1. Scope
This policy applies to every person and organisation that accesses Rowsh, including workspace administrators, members, guests, public-form users, and API or integration users. It forms part of the Terms of Service.
2. Lawful and authorised use
You may use Rowsh only for lawful business purposes and only with authority to submit, access, communicate, or direct processing of the relevant data. You must comply with laws applicable to you, including UK sanctions, export controls, anti-bribery, data-protection, employment, intellectual-property, and electronic-communications requirements where they apply.
3. Prohibited activity
- Breaking laws, sanctions, or court orders; infringing rights; facilitating fraud; or distributing unlawful, deceptive, defamatory, or harmful material.
- Accessing another account, workspace, system, or data without authorisation, or helping another person bypass a control.
- Uploading malware, probing production systems outside the responsible-disclosure process, interfering with availability, or evading rate, security, or usage limits.
- Sending spam or unlawful marketing, impersonating another person, or distributing content that threatens, exploits, abuses, or harasses people.
- Creating, soliciting, storing, or distributing child sexual abuse material, terrorist content, trafficking content, or other illegal content.
- Scraping, reselling, reverse engineering, or automating access in a way that violates the agreement, infringes rights, or creates unreasonable load.
- Using AI features to make legally or similarly significant decisions without required transparency, safeguards, and meaningful human review, or to generate prohibited content.
- Submitting secrets, regulated data, special-category data, or criminal-offence data unless your organisation has confirmed a lawful, contractually approved use and appropriate safeguards.
4. Customer administration
Workspace administrators must configure access appropriately, respond to misuse within their organisation, preserve relevant evidence, and ensure users receive necessary instructions and notices. Customers are responsible for content, workflows, integrations, and communications they authorise.
5. Enforcement
Rowsh may investigate credible reports and proportionately restrict content, features, integrations, accounts, or workspaces where reasonably necessary to prevent harm, preserve security, comply with law, or enforce the agreement. Urgent protective action may occur before notice. Where appropriate, Rowsh will provide notice and an opportunity to correct the issue and may preserve or disclose evidence where law requires.
6. Reporting
Report abuse through the Contact page. Report security vulnerabilities under the Responsible Disclosure process. Do not include unlawful content or personal data beyond what is necessary to investigate.