Acceptable Use Policy
Effective date: August 29, 2026
This policy governs how ByteSeek Tokens (operated by ByteSeek Limited) may be used, and forms part of your agreement with us together with the Service Terms. Its goals: protect service quality and account safety for normal users, and keep both the platform and its users clear of legal and upstream-compliance risk caused by misuse.
This service relies on upstream model providers (such as OpenAI and Anthropic). Do not use this service for anything that violates an upstream provider's usage policies, including but not limited to reverse engineering, system-prompt extraction, or circumventing safety limits.
Upstream providers detect and ban violating traffic. The platform runs its own risk-control detection in parallel; once a violation is detected and confirmed, the account is banned immediately with no refund, and any resulting losses rest with the violator.
Scope
This policy applies to all of the following:
- Using the ByteSeek Tokens website, console, or API;
- Creating, storing, managing, configuring, or using API keys;
- Connecting through Claude Code, Codex, OpenCode, Cherry Studio, or any other client;
- Automations, bots, applications, or other integrations built on this service.
Connecting via compatible clients, your own programs, or other integrations is not prohibited in itself — but it must not be used to bypass the platform's authentication, quotas, rate limits, security protections, or product terms.
Prohibited usage
Illegal and infringing activity
Do not use this service to conduct, assist, or promote any illegal or infringing activity, including but not limited to:
- Fraud, money laundering, gambling, illegal fundraising, pyramid schemes, or other unlawful activity;
- Manufacturing or trading prohibited goods, or obtaining instructions to do so;
- Infringing others' intellectual property, trade secrets, likeness, reputation, or other lawful rights;
- Generating or distributing content prohibited under applicable law.
Fraud, impersonation, and deception
Do not use this service to generate, distribute, or automate:
- Content impersonating real individuals, organisations, customer service, or official identities;
- Content for scams, social engineering, phishing, payment luring, or false promises;
- Content you know to be false and use to mislead, including fabricated news, fabricated evidence, or deepfakes of another person's likeness or voice;
- Bulk spam, spam marketing, fake reviews, astroturfing, or harassment;
- Content designed to interfere with elections, manipulate public opinion, or impersonate grassroots sentiment.
Harmful content
Do not use this service to create, distribute, or assist in generating:
- Any sexualised content involving minors — zero tolerance; immediate permanent ban and report as required by law;
- Content promoting or glorifying self-harm, suicide, or eating disorders, or content targeting individuals in crisis;
- Content promoting terrorism, extremism, or mass violence, or recruiting or fundraising for them;
- Hate, discrimination, harassment, threats, humiliation, or personal attacks against individuals or groups;
- Sexual exploitation, non-consensual intimate imagery, or other severely harmful content;
- High-harm instructions such as weapons development (including biological, chemical, nuclear, radiological) or explosives manufacture.
Privacy and data-rights violations
Do not:
- Illegally collect, trade, publish, or misuse others' personal information;
- Use leaked data, non-public data, or data without lawful provenance for identification, profiling, tracking, locating, or harassment;
- Conduct unauthorised surveillance, doxxing, or biometric identification of individuals;
- Generate or process content that violates others' privacy, likeness, reputation, or identity rights.
Cyberattacks and malware
Do not use this service to conduct or assist:
- Intrusion, scanning, brute-forcing, credential stuffing, phishing, privilege escalation, or other unauthorised probing or access;
- Writing, distributing, debugging, or optimising malicious code, trojans, ransomware, spyware, or other destructive programs;
- DDoS, resource-exhaustion, or other availability attacks against any system;
- Evading other systems' security protections (so-called "security testing" without the target owner's written authorisation is equally prohibited).
Fighting the platform and bypassing limits
Do not:
- Bypass or attempt to bypass the platform's authentication, quotas, rate limits, balance checks, risk controls, or security protections;
- Forge or tamper with request characteristics (client fingerprints, forged headers) to evade client or group restrictions;
- Maliciously consume platform resources through abnormal calls, idle-loop requests, or volume inflation;
- Probe internal implementation, run penetration tests, or exploit vulnerabilities (report security issues responsibly to support).
Violating upstream model providers' policies
When using this service you must also comply with the usage policies of the upstream provider behind each model. Do not:
- Reverse engineer upstream models, interfaces, or services, probe internal implementation, or extract system prompts;
- Use "jailbreaks" or similar to bypass upstream safety policies, content filters, or usage restrictions;
- Use model outputs to train or distil models that compete with the upstream provider (where its policy prohibits this);
- Take any other action that violates upstream providers' usage policies.
