← Back to home

Acceptable Use Policy

Version 2.0 · Effective: August 27, 2026 · Entity: AiTrade LLC, a Florida limited liability company

Published for review. This is Version 2.0 and it replaces Version 1.0. It has not been reviewed by counsel. Version 1.0 prohibited building a competing product and reverse-engineering RailCall — both of which the MIT licence shipping inside the product expressly permits, and both of which the Terms of Service expressly permit at §3.2. Those two prohibitions are deleted, not narrowed. §6 lists every change. If something reads unfairly, email legal@railcall.ai.

Use the Services responsibly. This policy defines conduct that is prohibited on the systems we operate. Violation may result in suspension or termination of your account.

0. What this policy reaches, and what it does not

This policy uses the two defined terms from the Terms of Service, and the distinction is the whole point of reading this section first.

This policy applies to the Services — the hosted gateway, RailHub, the Marketplace, the dashboard, accounts, entitlements, and metering. Terms of Service §7 incorporates this policy into those Terms, so everything below is part of that agreement.

This policy places no restriction on the Software — RailCall Station, RailHub Studio, and the RailCall CLI running on your own hardware. That software is licensed by the LICENSE file in the release you downloaded; every version released to date is MIT. Nothing in this document limits, conditions, or reaches what you may do with a copy you hold. If a line below ever appears to, the LICENSE file wins and that line is void as to that copy.

Concretely, and because Version 1.0 said otherwise: building a product that competes with ours is permitted, and reverse-engineering the Software is permitted. Both are rights the MIT licence already granted, on code we already distributed, and a policy cannot take them back. Terms of Service §3.2 says the same thing in the same words.

1. General Principles

The Services exist for legitimate automation, governance, and verification. You must use the Services lawfully, ethically, and in compliance with:

  • All applicable laws and regulations
  • The Terms of Service and this Acceptable Use Policy
  • Third-party service provider terms (Slack, Stripe, GitHub, etc.)
  • Intellectual property and privacy rights of others

2. Prohibited Activities

2.1 Illegal Conduct

You may not use RailCall for:

  • Any illegal activity, including fraud, money laundering, or terrorist financing
  • Violating export controls, sanctions, or embargoes
  • Unauthorized access to computer systems or data (hacking, cracking)
  • Distribution of malware, viruses, or malicious code
  • Circumventing digital rights management (DRM) or security measures

2.2 Abuse & Harassment

  • Harassment, threats, stalking, or intimidation
  • Hate speech, discrimination, or incitement to violence
  • Doxxing (publishing private information without consent)
  • Impersonation or misrepresentation of identity

2.3 Spam & Unsolicited Communication

  • Sending unsolicited bulk messages (spam) via Slack, email, SMS, etc.
  • Phishing or social engineering attacks
  • Automated account creation or scraping without permission
  • Chain letters, pyramid schemes, or multi-level marketing

2.4 Intellectual Property Infringement

  • Copyright infringement (unauthorized distribution of protected works)
  • Trademark infringement or brand impersonation — including shipping a fork under our name, or claiming a certification, verification, or partnership we did not grant (see the Trademark Policy)
  • Theft or misappropriation of trade secrets

Deleted from Version 1.0:“Using RailCall to build a competing product without license.” The MIT licence on every released version permits exactly that, the homepage invites it, and Terms of Service §3.2 confirms it. Competing with us using the code is permitted. Competing with us using our name is what §2.4 above prohibits, and that is a trademark question, not a licence one.

2.5 Financial & Payment Abuse

  • Credit card fraud, chargebacks abuse, or payment disputes in bad faith
  • Using stolen API keys or credentials
  • Unauthorized charges or transactions via Stripe, PayPal, etc.
  • Wash trading, market manipulation, or pump-and-dump schemes

2.6 Privacy Violations

  • Collecting, storing, or transmitting personal data without lawful basis
  • Violating GDPR, CCPA, HIPAA, or other privacy regulations
  • Scraping or harvesting user data without consent
  • Selling or sharing user data without authorization

2.7 Service Abuse

  • Denial-of-service (DoS) attacks or resource exhaustion against the Services
  • Evading a rate limit, quota, or suspension on the Services, including by creating multiple accounts, or obtaining a promotional or trial allowance you are not entitled to
  • Reverse engineering the non-public internals of the Services in order to circumvent an entitlement check, licence validation, metering, or a rate limit, or to build a substitute for a Service in breach of Terms of Service §8.4
  • Using the Services to attack, test, or exploit third-party services without authorization

Not prohibited, and never will be.Version 1.0 prohibited “reverse engineering RailCall for competitive purposes.” The Software ships as readable source under MIT. Studying it, decompiling it, reverse-engineering it, and doing so specifically in order to compete with us are all permitted — see Terms of Service §3.2 and §8.7.

