Usage Policy

Effective date: September 10, 2026

Last updated: September 10, 2026

Version: 1.0

Introduction

This Usage Policy governs use of orchcast.ai, ChannelRelay, OrchcastAI applications, APIs, integrations, models, content-generation tools, and related services (collectively, the “Services”). It forms part of the OrchcastAI Terms of Service. Capitalized terms not defined here have the meanings given in those Terms.

This Policy applies to each Customer, Authorized User, developer, administrator, contractor, agent, and other person who accesses or uses the Services through a Customer account. Customer is responsible for its Authorized Users and for activity performed with credentials, API keys, tokens, workspaces, or connected accounts under Customer’s control

Platform Responsibilities

1. Human review and accountability

The Services use artificial intelligence and automation. Inputs and Outputs may be inaccurate, incomplete, biased, offensive, non-unique, outdated, or unsuitable. Customer must apply competent human review before relying on, approving, distributing, or publishing Output. Customer not OrchcastAI is responsible for decisions, claims, disclosures, audiences, permissions, and consequences arising from Customer Content or Customer’s use of Output.

Customer must independently verify factual claims, citations, rights, legal requirements, advertising substantiation, platform compliance, and professional suitability. An OrchcastAI score, recommendation, workflow status, or approval feature is not legal, regulatory, editorial, medical, financial, accounting, or other professional approval.

2. Accounts and credentials

Credentials are for the designated Authorized User or approved service account and must not be shared outside the authorized scope. Customer must:

  • Provide accurate and current account and Authorized User information
  • Use strong unique passwords and available multi-factor authentication
  • Restrict access by role and promptly remove access that is no longer required
  • Protect API keys, OAuth tokens, refresh tokens, secrets, and connected-platform credentials
  • Never place secrets in prompts, public repositories, client-side code, shared documents, or published content
  • Notify OrchcastAI promptly at [email protected] of suspected compromise or unauthorized activity
  • Cooperate with reasonable containment, revocation, investigation, and recovery measures.

Customer may not access another person’s account without authorization, share individual credentials to avoid seat limits, or bypass authentication, authorization, approval, metering, or security controls.

3. Customer permissions and content rights

Customer must possess all rights, license, consents, releases, notices, and lawful bases needed to submit and use Customer Content and to instruct OrchcastAI and enabled providers to process it. This includes rights relating to copyright, trademarks, confidential information, personal information, publicity, likeness, voice, music, performances, guilds, residuals, and connected-platform content.

Customer must not submit sensitive personal information, regulated data, or third-party confidential information unless a written agreement expressly authorizes that category and required safeguards are operational.

4. Connected services

Customer is responsible for obtaining and maintaining the rights, license, accounts, permissions, tokens, configurations, and approvals required for each Third-Party Product.

Customer must comply with the provider’s terms, policies, rate limits, review requirements, and content rules. OrchcastAI may rely on instructions from Authorized Users acting within their apparent account permissions. Customer must configure roles, review gates, publishing destinations, and spending controls appropriately.

5. Operational monitoring

OrchcastAI may monitor metadata, usage, performance, and activity reasonably necessary to operate and secure the Services, enforce agreements, prevent abuse, investigate incidents, comply with law, and allocate shared resources. Monitoring does not create a duty to review every Input, Output, message, publication, or customer action

Acceptable Use Policy

Customer may not use the Services, directly or indirectly, to create, transform, store, retrieve, publish, transmit, target, promote, facilitate, or materially assist content or conduct described below.

1. Illegal activity and regulated misconduct

Prohibited uses include:

  • Violating applicable law, court orders, sanctions, export controls, contractual restrictions, or binding platform rules
  • Facilitating fraud, theft, extortion, money laundering, bribery, evasion, trafficking, unlawful gambling, payday lending, or sale of illegal or regulated goods
  • Meaningfully assisting the procurement, construction, deployment, or concealment of weapons intended to harm people
  • Providing instructions designed to evade law enforcement, regulatory controls, sanctions, identity verification, or safety restrictions
  • Generating or distributing material that Customer knows is unlawful in the intended jurisdiction.

2. Child safety

Customer may not use the Services for child sexual abuse material, grooming, sexualization of minors, exploitation, trafficking, predatory conduct, or content that depicts, promotes, solicits, facilitates, or normalizes sexual abuse of children. This prohibition includes synthetic, altered, illustrated, and photorealistic content.

OrchcastAI may immediately suspend access, preserve relevant evidence, and report apparent child exploitation to appropriate authorities or reporting organizations when legally required or permitted.

