Version dated 16 September 2026. These Rules form part of the Public Offer and Licence Agreement and apply together with the Privacy Policy and the Model and Route Terms Registry.
1. Purpose and boundaries of these Rules
1.1. These Rules set the baseline boundaries for use of Cicora’s own Service: its website, applications, API, workspace, Input Materials, Outputs, and permitted integrations. They apply to the User, the User’s workspace members and authorised persons and, in the case of an API integration, to the end users of the Customer’s product to the extent that the Customer gives them access to Cicora.
1.2. Cicora provides access to different Models and Routes. They may have additional mandatory limits relating to age, country, organisation, Content type, Output distribution, safety, licence, data, or technical limits. Those limits are shown before use in the Model and Route Terms Registry and in the feature card. A rule of that kind applies to the relevant Route and is not treated, without a basis, as a universal prohibition for every other Model.
1.3. A User must not use the Service if the selected Route, country, role, age, data, or purpose is incompatible with it. A change of Model, automated fallback, or processing region may not be used to circumvent an agreed budget, data requirement, availability condition, or mandatory provider restriction.
1.4. These Rules do not promise that Cicora will identify every breach in advance, continuously moderate every request, or prevent every harmful Output. We may review the data needed by automated means and by people when this is required for safety, compliance with law, complaint handling, protection of rights, or operation of a particular feature. The review is limited by its purpose and applicable law.
2. General obligations of the User
2.1. The User must comply with applicable law, the Order terms, these Rules, the rules of the selected Model, and third-party rights. The User is responsible for the lawfulness of Input Materials, instructions, Route selection, use of Outputs, and actions the User asks an available feature to take.
2.2. The User must have the required rights, licences, authority, and consent to upload, process, transfer, publish, and use every item of material. The User may not impersonate another person, organisation, Cicora representative, or Model provider without a lawful basis and express permission.
2.3. A Business Customer or developer offering its product through the Cicora API must pass applicable restrictions and required AI notices to its end users, obtain required consent, and not grant them rights beyond its Order and the Model Terms. In a user-facing chat or another interface, the Customer must clearly disclose use of AI where law, the selected Route, or the nature of the interaction requires it. Integrating a permitted API into the Customer’s own application is allowed. It does not create a right to transfer a third-party account or provider key, or to broker access to third-party technology without disclosure.
2.4. A User may not bypass age, territory, organisation, payment, limit, Model, data-mode, or safety requirements by misrepresenting identity, country, request source, account, or other information. Use of a VPN, proxy, or other network-security tool is not prohibited by itself, but may not be used to obtain access that is prohibited.
3. Prohibited unlawful and harmful use
3.1. The Service may not be used for conduct that is unlawful in itself or to knowingly and materially facilitate it. This includes human trafficking, exploitation, extortion, fraud, identity or credential theft, forgery of documents, currency, or payment information, counterfeit-goods sales, operating or facilitating real-money gambling, unlawful trade in prohibited goods or services, and concealing the criminal origin of funds or data.
3.2. The Service may not be used to create, organise, direct, or materially facilitate threats, intimidation, stalking, violence, terrorism, extremist violence, discriminatory practices, cruelty toward people or animals. A User may not request practical instructions that increase the ability to cause serious physical harm or to create, acquire, deliver, or use weapons, high-risk explosives, chemical, biological, radiological, or nuclear means, or to bypass mandatory controls over them.
3.3. A User may not damage, disrupt, or gain unauthorised access to critical infrastructure, communications, transport, energy, healthcare, financial systems, water systems, or other critical systems. Lawful risk analysis, safety education, historical or academic discussion are not breaches by themselves, provided that the request does not become instructions for unlawful action against a real target.
3.4. A User may not cause psychological harm or exploit a person’s vulnerability: encouraging suicide, self-harm, eating disorders, dangerous challenges, body shaming, sexual violence, graphic violence for harassment, or manipulative emotional pressure. Supportive, preventive, educational, artistic, and fictional discussion of these subjects is not prohibited by itself. An Output does not replace emergency assistance, a doctor, a psychologist, or another qualified source of help.
