In plain language
Don't use Desert Desk to break the law, to hurt people, to pretend an AI is a human when someone asks directly, or to collect data you shouldn't be collecting. Don't deploy the widget on a site you don't control. Don't try to break the platform.
Most of this is what you'd expect. The two sections worth reading properly are section 5, on data you must not configure the widget to request, and section 8, on use cases where an AI answering wrongly could genuinely hurt someone.
This summary is for orientation only. The numbered sections are the policy.
Contents
Scope
This Acceptable Use Policy governs how the Desert Desk service may be used. It is incorporated into the Terms of Service, and breaching it is a breach of those Terms.
It applies to you, to everyone you give access to your account, and to the conduct you enable through your configuration of the widget. It also applies to conduct by your end users where you knew about it and did nothing.
Where our AI provider imposes its own usage policies on the underlying models, those apply in addition to this one.
Illegal and harmful use
You may not use the service to:
- violate any applicable law or regulation;
- promote, facilitate, or engage in violence, terrorism, or the exploitation or abuse of children;
- harass, threaten, defame, or incite hatred against any person or group;
- distribute malware, phishing content, or anything designed to compromise systems or credentials;
- infringe intellectual property or misappropriate trade secrets;
- facilitate fraud, money laundering, or the sale of stolen goods or data;
- sell or promote weapons, controlled substances, or other goods whose sale is restricted where your end users are located, without holding the necessary authorisations; or
- send unsolicited bulk messages, or use the widget as a channel for spam.
Misuse of the AI agent
The AI agent exists to answer questions about your business from a knowledge base you control. You may not:
- configure it to generate content that would breach section 2 if you wrote it yourself;
- use it as a general-purpose model endpoint unrelated to supporting your own customers — reselling inference capacity is not a permitted use;
- attempt to extract the underlying model's weights, training data, or system instructions;
- deliberately craft instructions designed to defeat the model provider's safety measures; or
- configure it to produce content that is deceptive about material facts affecting a person's money, health, safety, or legal position.
You are responsible for the instructions you write and the documents you upload. The agent will follow your configuration, which means a careless instruction becomes your liability, not a platform defect.
Deception and impersonation
You may name and style the AI agent however you like. You may not:
- claim the agent is a human being when an end user directly asks, or configure it to deny being automated;
- impersonate another business, brand, or individual;
- use the widget to conduct a transaction the end user would reasonably expect to be reviewed by a person, without disclosing that it isn't; or
- suppress or obscure disclosures that the law in your end users' jurisdiction requires for automated systems.
Several jurisdictions require affirmative disclosure that a person is interacting with a bot. Determining what applies to you is your responsibility; our AI & Bot Disclosures page explains what the product does by default.
Data you must not collect
You must not configure the widget — including the pre-chat contact form, quick prompts, or agent instructions — to solicit:
- payment card numbers, bank account details, or other financial account credentials;
- government-issued identifiers such as Social Security, passport, or driving licence numbers;
- health or medical information, or information about disability;
- passwords or authentication codes for any system, including your own;
- precise geolocation;
- biometric identifiers; or
- information about a person's race, religion, political opinions, sexual orientation, union membership, or immigration status.
The service automatically detects and masks card-like numbers that appear in conversation text, but that is a safety net, not permission. Deliberately routing sensitive data through the widget breaches this policy regardless of any redaction that happens afterwards.
You must also not use the service to knowingly collect personal information from children under 16.
Where you may deploy the widget
You may embed the widget only on websites and applications you own or are authorised to modify. You may not:
- inject it into a third party's site through a browser extension, proxy, or script you distribute;
- embed it in a way that obscures the host site's own content or misleads visitors about who operates the chat; or
- deploy it on a site whose content breaches section 2.
The same applies to tooltips, site cards, and any other on-page surface the product provides.
Technical restrictions
You may not:
- circumvent rate limits, plan restrictions, billing controls, or authentication;
- access another customer's data, or attempt to;
- scrape, crawl, or bulk-extract the service other than through the export tools and documented interfaces we provide;
- use automated means to create accounts;
- point a webhook endpoint at internal network addresses in an attempt to reach systems that aren't yours;
- load the service with traffic intended to degrade it for others; or
- conduct penetration testing or vulnerability scanning without following the process on our Trust Center.
Good-faith security research conducted in line with that process is welcome and will not be treated as a breach.
High-risk use cases
The service is a customer-support tool. It is not built, tested, or certified for situations where a wrong automated answer could cause serious harm.
You must not deploy it as the sole or primary channel for:
- medical diagnosis, triage, treatment advice, or mental-health crisis support;
- emergency services, safety-critical incident reporting, or anything a person might reach for in danger;
- legal advice, or determinations affecting someone's legal rights;
- credit, lending, insurance, housing, or employment decisions; or
- the operation or monitoring of industrial, transport, or life-support systems.
Where your business touches these areas, you may still use the service for genuine support functions — but a human must review any output that materially affects a person, and you must make the availability of a human clear.
If an end user appears to be in crisis, your configuration should route them to a human or to appropriate emergency resources rather than leaving an AI agent to respond. This is a condition of use, not a suggestion.
Responsibility for end users
Your end users will type things you did not anticipate. You are not in breach of this policy because someone sent something abusive to your widget.
You are responsible for taking reasonable steps once you become aware of a pattern — for example, if your widget is being used as a channel to distribute illegal content, or if a single party is abusing it at volume. Configure your agent sensibly, review your conversations, and act on what you find.
How we enforce this
Where we reasonably believe this policy has been breached, we may, proportionately to the seriousness:
- contact you to ask about the activity;
- require you to change a configuration;
- disable a specific feature or integration;
- suspend your account under section 8 of the Terms; or
- terminate your account and, where required, report the matter to authorities.
We will normally contact you first and give you a chance to fix the problem. We may act immediately without notice where the breach is serious, ongoing, or poses a risk to other customers, to end users, or to us.
On how we investigate. We do not routinely read customer conversations. Where we investigate a report, we access the minimum necessary to assess it, and that access is recorded in an audit log. Where content is redacted, unmasking it requires an explicit permission and a written justification.
Reporting abuse
To report a Desert Desk widget being used in breach of this policy, email legal@desertdesk.app with the website address where you saw it and enough detail for us to understand the concern.
To report a security vulnerability, use security@desertdesk.app and follow the process on our Trust Center instead.
We read every report. We may not be able to tell you the outcome, since that often involves another customer's confidential information.
Changes
We may update this policy as the product changes and as new patterns of misuse appear. The “Last updated” date at the top reflects the current version, and material changes are notified as described in the Terms of Service.