3. Violence, terrorism, and self-harm

Customer may not use the Services to threaten, celebrate, facilitate, coordinate, or provide operational assistance for violent wrongdoing, terrorism, violent extremism, targeted physical harm, or non-consensual injury. Customer may not encourage or instruct an individual to engage in suicide, self-harm, starvation, or dangerous challenges.

Good-faith news, documentary, prevention, recovery, academic, safety, or counter speech uses may be permitted when they do not provide operational assistance or glorify harm.

4. Hate, harassment, and exploitation

Customer may not generate or distribute content that incites hatred, discrimination, dehumanization, exclusion, or violence against a person or group based on a protected characteristic; facilitates stalking or targeted harassment; publishes private information to intimidate or harm; or exploits a vulnerable person.

This does not prohibit lawful discussion, criticism, counter speech, education, or documentation that is contextualized and not used to target or harm protected persons.

5. Sexual content and intimate privacy

Customer may not create or distribute non-consensual intimate imagery, sexual content depicting a real person without verified consent, sexual exploitation, sextortion, or content intended to facilitate sexual services where unlawful. Sexual content involving minors is always prohibited.

6. Privacy, surveillance, and biometrics

Customer may not:

  • Collect, expose, infer, identify, track, or monitor a person without lawful authority and required notice or consent
  • Reveal private contact, location, credential, financial, health, government-identifier, or other sensitive information
  • Use facial recognition, voiceprints, biometric identification, emotion recognition, or similar sensitive inference unless expressly authorized in writing and lawful
  • Conduct unlawful workplace, consumer, political, or public surveillance
  • Combine Meta Platform Data with unrelated information for undisclosed profiling
  • Sell, broker, or transfer platform data contrary to provider rules or
  • Re-identify information that OrchcastAI or another party maintains as aggregated or de-identified.

7. Deception, impersonation, and manipulated media

Customer may not

  • impersonate a person or organization without authorization or falsely imply endorsement, affiliation, approval, or origin
  • create deceptive deepfakes, cloned voices, synthetic identities, forged evidence, fake testimonials, or fraudulent documents
  • generate or coordinate fake reviews, fake engagement, fake followers, undisclosed paid endorsements, or coordinated inauthentic behavior
  • make false or misleading commercial, health, financial, legal, environmental, performance, or political claims or
  • conceal material AI involvement where disclosure is required by law, platform policy, contract, or the reasonable expectations of the intended audience.

Parody, satire, artistic, and authorized synthetic-media uses must be clearly contextualized where a reasonable person could otherwise be materially misled.

8. Spam and platform manipulation

Customer may not send unsolicited or unauthorized commercial messages; distribute chain letters; conduct abusive bulk posting; evade unsubscribe requests; scrape or harvest contacts unlawfully; circumvent rate limits; manipulate trends, rankings, search results, recommendations, or engagement metrics; or use automated accounts contrary to platform rules.

Commercial electronic messages must have the consent or lawful basis, sender identification, contact information, and functioning unsubscribe mechanism required by Canada’s Anti-Spam Legislation, applicable U.S. law, and the destination platform.

9. Intellectual property and confidential information

Customer may not infringe or misappropriate copyright, trademark, patent, trade secret, publicity, moral, database, contractual, or other rights; remove ownership notices; submit material subject to incompatible licences; or disclose confidential information without authority.

10. Cybersecurity abuse

Customer may not use the Services to develop, deploy, distribute, conceal, or facilitate malware, ransomware, spyware, credential theft, phishing, destructive code, botnets, unauthorized intrusion, exploitation, denial of service, data exfiltration, or evasion of security controls.

Customer may not probe, scan, benchmark for exploitation, reverse engineer, or test OrchcastAI or a third party without prior written authorization. Good-faith security research is permitted only under an applicable written authorization or published vulnerability-disclosure program and within its scope.

11. High-impact decisions and professional advice

Unless expressly authorized by a separate written agreement, Customer may not use the Services to make or materially support decisions about a person’s employment, housing, credit, lending, insurance, healthcare, education admissions, legal services, immigration, law enforcement, essential government services, critical infrastructure access, or other rights-impacting domain.

Customer may not provide individualized legal, medical, financial, tax, or other regulated professional advice generated through the Services without review and responsibility by a properly qualified professional and any disclosure required by law.

12. Political and civic activity

Customer may not use the Services to

  • suppress or deter lawful voting or civic participation
  • misrepresent election procedures, eligibility, dates, locations, or official results
  • target political persuasion using sensitive personal information or unlawfully obtained data
  • impersonate candidates, officials, parties, election authorities, or news organizations; • create coordinated inauthentic political engagement or
  • generate individualized political persuasion or lobbying material without a separate written authorization from OrchcastAI and compliance with applicable election, advertising, disclosure, privacy, and platform rules.

