go home

Acceptable Use Policy

Last updated: 2026-08-08

1. Introduction

This Acceptable Use Policy ("AUP") governs all use of the Maestrio platform, including the web dashboard at app.maestrio.ai, the JavaScript widget SDK, the REST API, the MCP server, and any other products or services provided by Maestrio ("Service"). It applies to all customers, team members, and anyone else who accesses or uses the Service ("you").

This AUP is incorporated by reference into the Maestrio Terms of Service. Capitalised terms not defined here have the meanings given in the Terms of Service. Violations of this AUP may result in warnings, suspension of access, or termination of your account, as described in Section 7 (Enforcement) below.

2. Permitted Uses

Subject to the Terms of Service and this AUP, you may use the Service to:

  • Collect product feedback, bug reports, and feature requests from end users of your own software products.
  • Automate code changes including opening pull requests and committing code in repositories you own or have explicit written authorisation from the repository owner to modify.
  • Integrate with third-party services (such as GitHub and Linear) to which you have legitimate, authorised access.
  • Access the Service programmatically via the REST API or MCP server for purposes consistent with this AUP.

3. Prohibited Uses

You may not use the Service to:

3.1 Data and Privacy Violations

  • Submit personal data of your end users unless you have a lawful legal basis for doing so under applicable data protection law (including the GDPR, UK GDPR, LGPD, and CCPA) and have accepted the Maestrio Data Processing Agreement at registration. No separate paper signature is required for the standard Brazil-focused Service; see the DPA at /legal/dpa for the acceptance mechanism.
  • Submit special-category personal data as defined under GDPR Article 9 — including health or medical information, biometric data, political opinions, religious or philosophical beliefs, racial or ethnic origin, trade union membership, sexual orientation, or criminal history — via the widget or API without a separate written agreement with Maestrio.
  • Submit protected health information (PHI) as defined under HIPAA. Maestrio does not offer HIPAA-compliant services and does not execute Business Associate Agreements. PHI must not be submitted under any circumstances.
  • Collect feedback from individuals you know or have reason to believe are under the age of 18.

3.2 Security and Credentials

  • Submit production credentials, API secrets, private keys, auth tokens, passwords, or other sensitive authentication material in feedback content, endUserProperties fields, or any other part of the API payload.
  • Circumvent, disable, or attempt to bypass rate limits, quotas, access controls, or authentication mechanisms.
  • Attempt to gain unauthorised access to other customers' accounts, data, or environments.

3.3 Widget and API Misuse

  • Embed the widget on domains you do not own, operate, or have authorisation to represent.
  • Use the Service to collect feedback on behalf of third parties without their knowledge and without your own authorisation.
  • Access the Service using automated scrapers, bots, or other non-API means beyond normal programmatic API use.

3.4 AI Agent Misuse

  • Use Maestrio agents to open pull requests, commit code, or make any modifications to repositories without the explicit authorisation of the repository owner.
  • Merge AI-generated pull requests from Maestrio into production systems without human review. All Maestrio-generated code must be reviewed by a qualified engineer before deployment.
  • Attempt to reverse engineer, decompile, disassemble, or extract Maestrio's source code, machine learning models, system prompts, or proprietary algorithms.

3.5 Unlawful or Harmful Content

  • Generate, transmit, store, or enable content that is illegal, defamatory, harassing, threatening, hateful, obscene, or that violates third-party intellectual property rights.
  • Use the Service in any way that violates applicable laws or regulations, including data protection, export control, and anti-money laundering laws.
  • Use the Service to gather competitive intelligence about Maestrio's technology, business, or customers.
  • Resell, sublicense, or otherwise make the Service available to third parties without Maestrio's prior written authorisation.

4. Widget & SDK Use

Customers who embed the Maestrio JavaScript widget must:

  • Keep their Maestrio API key confidential and not expose it in public repositories, client-side code bundles, or other publicly accessible locations.
  • Accurately configure the allowed domains list in the Maestrio dashboard; only domains you own or operate should be listed.
  • Inform their end users through a privacy notice, cookie banner, or other appropriate disclosure that feedback submitted via the widget is collected and processed by Maestrio, and obtain any consent required by applicable law.
  • Not use the widget or API to transmit data on behalf of third parties without appropriate authorisation.

5. AI Agent Conduct

Maestrio's AI coding agents operate on customer-provided repositories under customer authorisation. By authorising agents to access a repository, you represent that you have the right to grant such access.

You acknowledge and agree that:

  • You are solely responsible for reviewing AI-generated pull requests before merging them into any branch.
  • Maestrio does not guarantee the correctness, completeness, security, or fitness for purpose of any code generated or modified by Maestrio agents.
  • AI-generated code may contain bugs, security vulnerabilities, or other errors. Human review is required before deployment to production.
  • Agents may fail, time out, produce unexpected output, or require re-running. Maestrio is not liable for consequences arising from automated code changes that are merged without review.

6. Reporting Violations

If you become aware of any use of the Service that appears to violate this AUP, please report it to [email protected]. Messages sent to this address are routed to the same legal mailbox. Include as much detail as possible — account identifiers, timestamps, and a description of the suspected violation.

Maestrio will investigate all credible reports and take appropriate action, which may include removing content, suspending or terminating accounts, and referring matters to law enforcement where required.

7. Enforcement

Maestrio reserves the right to investigate suspected violations of this AUP at any time. Where Maestrio reasonably determines that a violation has occurred or poses an imminent risk of harm to the Service, other customers, or third parties, Maestrio may:

  • Issue a warning and request that the violating activity cease immediately.
  • Suspend access to the Service, in whole or in part, with or without prior notice.
  • Terminate the customer's account and any associated subscriptions.
  • Remove or disable access to content or data that violates this AUP.
  • Report the activity to relevant law enforcement or regulatory authorities.

Customers are responsible for the acts and omissions of their team members, employees, contractors, and end users in connection with the Service. Maestrio's enforcement decisions are final.

8. Changes to This Policy

Maestrio may update this AUP from time to time. For material changes, Maestrio will notify you via email to your registered address, at least 30 days before material changes take effect. In-app notices may be provided as a supplemental channel. For minor or clarifying changes, Maestrio may update this AUP without advance notice.

Continued use of the Service after the effective date of any update constitutes your acceptance of the revised AUP. If you do not agree with a change, you must stop using the Service before the change takes effect.

This Acceptable Use Policy is part of the Maestrio legal framework. See also the Terms of Service, Privacy Policy, and Cookie Notice.