Account and risk-control evasion
Do not:
- Borrow, steal, or impersonate another person's account, identity, or payment instruments;
- Evade platform limits or risk controls, or farm promotion rewards (including self-referrals), through bulk registration, fake identities, or scripted flows;
- Buy, sell, rent out, or lend accounts, or use accounts for grey-market recharging or paid-on-behalf schemes;
- Top up using stolen payment instruments — accounts involved in payment fraud are frozen and handled with payment channels and law enforcement.
No redistribution
Without our express written authorisation, do not redistribute, resell, sublease, share, proxy, or repackage this service, API keys, call quota, model channels, or interface capabilities in any form, including but not limited to:
- Selling, renting, lending, or sharing API keys, quota, or model channels with third parties;
- Operating relay stations, reseller panels, shared endpoints, account pools, bot services, or anything else third parties can call;
- Wrapping this service as your own API, SaaS, plugin, client, or automation offered to third parties;
- Evading account, billing, quota, or risk-control rules through group-buying, recharge-on-behalf, agency resale, or private transfers.
Once redistribution or suspected redistribution is found, we may immediately ban the accounts involved, disable the keys, terminate service, and refuse refunds or pursue further liability as appropriate. The legitimate way to share quota across people is Teams: each member gets their own key, own limits, and auditable spending.
Data-sharing groups
If you select a group explicitly labelled "data sharing" or similar, you confirm you have the right to submit the associated inputs, outputs, and call data to the data arrangements described for that group. Do not submit through such groups:
- Unauthorised personal information, sensitive information, or private content;
- Data bound by NDAs, employment, client agreements, or other confidentiality obligations;
- Trade secrets, source code, internal documents, or other third-party materials you have no right to share;
- Data obtained illegally, through leaks, or of unknown provenance.
High-risk use restrictions
Do not use this service's output as the sole basis for decisions that materially affect individuals' rights, including but not limited to:
If you must use this service in these domains, you are responsible for ensuring qualified human review of final decisions, necessary disclosure to affected parties, and full compliance with the law of your jurisdiction. See also the Disclaimer.
API key and account security requirements
Keep your account and API keys safe, and use them only in authorised members, servers, or integration environments under least privilege:
- Never put API keys in public repositories, public clients, front-end code, or anywhere third parties can obtain them;
- Use separate keys per purpose instead of one long-lived shared key;
- On suspected leakage, immediately rotate, disable, or delete the key on the API keys page;
- Enable two-factor authentication — see Account & Security.
Calls and spending made through your account and keys are, in principle, the account holder's responsibility.
Behaviour that triggers rate-limiting
The following is not a violation, but will be automatically deprioritised or temporarily throttled:
- Abnormally high concurrency in short bursts, dense retries without backoff;
- Sustained streams of clearly invalid requests (large volumes of consecutive 4xx).
Normal traffic peaks are unaffected; contact support for higher concurrency quotas.
Boundaries of tutorials and integration guides
The docs, examples, and integration guides on this site exist solely to help users configure and use this service lawfully. They do not constitute:
- Additional authorisation for any third-party product, model, or platform;
- Permission for bypassing limits, evading risk controls, bulk abuse, or attacks;
- Any guarantee of the legality, compliance, or availability of your specific use case.
Do not use this site's docs, examples, or guides to feign official certification, fabricate partnerships, or mislead others into believing an integration method carries extra authorisation.
Enforcement
Where there is reasonable ground to believe a usage pattern may violate this policy, affect platform stability, or pose a security risk, we may take one or more of the following measures depending on severity:
- Request an explanation of the use case;
- Temporarily limit call rates, model range, or account capabilities;
- Disable the API keys involved;
- Suspend or terminate some functions or services;
- Permanently ban the account;
- Report suspected illegality to the authorities and cooperate with investigations.
We weigh known facts, risk level, and platform stability. When a restriction triggers, the console shows the reason and scope where possible.
Appeals and contact
If you believe an account, key, or request was wrongly restricted, contact support with as much of the following as possible:
- Account identifier (registered email);
- Key name or purpose;
- Time range of the issue;
- Description of the use case;
- Error messages or request IDs from usage logs.
Unused balance in banned accounts can be refunded on request, provided fraud and malicious violation are ruled out.
Updates
We may update this policy in response to business, risk-control, legal, or upstream-policy changes. Updated versions are published on this page with a new effective date; material changes are announced in reasonable ways such as site notices. Continuing to use the service after an update takes effect constitutes acceptance.
Related: Service Terms · Privacy Policy · Supported Regions · Disclaimer