Recovea Acceptable Use Policy
Last updated: 2026-06-26
1. Introduction and Scope
This Acceptable Use Policy (this "AUP") governs the access to and use of the products, application programming interfaces, command-line tools, software development kits, websites, dashboards, and related services made available by Recovea, Inc., a Delaware corporation ("Recovea," "we," "us," or "our"). Together, these are the "Service" (defined more fully in Section 10).
This AUP is incorporated by reference into, and forms a part of, the agreement under which you access the Service — whether that is Recovea's online Terms of Service (the "ToS"), a negotiated Master Services Agreement (the "MSA"), the Data Processing Addendum (the "DPA"), the BYO-Key Addendum, and/or any Order Form (collectively, with this AUP and all policies incorporated therein, the "Agreement"). Capitalized terms used but not defined in this AUP have the meanings given in the ToS or MSA. In the event of a conflict between this AUP and the body of the ToS or MSA on a matter this AUP expressly addresses, this AUP controls as to acceptable use; this control is itself subject in all cases to the order of precedence stated in Section 17.2, and to any contrary term expressly stated in the MSA or a signed Order Form.
By accessing or using the Service, the entity that contracts with Recovea (the "Customer," "you," or "your") agrees, on its own behalf and on behalf of each of its Authorized Users, to comply with and be bound by this AUP. The Service is offered to business customers only, for business and professional purposes; it is not intended for personal, family, or household use, and is not directed to individuals under 18 years of age.
Recovea is a bootstrap-funded US company; nothing in this AUP concerns investment or securities.
This AUP is not exhaustive. Recovea may identify additional prohibited conduct over time, and the absence of a specific activity from the list below does not imply that Recovea approves of it.
2. How the Service Works (Conduit Posture)
Understanding the structural posture of the Service is necessary to understand the allocation of responsibility under this AUP.
2.1 BYO-Key, in-path conduit. The Service operates on a "bring-your-own-key" model. The Customer brings and owns its own accounts, relationships, and API keys with third-party model, inference, and infrastructure providers, including (without limitation) OpenAI, Anthropic, and OpenRouter (each, a "Provider"; such keys, "Provider Keys"). The Customer contracts with, and pays, its Providers directly. Recovea acts as a neutral conduit that proxies the Customer's "in-path" traffic to and from the Customer's chosen Providers using the Customer's own Provider Keys. Recovea does not resell, mark up, sponsor, fund, or take custody of Provider tokens or Provider spend, and Recovea is not a party to the Customer's agreements with its Providers.
2.2 Providers are the Customer's recipients, not Recovea's sub-processors. The Customer's Providers are the Customer's own processors, recipients, and/or independent controllers with respect to the content the Customer transmits through them. They are not Recovea sub-processors. The Customer is solely responsible for its relationship with, and its compliance with the terms and usage policies of, each of its Providers.
2.3 No content monitoring; no moderation duty. Recovea is an infrastructure, observability, and cost-optimization conduit. Recovea does not review, monitor, moderate, filter, screen, edit, or curate the prompts, inputs, outputs, completions, embeddings, or other content that the Customer or its Authorized Users transmit to, or receive from, Providers through the Service ("Inference Content"). Recovea has no obligation to do so. Recovea's optimization features (for example, exact-cache and deduplication/single-flight) do not synthesize, author, or alter the substance of any Inference Content; such features are designed to return responses that are byte-identical to the Provider's original response, but this is a design objective and not a warranty (see Section 11). Recovea's processing of metadata and Usage Data for metering, optimization, control, reporting, and verification purposes does not constitute content monitoring or moderation. Nothing in this AUP creates, and the Customer shall not construe anything in this AUP as creating, an affirmative duty on Recovea to monitor, police, or pre-screen Inference Content or Customer conduct. Recovea's reservation of the right to act on violations (see Section 8) is a right, not an obligation.
2.4 Customer is the deployer. As between the Customer and Recovea, the Customer (and not Recovea) is the operator, developer, and/or deployer of any AI system, application, agent, or workflow that the Customer builds, configures, or runs using the Service. Recovea operates the Service as infrastructure, observability, and cost tooling; as between the parties, Recovea does not, by providing the Service, act as the provider, developer, or deployer of any AI system the Customer builds or operates, nor as a general-purpose AI model provider, and the legal and regulatory duties of such roles sit with the Customer. See Section 6.