Neutral civic education, public-policy analysis, news reporting, and authorized campaign content may be permitted when lawful, accurate, properly disclosed, and subject to human review.

13. Academic and professional integrity

Customer may not use the Services to facilitate cheating, fabricate research, falsify credentials, impersonate an author, evade plagiarism controls, or misrepresent AI-generated work as independently completed human work when disclosure is required.

14. Competitive and unauthorized commercial use

Except where an agreement expressly permits it, Customer may not sell, resell, rent, lease, sublicense, timeshare, operate a service bureau with, or commercially distribute access to the Services; reproduce the product experience; use the Services to train or develop a competing generalized model; scrape or extract OrchcastAI Materials; publish non-public benchmarks; or access the Services for competitive monitoring.

Publication and Disclosure Requirements

Before publishing or distributing Output, Customer must

  • Perform meaningful human review appropriate to the risk and audience
  • Verify factual assertions and primary-source citations
  • Confirm rights, permissions, releases, license, and required attribution
  • Confirm compliance with advertising, endorsement, accessibility, privacy, intellectual-property, and platform rules
  • Avoid representing Output as independently human-created or wholly machine-created when either statement would be materially misleading
  • Disclose AI assistance where required by law, contract, professional standards, platform policy, or context
  • Identify the responsible person or organization where legally required and
  • preserve approval and substantiation records appropriate to the content and campaign.

Customer must not treat automated brand, compliance, SEO, accessibility, safety, or approval scores as a substitute for professional judgment.

Social-Media and Publishing Integrations

Customer may connect and publish only to accounts, Pages, profiles, channels, or workspaces it is authorized to manage. Customer must

  • Use provider-issued authorization and never provide third-party passwords to OrchcastAI
  • Grant only permissions reasonably necessary for enabled features
  • Configure workspace roles and approval gates before enabling publishing
  • Review the destination, audience, content, schedule, and campaign settings before approval
  • Comply with Meta, Facebook, Instagram, LinkedIn, Google, and other applicable platform rules;
  • Avoid duplicate, abusive, deceptive, or unsolicited bulk publication
  • Promptly revoke access for departed personnel and disconnect unused integrations
  • Investigate unexpected publications, permission changes, or token activity immediately.

OrchcastAI may pause a publishing integration if credentials appear compromised, permissions are excessive or invalid, a platform restricts access, activity threatens users or systems, or continued operation may violate law or provider policy

Fair Use Policy

The Services rely on shared computing, storage, AI-provider, media-processing, messaging, and integration resources. To preserve security, availability, quality, and predictable performance, OrchcastAI may apply reasonable technical parameters, rate limits, concurrency limits, file-size limits, storage limits, timeout limits, credit limits, and abuse thresholds consistent with the purchased plan, Documentation, provider constraints, and applicable order form.

Customer may not evade limits by opening duplicate accounts, sharing credentials, rotating API keys, distributing a coordinated workload across identities, automating prohibited requests, or disguising the source or nature of traffic.

If usage materially exceeds applicable limits or threatens shared resources, OrchcastAI may

  1. provide a usage warning and request corrective action where practicable
  2. temporarily queue, throttle, limit, or pause the affected operation
  3. require a plan change or additional capacity agreement or
  4. suspend the affected access under Section 7 when the issue is serious, repeated, fraudulent, or not corrected.

OrchcastAI will not impose an undisclosed automatic overage charge. Overage charges apply only when Customer has expressly enabled them after the rate and measurement method are disclosed. Customer may use available spending caps, and covered processing will stop when an enabled cap is reached.

Usage parameters may change to address security, provider, capacity, or product requirements. Material reductions to paid-plan limits will receive advance notice when reasonably practicable and as required by the Terms or applicable law.

API Service Terms

This section applies when Customer is authorized to access an OrchcastAI API.

Customer may use the API only to develop and operate authorized applications that communicate with the Services for Customer’s internal business purposes or another use expressly stated in an order form. Customer must comply with Documentation, authentication requirements, rate limits, data restrictions, and technical instructions.

Customer must:

  • Restrict API keys and secrets to personnel and systems with a legitimate need
  • Store keys in an appropriate secret-management system and never expose them in client-side applications, public repositories, logs, screenshots, prompts, or support messages
  • Rotate and revoke keys promptly after suspected exposure or personnel changes
  • Validate webhook signatures and protect callback endpoints against replay, forgery, injection, and unauthorized access
  • Use encrypted transport and reasonable access, logging, monitoring, and incident-response controls
  • Minimize data requested and retain it only for authorized purposes and
  • Promptly correct use that does not comply with Documentation or this Policy.

