Lythe

Acceptable Use Policy

Effective Date: 1 JULY 2026

1. Purpose

This Acceptable Use Policy ("Policy") sets out the rules for accessing or using Lythe products and services provided by Lythe Inc. or its applicable affiliate, including Lythe Pte. Ltd. (collectively and as applicable, "Lythe"), including Fraser Simulation Studio, websites, applications, APIs, dashboards, public demos, AI personas, subagents, simulations, automated evaluation workflows, agent orchestration tools, visual evaluation systems, bug-testing workflows, integrations, documentation, and related services (collectively, the "Services").

For use of Lythe's self-serve offerings, Lythe Inc. is the entity providing the Services worldwide. Lythe Pte. Ltd. may provide Services only where it is separately and expressly identified as the responsible entity in an applicable Order Form, customer agreement, master services agreement, Terms of Service, or other written agreement.

The purpose of this Policy is to prevent misuse of the Services, protect End Users, customers, and third parties, support lawful business research and product evaluation, reduce fraud and spam, prevent misleading synthetic research, and maintain safe, reliable, and trusted AI-powered simulation and evaluation products.

Capitalized terms used but not defined in this Policy have the meanings given to them in the Lythe AI Use Policy, applicable Terms of Service, applicable Terms of Use, or other applicable agreement.

2. Scope

This Policy applies to all customers, users, administrators, developers, contractors, agents, affiliates, and any person or entity that accesses or uses the Services.

Customers are responsible for the conduct of their users, agents, representatives, systems, integrations, campaigns, simulations, AI personas, uploaded materials, prompts, workflows, and third parties that use the Services through their account.

This Policy supplements the applicable Lythe Terms of Service, Terms of Use, Lythe AI Use Policy, Lythe Cookie Policy, Lythe Privacy Policy, Order Forms, customer agreements, and any other applicable product-specific terms that expressly incorporate or reference this Policy.

If this Policy conflicts with a signed customer agreement, the signed customer agreement controls to the extent of the conflict. Notwithstanding the foregoing, the applicable Lythe entity may take actions reasonably necessary to comply with applicable law or to protect the safety, security, integrity, or lawful operation of the Services, subject to the applicable customer agreement and applicable law.

Nothing in this Policy limits or modifies the obligations of Lythe Inc. or Lythe Pte. Ltd., as applicable, under any applicable Privacy Policy, Data Processing Addendum, data processing agreement, or applicable data protection law.

3. Customer Responsibilities

Customers are responsible for ensuring that their use of the Services complies with applicable law, industry rules, platform terms, and internal policies. This includes responsibility for websites, domains, URLs, uploaded materials, product flows, prototypes, call recordings, transcripts, conversation metadata, research materials, AI persona and subagent configuration, simulation parameters, evaluation criteria, and downstream actions or decisions triggered by the Services.

  • Use the Services only for lawful, authorized, and legitimate business purposes.
  • Obtain and maintain all required permissions, consents, notices, registrations, lawful bases, and opt-out records before uploading data, connecting or processing call audio or conversation data, running simulations, or processing personal data.
  • Ensure that AI personas, subagents, simulations, and outputs do not misrepresent who or what they are, who they represent, the source of feedback, or the purpose of an interaction or evaluation.
  • Use accurate, current, lawfully obtained, and properly permissioned customer records, research materials, uploaded files, URLs, screenshots, prototypes, product flows, call recordings, transcripts, conversation metadata, datasets, and integration data.
  • Configure appropriate human escalation paths for sensitive, high-risk, uncertain, failed, or regulated interactions, simulations, and workflows.
  • Monitor agent, simulation, and AI persona performance and investigate complaints, anomalies, policy violations, unreliable outputs, harmful outputs, hallucinations, misleading synthetic research, and abnormal usage patterns.
  • Maintain security controls for account access, API keys, integrations, CRM systems, call recordings, transcripts, conversation metadata, simulation data, uploaded materials, and generated reports.
  • Promptly notify Lythe of suspected misuse, unauthorized access, security incidents, privacy issues, legal complaints, or harmful behavior related to the Services.

4. Prohibited Uses

Customers and users may not use the Services, or allow the Services to be used, for any of the following activities.