3. Customer Responsibility for Authorized Users and Downstream Use
3.1 Authorized Users. The Customer is responsible for all activity occurring under its account and its Recovea-issued API keys. Recovea-issued keys are prefixed rcv_ (and, for certain key classes or environments, rcva_) (each such key, an "rcv\_ key," and together the "rcv\_ keys"). The Customer is responsible for the credentials of its Authorized Users, whether or not the Customer authorized that specific activity. The Customer shall: (a) ensure that each Authorized User complies with this AUP and the Agreement; (b) maintain the confidentiality and security of all account credentials, Provider Keys, and rcv\_ keys, and not share them except as permitted by the Agreement; (c) promptly disable, rotate, or revoke any credential or key that is, or that the Customer reasonably suspects may be, lost, stolen, compromised, or misused; and (d) be liable for the acts and omissions of its Authorized Users as if they were the Customer's own.
3.2 Downstream and end-user use. The Customer is responsible for the use of any application, product, agent, or service that the Customer builds on or operates through the Service, including the conduct of the Customer's own customers, end users, and other downstream recipients ("Downstream Users"). The Customer shall maintain and enforce its own acceptable-use, content, and safety policies with respect to Downstream Users that are at least as protective as this AUP and as the usage policies of the Customer's Providers, and shall take reasonable steps to prevent, detect, and remediate prohibited use by Downstream Users.
3.3 Compliance with applicable law and third-party terms. The Customer is solely responsible for ensuring that its use of the Service, its Inference Content, its applications, and its Downstream Users' conduct comply with all applicable laws, regulations, industry standards, contractual obligations, and third-party rights, in every jurisdiction in which the Customer operates or directs the Service.
4. Provider AUP Flow-Down
Because the Service operates on the Customer's own Provider Keys and routes traffic to the Customer's own Provider accounts, the Customer must independently comply with the acceptable-use, usage, content, safety, and other policies and terms of each Provider the Customer uses (each, a "Provider AUP"), as those policies may be updated by the Provider from time to time. Provider AUP obligations flow down to and bind the Customer and its Authorized Users and Downstream Users.
Without limitation: (a) conduct prohibited by a Provider AUP is also prohibited under this AUP when conducted through the Service; (b) the Customer must honor any model-specific, use-case-specific, geographic, or industry-specific restriction imposed by its Providers; (c) the Customer must respect Provider rate limits, quotas, and fair-use requirements; and (d) the Customer is responsible for monitoring changes to each Provider AUP. Recovea does not interpret, enforce, or guarantee compliance with any Provider AUP on the Customer's behalf, and Recovea's conduct of traffic does not relieve the Customer of, or constitute Recovea's assumption of, any Provider AUP obligation. A Provider's suspension, throttling, or termination of the Customer's Provider account or Provider Keys is a matter between the Customer and that Provider; Recovea is not responsible for, and disclaims all liability arising from, such actions, and the fail-open posture described in the Agreement does not guarantee continuity where a Provider has restricted the Customer.
5. Prohibited Uses — General
The Customer shall not, and shall not permit any Authorized User or Downstream User to, use the Service to engage in, facilitate, promote, or further any of the following. The Customer shall not, and shall not attempt to, directly or indirectly:
5.1 Unlawful, infringing, or harmful activity.
- (a) Violate, or encourage or enable any third party to violate, any applicable law, regulation, sanction, export control, or governmental order, or use the Service for any unlawful, fraudulent, deceptive, or malicious purpose.
- (b) Infringe, misappropriate, or violate the intellectual property, publicity, privacy, contractual, or other rights of any person, including by transmitting content that the Customer does not have the right to transmit.
- (c) Transmit, generate, store, or distribute content that is defamatory, libelous, harassing, threatening, abusive, or that constitutes unlawful hate speech, incitement to violence, or unlawful discrimination.
- (d) Create, transmit, or facilitate child sexual abuse material ("CSAM") or any content that sexually exploits, endangers, or abuses minors. Any apparent CSAM of which Recovea acquires actual knowledge will be reported to the National Center for Missing & Exploited Children (NCMEC) as required by 18 U.S.C. § 2258A, and may otherwise be reported to law enforcement, in each case as required or permitted by law.
- (e) Create or distribute non-consensual intimate imagery, or use the Service to stalk, dox, threaten, intimidate, or harm any individual.
- (f) Engage in or facilitate human trafficking, exploitation, or any activity that endangers the health or safety of others.
