This Acceptable Use Policy (“AUP”) is part of the Henry Terms of Service and applies to everyone who uses Henry (the “Service”) on any surface: the web app, the iOS, Android, and desktop apps, the Slack and Microsoft Teams apps, the email channel, the texting channel, and the Agent Browser. Capitalized terms have the meanings given in the Terms of Service. If you see something that violates this policy, tell us at abuse@usehenry.ai.
1. The short version
Use Henry for legitimate work. Do not use it to harm people, break the law, break our systems, or misuse the tools and data you connect to it. You are responsible for what you and your Authorized Users do with Henry, including the actions Henry takes on your behalf after you confirm them.
2. Prohibited uses
You may not use, or allow anyone else to use, the Service to:
Illegal, harmful, or abusive activity
- Violate any law or regulation, including privacy, employment, consumer protection, anti-discrimination, export control, sanctions, intellectual property, and telemarketing laws.
- Generate, store, or distribute child sexual abuse material or any content that sexualizes minors. We report such material to the National Center for Missing and Exploited Children and to law enforcement.
- Harass, threaten, defame, stalk, or intimidate any person, or promote violence, terrorism, or hatred against individuals or groups.
- Create or spread malware, phishing content, or instructions for building weapons capable of mass casualties.
- Deceive people at scale: scams, fraud, fake reviews, impersonation of a real person or organization, or undisclosed AI-generated content presented as human where the law or context requires disclosure.
Misuse of connected tools and data
- Connect an account, channel, mailbox, phone number, or data source you do not own or are not authorized to use.
- Use Henry to access, scrape, export, or exfiltrate data from a connected tool beyond what your own permissions in that tool allow, or in violation of that tool's terms.
- Add Henry to channels or conversations to capture other people's messages when your organization's policies or applicable law (including workplace monitoring and consent laws) do not permit it.
- Submit protected health information, payment card numbers, government identification numbers, or other highly sensitive data unless your Agreement with us expressly permits it. Henry is not designed for regulated data categories such as HIPAA-covered information.
- Submit personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland without a lawful basis and, where required, our Data Processing Addendum in place.
Misuse of AI capabilities
- Make consequential automated decisions about people (employment, credit, housing, insurance, education, medical care, legal status) without meaningful human review of Henry's Output.
- Use Henry to provide legal, medical, financial, or other professional advice to third parties without a qualified professional reviewing the Output.
- Attempt to bypass, disable, or manipulate safety systems, confirmation prompts, tool permissions, or content restrictions of Henry or of the underlying model providers, including through prompt injection, jailbreaks, or hidden instructions placed in content Henry will read.
- Use Output to train, fine-tune, or benchmark a competing AI product or service, or to build a product that substitutes for the Service.
- Represent Output as human-authored where that would mislead, or remove notices that content was AI-generated where we or the law require them.
Texting channel
- Enroll a phone number you do not own, or continue to use a number after you give it up.
- Use the texting channel to send unsolicited messages, marketing, or bulk messages to other people, or to relay content to third parties who have not consented to receive it.
- Interfere with STOP, START, or HELP keyword handling, or attempt to text Henry from a number that has opted out.
Agent Browser
- Direct Henry to a website, account, or portal you do not have the right to use, or sign the browser in to an account that is not yours.
- Use the Agent Browser on a site in a way that site's terms prohibit, including where the site forbids automated access, or to evade a block, CAPTCHA, rate limit, or other access control a site has put in place.
- Buy up limited inventory or tickets for resale, create accounts or sign-ups in bulk, post spam or fake reviews, or otherwise use automation to gain an unfair advantage over other users of a site.
- Collect data from websites for resale, to build a competing dataset, or in bulk beyond what a task for your own use requires.
- Use the Agent Browser to harass, defraud, impersonate, or surveil a person, or to act on another person's account without their authority.
- Attempt to make Henry type or read a password, one-time code, or other credential, or to take an irreversible action on a website without your explicit confirmation.
Security and integrity of the Service
- Probe, scan, or test the vulnerability of the Service or any related system, or breach any security or authentication measure, except as permitted under our responsible disclosure program on the Security page.
- Access or attempt to access another customer's workspace, data, or connections.
- Reverse engineer, decompile, or disassemble the Service or its apps, except to the extent applicable law prohibits this restriction.
- Use bots, scripts, or automated means to access the Service in a way that circumvents rate limits, credit metering, trials, or plan limits, or to create accounts in bulk.
- Interfere with the Service's operation, including by sending malware, excessive requests, or content designed to crash or degrade the Service.
- Share account credentials, or allow more people to use the Service than your plan or Agreement permits.
- Resell, sublicense, or provide the Service to third parties as a service bureau or white-labeled offering without a written agreement with us.
3. Your responsibilities
- Human in the loop. Henry asks for confirmation before consequential actions in your connected tools and on websites it operates through the Agent Browser. When you (or a standing approval you configured) confirm an action, you are responsible for it as if you had performed it yourself.
- Your users. Workspace owners and admins are responsible for their Authorized Users' compliance with this policy, for configuring capture, permissions, and integrations appropriately, and for giving any notices to their team members that applicable law requires.
- Your content. You must have the rights and permissions needed for any content you submit to Henry or make available through connected tools and captured channels.
- Your integrations. Your use of each connected tool remains subject to that provider's own terms. Henry acts only within the permissions you grant.
- Your websites. Each site you direct the Agent Browser to has its own terms of use, and you are responsible for complying with them. A site may refuse automated access; Henry will not try to get around that.
4. How we enforce this policy
We may investigate suspected violations using account metadata, usage patterns, abuse reports, and automated signals. Our staff cannot read your conversations or Customer Content through our administrative tools; where an investigation requires content review, we will do so only with your consent, under legal compulsion, or where necessary to prevent imminent harm, and we will document the access.
Depending on severity, we may warn you, remove or block content, disable a channel or integration, limit features, suspend an Authorized User or Workspace, or terminate your account as described in the Terms of Service. We will try to notify you and give you a chance to fix the problem before suspending, unless the violation is severe, creates legal or security risk, or notice is prohibited. We may also report illegal activity to law enforcement and cooperate with investigations.
Our model providers have their own usage policies. Where a provider suspends or restricts our access because of your activity, we may pass that restriction on to you.
5. Reporting abuse
To report content or activity that violates this policy, email abuse@usehenry.ai with a description, the workspace or phone number involved if known, and any relevant screenshots or message identifiers. To report a security vulnerability, follow the process on the Security page.
6. Changes
We may update this policy as the Service and the law evolve. Material changes are announced on this page and, for changes that restrict existing uses, by email to workspace owners in advance. Continued use of the Service after a change takes effect constitutes acceptance.
Contact
Questions: legal@usehenry.ai