4.1 Illegal, Harmful, or Abusive Activity

  • Any activity that violates applicable laws, regulations, court orders, sanctions, export controls, industry rules, platform policies, carrier rules, or third-party rights.
  • Harassment, intimidation, threats, stalking, coercion, hate, abuse, exploitation, targeted humiliation, or non-consensual surveillance.
  • Fraud, scams, phishing, impersonation, identity theft, extortion, blackmail, or deceptive schemes.
  • Attempts to obtain sensitive information through deception, including passwords, one-time codes, account credentials, banking details, government identifiers, authentication secrets, or private security information.
  • Activities that facilitate violence, self-harm, terrorism, human trafficking, child exploitation, or other serious harm.
  • Generating or distributing malware, unauthorized code, credential theft tools, or instructions for compromising systems.
  • Calls, messages, simulations, outputs, reports, or automated workflows that are unlawful, unsolicited, misleading, coercive, deceptive, abusive, or harmful.

4.2 Spam, Unwanted Communications, and Contact Data Misuse

  • Sending or initiating spam, unsolicited emails, messages, or other unwanted communications using the Services or outputs.
  • Failing to comply with applicable data-protection, privacy, and communication laws regarding research communications, including required notices, consents, and lawful bases for collecting or using personal data.
  • Contacting individuals or data subjects without required consent, notice, lawful basis, business relationship, or other authorization required by applicable law.
  • Using purchased, scraped, stolen, rented, misleading, outdated, or unlawfully obtained contact lists or research data.
  • Ignoring opt-outs, revocation of consent, suppression lists, deletion requests, or unsubscribe requests.
  • Using the Services, outputs, or reports to evade compliance rules, regulatory requirements, carrier rules, or platform enforcement.
  • Using misleading identities, spoofing names, rotating domain names, or concealing the origin or sponsor of research or evaluations.
  • Conducting high-volume unsolicited outreach or research communications without appropriate compliance review, lawful bases, consent records, and opt-out mechanisms.
  • Contacting individuals on do-not-contact registries, suppression lists, or other opt-out mechanisms in any applicable jurisdiction.
  • Using the Services for sales outreach, marketing communications, promotional campaigns, fundraising, or outbound lead generation unless expressly approved in writing by Lythe and conducted in compliance with applicable law, platform requirements, and Lythe policies.
  • Disguising sales, marketing, lead generation, fundraising, promotional, or debt-collection communications as feedback, support, technical support, customer success, research, or requested evaluation communications.
  • Soliciting, collecting, or processing personal data through deceptive, coercive, or misleading means.

4.3 Misrepresentation, Impersonation, and Deceptive AI

  • Making an AI persona, subagent, simulation, or automated evaluator pretend to be a specific real person without authorization.
  • Making an AI persona, subagent, simulation, or automated evaluator falsely claim to be human where disclosure is required or where non-disclosure would be deceptive or harmful.
  • Impersonating government officials, emergency services, banks, healthcare providers, legal representatives, employers, public agencies, customers, experts, public figures, protected groups, or other trusted institutions without authorization.
  • Misrepresenting the customer, sponsor, identity, research methodology, source of feedback, purpose of the simulation or evaluation, product, pricing, legal effect, or recipient obligations.
  • Using names, likenesses, identities, or customer personas without required consent and rights.
  • Using Lythe services to manipulate, pressure, or deceive vulnerable individuals, including older adults, minors, patients, consumers in financial distress, or people in emergency situations.
  • Creating, presenting, or distributing simulated feedback, AI persona responses, outputs, evaluation results, or reports as real user feedback, real customer interviews, verified market research, or statistically valid survey results without appropriate disclosure and validation.

4.4 Regulated and High-Risk Activities

The Services may not be used for regulated or high-risk activities without Lythe's prior written approval, unless Lythe expressly states in writing that prior approval is not required for a particular category of use. Any approved deployment must be supported by appropriate controls, contracts, disclosures, compliance documentation, human oversight, and legal review appropriate to the proposed use.

  • Medical diagnosis, emergency medical triage, clinical decision-making, or providing medical treatment instructions without qualified human oversight.
  • Legal advice, immigration advice, tax advice, financial advice, investment recommendations, lending decisions, insurance underwriting, or eligibility determinations without qualified human oversight and required licenses.
  • Credit, housing, employment, education, insurance, healthcare, public benefits, criminal justice, or other consequential decisions about individuals without appropriate legal basis, human review, auditability, and appeal mechanisms.
  • Political campaigning, voter persuasion, fundraising, polling, or election-related calls, messages, simulations, or targeting where disclosure, consent, registration, or caller-identification rules apply, unless approved in writing and configured to comply with applicable law.
  • Debt collection, repossession, collections outreach, or enforcement activity without written approval and compliance controls.
  • Emergency services, crisis hotlines, law enforcement dispatch, or safety-critical systems where failure, delay, hallucination, or incorrect output could cause serious harm.