5.2 Security, integrity, and abuse.
- (a) Gain or attempt to gain unauthorized access to the Service, to other customers' accounts or data, to Recovea systems, or to any connected network or system; or breach, defeat, or circumvent any authentication, authorization, tenant-isolation, rate-limiting, egress-allowlist, or security measure.
- (b) Probe, scan, or test the vulnerability of the Service or Recovea systems, or conduct penetration testing, except under, and strictly in accordance with, a written authorization or a published vulnerability-disclosure/security policy. Good-faith security research conducted within the bounds of Recovea's vulnerability-disclosure process is permitted to the extent that policy provides.
- (c) Introduce, transmit, or attempt to introduce malware, ransomware, worms, time bombs, Trojan horses, or other malicious or harmful code; or use the Service to develop, host, distribute, or command-and-control such code.
- (d) Interfere with, disrupt, degrade, or impose an unreasonable or disproportionate load on the Service, Recovea's infrastructure, or any Provider's or third party's systems, including via denial-of-service or distributed-denial-of-service activity.
- (e) Impersonate any person or entity, forge or manipulate headers or identifiers, spoof or obfuscate the origin of traffic, or misrepresent your affiliation with any person or entity.
- (f) Spam, phish, or send unsolicited or unlawful bulk communications, or generate content to facilitate any of the foregoing.
- (g) Collect, harvest, or scrape personal data or other content from any source in violation of applicable law or the source's terms.
5.3 Service abuse and circumvention.
- (a) Resell, sublicense, rent, lease, time-share, or operate a service bureau with the Service, or otherwise make the Service available to third parties, except as expressly permitted by the Agreement (the BYO-Key conduit model does not authorize the Customer to repackage the Service itself for resale).
- (b) Reverse engineer, decompile, or disassemble the Service, or attempt to derive its source code, underlying ideas, algorithms, or trade secrets, except to the extent this restriction is unenforceable under applicable law.
- (c) Copy, frame, mirror, benchmark for competitive purposes, or build a competing product or service using the Service or any non-public Recovea methodology, system, or technology, except as expressly permitted by the Agreement.
- (d) Use the Service to circumvent, defeat, or interfere with metering, billing, the usage and verification records Recovea maintains (the "Ledger"), usage measurement, or any control feature (including budget caps, kill-switch, or alerts), or to falsify, tamper with, or manipulate Usage Data or Ledger records.
- (e) Submit synthetic, artificial, or manipulative traffic for the purpose of inflating, deflating, or distorting metering, cost measurement, savings measurement, scoring, or verification outputs.
- (f) Misuse another customer's or a third party's Provider Keys, credentials, or account, or transmit credentials you are not authorized to use.
- (g) Use any output of the Service, any Usage Data, or any Ledger record to train, fine-tune, or develop any machine-learning model, or to build a dataset or benchmark for any such purpose, except as expressly permitted by the Agreement.
5.4 Misuse of credentials and keys. The Customer shall not embed, expose, log, or transmit Provider Keys, rcv\_ keys, or session tokens in any insecure manner, nor use Recovea credentials to access Providers other than as intended by the Service. The Service is designed to strip inbound rcv_/rcva_ prefixes before any upstream call; this is a design objective and not a warranty (see Section 11), and the Customer remains responsible for the security and lawful use of its Provider Keys.
5.5 Regulated and special-category data. Unless separately agreed by the parties in a signed writing, the Customer shall not submit to or transmit through the Service any protected health information governed by the Health Insurance Portability and Accountability Act (HIPAA), payment-card / cardholder data subject to PCI DSS, biometric identifiers, government-issued identification numbers, data of or directed to children, or other special-category, sensitive, or regulated data. Recovea is not a HIPAA Business Associate, and the Service is not HIPAA-validated or PCI-validated. The Customer is solely responsible for compliance with all laws applicable to such data and for not transmitting it through the Service except as expressly agreed in a signed writing.
6. Prohibited AI Uses, Excluded Uses, and Regulated Domains
In addition to the general prohibitions above, and because the Service conducts AI inference traffic, the following AI-specific rules apply. These rules are designed to align with Provider AUPs and with applicable AI governance frameworks, including the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) and the Colorado Artificial Intelligence Act (Colo. Rev. Stat. § 6-1-1701 et seq.) and analogous US state laws, to the extent they apply to the Customer's deployment. As the deployer/operator, the Customer — not Recovea — bears responsibility for determining the applicability of, and complying with, all such laws.
