All policies

Acceptable Use Policy

Last updated:

This Acceptable Use Policy forms part of the Agreement between Flowstate and the Customer. Capitalised terms not defined here have the meaning given in the Terms of Service. The Customer is responsible for ensuring that it, its Authorised Users and its Customer Code comply with this policy.

1. Scope

1.1 This policy applies to every part of the Services, including:

  • the Flowstate web application (the “Application”);
  • Flowstate’s application programming interfaces (the “API”);
  • Flowstate’s Model Context Protocol server (the “MCP Server”);
  • the AI Router and the Failover Service;
  • Eddy, Flowstate’s AI assistant (“Eddy”); and
  • Customer Code executed on the Services.

2. General prohibitions

The Customer shall not, and shall ensure that no Authorised User or Customer Code shall, use the Services to:

  • breach any applicable law or regulation, or infringe the rights of any person;
  • access, or attempt to access, any data, account, Tenant or system without authorisation;
  • interfere with, disrupt or degrade the integrity or performance of the Services or the data of any other customer;
  • probe, scan or test the vulnerability of the Services, or circumvent any security, authentication, rate limit, quota or other control;
  • upload, transmit, store or execute any virus, malware or other harmful code;
  • send unsolicited communications, or transmit material that is unlawful, defamatory, harassing or obscene;
  • process special category personal data, or personal data of children, through the Services; or
  • share credentials or API keys between individuals, or permit any person other than an Authorised User to access the Services.

3. Immediate suspension

3.1 Flowstate may suspend the Customer’s account, any Authorised User’s access, or any Customer Code immediately and without notice, pending review, where Flowstate reasonably suspects that:

  • any Customer Code or Authorised User has called, scanned or probed any IP address or hostname within Flowstate’s private networks or virtual private clouds;
  • any malware has been uploaded, executed or distributed through the Services;
  • the Application, API or MCP Server has been misused, including through anomalous, automated or abusive request patterns;
  • any person has attempted to access another customer’s data;
  • any security control, limit or hostname restriction has been circumvented or attempted to be circumvented; or
  • the Services have been used for any malicious or unlawful purpose, including attacks on third parties.

3.2 Flowstate shall contact the Customer following any suspension under clause 3.1. Flowstate’s determination following review is final.

4. Application

4.1 Flowstate applies rate limits to the Application.

4.2 Flowstate monitors requests to the Application and the API for anomalies. Misuse may result in suspension of the relevant Authorised User’s account under clause 3.

5. API

5.1 Flowstate does not currently apply fixed rate limits to the API.

5.2 Flowstate may contact the Customer if its use of the API exceeds acceptable levels or affects Flowstate’s infrastructure, and may impose limits at any time.

5.3 Flowstate may queue write requests made through the API. Queuing may delay the processing of Customer Data. The Customer accepts all consequences of any such delay, and no such delay constitutes Downtime under the SLA or gives rise to any liability on the part of Flowstate.

6. MCP Server

6.1 Flowstate applies rate limits to the MCP Server on a per-Authorised User basis. Each plan includes a usage allowance, as stated in Flowstate’s documentation.

6.2 Flowstate may throttle or block requests that exceed the applicable rate limit or allowance.

6.3 The Customer shall not route the requests of multiple individuals or systems through a single Authorised User’s MCP access in order to avoid per-user limits.

7. AI Router and Failover Service

7.1 The Customer is solely responsible for the content of all Requests and for ensuring that its use of each Third-Party AI Provider complies with that provider’s terms and usage policies.

7.2 The Customer shall not use the AI Router or the Failover Service to circumvent any Third-Party AI Provider’s limits, safety controls or usage policies.

7.3 Flowstate may block, reject or decline to forward any Request that it reasonably believes breaches this policy or applicable law.

8. Eddy

8.1 The Customer shall not, and shall ensure that no Authorised User shall:

  • attempt to manipulate, jailbreak or inject instructions into Eddy, or to extract Eddy’s system instructions or configuration;
  • use Eddy to access data that the Authorised User is not authorised to access; or
  • use Eddy to generate content that breaches clause 2.

8.2 Eddy’s outputs are Insights. The Customer shall verify all outputs before relying on them, in accordance with the Terms of Service.

9. Customer Code

9.1 Flowstate limits the time, memory, CPU and network resources available to Customer Code. Flowstate may terminate any execution that exceeds a limit, without notice. Time spent awaiting responses to outbound network requests does not count towards CPU usage.

9.2 Customer Code may only make outbound requests to hostnames that Flowstate has approved. The Customer may request approval of additional hostnames through its support channel. Flowstate may grant or refuse any request at its sole discretion.

9.3 Flowstate records the network requests made by Customer Code, to support the Customer’s development and debugging and for security purposes. Flowstate retains these records for 30 days.

9.4 The limits in force at the date of this policy are set out below. Flowstate may change these limits at any time by updating its documentation, which prevails over this clause.

Single hooks

LimitPull hookPush hook
Memory128 MB128 MB
Time running code30 s10 s
HTTP requests per run5050
Wait for one HTTP request60 s60 s
Pages per pull100Not applicable

Workflows

LimitValue
Each JavaScript step10 s of running code, subject to a limit on elapsed time
Each connector call15 s elapsed, with up to 3 attempts on 429 or 5xx errors, waiting 500 ms then 1.5 s
Whole run, all steps and pages60 s elapsed
Each step’s input or output, and each incoming webhook body256 KB. Oversized webhook bodies are rejected with HTTP status 413

10. Fair use

10.1 The Customer shall not use any part of the Services in a manner that, in Flowstate’s reasonable opinion, places a disproportionate load on Flowstate’s infrastructure or degrades the Services for other customers.

10.2 Where Flowstate considers the Customer’s use excessive, Flowstate may contact the Customer, apply limits, throttle or queue requests, or require migration to a dedicated regional deployment under the Terms of Service.

11. Monitoring

Flowstate may monitor use of the Services to verify compliance with this policy, to maintain security and reliability, and as otherwise permitted by the Agreement.

12. Enforcement

12.1 Where Flowstate reasonably suspects a breach of this policy, it may, at its sole discretion and without liability, take any one or more of the following actions: issue a warning; throttle, queue or block requests; halt or remove Customer Code; suspend any Authorised User or the Customer’s account; or terminate the Agreement under the Terms of Service.

12.2 No Fees shall be refunded as a result of any enforcement action.

13. Reporting

13.1 The Customer shall report any actual or suspected security vulnerability or incident to security@flowstate.inc immediately.

13.2 The Customer shall report any suspected breach of this policy to support@flowstate.inc.