4.5 Sensitive Data Misuse

  • Collecting, requesting, inferring, storing, uploading, or using sensitive personal data without a lawful basis, required consent, and appropriate safeguards.
  • Requesting passwords, authentication codes, full payment card numbers, government IDs, biometric identifiers, precise location, health information, or other sensitive data unless expressly authorized, legally permitted, and technically secured.
  • Uploading or processing personal data, call recordings, transcripts, CRM records, research data, customer feedback, product materials, or datasets that the customer is not authorized to process.
  • Using call transcripts, recordings, CRM records, customer data, research data, simulation outputs, or AI persona responses to discriminate, profile, exploit, or target individuals unlawfully.
  • Attempting to re-identify, deanonymize, or combine data in a manner that violates law, contract, or privacy commitments.

4.6 Platform Abuse, Security Abuse, and Reverse Engineering

  • Interfering with, disrupting, overloading, scanning, probing, scraping, crawling, attacking, or compromising the Services or related infrastructure.
  • Bypassing rate limits, usage caps, authentication, access controls, monitoring systems, safety filters, billing controls, or compliance controls.
  • Sharing, selling, exposing, or failing to secure API keys, access tokens, credentials, secrets, call data, simulation data, uploaded materials, or integration credentials.
  • Reverse engineering, copying, decompiling, or attempting to extract source code, model prompts, system prompts, agent orchestration logic, simulation methods, evaluation methods, scoring methods, or proprietary systems except where law expressly permits.
  • Using the Services, outputs, evaluation results, prompts, workflows, or proprietary materials to benchmark, train, improve, or build a competing product in violation of an applicable agreement or Lythe's intellectual property or contractual rights.
  • Using automated systems to create accounts, simulate usage, generate artificial simulation traffic, or manipulate billing, analytics, reputation, deliverability, conversion metrics, or platform metrics.
  • Using public demos or Services to crawl, scrape, test, evaluate, overload, or analyze third-party websites, applications, prototypes, products, or systems without authorization.

4.7 Content and Intellectual Property Misuse

  • Uploading, generating, transmitting, storing, or analyzing content that infringes intellectual property, privacy, publicity, contractual, confidentiality, or other rights.
  • Using copyrighted materials, proprietary scripts, recordings, voices, datasets, screenshots, websites, product materials, user research materials, or customer records without required rights.
  • Removing ownership notices, watermarking, audit markers, compliance disclosures, or provenance information.
  • Using Lythe services to create defamatory, deceptive, illegal, infringing, or harmful content.

5. Call and Conversation Data Requirements

Because the Services may process customer-provided call audio, call recordings, transcripts, conversation metadata, and related interaction data for the purpose of AI persona generation, simulations, research, and evaluations, customers must follow additional requirements.

5.1 Consent and Notices for Call and Conversation Data

  • Customers must have all required consents, notices, lawful bases, and authorizations before uploading, recording, transcribing, analyzing, or otherwise processing call audio, call recordings, transcripts, conversation metadata, or related interaction data through the Services.
  • Customers must comply with applicable call recording, privacy, and data-protection laws (including one-party, two-party, all-party, or other consent rules) in relevant jurisdictions.
  • Customers must maintain records of consent, lawful bases, call purposes, and required disclosures where required.
  • Customers must not upload or process call audio, call recordings, or conversation data without providing required notices or obtaining required consent.

5.2 Disclosure and Transparency for Persona Generation

  • Customers must accurately disclose the purpose of call and conversation data usage and must not misrepresent or conceal that call or conversation data may be processed by AI personas, simulations, or automated evaluators.
  • Customers must not configure AI personas, subagents, simulations, or automated evaluators to deny that they are AI, falsely claim to be human, or mislead individuals about automation.
  • Customers must use clear, accurate, and non-deceptive language about persona identity, sponsor, purpose, capabilities, and data usage.
  • Customers must ensure that there is a clear, easy path to appropriate human review or escalation where required by law, contract, or the nature of the interaction or evaluation.
  • Customers must not configure AI personas, subagents, simulations, or automated evaluators to conceal that they are automated when a reasonable person would be misled, deceived, or materially influenced by that concealment.

