Acceptable Use Policy
Last updated September 10, 2026 · version 2026-09-10
Galaxy Unit runs real businesses' customers, money and paperwork. These are the rules that keep it safe for everyone on it. They are part of the Terms of Service.
Use it lawfully, for your own business
Use the product for lawful purposes, within the permissions you were given, and in line with the laws that apply to you. You are responsible for everyone you invite into your workspace and for every automation and integration you switch on.
You must not use Galaxy Unit to:
- commit or hide fraud — fake invoices, forged records, phishing, impersonation, laundering;
- violate someone else’s rights — their privacy, their intellectual property, their contract with you;
- hold or import personal information you have no right to hold, including your customers’ details;
- send messages your customers did not agree to receive, or without the identification and unsubscribe the law requires;
- make unlawful discriminatory decisions;
- breach sanctions or export rules.
Do not attack the service
- Do not try to reach another business’s workspace, another person’s account, our administrative systems, databases, source code or secrets.
- Do not bypass sign-in, permissions, rate limits, plan limits or any other safeguard.
- Do not upload or run malware, or flood, overload or destabilise the service.
- Do not run security testing against production without our written permission. If you find a weakness, tell us (choose “Security”) rather than using it; we will not pursue anyone who reports a genuine fault in good faith and gives us a fair chance to fix it.
- Do not share, sell or stuff credentials, and do not create extra accounts to dodge payment, limits, a suspension or the law.
AI and automation
The same rules apply when the AI does the typing. In addition, do not present what Copilot produced as licensed legal, accounting, tax or medical advice, or as an audited or certified result — it is none of those (see the AI & Data Use Notice). Do not prompt or automate your way toward another business’s data, our system prompts or provider keys. Do not use automation for bulk spam, list bombing, review or metric manipulation, or to destroy records you are legally required to keep.
What we may do to protect the service
We use rate limits, spam and fraud detection, anomaly detection and similar controls, and where a violation is suspected an authorised person may look at the records needed to investigate. That is a right, not a duty: we do not pre-screen every message, file, invoice or AI answer, and we do not promise to catch every abuse. We may ask you for information to verify lawful use, preserve evidence while we investigate, and cooperate with providers, payment processors, regulators and law enforcement as the law allows or requires.
What happens when a rule is broken
Depending on the risk we may warn you, ask you to fix it, remove content, throttle or block a feature (messaging, AI, automation, exports, an integration), require a password reset, suspend a person or a whole workspace, or end the account. We keep the measure as narrow as the risk allows.
For a security compromise, active fraud, malware, unlawful activity, mass spam, access to another business’s data or repeated evasion we act immediately and without notice. For a breach that can be fixed and is not urgent we normally give you a reasonable chance to fix it first. An account closed for a serious violation is not owed a refund. Our not acting on a violation today does not mean we cannot act on it later.