4. System security and good-faith technical research
4.1. The following are prohibited: creation, delivery, or use of malicious code, ransomware, botnets, phishing, credential harvesting, unauthorised scanning, exploitation of a vulnerability, denial of service, interception of communications, persistence, covert component installation, circumvention of security measures, tampering with hardware or firmware, and obtaining or publishing another party’s secrets.
4.2. The Service may not be used for unauthorised red teaming, social engineering against real people, evading another service’s limits, jailbreaking for a harmful result, or preparing a large-scale compromise. Automation, multiple accounts, proxies, keys, or technical errors may not be used to evade a rate limit, quota, block, verification process, or charge.
4.3. Lawful defensive research, an audit of the User’s own resource, study work, vulnerability analysis authorised by the owner, and development of defensive tools are permitted. The User must have authority, keep testing to its own system or an agreed scope, refrain from extracting others’ data, and not use an Output against a real target without authorisation. If the selected Route requires prior approval for that activity, that requirement applies.
5. Privacy, identity, and biometric information
5.1. A User may not collect, buy, sell, disclose, combine, monitor, or profile another person’s private, confidential, contact, health, financial, account, biometric, neural, or other sensitive information without the necessary right and consent. Doxxing, covert surveillance, unauthorised location tracking, interception of communications, and attempts to obtain a password, banking code, or other secret are prohibited.
5.2. A User may not create a facial-recognition database, conduct remote biometric identification in a public space, create social scoring, infer sensitive characteristics, emotions, health, sexuality, religion, political views, or risk of criminal conduct about a person without a lawful basis and required safeguards. It is especially impermissible to use such inferences to control workers, students, or other vulnerable people where prohibited by law or the Route terms.
5.3. An image, voice, video, name, signature, personal style, or other signifier of a person may not be used to plausibly represent that person’s involvement, statement, or consent without the necessary rights and consent. A User may not present AI as a human or conceal the artificial origin of an Output where this misleads the recipient or violates law, personality rights, or a selected Model rule.
6. Minors and sexual content
6.1. Child sexual abuse material, including AI-generated or altered material, grooming, sexualisation of or impersonation of a minor, involving a child in a dangerous or age-restricted activity, concealing exploitation, and every attempt to bypass age protection are strictly prohibited. Where there is a clear risk to a child, we may take urgent action and act as required by law.
6.2. A User may not create or distribute non-consensual intimate material, sexual violence, images or recordings of a person without consent, or use the Service for sexual coercion, harassment, or blackmail.
6.3. These general Rules do not automatically prohibit every lawful adult discussion of relationships, sexual health, culture, literature, art, or fictional scenarios. A particular Model may, however, prohibit explicit sexual content, erotic roleplay, or another category of adult material in full. That stricter rule applies only to the expressly identified Route and must be visible before the request is submitted.
7. Accuracy, manipulation, and socially significant decisions
7.1. A User may not use an Output to deceptively misrepresent a person, source, event, organisation, law, science, health, or another material fact. Fake reviews, forged endorsements, fake documents, false attribution of authorship or source, presenting synthetic media as authentic, covert voice or likeness imitation for deception, and presenting AI work as the User’s independent work in an assessment where this breaches the applicable institution’s or assignment’s rules are prohibited.
7.2. The Service may not be used for targeted political persuasion of specific people based on their profile, deceptive electoral campaigns, false voting information, voter suppression, or disruption of an electoral process. Lawful information, neutral analysis, journalism, research, historical, and public discussion are not prohibited by themselves where they do not become deception or unlawful interference.
7.3. A User may not use AI as the sole or automatically final mechanism for a decision that has legal or comparably significant consequences for a specific person, including a decision about credit, insurance, employment, dismissal, housing, education, healthcare, legal status, access to an essential public service, migration, law enforcement action, or product safety. Permitted supporting work requires a lawful basis, qualified human review before the final decision, Output verification, and any required AI notice.
7.4. Outputs about law, medicine, mental health, finance, investments, insurance, taxes, safety, or another regulated field are not by themselves a professional service, diagnosis, personal recommendation, or guarantee of compliance. The User must provide qualified review and comply with the special requirements of applicable law and the Route.