Customer may not use an API to replace or reproduce the OrchcastAI user experience, provide unauthorized third-party access, defeat metering or review gates, conduct abusive scraping, exceed documented limits, or enable a prohibited use. API keys remain controlled by OrchcastAI and may be restricted or revoked in connection with security response, expiration, account closure, or a permitted suspension.

Enforcement

OrchcastAI may investigate suspected violations using information reasonably necessary for security, compliance, and enforcement. Depending on severity, recurrence, intent, harm, and legal obligations, OrchcastAI may warn Customer, require remediation, remove or restrict content, revoke credentials or tokens, limit features, throttle activity, temporarily suspend access, permanently terminate access, preserve evidence, notify an affected provider, or report conduct to authorities where required or permitted by law.

OrchcastAI will generally use proportionate enforcement and provide notice and an opportunity to cure when reasonably practicable. Immediate action may be taken without advance notice when reasonably necessary to address child exploitation, credible threats of violence, malware or intrusion, fraud, compromised credentials, unlawful activity, serious privacy or intellectual-property harm, sanctions risk, platform mandates, risk to shared systems, or another urgent legal or safety concern.

OrchcastAI may retain limited enforcement records for the periods stated in the Privacy Policy to prevent repeat abuse, investigate incidents, respond to disputes, and demonstrate compliance. Enforcement does not require deletion of Customer data outside the retention, preservation, and legal-exception rules in the Privacy Policy and Terms.

Where appropriate, Customer may request review of an enforcement decision by emailing [email protected] with the subject “Usage Policy Appeal”, identifying the account, decision, relevant facts, and requested resolution. An appeal does not suspend an urgent protective measure.

Reporting Violations and Vulnerabilities

Report suspected violations to [email protected] with the subject “Usage Policy Report.” Include sufficient detail to locate and assess the activity, but do not send passwords, complete payment-card data, government identifiers, access tokens, malware, or unlawful content unless OrchcastAI provides a secure approved method.

Report suspected vulnerabilities to [email protected] with the subject “Security Report.” Do not exploit a vulnerability, access data that is not yours, disrupt service, demand payment, publicly disclose an unremediated issue, or exceed the scope of written authorization.

Changes to This Policy

OrchcastAI may update this Policy to address changes in law, provider requirements, security risks, abuse patterns, or the Services. We will post the revised version and update the date above. We will provide at least 30 days’ advance notice of a material change that reduces Customer rights or materially restricts an existing paid use, unless a shorter period is reasonably necessary for law, security, abuse prevention, or a platform requirement.

Relationship to Other Agreements

This Policy supplements the Terms of Service, Privacy Policy, Cookie Policy, Documentation, order forms, and any signed agreement. If there is a direct conflict, the signed master agreement controls, followed by the order form for its subject matter, the Terms, this Policy, and Documentation except that a stricter safety, security, privacy, sanctions, or platform requirement applies to the extent necessary to prevent harm or comply with law.

Contact

OrchcastAI 437 Helmcken Street Vancouver, British Columbia V6B 2E6, Canada Email: [email protected]

Publication Readiness Schedule

Before publication, OrchcastAI’s legal, product, security, engineering, and operations owners must confirm:

  1. the public URL, version number, effective date, and links from the Terms and product
  2. prohibited-use categories against every enabled AI and platform provider’s binding policies
  3. whether political, regulated-industry, professional advice, biometric, or sensitive-data uses require narrower prohibitions or separate agreements
  4. implemented content-reporting, security-reporting, appeal, investigation, evidence-preservation, and escalation workflows
  5. actual plan, API, file, storage, concurrency, credit, timeout, and rate-limit parameters
  6. that overage billing requires affirmative opt-in and spending caps work as described
  7. that workspace locks, throttling, token revocation, content restriction, suspension, restoration, and termination controls behave as stated
  8. that connected-platform permissions, publishing approval gates, and departed-user removal are tested
  9. that logs and enforcement records follow the published retention schedule and privacy access controls
  10. the approved vulnerability-disclosure process and secure channel for sensitive reports
  11. compliance with PIPEDA, applicable provincial privacy laws, CASL, applicable U.S. laws, sanctions and export controls, and third-party platform rules
  12. final approval by qualified Canadian and United States legal counsel.
Orchcast.ai

AI content operations for B2B marketing teams. Generate, approve, and publish from one platform.

© 2026 Orchcast.ai, Inc. All rights reserved