6.1 Prohibited AI practices. The Customer shall not use the Service to develop, train, operate, or deploy any AI system, model, application, or agent that:
- (a) deploys subliminal, manipulative, or deceptive techniques that materially distort behavior in a manner that causes or is reasonably likely to cause significant harm;
- (b) exploits the vulnerabilities of a person or group due to age, disability, or a specific social or economic situation, in a manner that causes or is reasonably likely to cause significant harm;
- (c) performs social scoring leading to detrimental or unjustified treatment in unrelated contexts or disproportionate to the underlying behavior;
- (d) performs unlawful biometric categorization to infer sensitive attributes (such as race, political opinions, trade-union membership, religious or philosophical beliefs, sex life, or sexual orientation), or untargeted scraping of facial images to build or expand facial-recognition databases;
- (e) conducts emotion inference in workplace or educational settings except where permitted by law for medical or safety reasons;
- (f) conducts real-time remote biometric identification in publicly accessible spaces, or individual criminal-offense risk assessment based solely on profiling, except as permitted by law; or
- (g) is otherwise prohibited under Article 5 of the EU AI Act or any analogous prohibition under applicable law.
6.2 Excluded Uses (safety-critical) — prohibited. The Service is general-purpose infrastructure and is not designed, validated, intended, or authorized for use in any context where failure, error, inaccuracy, unavailability, or a degraded or unverified output could lead to death, personal injury, or severe physical, environmental, financial, or rights-based harm (each, an "Excluded Use"). Excluded Uses are prohibited and include, without limitation: the operation of safety-critical systems, life-support, medical devices, clinical decision-making or diagnosis, emergency services, aircraft or other vehicle navigation or autonomous control, nuclear or critical-infrastructure operation, weapons systems, and law-enforcement or military targeting. Recovea makes no representation that the Service is suitable for any Excluded Use, disclaims all such suitability, and may decline to support, or may restrict, such use.
6.3 Regulated high-risk domains — permitted subject to deployer obligations. Separate and distinct from the Excluded Uses prohibited in Section 6.2, the following are domains that applicable AI law (for example, Annex III of the EU AI Act) and/or Provider AUPs treat as "high-risk" or sensitive. Use of the Service in these domains is permitted but is conditioned on the Customer's satisfaction of all applicable deployer, developer, operator, and provider obligations and requires heightened Customer diligence: employment and worker management; education and vocational training; access to and enjoyment of essential private and public services and benefits (including credit, insurance, and emergency services); creditworthiness or insurance risk assessment of natural persons; biometrics; critical infrastructure; law enforcement, migration, asylum, and border control; administration of justice; and the provision of legal, medical, financial, or other professional advice to consumers.
Section 6.3 permits use in the listed domains only to the extent the use is not an Excluded Use under Section 6.2; in any conflict, Section 6.2 controls. In this Section 6.3, "emergency services" refers to determinations of eligibility for and access to such services (for example, benefits or coverage determinations) — not the operation, dispatch, triage, or clinical delivery of emergency or medical care, which are and remain Excluded Uses under Section 6.2.
If the Customer uses the Service in any regulated high-risk domain under Section 6.3, the Customer represents, warrants, and covenants that it does so at its own risk and that it shall: (a) be solely responsible for all deployer, developer, operator, and provider obligations under applicable AI law (including transparency, human oversight, risk management, logging, impact assessment, accuracy, robustness, and post-market-monitoring duties); (b) implement appropriate human review, fail-safes, testing, validation, and monitoring suited to the risk; (c) make all legally required disclosures to affected individuals; (d) not rely on the Service or any Provider output as the sole basis for any decision producing legal or similarly significant effects on a natural person; and (e) ensure its use is permitted by each applicable Provider AUP.
6.4 Other prohibited AI uses. The Customer shall not use the Service to: generate or facilitate disinformation, election interference, or unlawful political manipulation; impersonate a real individual or generate deceptive synthetic media ("deepfakes") without clear and lawful disclosure; provide individualized legal, medical, or financial advice in a manner that violates applicable professional-licensing or consumer-protection law; generate content that facilitates the development, acquisition, or use of weapons (including chemical, biological, radiological, nuclear, or high-yield explosive weapons) or other instruments designed to cause mass harm; facilitate illegal surveillance; or engage in any use prohibited by an applicable Provider AUP.
6.5 No automated individual decision-making by Recovea. Recovea's routing, caching, deduplication, metering, and control functions operate on metadata and traffic patterns; they are not designed to, and Recovea does not use them to, perform individual automated decision-making about, or profiling of, natural persons. Any automated decision-making with legal or similarly significant effects is performed, if at all, by the Customer's own application and is the Customer's responsibility.