5.3 Human Oversight and Safety

  • Customers must configure escalation to a qualified human or appropriate reviewer for sensitive, uncertain, disputed, high-risk, or failed interactions, simulations, or evaluations.
  • Customers must not use AI personas, subagents, simulations, or automated evaluators to make final determinations in regulated, safety-critical, or consequential contexts unless expressly approved in writing by Lythe and supported by applicable legal authority, qualified human oversight, appropriate controls, and required documentation.
  • Customers must review and correct persona or evaluator behavior when they produce inaccurate, unsafe, discriminatory, or non-compliant outputs.
  • Customers must not rely on the Services as the sole system for emergencies, crisis response, or legally required human communications.
  • The Services are not designed for emergency calling, crisis response, law enforcement dispatch, medical emergencies, or any situation where delay, failure, or incorrect output could result in death, injury, or serious harm.

6. Fraser Simulation Studio Specific Requirements

Because Fraser Simulation Studio enables AI personas, simulated product feedback, automated evaluations, and product research workflows, customers must follow additional requirements.

6.1 Simulation Inputs and Permissions

  • Customers must have all rights, permissions, consents, notices, lawful bases, and authorizations required to upload, connect, analyze, evaluate, or otherwise process product materials, websites, URLs, screenshots, prototypes, landing pages, customer feedback, user research materials, CRM records, call audio, call recordings, transcripts, conversation metadata, Android application packages (APKs), datasets, files, and other inputs through Fraser Simulation Studio.
  • Customers must not upload confidential information, personal data, customer records, CRM data, call audio, call recordings, transcripts, conversation data, sensitive information, proprietary third-party materials, malicious or unauthorized APKs or executable files, or materials they are not authorized to provide unless appropriate safeguards are in place and the use is permitted by applicable agreements and law.
  • Customers must not use Fraser Simulation Studio to crawl, scrape, test, evaluate, overload, or analyze third-party websites, applications, prototypes, products, systems, digital assets, or APKs without authorization.

6.2 Synthetic Feedback and Research Claims

  • Customers must not present AI personas, simulated users, automated evaluations, synthetic feedback, simulation reports, or outputs as real people, real customer interviews, verified market research, statistically valid survey data, or guaranteed market truth unless independently validated through appropriate research methods.
  • Customers must use clear, accurate, and non-deceptive language when describing simulation outputs, assumptions, limitations, research methodology, evaluation criteria, and the synthetic nature of AI persona feedback.
  • Customers must not use AI personas or simulations to impersonate a specific real person, customer, employee, expert, public figure, or protected group without authorization.

6.3 Reliance and Human Review

  • Customers must not rely solely on simulation outputs for regulated, high-impact, consequential, safety-critical, product-launch, investment, legal, compliance, employment, housing, insurance, financial, medical, or legally binding decisions.
  • Customers must independently verify product critiques, simulated feedback, classifications, recommendations, reports, and other outputs before relying on them for consequential, regulated, or legally significant actions.
  • Customers must define evaluation goals, success criteria, failure conditions, prohibited behaviors, review procedures, and rollback procedures where simulations are used in production or externally relied-on workflows.

7. Prohibited Content, Prompts, and Configurations

Customers may not submit prompts, scripts, instructions, datasets, knowledge base content, call flows, voices, examples, simulations, evaluation criteria, AI persona configurations, or integrations that are designed to cause Lythe services to violate this Policy, bypass safety controls, deceive users, misrepresent synthetic feedback, or produce prohibited outputs.

This includes prompt injection, jailbreak attempts, hidden instructions, adversarial inputs, tool misuse, synthetic identity instructions, unauthorized persona creation, misleading research instructions, unauthorized website testing instructions, or any configuration intended to evade Lythe monitoring, safety systems, billing systems, or compliance controls.

8. Customer Data, Contact Lists, and Uploaded Materials

Customers represent and warrant that they have all rights, consents, authorizations, and lawful bases needed to upload, transmit, use, and process Customer Data through the Services. This includes customer records, research materials, user research data, product flows, websites, screenshots, prototypes, landing pages, URLs, uploaded files, call audio, call recordings, transcripts, conversation metadata, CRM records, integration data, research notes, datasets, Android APK files, and other uploaded materials.

