfere with or disrupt the Service, its infrastructure, or other customers' use of it, including by denial of service attacks or by placing an unreasonable load on our systems;
- use the Service to attack, probe or disrupt any other system or network; or
- share, sell or publish credentials, API keys or access tokens.
9.2 Security testing rules
You may not perform penetration testing, vulnerability scanning or other security testing of the Service without our prior written authorization. If we authorize testing, you must follow the scope, timing and rules we set, test only your own tenant and accounts, never access or modify another customer's data, never degrade the Service, never use social engineering or physical attacks, stop immediately and tell us if you encounter data that is not yours, and keep your findings confidential until we have fixed them. [[FILL: decision whether to publish a vulnerability disclosure policy with a good faith safe harbor.]]
9.3 Reporting vulnerabilities
If you believe you have found a security vulnerability in the Service, please report it promptly to info@cheetahos.app [[FILL: dedicated security reporting address, if any]] with enough detail for us to reproduce it, and do not exploit it or disclose it publicly until we have addressed it.
10. Malware and Harmful Files
You must not upload, send or link to viruses, worms, ransomware, spyware, trojans, malicious macros, or any other code or file designed to damage, interfere with, intercept or take control of any system or data. We scan uploaded files for malware and may block, quarantine or delete any file we reasonably believe is harmful, and we may suspend the account that uploaded it while we investigate.
11. Scraping, Reverse Engineering and Automated Access
You must not:
- scrape, crawl, spider or harvest data from the Service, or use bots, scripts or other automated means to access it, except through an API or integration we make available and within its documented limits;
- copy, frame or mirror any part of the Service;
- reverse engineer, decompile, disassemble or attempt to derive the source code, models, prompts or underlying structure of the Service, except to the extent the law expressly permits despite this restriction; or
- access the Service to build or benchmark a competing product, or to copy its features, design or content.
12. Account Sharing, Resale and Circumvention
You must not share one seat among multiple people; create accounts with false information; create multiple demo or trial accounts to avoid paying; load real personal or financial data into a demo account; resell, sublicense or provide the Service to anyone outside your business (for example as a service bureau) unless we have agreed in writing; or circumvent any plan limit, usage limit or billing control.
13. Sanctions and Export
You must not use or access the Service from, or for the benefit of anyone located in, a country or region subject to comprehensive U.S. sanctions, or by or for any person on a U.S., UK or United Nations sanctions or restricted party list. You must not use a VPN, proxy or other means to hide your location to avoid our geographic restrictions. Section 32 of the Terms of Service contains the full sanctions and export terms.
14. Intellectual Property and Content
You must not upload, send or publish content that infringes or misappropriates anyone's copyright, trademark, trade secret, patent, privacy, publicity or other rights, or that is defamatory. If you believe content in the Service infringes your copyright, see Section 21 of the Terms of Service. We may suspend or terminate the accounts of repeat infringers.
15. Rules of Our Providers
The Service depends on third-party providers, including our telephony carrier, the carriers and registries that govern business text messaging, our payment processor, our hosting and infrastructure providers, email and mailbox providers, and AI model providers. Many of them have their own acceptable use rules. You must not use the Service in a way that would cause us to breach those rules, and you must comply with any rule of a provider that we pass on to you. If a provider tells us your use breaches its rules, we may act under Section 17 of this Policy even if your conduct is not otherwise listed here.
16. Reporting Abuse
If you believe someone is using the Service in violation of this Policy, including unwanted calls or texts from a number or sender that uses the Service, please email info@cheetahos.app with as much detail as you can (for example the number or sender, the date and time, and the content). We review reports and act on them, and we may share a report with the customer involved, our providers, or law enforcement where appropriate and lawful.
17. Enforcement
17.1 Our rights
We are not obligated to monitor use of the Service, but we may review account activity, communication metadata, complaint data and abuse signals to enforce this Policy, and we may review content where reasonably necessary to investigate a complaint or suspected violation. If we reasonably believe this Policy has been violated, we may, at our discretion and without liability to you:
- warn you and require you to fix the problem;
- remove, block or disable content, files, numbers, campaigns, sending mailboxes, AI features, End User portals or integrations;
- suspend or limit any User, feature or account, as described in Section 23 of the Terms of Service;
- terminate your account under Section 27 of the Terms of Service;
- preserve records relating to the violation;
- report the conduct to, and cooperate with, carriers, industry traceback groups, payment processors, regulators and law enforcement; and
- recover the costs of investigating and responding to the violation, including carrier fines and penalties passed through to us.
17.2 How we decide
We will generally act in proportion to the seriousness of the violation, and we will try to notify you and give you a chance to fix it first. However, we may act immediately and without prior notice where we reasonably believe it is necessary to prevent harm to people, to protect the Service or other customers, to meet a provider's or regulator's demand, or to comply with law. Termination for a serious or repeated violation of this Policy does not entitle you to a refund.
17.3 Your responsibility
You are responsible for any violation of this Policy by your Users and End Users, and you must indemnify us as provided in Section 26 of the Terms of Service.
18. Changes to This Policy
We may update this Policy as laws, carrier rules and risks change. We will give notice of material changes as described in Section 33 of the Terms of Service, except that we may apply stricter rules immediately where a change in law, a provider's rules or an urgent risk of harm requires it.
Contact
- Cheetah Technologies LLC
- Email: info@cheetahos.app
- Mailing address: [[FILL: mailing address]]
Report abuse, suspected violations or security issues to info@cheetahos.app.