7. Rate, Volume, and Resource Limits
7.1 Limits. The Customer's use of the Service is subject to the rate limits, request quotas, concurrency limits, payload-size limits, and other technical or volumetric limits set out in the Order Form, in product documentation, or as otherwise communicated by Recovea, and to the limits imposed by the Customer's own Providers. Recovea may set, modify, and enforce reasonable limits to protect the stability, security, performance, and integrity of the Service and to ensure fair use across customers.
7.2 Fair use and protective throttling. Recovea may throttle, queue, rate-limit, or temporarily restrict traffic that, in Recovea's reasonable judgment, is abusive, anomalous, automated beyond fair use, or that threatens the availability, security, or integrity of the Service or of any Provider or third-party system. Such protective measures are not a breach of the Agreement and do not constitute an availability commitment. The Service is provided on a best-effort, fail-open basis with no contractual uptime commitment, no service credits, and no guarantee of availability, throughput, or latency, except as may be expressly stated in an applicable Order Form or service level agreement.
7.3 No circumvention of limits. The Customer shall not use multiple accounts, automated key rotation, distributed traffic sources, or other techniques to evade, reset, or exceed applicable limits.
8. Enforcement, Suspension, and Remedy Ladder
8.1 Right, not obligation. Recovea has no duty to monitor for violations of this AUP, and Recovea's enforcement is discretionary. Recovea's failure to enforce any provision of this AUP in a given instance is not a waiver of its right to enforce that or any other provision later.
8.2 Remedy ladder. Where Recovea becomes aware of conduct that it reasonably believes violates this AUP, or that exposes Recovea, its customers, its Providers, or third parties to legal, security, reputational, or operational risk, Recovea may take one or more of the following actions, generally in proportion to the severity, frequency, and risk of the conduct, but in any order Recovea reasonably deems appropriate:
- Notice. Notify the Customer of the violation and request that the Customer cure it within a stated period.
- Restriction or throttling. Restrict, throttle, rate-limit, disable a feature, or block specific traffic, endpoints, models, or use cases.
- Suspension. Suspend the affected Authorized User's, endpoint's, key's, or the Customer's access to all or part of the Service.
- Removal or disablement. Disable a key, revoke a credential, or remove access to specific functionality.
- Termination. Terminate the affected Order Form, subscription term (as defined in the ToS or MSA), or the Agreement in accordance with its terms.
- Reporting and referral. Report conduct to the affected Provider, to law enforcement, or to other authorities, and cooperate with lawful investigations, as required or permitted by law.
8.3 Immediate action. Notwithstanding the ladder above, Recovea may suspend or restrict access immediately and without prior notice where Recovea reasonably determines that: (a) the conduct poses a material, imminent, or ongoing threat to the security, integrity, availability, or lawful operation of the Service, of other customers, of any Provider, or of third parties; (b) the conduct is unlawful or exposes Recovea or others to legal liability; (c) a Provider, court, or governmental or regulatory authority requires it; or (d) the conduct involves CSAM, credible threats of harm, or other egregious abuse. Recovea will use commercially reasonable efforts to provide notice promptly thereafter where lawful and practicable, and to limit any suspension to the offending traffic, user, key, or use case where reasonably feasible.
8.4 Restoration. Recovea will restore suspended access promptly after the Customer has, to Recovea's reasonable satisfaction, cured the violation and taken reasonable steps to prevent recurrence, unless Recovea has terminated the Agreement.
8.5 No liability; no credits. Recovea is not liable to the Customer or any third party for any action taken in good faith under this AUP, and the Customer is not entitled to any fee credit, refund, or compensation for any period of suspension, restriction, or termination resulting from the Customer's violation of this AUP. The Customer remains responsible for all Fees accrued and for any Provider charges incurred through the Customer's own Provider accounts.
8.6 Cooperation. The Customer shall reasonably cooperate with Recovea to investigate and remediate suspected violations and to mitigate harm.