  • Do not upload stolen, scraped, purchased, unlawfully obtained, or unauthorized customer data, research data, call recordings, transcripts, product materials, datasets, APK files, or third-party content.
  • Do not upload data subject to special legal restrictions, such as regulated personal data or call data requiring consent, unless your agreement with Lythe permits that use and required safeguards are in place.
  • Promptly delete or suppress contacts who opt out, revoke consent, or request deletion where required.
  • Keep CRM, integration, workspace, and product permissions limited to what is necessary for the intended workflow.
  • Do not use the Services to enrich, profile, or target individuals in ways that violate law or contract.
  • Do not use simulation outputs or AI persona responses to make unsupported claims about real users, market demand, product-market fit, customer intent, investment outcomes, or customer behavior.

9. Monitoring, Enforcement, and Remediation

Lythe may monitor use of the Services to detect abuse, enforce this Policy, protect the platform, comply with law, and respond to complaints. Monitoring may include review of account metadata, usage patterns, reports, complaints, logs, prompts, scripts, simulation settings, evaluation criteria, transcripts, recordings, conversation metadata, uploaded materials, outputs, and reports, subject to applicable law and customer agreements.

If Lythe believes that a customer or user has violated this Policy, Lythe may take enforcement action with or without prior notice where necessary to prevent harm, comply with law, protect the Services, respond to complaints, or prevent abuse.

Enforcement actions may include:

  • Requesting additional information, compliance evidence, consent records, proof of rights, data-source details, workflow documentation, or research methodology documentation.
  • Requiring changes to prompts, disclosures, workflows, integrations, AI personas, subagents, simulation settings, evaluation criteria, uploaded materials, or usage practices.
  • Suspending or limiting specific APIs, features, integrations, simulations, reports, workspaces, uploads, or accounts.
  • Blocking traffic, prompts, files, uploads, simulations, or outputs.
  • Removing, quarantining, or disabling content, data, configurations, reports, or workflows.
  • Reporting suspected illegal activity to appropriate authorities, service providers, affected parties, or third-party platforms where required or appropriate.
  • Terminating access to the Services.
  • Seeking indemnification, damages, or other remedies available under contract or law.

Lythe may require proof of consent, data-source details, rights documentation, workflow descriptions, simulation purpose, business identity information, recording notices, AI disclosures, human-review workflows, research methodology, evaluation criteria, and other compliance documentation before enabling or continuing any workflow, simulation, upload, or use case.

Customer indemnification obligations are set out in the applicable Terms of Service, Master Service Agreement, Order Form, or other written agreement with the applicable Lythe entity.

10. Compliance Review and High-Volume or High-Risk Use

Lythe may require compliance review before enabling or continuing certain use cases, including regulated industry workflows, political or public-sector evaluations, healthcare, financial services, insurance, debt collection, government services, processing or analyzing large volumes of call audio or conversation data, sensitive data processing, high-volume simulations or evaluations, public-facing AI persona outputs, unauthorized or third-party website, application, APK, or digital asset testing, externally relied-on research outputs, or unusual traffic patterns.

Customers must cooperate with reasonable compliance reviews and provide accurate information about their use case, lawful basis, consents or notices for call audio or conversation data processing, data processing requirements, simulation purpose, uploaded materials, research methodology, evaluation criteria, and human-review or escalation controls.

Customers must not launch, continue, or materially change any use case requiring compliance review until Lythe has provided written approval.

Lythe does not provide legal, regulatory, research, statistical, or compliance advice. Customers are responsible for obtaining their own legal, regulatory, research, and compliance advice regarding their use of the Services.

11. Reporting Abuse

Anyone may report suspected abuse, illegal activity, spam, impersonation, unauthorized call recordings or conversation data, misleading synthetic research, unauthorized website or digital asset testing, privacy concerns, security issues, or violations of this Policy to Lythe using the contacts below.

  • Abuse contact: team@lythe.ai
  • Security contact: team@lythe.ai
  • Privacy contact: team@lythe.ai

Reports should include relevant information such as account names, URLs, domain names, uploaded materials, call audio, call recordings, transcripts, conversation metadata, simulation reports, and a description of the concern.

The Lythe entity responsible for a customer's use of the Services is identified in the applicable Terms of Service, Order Form, customer agreement, or other written agreement.

12. Changes to This Policy

Lythe may update this Policy from time to time to reflect changes in the Services, legal developments, telephony requirements, AI requirements, carrier or platform requirements, safety learnings, risk controls, business practices, research abuse patterns, or other abuse patterns. Updated versions will be posted or otherwise made available to affected customers and users.

Unless otherwise required by applicable law or agreed in writing, material changes will apply prospectively from the effective date stated in the updated Policy. Continued use of the Services after the effective date of an updated Policy constitutes acceptance of the updated Policy, subject to any contrary terms in a signed customer agreement.