Acceptable Use Policy — Cogitent
DRAFT — pending counsel review. Not legal advice. Not yet binding until ratified in M1 final.
| Field | Value |
|---|---|
| Version | 1.0 |
| Status | Draft — pending counsel review |
| Effective date | [DATE — set on M1 ratification] |
| Governing entity | Cogitent SAS (in formation) |
1. Purpose and Scope
This Acceptable Use Policy ("AUP") establishes the rules for using Cogitent software and Cogitent-operated services. It applies to:
- All users of the Community Edition (CE) and Plus Edition of Cogitent;
- All parties who interact with Cogitent-operated infrastructure, including the Entitlement Service (license-key validation), the Federated-Learning (FL) Aggregator, and the Telemetry Collector;
- API integrators and developers building on Cogitent components.
This AUP is incorporated by reference into the Plus Edition EULA (docs/legal/eula.md). CE users are bound by this AUP as a condition of accessing CE-only Cogitent-operated services. This AUP does not govern purely local use of the CE software that makes no calls to Cogitent-operated services.
Where this AUP conflicts with a Commercial Exemption agreement, the Commercial Exemption governs. All other uses must comply with this AUP.
2. Prohibited Uses — General
You must not use Cogitent software or services for any purpose that:
2.1 Violates Applicable Law
- Facilitates, promotes, or constitutes any violation of applicable law, including French criminal law, EU law, or the law of your jurisdiction.
- Involves the creation, storage, transmission, or distribution of illegal content, including content that glorifies violence, incites racial hatred, or constitutes defamation under French law (Loi du 29 juillet 1881 sur la liberté de la presse).
- Generates or processes child sexual abuse material (CSAM) or any content that sexually exploits or abuses minors in any form.
2.2 Malware and Unauthorized Access
- Develops, stores, deploys, or distributes malware, ransomware, spyware, adware, or any malicious code.
- Attempts to gain unauthorized access to any computer system, network, database, or device — whether Cogitent's or a third party's.
- Exploits any vulnerability in Cogitent's systems beyond the scope of responsible disclosure (see Section 9 on reporting).
2.3 Denial-of-Service and Abuse
- Conducts, facilitates, or participates in any denial-of-service (DoS) or distributed denial-of-service (DDoS) attack against Cogitent services or any third-party infrastructure.
- Sends spam or unsolicited bulk communications using data or tooling provided by Cogitent.
- Systematically abuses the Entitlement Service, FL Aggregator, or Telemetry Collector through excessive automated requests, artificially generated load, or API scraping beyond documented rate limits.
2.4 Harassment and Harm
- Harasses, threatens, intimidates, or stalks any person.
- Promotes, facilitates, or glorifies sexual exploitation or abuse, trafficking, or violence against any person.
3. AI Act Prohibitions (Title II)
In conformance with the EU AI Act (Regulation (EU) 2024/1689), you must not use Cogitent — directly or as part of an AI pipeline — for any purpose that the AI Act prohibits, including but not limited to:
3.1 Subliminal manipulation: deploying AI techniques that manipulate persons through subliminal means beyond their awareness in a way that impairs free will and is likely to cause harm.
3.2 Exploitation of vulnerabilities: exploiting the vulnerabilities of specific groups (age, disability, social or economic circumstances) to distort behaviour in a harmful way.
3.3 Social scoring: evaluating or classifying natural persons based on their social behaviour or personal characteristics to produce a social score that leads to detrimental or discriminatory treatment.
3.4 Real-time remote biometric identification (RTBID) in public spaces: using biometric systems for real-time remote biometric identification of natural persons in publicly accessible spaces for law-enforcement purposes, except within the narrow exceptions specified in the AI Act.
3.5 Biometric categorisation for sensitive attributes: inferring sensitive attributes (race, political opinion, trade union membership, religious belief, sexual orientation, health data) from biometric data in ways prohibited by the AI Act.
3.6 Emotion recognition in restricted contexts: deploying emotion-recognition systems in workplaces or educational institutions in contravention of the AI Act.
3.7 Training surveillance systems: using Cogitent's FL or telemetry infrastructure to train or improve systems designed for mass or targeted surveillance in violation of applicable law.
This Section is not exhaustive; the full list of prohibited AI practices is set out in Art. 5 of the AI Act. Cogitent will update this Section as the AI Act becomes effective and as OJEU-published implementation acts are issued.
4. Prohibited Misuse of the Federated-Learning Channel
The FL contribution channel is a shared infrastructure resource. Its integrity is essential to the quality of Cogitent's models and to all users who benefit from them. You must not:
4.1 Poison the model: submit gradient contributions that are deliberately crafted to degrade model performance, introduce targeted backdoors, bias model outputs toward a specific agenda, or corrupt shared model parameters.