9. Honesty Bar and Anti-Attribution (No Misrepresentation of Recovea Verification)
9.1 No misrepresentation of verification. Recovea reserves to itself the exclusive right to designate any savings, cost, efficiency, quality, or other figure or claim as "verified," "settled," or "proven," and to do so only in writing and only where Recovea's methodology supports the designation. The Customer shall not, and shall not permit any Authorized User or Downstream User to:
- (a) state, suggest, or imply that any output, savings figure, cost figure, efficiency figure, result, model, application, or third-party offering has been verified, validated, certified, attested, scored, audited, endorsed, or approved by Recovea, or carries any Recovea verification status, unless Recovea has in fact issued such a designation in writing and it remains in effect;
- (b) display, reproduce, or use any Recovea trust mark, badge, seal, score, certification, attestation, verification status, or designation that Recovea may issue, or the Recovea name or logos, except as and to the extent Recovea has expressly authorized in writing and strictly in accordance with Recovea's then-current brand and usage guidelines;
- (c) alter, forge, fabricate, backdate, or misrepresent any Ledger record, verification artifact, score, badge, certificate, or attestation, or present a draft, expired, revoked, conditional, or "proof-pending" status as final or verified;
- (d) characterize any Recovea estimate, measurement, or "applied"/"measured" figure as "verified" or guaranteed, it being understood that any savings, cost, or efficiency figure is an estimate unless Recovea has expressly designated it "verified" in writing; or
- (e) make any public statement attributing a capability, certification, maturity, customer count, ranking, standard-setting, or authority status to Recovea that Recovea has not expressly and accurately stated in writing.
9.2 Provider and third-party attribution. The Customer shall not misrepresent its relationship with, or the endorsement of its offering by, any Provider or other third party.
9.3 Enforcement. Violation of this Section 9 is a material breach. In addition to the remedy ladder in Section 8, Recovea may require immediate correction or retraction of any non-compliant statement or display, and may pursue any available remedy at law or in equity, including injunctive relief, for misuse of its marks or misrepresentation of its verification.
10. Reservation of Rights; Evolving Service
Recovea reserves all rights not expressly granted. The "Service" is an umbrella that includes, without limitation, spend metering and observability; cost optimization; spend control (including budget caps, kill-switch, and alerts); reporting and analytics; SDKs and APIs; related managed services; and any additional features or capabilities Recovea may develop or make available from time to time. Any such capability is governed by the terms in effect when Recovea makes it available and is not active or licensed under this AUP unless Recovea expressly states otherwise. Recovea may, at its discretion, add, modify, discontinue, or restrict features, models, endpoints, and capabilities, and may offer subscription, usage-based, and savings- or outcome-based pricing models; any savings- or outcome-based model applies only on the Customer's separate, affirmative election, and subject to the Agreement and to any required consent. This AUP applies to all such current and future capabilities. Nothing in this AUP commits Recovea to release, or to any timing for, any capability, and any categories described herein are capabilities Recovea may offer, not commitments.
11. Disclaimers
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," WITH ALL FAULTS AND WITHOUT WARRANTY OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED BY LAW, RECOVEA DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING, USAGE, OR TRADE PRACTICE (UCC § 2-316). RECOVEA DOES NOT WARRANT, AND EXPRESSLY DISCLAIMS ANY GUARANTEE OF, ANY SAVINGS, COST REDUCTION, FINANCIAL OUTCOME, UPTIME, AVAILABILITY, OR THE ACCURACY, QUALITY, RELIABILITY, OR FITNESS OF ANY THIRD-PARTY PROVIDER OUTPUT. ANY SAVINGS, COST, OR EFFICIENCY FIGURE IS AN ESTIMATE UNLESS RECOVEA EXPRESSLY DESIGNATES IT "VERIFIED" IN WRITING. The Service is designed to fail open and to attempt to stop spend at configured caps, but such behavior is a design objective and a reversible exit, not an availability, correctness, or hard-stop warranty; Recovea does not provide mid-stream failover, and once a response begins streaming, a failure surfaces as a clean error rather than a silent splice. This Section is mirrored across, and is no narrower than, the disclaimers in the ToS, MSA, and other Agreement documents.
12. Limitation of Liability; Cap
To the maximum extent permitted by law, neither party will be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, data, or goodwill, arising out of or relating to this AUP, even if advised of the possibility. Each party's aggregate liability arising out of or relating to this AUP is subject to, and counts toward, the limitations and the aggregate liability cap (including the general cap, any fixed-dollar floor of US $25,000, the enhanced super-cap equal to two times the general cap for breaches of confidentiality and of data-protection/security obligations, and the uncapped carve-outs) set out in the MSA or ToS, which are incorporated by reference and control.
