Version 2026-09-07.1
This policy is part of the AFA Protocol beta terms. You accept it at the same time and it binds you the same way.
Counsel has not reviewed this document. It was written and approved by the operator of the service. A review is pending, and this paragraph will be removed when it has happened, which will change the version and the hash.
Why this document is short
Most of what a policy like this usually forbids is already impossible here, or is somebody else's rule and not ours to restate. What is left is the small set of things that would make the record worth less than nothing, plus the things that would stop the service working for other people.
Do not use the service unlawfully
Do not use AFA Protocol to break a law that applies to you, to reach a system you are not authorised to reach, or to help somebody else do either.
Do not use it to store or transmit material you are not entitled to hold.
Do not attack the record
This is the part that matters most, because the record is the entire product.
- Do not produce a record you know to be false. Recording an action that did not happen, an approval nobody gave, or a policy check that did not run, is the one use of this service that makes every other record here worth less.
- Do not attempt to alter, reorder, delete or backdate a stored record, or to make a chain read as continuous across a break that happened.
- Do not present a record as showing more than it shows. The terms list the three things a record can tell you. Quoting a record as evidence of anything else is a misuse of it, and we will say so if we are asked.
- Do not share, publish or reuse another account's records, keys or identifiers, or attempt to read them.
Do not attack the service
- Do not attempt to bypass authentication, capability scopes, rate limits, seat limits or the free-period gate.
- Do not attempt to gain access to another account, to our infrastructure, or to data that is not yours.
- Do not probe, scan or load-test the hosted service without asking us first. Ask and we will usually say yes and tell you when.
- Do not use one account or one key for parties who should not see each other's records. One key is one machine.
Do not use it where the record is safety-critical
Do not use AFA Protocol where its record would be relied on for a decision that affects someone's safety, health, or physical wellbeing, or for the operation of a system where a failure could cause injury or death.
We are stating that as a prohibition rather than a disclaimer because the distinction is real. The service has not been assessed against any safety-critical standard, none of it is designed to fail safe in the sense that field means, and a record that is unavailable during an incident is a normal outcome here and an unacceptable one there.
Keep your credentials
Sign-in codes and API keys are yours and are not to be shared.
Do not put a key in a prompt, a payload, a URL, a screenshot or a committed file. If you think a key has been exposed, revoke it and issue another; both take one call and neither needs us.
Automated use
Automated and agent-driven use is the point of this service and is expected.
Stay inside the published rate limits. If you need more, ask. A request for more is a normal conversation and not a violation of anything.
What we do about a breach
We may suspend an account that breaches this policy. We will tell you the reason at the address on the account, and where the breach can be fixed, we will say what would fix it.
A breach that is not fixed, or one that cannot be, may end the account. The beta terms say what happens then, including that you can still export.
We may report unlawful activity where we are required to.
Telling us about a problem
If you find a defect that lets somebody do any of the above, write to idgafholdingsllc@gmail.com and say so. We will not treat a report made in good faith as a breach of this policy, and finding one is worth more to us than the inconvenience of hearing about it.
Contact
Infrastructure Driven Growth And Future (IDGAF Holdings LLC)
idgafholdingsllc@gmail.com
This is the text the console shows at sign-in; the version and hash recorded with your acceptance are the ones above.
Back to the legal index