4.2 Model-extraction attacks: use the FL round contribution mechanism to systematically extract proprietary model weights, architectures, or training data.
4.3 Bias injection: deliberately introduce false, skewed, or adversarially selected training signals intended to make the shared model produce systematically biased outputs.
4.4 Sybil contributions: create or control multiple install UUIDs for the purpose of gaining disproportionate influence over a federated round. Each install UUID must correspond to a genuine, independent installation.
Violations of this Section are treated as material breaches of the EULA or CE terms (as applicable) and will result in immediate suspension of FL access.
5. Prohibited Misuse of the Telemetry Channel
The telemetry channel provides Cogitent with aggregate usage data. Misuse of this channel harms the reliability of data that drives product decisions. You must not:
5.1 Spoof install UUIDs: generate, reuse, or rotate install UUIDs in a way that does not correspond to genuine software installs, for the purpose of inflating install counts or obtaining false trial entitlements.
5.2 Fake event injection: submit synthetic telemetry events that do not reflect actual software usage.
5.3 Replay attacks: capture and re-submit previously recorded telemetry events.
5.4 Event flooding: send telemetry events at a rate substantially exceeding what genuine software operation would produce, for the purpose of disrupting the telemetry collector.
6. Suspension of Service
6.1 Grounds
Cogitent may suspend your access to any Cogitent-operated service — including the Entitlement Service (which will cause License Key validation to fail), the FL Aggregator, and the Telemetry Collector — upon a reasonable determination that you have violated this AUP.
6.2 Cure Period
Before suspension, Cogitent will give you 7 days' written notice (to the email associated with your install or license) and an opportunity to cure the violation, unless:
- Continued operation would cause active harm to Cogitent's systems, other users, or third parties (e.g., ongoing DoS, active model poisoning);
- The violation involves CSAM, illegal content, or real-time harm;
- The violation is a repeat offence.
In those cases, suspension is immediate, with written notice to follow as soon as practicable.
6.3 Effect of Suspension
Suspension of the Entitlement Service means the Software will fail license-key validation after the offline grace period (7 days) and enter degraded mode. Suspension does not delete local data on your device.
6.4 Restoration
If you cure the violation within the notice period, Cogitent will restore service within 2 business days of written confirmation. Restoration decisions are at Cogitent's reasonable discretion.
7. Law Enforcement Cooperation
7.1 Cogitent will cooperate with lawful requests from French or EU law-enforcement authorities and competent courts, provided that such requests are made through legally prescribed procedures and comply with applicable due-process requirements (Code de procédure pénale; EU Framework).
7.2 CLOUD Act: To the extent that Cogitent is subject to data requests from non-EU jurisdictions (e.g., under the US CLOUD Act), Cogitent will assert available legal protections under EU and French law and will notify affected users where legally permitted.
7.3 Cogitent does not proactively monitor or scan user data — including episode content, FL gradients, or queries — except when responding to a lawful court order or in the narrow circumstances described in this AUP.
8. No Content Scanning Commitment
Cogitent is designed around the principle that your memory episodes and coding sessions are yours. We commit that:
- Cogitent does NOT scan episode content for competitive analysis, model training, or any purpose other than the technical operation of the software.
- FL gradient contributions are aggregated using cryptographic secure aggregation (SecAgg) — the aggregator server does not read individual gradients in plaintext.
- The AUP-enforcement triggers in this policy are based on usage-pattern signals (API call rates, FL round structure, install UUID patterns), not on reading content.
If Cogitent ever needs to change this commitment (e.g., to comply with a new legal obligation), we will provide at least 30 days' written notice and publish a policy update.
9. Reporting Violations and Security Issues
If you discover an AUP violation by another user, or a security vulnerability in Cogitent's systems, please report it:
- AUP violations and abuse:
[email protected] - Security vulnerabilities: follow the responsible-disclosure process in docs/security/
We commit to acknowledging AUP abuse reports within 2 business days and security reports within 1 business day, and to providing regular updates on investigation status.
10. Cross-References
| Document | Relevant sections |
|---|---|
| Plus Edition EULA (docs/legal/eula.md) | §3 (Restricted Uses), §11 (Termination) |
| Privacy Policy (docs/legal/privacy-policy.md) | §2.3 (FL gradients), §9 (Security), §7 (Law enforcement) |
| Commercial Strategy (docs/commercial-strategy.md) | §6 (Telemetry) |
11. Changes to This Policy
Cogitent may update this AUP at any time. Changes materially restricting permitted uses will be announced via release notes and, where technically feasible, in-app, at least 30 days before taking effect. Continued use of Cogitent services after the effective date of an updated AUP constitutes acceptance.
End of Acceptable Use Policy v1.0 — Cogitent