Carve-out from the damages exclusion. The exclusion of indirect, incidental, special, consequential, exemplary, or punitive damages and of lost profits, revenue, data, or goodwill in the first sentence of this Section does not apply to the Customer's breach of Section 9 (Honesty Bar and Anti-Attribution / misuse of Recovea marks or verification) or of Section 5.3(b)–(c) (reverse engineering / competitive build), which damages remain recoverable consistent with the uncapped and super-cap carve-outs in the MSA or ToS. Nothing in this AUP limits liability that cannot be limited under applicable law. This Section does not limit the Customer's payment obligations or its indemnification obligations under Section 13.
13. Indemnification
The Customer shall defend, indemnify, and hold harmless Recovea and its officers, directors, employees, agents, and affiliates (the "Recovea Indemnified Parties") from and against any third-party claim, demand, action, investigation, loss, liability, damage, fine, penalty, cost, and expense (including reasonable attorneys' fees) arising out of or relating to: (a) the Customer's, any Authorized User's, or any Downstream User's violation of this AUP, of any Provider AUP, or of applicable law; (b) the Customer's Inference Content, applications, products, or use cases (including any Excluded Use or use in a regulated high-risk domain); (c) any claim that the Customer's use of the Service, Inference Content, or downstream offering infringes, misappropriates, or violates the rights of a third party; (d) any misrepresentation of Recovea verification, certification, or marks in violation of Section 9; or (e) the Customer's relationship with, or charges incurred through, its Providers. This indemnity is in addition to, and not in limitation of, any indemnity in the MSA or ToS, and is subject to the procedures stated there (prompt notice, sole control of defense, and reasonable cooperation).
14. Intellectual Property; Confidentiality; Data and Privacy
14.1 IP. As between the parties, Recovea retains all right, title, and interest in and to the Service, the Ledger, the Recovea marks (asserted as common-law/unregistered marks until any registration issues), and all related methodology and technology. The Customer retains its rights in its Inference Content and applications, subject to the Agreement. Recovea takes no position on the ownership of Provider outputs as between the Customer and its Providers. Recovea's reservation of Aggregated/De-identified Data and methodology rights is as set out in the Privacy Notice and DPA.
14.2 Confidentiality. Each party's confidentiality obligations are governed by the MSA or ToS and, as to Customer Personal Data, the DPA. Nothing in this AUP narrows those obligations.
14.3 Data and privacy. Recovea's processing of personal data, the controller/processor split, retention, the immutable-Ledger erasure carve-out, sub-processor change notice, and data-transfer mechanics are governed by the Privacy Notice and the DPA, which control over this AUP on those subjects. Where Recovea Processes Customer Personal Data on the Customer's behalf, the DPA — including its CCPA/CPRA service-provider terms and US-state addendum — is automatically incorporated into and forms part of the Agreement. As used in this AUP, "Customer Personal Data" means personal data, personal information, or personally identifiable information (as defined by applicable data-protection law) that Recovea Processes on the Customer's behalf in connection with the Service. As to Inference Content, the Customer is the controller and Recovea is a processor acting on the Customer's documented instructions; the Customer's Providers are the Customer's own recipients and not Recovea sub-processors.
15. Term, Termination, and Survival
This AUP applies for as long as the Customer accesses or uses the Service. Termination is governed by the ToS or MSA. Sections that by their nature should survive termination — including Sections 1 (definitions and scope), 2 (conduit posture and no-monitoring disclaimer), 3, 4 (Provider flow-down), 5, 6, 8.5, 9, 10 (reservation of rights and limits), 11, 12, 13, 14, 16, and 17 — survive any expiration or termination of the Agreement.
16. Dispute Resolution; Governing Law; Venue
16.1 Arbitration and class waiver. Except for the carve-outs in Sections 16.3 and 16.4, any dispute, claim, or controversy arising out of or relating to this AUP or the Agreement will be resolved by binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules, by one arbitrator, seated in Wilmington, Delaware. Judgment on the award may be entered in any court of competent jurisdiction. The parties waive any right to bring or participate in a class, collective, consolidated, or representative action, and each party may bring claims only in an individual capacity. Each party bears its own fees as provided by the AAA Commercial Rules; the Service is a business-property service offered to business customers, and the parties intend the AAA Commercial Arbitration Rules to apply, subject to the Agreement's Consumer-Rules fallback and mass-arbitration protocol (Terms of Service §24.2 and §24.7 / MSA §23.2 and §23.6): if the AAA or a court of competent jurisdiction determines that the AAA Consumer Arbitration Rules apply to a dispute involving an individual, those rules govern that dispute and Recovea pays the filing, administrative, and arbitrator fees the AAA consumer fee schedule assigns to the business. These provisions are also stated in, and are consistent with, the dispute-resolution provisions of the ToS or MSA, which are incorporated by reference.
