# Acceptable Use Policy and refusal list — handsfor.ai

**Version:** 0.1 draft for soft-launch  
**Related:** Terms of service; Authority attestation  
**Language:** British English  

This AUP forms part of our Terms. We **will refuse** jobs that fall in the refusal list. Disclaimers do not make a prohibited job acceptable.

**Product positioning:** We help Principals with **authorised** human steps in *their* workflows. We do **not** market or operate as a general-purpose captcha bypass, login bypass, or unauthorised-access service.

---

## 1. Acceptable use (examples)

Allowed when you have lawful authority and complete any required attestation:
- Physical-world errands you are entitled to request
- Phone calls you are entitled to make or receive help with
- Ambiguous judgment / triage on *your* content or business processes
- Completing a human gate, captcha, or verification **on a system or account you own or administer**, or where the owner has authorised you
- Account actions on *your* accounts where the provider’s terms allow assisted access

---

## 2. Hard refusal list (non-exhaustive)

We refuse and may report where appropriate:

### Computer misuse / unauthorised access
- Accessing accounts, emails, cloud, banking, social, or admin panels **without** authority
- Captcha, 2FA, OTP, or “human verification” to get into systems you do not own/administer
- Credential stuffing, password guessing, session hijacking, SIM-swap assistance
- Supplying tools or steps whose purpose is unauthorised access (Computer Misuse Act 1990, including related assistance offences)

### Fraud and deception
- Phishing, social engineering, impersonation of banks, government, employers, or individuals
- Romance/investment scams, mule activity, fake invoices
- Synthetic identity or forged documents

### Illegal content and serious crime
- CSAM or any sexual content involving minors
- Terrorism, extremism facilitation
- Drugs, weapons, explosives (illegal supply or instructions)
- Trafficking, violent crime planning

### Privacy / harassment
- Stalking, harassment, doxxing, covert recording where unlawful
- Unlawful surveillance or “find this person” with no lawful basis

### Financial crime
- Money laundering, layering crypto, cashing out for unknown third parties
- Acting as a money mule or payment passthrough unrelated to our service fee

### Platform / IP abuse
- Bulk creation of fake accounts to evade bans
- Clear copyright piracy fulfilment as the job’s purpose

### Other
- Anything that would require us to break UK law or evade sanctions
- Jobs with no identifiable Principal (human/org behind the agent)

---

## 3. Captcha / account / human-gate rule

**Default refuse** unless the Principal completes the **authority attestation** and we reasonably believe the attestation is true.

We may ask for proof of ownership/admin (domain WHOIS, dashboard screenshot with username, support ticket id, etc.) for higher-risk jobs.

---

## 4. Our process

1. Intake review against this list  
2. Refuse promptly if prohibited; brief reason logged internally  
3. No “complete first, check later” for high-risk access jobs  
4. Repeat offenders: ban; retain minimal fraud-prevention records  

---

## 5. Changes

We may update this list. The published version at job acceptance applies.
