Terms · Privacy · Subprocessors · Security · AI · Acceptable use · Accessibility · DPA · Français
Acceptable Use Policy
Version 1.0 · Effective 2026-08-20 · Last updated 2026-08-20
This policy says what you may not do with LobiPlan. It is part of the Terms of Service and it binds every account holder, every member of a workspace, and anyone acting on their behalf.
Why this is a separate document
Most of what is here is specific to this product rather than generic. LobiPlan has an AI assistant, an email address that answers strangers, a video stack that can record, a bank feed, and links that show a child's afternoon to somebody without an account. A policy that only prohibited spam and malware would miss every one of those.
Keeping it separate also means we can update it on notice — see the last section — without re-papering the whole agreement.
1. Who this applies to, and who has to enforce it
It applies to you and to everyone in your workspace. You are responsible for your members, and for your guests — the people who join a meeting you host or open a link you shared. Those people have no agreement with us, so where a rule below is about them, it is a rule about what you must do.
2. Content and conduct
Do not use LobiPlan to:
- store, send or publish unlawful content — including content that is defamatory, that harasses or threatens somebody, that incites violence, or that sexualises a child;
- infringe somebody else's rights — copyright, trademark, trade secret, privacy or anything else;
- upload malware, or anything designed to damage or gain unauthorised access to a computer system;
- impersonate another person, or misrepresent who you are or who you act for;
- put somebody else's personal information into a workspace when you have no right to hold it — that includes contacts, employee records, a customer's financial documents and photographs of other people's children;
- use it for anything the law where you are forbids.
3. The Service itself
Do not:
- circumvent rate limits, entitlement checks or seat caps, or try to;
- access a workspace, an account or data that is not yours, or try to;
- scrape the Service, or extract data from it by automated means beyond the export and the interfaces we provide;
- resell the Service, or make it available to a third party as if it were your own;
- reverse engineer the Service, except where the law expressly permits it;
- publish benchmark or performance results about the Service without our written consent.
4. Security testing, and how to report something
Do not run security testing against LobiPlan without our written permission. That includes vulnerability scanning, penetration testing, load or stress testing, and anything that degrades the Service for other customers.
If you find a vulnerability, we want to hear about it and we will not be difficult about it. Report it to bsimba6@gmail.com, tell us what you found and how to reproduce it, and give us a reasonable chance to fix it before telling anybody else. Do not access, modify or keep data that is not yours while investigating — a proof of concept that stops at the door is enough.
Our disclosure route and what we do about reports is described at Security.
5. The AI assistant
The assistant proposes; a person accepts. Do not use it to:
- extract another customer's data, or attempt to reach anything outside your own workspace;
- circumvent the rate limits or the entitlement checks that govern AI usage, including by automating requests;
- generate content you would not be entitled to produce yourself — the assistant does not give you rights you do not have;
- train a competing model on Outputs, or use Outputs to build a service that competes with LobiPlan.
And do not treat an Output as verified. Section 10 of the Terms explains what the AI in this product may and may not do; reviewing what it proposes is your job, and it is deliberately built so that a person has to press the button.
6. The inbound email agent
LobiPlan can accept work by email, at an address on agent.lobiplan.com. It answers whoever writes to it, identifies the sender by their email address, and spends the workspace's AI budget doing it. So:
- Do not use it as a mail relay or to forward mail through us to somebody else.
- Do not write from a spoofed or borrowed address in order to act as another member. The address is the identity here; using someone else's is impersonation.
- Do not submit content you have no right to submit into somebody's workspace.
- Do not send bulk or automated mail to it. It is for a person sending a message about work.
We may disable this channel for a workspace without disabling the workspace, and we will normally do that rather than take anything else away.
7. Meetings, recording and consent
Recording and transcription are off by default and switched on per meeting by the host. When they are on, LobiPlan shows a consent screen before anyone joins and broadcasts a notice in the call.
Those are notices. They are not consent, and we cannot obtain consent for you.
You are responsible for obtaining any consent the law requires before recording or transcribing a meeting, from every participant — guests included. Some jurisdictions require the consent of every party, not just one. LobiPlan provides a notice and a consent screen; it does not get consent on your behalf and cannot verify that you have it.
Two things to know about the in-call notice, because relying on it without knowing its limits would be unwise: it is broadcast by the host's own browser, so if the host's connection drops, other participants can be left without a visible banner while a recording continues. And a guest who is admitted mid-call has seen the pre-join screen but nothing after it.
Do not record a meeting for a purpose you have not told participants about, and do not use a recording or transcript for a purpose the participants would not expect.
8. Day links and other shared links
A day link is a URL a household administrator creates so that somebody without an account — a grandparent, a sitter — can see what is happening today. It shows a child's name, where they are meant to be, and the venue's address and phone number.
A day link is a secret URL. Anyone who has it can see what it shows, without signing in. It does not expire unless you give it an expiry date when you create one. Do not post it publicly, do not put it in a group chat you do not control, and do not send it to anyone you would not show that information to in person. Reset it from Family as soon as you want it to stop working.
The same holds for a calendar feed URL: the address itself is the credential, so anyone who has it can subscribe to what it shows.
If a link has gone somewhere you did not intend, reset it. If you need help, write to bsimba6@gmail.com.
9. Bank connections and uploaded statements
- Only connect a bank account you are authorised to connect. If an account is shared with somebody else, connecting it puts their transactions in front of whoever can see that workspace.
- Only upload a statement you are entitled to upload. Do not upload another person's statement without their agreement — and remember what is usually printed on one: the full account and transit number, the mailing address, anyone else named on the account, and sometimes images of cheques carrying a signature.
- Do not upload a document you would not want stored. Uploaded statements are kept for about 30 days so that you can check the figures against the source, and are then deleted. You can delete one sooner yourself.
LobiPlan never receives your bank sign-in details and cannot move money in any account. Nothing in this product initiates a payment.
10. Households and children
The account holder must be an adult with authority over the household. Children do not have accounts — a child is a record you create, holding a name and, if you enter one, a birth date.
Photographs of children are off by default. Turning them on is a decision for the household administrator, and you should only add a photo of a child you are responsible for.
One thing we need to say plainly, because the opposite assumption would be dangerous:
Kid Mode and the per-device profile are not parental controls. They change how this device presents the workspace — bigger type, a simpler screen, whose name is shown first. They restrict nothing. Every member of a household workspace can see the household's work data regardless of which mode a device is in. If a piece of information should not be visible to a child, do not put it in the household workspace.
11. What happens if this policy is breached
We may:
- suspend a workspace immediately where there is a risk of imminent harm to the Service, to another customer, or to a person — or where we receive a credible legal demand;
- otherwise, tell you what the problem is and give you a chance to fix it before suspending anything;
- disable one feature rather than the whole workspace where that is enough — the email agent and a shared link are the usual candidates;
- terminate for a serious or repeated breach, under section 19.2 of the Terms.
Suspending one workspace does not suspend the other workspace on your account.
We may monitor use of the Service, and we are not obliged to. We do not read your work in the ordinary course, and nothing here creates a duty on us to police what happens in your workspace — the responsibility for that is yours.
If we suspend something and you think we got it wrong, write to bsimba6@gmail.com. A person reads it.
Changes to this document
Changes to this policy are published here with the version bumped and a line in the changelog.
A change that adds a new prohibition, or that would make something you are currently doing a breach, gets 30 days' notice by email to every workspace administrator before it takes effect.
Previous versions are available on request from bsimba6@gmail.com.
Changelog
| