Credential responsibility
API keys must remain private and server-side. Activity made with a valid key is attributed to its owning account unless QFOXAI confirms another cause. Use separate keys for separate projects, apply expiry and IP restrictions where appropriate, and revoke a key immediately if it appears in public code, logs, screenshots, browser traffic, or an unauthorized device.
Traffic and quota abuse
Prohibited behavior includes intentional rate-limit evasion, rotating accounts or keys to bypass limits, unbounded retry loops, coordinated request floods, hidden resale, unauthorized proxying, unpaid consumption, or automated traffic that degrades service for others.
Scanning and interference
Do not probe, enumerate, scrape, reverse engineer, benchmark abusively, or attempt unauthorized access to QFOXAI infrastructure, internal routes, provider credentials, customer records, private model information, or security controls. Authorized security reports should use the published support channel and avoid accessing data beyond what is necessary to demonstrate the issue.
Content and downstream misuse
API customers must enforce the Acceptable Use Policy in their applications. Repeated unsafe requests, fraud, malware, non-consensual imagery, spam, privacy abuse, or attempts to defeat moderation may lead to model, key, project, or account restrictions even when traffic stays within numeric quotas.
Signals and investigation
QFOXAI may use request rate, token volume, status patterns, IP and key changes, account state, safety outcomes, payment signals, and other operational metadata to identify suspicious behavior. Investigations are based on risk and context; a single error does not automatically mean abuse.
Protective actions
Depending on risk, QFOXAI may return a clear error, reduce speed, hold a request, disable a model, revoke or quarantine a key, require verification, pause billing, remove public content, suspend a project, or restrict an account. Urgent threats, credential compromise, legal duties, or severe abuse may require immediate action without advance notice.
Recovery and appeal
If a key is exposed, revoke it, create a replacement, review recent usage, update the consuming application, and narrow permissions before restoring traffic. If you believe an action was incorrect, contact support@qfoxai.com with the account email, UTC timestamp, endpoint, public model alias, HTTP status, and QFOXAI request ID. Never include the full secret.