Acceptable use policy

Effective: August 2025.

This policy is part of the Terms of service. Violations may suspend or terminate accounts, including linked accounts.

1. Age and content

  • Regular: no age gate.
  • Roleplay: adults only, 18 and over, confirmed by Sumsub age assurance. Roleplay can serve adult content.
  • Cybersecurity: identity verified, no separate age gate.

Content prohibitions apply at every tier and every age. Age gating is a compliance control, not a licence. Regardless of the gate, you may not use Merki to create or distribute child sexual abuse material, non-consensual intimate imagery, or any other illegal content. Merki reports child sexual abuse material as required by law. Refused requests return 409 refused and bill nothing. See Content safety.

2. Prohibited use

You may not use Merki to:

  • Break the law, or help others do so.
  • Harm people, or produce content that sexualizes minors.
  • Abuse, overload, or attempt to bypass the service, its limits, or its billing. This includes bonus farming across accounts, evading rate limits, or reselling access to circumvent tier checks.
  • Evade enforcement, including by opening accounts to continue after a termination.
  • Reverse engineer the service to extract the proprietary inference stack, or probe verification and revocation systems beyond good-faith security research under Security.
  • Misrepresent who you are, or the infrastructure you point Merki at, including false domain challenges.

3. API key hygiene

  • Do not commit API keys to git, including in tooling, harnesses, IDE configs, or any other file.
  • Do not publish keys anywhere public.
  • Merki revokes exposed keys automatically, typically within 24 hours of detection. A revoked key stays revoked. See API keys.

4. Domain verification rules

For Cybersecurity tiers:

  • Use a DNS TXT record or a .merki challenge file. Either one is accepted.
  • Challenges are valid for at most 7 days. Renew before expiry; day 6 is recommended.
  • No wildcards. Name exact hostnames.
  • Verification does not propagate to subdomains. Verify each hostname on its own.

5. Enforcement

  • Exposed keys are revoked automatically.
  • Failed or expired challenges suspend access to the affected hostname.
  • Violations may suspend or terminate accounts.
  • Linked accounts may be terminated together, based on signals such as shared payment instruments, shared verified identity, shared infrastructure, and account behavior.
  • Accounts closed for violation forfeit remaining balances, except where applicable law requires otherwise. See the Credit and refund policy.

6. Reporting

Report abuse: abuse@merki.dev. Report vulnerabilities: security@merki.dev. See Security. Include request IDs, timestamps, and the account or key prefix where applicable.