Independently implementing or publishing a verifier for our signatures, receipts, and evidence, and publishing the results of checking them — including results that make us look bad — are expressly permitted under Terms of Service §8.2. Good-faith security research on the Services, conducted without degrading them and without accessing other users’ data, is not a breach of this policy. We will not bring or support a claim under the Computer Fraud and Abuse Act, or under DMCA §1201, for research within that scope.

CounselThe trial and promotional-allowance line above describes a mechanism whose existence differs by page: the live pricing page says the protocol has no trial clock, while the live for-teams page advertises a 14-day free trial on the Team tier. The bullet is drafted to be correct either way — it prohibits obtaining an allowance you are not entitled to, without asserting that any particular trial exists. Confirm the trial actually offered before adoption.CounselThe security-research safe harbour above names the CFAA and DMCA §1201 deliberately. Researchers’ counsel look for an authorization statement, not a forbearance promise — authorization defeats the “without authorization” element rather than merely promising not to sue on it. Confirm the scope wording and whether a formal VDP or safe-harbour page should carry it instead.

2.8 Content Restrictions

  • Child sexual abuse material (CSAM) or child exploitation
  • Non-consensual intimate imagery (revenge porn)
  • Glorification of violence or self-harm
  • Disinformation campaigns or coordinated inauthentic behavior

2.9 Connected-Service Provider Violations

Because RailCall v1 sends approved actions directly from your machine to connected services (Slack, Stripe, GitHub, etc.), you must comply with each provider's terms. Prohibited uses include:

  • Slack: Spam, harassment, or bot abuse violating Slack's Acceptable Use Policy
  • Stripe: Prohibited businesses (per Stripe's Restricted Businesses list), chargebacks fraud, or money laundering
  • GitHub: Repository abuse, DDoS, or violating GitHub's Terms of Service
  • Other providers: Any activity prohibited by the provider's terms

AiTrade is not liable for your violations of third-party terms, but we may terminate your RailCall account if notified of abuse.

3. Enforcement

Monitoring

RailCall's local-first architecture means we do not routinely monitor your action content. However, we reserve the right to investigate if:

  • We receive a complaint from a third party (e.g., a connected-service provider)
  • Automated systems detect suspicious billing patterns
  • Required by law or court order

Actions We May Take

If we determine you have violated this policy, we may:

  • Issue a warning
  • Suspend or limit your account
  • Terminate your account immediately
  • Report illegal activity to law enforcement
  • Cooperate with third-party providers' investigations

No Refunds for Violations

Termination for policy violations ends your subscription without refund of the current period. You remain liable for unpaid amounts.

What enforcement cannot do

Every action listed above reaches your account and your access to the Services, and nothing else. Suspending or terminating an account does not terminate your licence in the Software, does not disable or degrade software running on your machines, does not touch your local vault, keys, receipts, or audit chain, and does not invalidate a receipt already issued. This mirrors Terms of Service §17.5, which states the same thing unconditionally.

4. Reporting Violations

If you become aware of activity that violates this policy, report it immediately:

Include as much detail as possible: account ID, timestamps, evidence (screenshots, receipts), and impact.

5. DMCA & Copyright Infringement

AiTrade respects intellectual property rights. If you believe your copyrighted work has been infringed via RailCall, submit a DMCA takedown notice to legal@railcall.ai with:

  • Identification of the copyrighted work
  • Location of the infringing material (URL, account ID)
  • Your contact information
  • A statement of good faith belief that use is unauthorized
  • A statement under penalty of perjury that the information is accurate
  • Physical or electronic signature of the copyright owner or authorized agent

5.1 Counter-notice

If material of yours was removed and you believe the removal was a mistake or a misidentification, send a counter-notice to the same address containing: your contact information; identification of the removed material and where it appeared; a statement under penalty of perjury that you have a good-faith belief the material was removed as a result of mistake or misidentification; your consent to the jurisdiction of the federal district court for your address (or, if outside the US, any district in which we may be found); and your physical or electronic signature. We forward valid counter-notices to the original complainant, and we may restore the material 10 to 14 business days later unless we are told an action has been filed.

