This text needs legal review before launch. It describes how Emojisense works today, but it is not final. Text in [brackets] is still to be filled in.
This policy applies to the Service that we operate: the API, the dashboard and the hosted features. It is part of the Terms of Service. It does not limit what the MIT License lets you do with the open-source software when you run it yourself.
Keys and access
- Keep secret keys on your servers. Never put them in a web page, an app bundle or a public repository.
- Limit production publishable keys to your own origins.
- Do not use a key that belongs to someone else.
- Do not try to get around origin checks, rate limits or plan limits. For example, do not rotate keys or open many free accounts to multiply a limit.
- Do not probe, scan or attack the Service, except as "Security research" below allows.
Traffic
- Do not send traffic that is made to slow down or overload the Service.
- Do not scrape the API to copy its results. The data packs are open source: download them instead.
Custom emoji and other content
Do not upload, import or name custom emoji with content that:
- you do not have the rights to, such as logos, characters or artwork that belong to others, without permission;
- shows the sexual abuse or exploitation of children. We remove it and report it to the authorities;
- is illegal where you or your users are;
- promotes violence or terrorism, or attacks people for their race, ethnicity, religion, disability, sex, gender identity, sexual orientation or similar characteristics;
- harasses a real person, or shows a person without their permission where the law requires it;
- holds personal data, such as names, email addresses or phone numbers, in emoji names or search phrases;
- contains malware or files that are made to attack image decoders.
Text and images that your app sends
- Send only text and images that you may process.
- Do not put personal data or secrets into search texts on purpose. Searches that reach the API become anonymous statistics (see the Privacy Policy). Message text for reaction suggestions is not stored.
- Do not send images that show the sexual abuse or exploitation of children.
AI models
The Service uses AI models that run on Cloudflare Workers AI. The open data packs include vectors that EmbeddingGemma made. When you use those vectors, the Gemma Terms of Use and the Gemma Prohibited Use Policy also apply to you.
Your users
When your app lets other people use Emojisense features, for example when your tenants upload custom emoji, your own terms must forbid the same things, and you must act on reports.
Security research
We welcome security research in good faith. Report a vulnerability to [Security email]. Do not access data that is not yours, do not degrade the Service, and give us a reasonable time to fix the problem before you publish details.
Enforcement
When content or use breaks this policy, we can remove the content, revoke keys or suspend the account. When we can, we tell you first and give you time to correct the problem. We do not wait when the risk is serious or when the law does not allow it.
To report abuse, write to [Abuse email].