16.2 Governing law. This AUP is governed by the laws of the State of Delaware, excluding its conflict-of-laws rules. The United Nations Convention on Contracts for the International Sale of Goods (CISG) does not apply.
16.3 Court carve-out; equitable relief. Notwithstanding the agreement to arbitrate, either party may bring an action in the Delaware state or federal courts located in Wilmington, Delaware for: (a) injunctive or other equitable relief to prevent the actual or threatened infringement, misappropriation, or violation of intellectual property or breach of confidentiality (including, in Recovea's case, misuse of its marks or verification under Section 9); and (b) any matter within the jurisdiction of small-claims court. The parties consent to the personal and subject-matter jurisdiction and venue of those courts for such matters.
16.4 Non-parties. Where this AUP or the Agreement permits reports or complaints by persons who are not contracting parties (for example, security researchers or rights-holders submitting takedown notices), such matters are carved out of the arbitration agreement and are subject to the Delaware state or federal courts located in Wilmington, Delaware.
17. General
17.1 Modification. Recovea may update this AUP from time to time. Material changes will be communicated through the Service or by other reasonable means, and will take effect as stated in the notice or, absent a stated date, upon posting. The Customer's continued use of the Service after the effective date constitutes acceptance. The current version is always available at Recovea's legal pages.
17.2 Incorporation and precedence. This AUP is incorporated into the ToS and MSA. Order of precedence among Agreement documents is as stated in the MSA/ToS: a signed Order Form (where it so states) > MSA > DPA (for processing of personal data) > BYO-Key Addendum (for Provider Key handling, Provider terms, Provider charges, and runaway-spend allocation) > incorporated policies (including this AUP) > the ToS body.
17.3 Assignment. The Customer may not assign or transfer this AUP or any rights or obligations under it without Recovea's prior written consent, except as permitted by the ToS or MSA. Recovea may assign it in connection with a merger, acquisition, reorganization, or sale of assets. Any prohibited assignment is void.
17.4 Force majeure. Neither party is liable for any failure or delay caused by events beyond its reasonable control, as further described in the ToS or MSA. Provider outages and Provider-imposed restrictions are outside Recovea's control.
17.5 No third-party beneficiaries. This AUP is for the sole benefit of the parties and their permitted successors and assigns. No person or entity other than the parties has, or may assert, any right, claim, benefit, or remedy under this AUP, except that (a) the Recovea Indemnified Parties may enforce the indemnification in Section 13, and (b) non-party reporters described in Section 16.4 may avail themselves of the channels referenced there. For the avoidance of doubt, no Provider and no Downstream User has, or may assert, any right or remedy under or to enforce this AUP.
17.6 Notices. Notices to Recovea under this AUP may be sent to legal@recovea.ai and, by mail, to Recovea, Inc., 2810 N Church St STE 89986, Wilmington, DE 19802; abuse, security, privacy, and infringement reports may be sent to the channels in Section 18. Notices to the Customer may be sent to the Customer's account contact or as otherwise provided in the ToS or MSA.
17.7 Electronic acceptance. The parties consent to transact electronically. Acceptance of this AUP and the Agreement by clickwrap, account creation, API key issuance, or continued use has the same legal effect as a handwritten signature under the E-SIGN Act and applicable state law.
17.8 Entire agreement. This AUP, together with the other Agreement documents, constitutes the entire agreement between the parties regarding acceptable use and supersedes all prior or contemporaneous understandings on that subject.
17.9 Severability; no waiver; headings. If any provision of this AUP is held unenforceable, the remaining provisions remain in full force, and the unenforceable provision will be reformed to the minimum extent necessary to make it enforceable. No waiver is effective unless in writing. Headings are for convenience only and do not affect interpretation.
18. Reporting Violations and Contact
To report a suspected violation of this AUP, abuse, or a security concern, or to submit an intellectual-property complaint, contact Recovea at:
- Abuse and general AUP matters: legal@recovea.ai
- Security and vulnerability reports: security@recovea.ai
- Intellectual-property / DMCA notices: dmca@recovea.ai
- Privacy matters: privacy@recovea.ai
- Legal notices: legal@recovea.ai
Recovea, Inc., 2810 N Church St STE 89986, Wilmington, DE 19802.