Skip to content

Acceptable Usage Policy

Last updated

This policy sets out what you may and may not do with Ragextract. It applies to everyone who uses the service, and it forms part of our Terms of Use. Where the Terms of Use govern your use of our website, this policy governs your use of the service itself — what you put into it, and what you do with what comes out.

“We” and “us” means Subworkflow AI Limited. “Content” means anything you upload to the service, and anything the service produces from it.

1. Content you may not upload

You must not upload, or instruct the service to process, any content that:

  • you do not own, and do not have the necessary rights, permissions or lawful basis to share with a third-party processor;
  • infringes another person’s intellectual property, confidentiality, or privacy rights;
  • is unlawful to possess or distribute in the United Kingdom or in your own jurisdiction, including child sexual abuse material and material that incites terrorism or violence;
  • contains malware, exploits, or anything designed to damage or interfere with our service or the systems of others;
  • is subject to regulatory or contractual restrictions that our service is not certified to meet. Ragextract is not certified for and must not be used to process payment card data governed by PCI DSS, protected health information governed by HIPAA, classified or government-restricted material, or material subject to export control.

If your documents contain personal data about other people, you are the controller of that data and remain responsible for having a lawful basis to process it and to share it with us. See our Privacy Notice for how we handle it.

2. How extracted output may be used

Ragextract uses automated systems, including machine learning models, to produce answers from documents. Those answers can be wrong. The service gives every answer a citation back to the page it was read from and a confidence indicator, so that it can be verified against the source.

You must not:

  • present extracted output as verified fact, or as human-reviewed work, without having actually verified it;
  • use extracted output as the sole basis for a decision with a legal or similarly significant effect on a person — for example a decision about credit, employment, insurance, housing, immigration status, or access to a public service — without meaningful human review;
  • use the service to provide legal, financial, medical, or other professional advice without the professional judgement that such advice requires;
  • use the service to build a profile of an identified individual for surveillance, scoring, or discriminatory purposes.

3. Fair use of capacity

Credits price the work you do, so there is no usage cap to game. There are, however, limits on capacity — the size of a single upload, how many jobs run at once, and how many pages one job may contain. You must not:

  • circumvent or attempt to circumvent those limits, including by creating multiple accounts or organisations for that purpose;
  • create accounts to obtain free signup credits repeatedly, or use false identity information to register;
  • resell, sublicense or provide the service to third parties as your own product without a written agreement with us;
  • use automated means to load the service beyond what the application itself would generate, or otherwise impose an unreasonable load on our infrastructure.

4. Security and integrity

You must not:

  • access, or attempt to access, any account, workspace, document or data that has not been shared with you;
  • probe, scan or test the vulnerability of the service, or breach or circumvent its authentication or access controls, except under a security testing arrangement agreed with us in writing;
  • reverse engineer, decompile, or attempt to extract the underlying models, prompts, or source code of the service;
  • share account credentials, or allow anyone else to use your account.

If you believe you have found a security vulnerability, please report it to security@subworkflow.ai rather than exploiting or disclosing it. We will not pursue action against good-faith research that follows this route and does not access other customers’ data.

5. Reporting a breach

If you believe someone is using Ragextract in breach of this policy, email abuse@subworkflow.ai with enough detail for us to investigate.

6. How we enforce this

Where we reasonably believe this policy has been breached, we may take any of the following steps, proportionate to the breach:

  • contact you and ask you to stop;
  • remove or restrict access to specific content;
  • suspend or restrict an account, an organisation, or a specific capability;
  • terminate access under the Terms of Use;
  • report the matter to law enforcement or another competent authority where we are required or permitted to.

We will normally contact you first, unless the breach is serious, unlawful, or ongoing and harmful. Unspent credits are not refunded where an account is suspended or terminated for a breach of this policy — see our Credits Policy.

7. Changes to this policy

We may update this policy from time to time. Any updated version takes effect on the date stated at the top of this page, and continuing to use the service after that date constitutes acceptance of it.

Contact

Questions about this policy: legal@subworkflow.ai. General support: support@subworkflow.ai.