5.2 Repeat-infringer policy

We terminate, in appropriate circumstances, the accounts of users and Marketplace Publishers who are repeat infringers. In practice: a takedown we act on is recorded against the account; an account that accumulates three recorded takedowns that are not withdrawn or successfully counter-noticed is terminated, and its Listings are removed; and a single instance of deliberate, large-scale infringement can result in termination on its own. Takedowns withdrawn by the complainant, or resolved in your favour after counter-notice, are not counted.

This paragraph exists because it has to. 17 U.S.C. §512(i) makes a published, reasonably implemented repeat-infringer termination policy a precondition of safe harbour — not an optional extra — and the Marketplace hosts third-party code and community threads.

CounselTwo open items on this section. (1) Designated agent.§512(c) safe harbour additionally requires an agent registered with the U.S. Copyright Office and identified on this page; registration costs $6 and the takedown process above confers no protection without it. Confirm whether one is registered, and publish the agent’s name and address here. (2) The three-strike threshold above is a drafted default, not a decision. Confirm the count, the window, and who adjudicates a disputed strike.

6. Modifications

We may update this policy. We will publish the updated version with a new version number and effective date, and keep the prior version accessible.

For a change that adds a new restriction, we will give at least 30 days’ notice before it takes effect — by in-product notice in the dashboard, by email to the address on your account if you have given us one, and by a dated entry on this page. A change that removes a restriction, or that corrects something inaccurate, takes effect immediately, because it only ever helps you. Continued use of the Services after the effective date is acceptance.

Why the notice method changed.Version 1.0 promised notice “via email or in-product notice.” Most people who run RailCall have no account and have never given us an email address, so neither mechanism could reach them — and under Version 2.0 that no longer matters, because this policy binds only people who use the Services, and using a Service means we have a way to reach you. The dated public entry on this page is the backstop.

CounselConfirm 30 days is the right notice period for new restrictions here, and that it matches Terms of Service §21.2. Note the sequencing constraint: the live Version 1.0 of the Terms promises 30 days’ notice of material changes, so any newly restrictive clause in this pass should carry a deferred effective date rather than taking effect on publication day. Nothing in Version 2.0 of this policy is newly restrictive — every substantive change removes or narrows a prohibition — so on the current draft it can publish immediately.

6A. What changed from Version 1.0

Not operative. Published because a correction nobody can read is not much of a correction.

  • Removed — §2.4 “Using RailCall to build a competing product without license.” MIT permits it, the homepage invites it, and Terms of Service §3.2 confirms it. This policy is incorporated into the Terms by §7 of those Terms, so leaving it in would have made the same agreement both grant and prohibit the identical act.
  • Removed — §2.7 “Reverse engineering RailCall for competitive purposes.” The Software ships as readable source. Replaced with a clause scoped to the non-public internals of the Services, which is the only part of it that was ever enforceable.
  • Replaced — the merged term “the Service.” Version 1.0 used one defined term for the MIT code and the hosted systems together, which is how the two clauses above came to sit on software we had already given away. §0 adopts the Software/Services split.
  • Added — §2.7 research and verification carve-out. Independent verification, independent verifiers, publication of adverse results, and good-faith security research are expressly permitted, with a named CFAA / DMCA §1201 authorization.
  • Added — §5.1 counter-notice and §5.2 repeat-infringer policy. §512(i) requires the latter as a precondition of safe harbour; Version 1.0 published a takedown process without one.
  • Corrected — §6 notice mechanism, to match Terms of Service §21.2 and §21.3.

7. Questions

Questions about this policy? Contact us:

Email: legal@railcall.ai

Entity: AiTrade LLC, a Florida limited liability company

Counsel — registered addressCounsel supplied the jurisdiction of formation on 2026-08-27, and the entity block above now reads "AiTrade LLC, a Florida limited liability company". The registered business address was not supplied and is not published anywhere on this site — we have not invented one. Provide it.

Entity: AiTrade LLC, a Florida limited liability company · Governing law: Florida · Version 2.0 · Effective: August 27, 2026
See also: Terms of Service · Privacy Policy · Data Flow Disclosure