Skip to the content
The operating system for desk work that lives in files
Try a sample
Legal · effective 2026-09-23

Acceptable Use Policy

Effective 2026-09-23.

This Acceptable Use Policy ("Policy") forms part of the Terms of Service (https://app.baseloom.app/?view=legal&doc=terms). It applies to everyone who uses the BaseLoom Service, including the free sandbox, subscribers, their users and partners. Words defined in the Terms have the same meaning here.

1. Unlawful use

You must not use the Service:

1.1 to process personal data or other information without a lawful basis, required notice or consent, or in breach of any data protection, privacy, confidentiality or professional secrecy law;

1.2 to commit, facilitate or conceal fraud, money laundering, tax evasion or any other crime; or

1.3 to infringe or misappropriate anyone's intellectual property, trade secrets or other rights.

2. Data you have no right to upload, and regulated data

You must not upload or paste:

2.1 data you do not have the right to use for the purpose, including data obtained in breach of contract, confidentiality or law;

2.2 protected health information under HIPAA, unless a Business Associate Agreement (https://app.baseloom.app/?view=legal&doc=baa) is signed between you and us;

2.3 ITAR technical data, EAR-controlled technology (other than EAR99 or equivalent), Controlled Unclassified Information (CUI) or classified information. Export and defence apps are designed for descriptions, metadata and redacted text;

2.4 special categories of personal data (such as health, biometric, genetic, racial or ethnic origin, religious belief, sexual orientation, criminal records or government identifiers) unless genuinely needed for the app's purpose and lawfully processed; or

2.5 payment card numbers or authentication data beyond what an app's documented purpose needs. The PCI DSS app is meant for configuration and policy evidence; do not upload live cardholder data to it.

3. Unlawful discrimination and automated decisions about people

3.1 You must not use the Service or its Outputs to discriminate unlawfully against any person, including in lending, credit, insurance, hiring, employment, housing or access to services. This includes, where they apply, the US Fair Credit Reporting Act (FCRA), the Equal Credit Opportunity Act (ECOA), the Fair Housing Act, fair lending rules, Title VII and equivalent laws elsewhere.

3.2 You must not use an Output as the sole basis of a decision that produces legal effects or similarly significant effects on an individual (for example refusing credit, rejecting a job applicant or ending a contract) without meaningful human review by someone with authority to change the decision. This reflects Article 22 of the EU and UK GDPR and similar laws. Apps that help with adverse action notices, fair lending analysis or hiring records support a human process; they do not replace it.

3.3 An app is not a "consumer report" and we are not a consumer reporting agency. You must not use the Service to furnish or obtain consumer reports.

4. Sanctions and export evasion

You must not use the Service to evade or help anyone evade sanctions or export controls, including by structuring transactions, altering party names, removing screening hits or preparing false export or customs documents. You must not access the Service from, or for persons in, any country or region listed in section 18.3 of the Terms.

5. Abuse of the Service

You must not:

5.1 scrape, crawl or harvest the Service, its reference tables, templates or other content by automated means, except through an API we have provided for your subscription and within its limits;

5.2 upload malware, viruses, macros intended to cause harm, or files crafted to exploit a parser (for example decompression bombs or malformed files designed to crash an app);

5.3 overload, flood or disrupt the Service, or bypass rate limits, usage limits or licence-key checks;

5.4 probe, scan or test the vulnerability of the Service, or breach its security or authentication, without our prior written permission. Good-faith security researchers should follow the Security page (https://app.baseloom.app/?view=legal&doc=security) and write to legal@baseloom.app first;

5.5 access another customer's session, licence key or data; or

5.6 resell, sublicense, time-share or offer the Service to third parties as your own service, or share licence keys outside your organisation, except as allowed to partners under the Partner Agreement.

6.1 You must not use the Service, support channels or any draft letter it produces to harass, threaten, defame or intimidate anyone, or to send content you know to be false.

6.2 Partners must not promote BaseLoom or their referral links by spam, unsolicited bulk messages, misleading claims, fake reviews or undisclosed paid endorsements. Partner marketing must comply with applicable email and marketing law (such as CAN-SPAM, CASL, the UK PECR, the EU ePrivacy rules and the Australian Spam Act) and must clearly disclose the referral commission where the law or the US FTC Endorsement Guides require it.

6.3 You must not use support channels to submit abusive, bulk or automated messages, or content designed to manipulate the automated support assistant.

7. Reporting abuse

If you believe someone is misusing the Service, or that the Service is being used to harm you, please write to legal@baseloom.app with enough detail for us to find the activity (such as the date, time, app and what happened). We will acknowledge reports promptly and look into them. Security vulnerabilities can be reported the same way.

8. Enforcement

8.1 We may investigate suspected breaches of this Policy. Because we do not store uploaded files, investigations rely on logs, billing records and information you or others give us.

8.2 If we reasonably believe this Policy has been breached, we may, depending on how serious the breach is: warn you, ask you to stop, suspend access, revoke a licence key, end a subscription or partner relationship, or report the matter to the relevant authority where the law requires or allows. Suspension follows section 13 of the Terms, including notice and a chance to fix the problem where that is reasonable and lawful.

8.3 Where required, we will cooperate with lawful requests from authorities.

8.4 We may update this Policy under section 27 of the Terms.