8. Intellectual-property rights, brands, and third-party materials
8.1. A User may not infringe copyright, related rights, patent rights, trademarks, trade secrets, likeness rights, contractual rights, or other third-party rights. The User must not upload restricted material, present another person’s work as its own, remove required attribution, or use an Output contrary to an applicable licence.
8.2. A User may not copy, sell, lease, distribute, reverse engineer, or extract non-public portions of Cicora, its interface, data, Models, algorithms, or systems, except where expressly permitted by law or published documentation. Permitted API access is not interface scraping and does not grant a right to mass-extract protected data, other users’ Outputs, or internal information.
8.3. A User may not use the names or marks of Cicora, RIZZ TRADE, a Model provider, or a third party in a way that suggests official partnership, certification, endorsement, or sale of a third-party account where none exists. The process for reporting a suspected rights violation is set out in the IP Notice Procedure.
9. Platform, accounts, and commercial use
9.1. Selling, gifting, transferring, or publishing another party’s API key, password, account, or access is prohibited, as are mass account creation to evade terms, reselling Cicora as undisclosed access to a third-party Model, and tampering with billing, logs, limits, availability, or payment. This does not prohibit building a product with the Cicora API where the plan permits it, provided the Customer follows documentation, discloses AI assistance to end users, performs required flow-down, and does not conceal mandatory Route restrictions.
9.2. Input Materials or Outputs may not be used to train, distil, extract, or create a competing model where the selected Model, provider, or product prohibits this. Cicora does not impose that restriction on other Routes without its own rule or a mandatory requirement; the applicable boundary appears in the Model and Route Terms Registry.
9.3. A User may not intentionally route confidential data through a Route for which it is prohibited, misclassify data, or bypass a route-specific data setting. If the data terms do not fit the task, the request must be rejected, deferred, or sent only by an option the User has lawfully selected and that expressly permits those data.
10. Public materials, external applications, and actions on the User’s behalf
10.1. Where the Service provides a public link, publication, user agent, connector, action, webhook, marketplace, or similar feature, it may be used only within the scope actually enabled. The User is responsible for public Content, rights in it, accuracy of its description, audience, and the consequences of sending data or commands to an external service.
10.2. An external account may not be connected and an agent may not be instructed unless the User has authority for the relevant data and actions. Such features may not be used for covert access to another system, automated spam, circumvention of external-service terms, or an action the User is not authorised to confirm. An external service operates under its own terms and policy; those terms do not replace the agreement with RIZZ TRADE and vice versa.
11. Response to a breach and appeal
11.1. Where there are reasonable indications of a breach, we may ask for an explanation or documents, issue a warning, restrict a particular request, Output, key, integration, Model, Route, budget, or account, remove a public link, or temporarily suspend access. The measure is selected in proportion to the risk, repetition, law, technical feasibility, and mandatory provider rules.
11.2. Where there is a threat to security, children, third-party rights, infrastructure, payment, or a mandatory legal requirement, action may be taken before notice. Otherwise, where possible, we will communicate the reason and an available way to correct the situation. Restriction of one Route does not mean automatic forfeiture of all lawfully paid services or denial of a mandatory refund.
11.3. A User may appeal an action through support@cicora.ai, identifying the account, request or notice ID, circumstances, and available supporting information. We review the appeal within a reasonable time in view of the risk. We do not have to disclose another person’s data, security methods, keys, investigation information, or information that law prohibits us from disclosing. A knowingly false complaint, fabricated evidence, or abuse of the appeal process may itself be a breach.
11.4. A suspected intellectual-property breach is reviewed under the separate IP Notice Procedure. Removing or restricting public material after a complaint is not a final court finding about rights.
12. Changes and contact details
12.1. These Rules may be updated because of changes to law, threats, actually available features, mandatory Model terms, or protection methods. A material change applies prospectively in the way stated in the Public Offer; it does not create a hidden retroactive obligation for a completed request.
12.2. Questions, breach reports, and appeals may be sent to support@cicora.ai or +998 90 051 48 40. Provider: RIZZ TRADE LLC, Republic of Uzbekistan, TIN 312432714, registration record 2944991 dated 15 September 2025, address: 3 Nukus Street, Abdulla Avloniy MFY, Mirabad District, Tashkent.