Acceptable Use Policy
What you may not do with Agily. Incorporated into the Terms of Service.
Last updated: 2026-09-12 · Effective: 2026-09-12
We are finalizing our legal documentation ahead of general availability. These pages describe our current practices; contact legal@agily.app with any questions.
This policy applies to everyone who uses the Agily Service. It is incorporated into the Terms of Service; “Customer”, “Authorized User”, “Service”, and “Customer Data” have the meanings given there. Customer is responsible for its Authorized Users’ compliance.
1. Prohibited content and conduct
You may not use the Service to:
Illegal or harmful content
- store, transmit, or process content that is illegal, that infringes or misappropriates another party’s intellectual property, privacy, or publicity rights, or that is defamatory, harassing, threatening, or hateful;
- store or transmit child sexual abuse material, or content that exploits or endangers minors;
- facilitate fraud, phishing, or other deceptive practices.
Security and integrity
- upload or transmit malware, ransomware, or other malicious code;
- attempt to gain unauthorized access to the Service, other customers’ data, or any system or network; escalate privileges; or bypass authentication, authorization, quotas, rate limits, or other access controls;
- probe, scan, or load-test the Service, or conduct penetration testing, except under a prior written authorization from us — see the coordinated-disclosure process on the Security Overview page;
- interfere with or disrupt the Service or the infrastructure that runs it (for example, through denial-of-service techniques or by generating abusive load through APIs or Integrations);
- misrepresent your identity or affiliation, or impersonate another person or entity.
Abuse of features and Integrations
- send unsolicited bulk messages (“spam”) through connected chat Integrations, or use standup/notification delivery to send content unrelated to the recipient’s work;
- use AI features to generate content that violates this policy, that is designed to deceive, or that would breach a third-party AI provider’s usage policies;
- scrape or systematically extract data from the Service other than data you are authorized to access, through supported export features;
- resell, sublicense, or provide the Service to third parties as a service bureau, or use it to build or benchmark a competing product without our written consent.
2. Prohibited data categories
Unless you have a separate written agreement with us that expressly permits it, you must not submit the following to the Service — including to free-text fields, comments, document bodies, standup answers, timesheet notes, or file attachments:
- Protected health information (PHI) or other data regulated by HIPAA or equivalent health-privacy laws. The Service is not HIPAA-eligible and we do not sign Business Associate Agreements by default.
- Full payment card numbers (PAN), card verification values, magnetic-stripe/track data, or PINs. The Service is not designed to store cardholder data.
- Government-issued identification numbers (e.g. national ID, passport, social security, tax ID, Aadhaar) except where strictly necessary and expressly agreed.
- Biometric identifiers or biometric templates.
- Special-category / sensitive personal data as defined by applicable data-protection law (racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, health data, data concerning sex life or sexual orientation) — including in the “reason” fields for leave or absence. Where your workflow requires a reason for leave, use the predefined leave-category options rather than free text.
- Data you do not have a lawful basis or the necessary rights/consents to process in a cloud service operated by us.
Customer is responsible for providing any notices to, and obtaining any consents from, individuals whose personal data appears in Customer Data.
3. Fair use and resource limits
- The Service enforces per-organization limits, including a storage allowance, AI usage ceilings, upload size limits, and API rate limits. Do not attempt to circumvent them.
- Automated or programmatic use must respect published rate limits and must not degrade the Service for others.
- We may apply reasonable technical limits to protect Service stability and other customers.
4. Monitoring and enforcement
- We do not routinely monitor the content of Customer Data. We may access it to the extent necessary to provide and secure the Service, to respond to a support request or legal process, or to investigate a suspected violation of this policy or law.
- If we believe a violation has occurred, we may remove or disable access to the offending content, throttle or suspend the affected account or feature, or — for serious or repeated violations — terminate the Agreement, in each case with notice where practicable.
- Where a violation poses an imminent risk to the Service, to us, or to a third party, we may act immediately and notify afterward.
5. Reporting abuse or a security issue
- Report abusive content or use to support@agily.app (or legal@agily.app for legal claims).
- Report a suspected security vulnerability to security@agily.app — see the Security Overview.
Questions? Email legal@agily.app. Privacy requests: privacy@agily.app. Report a security issue: security@agily.app.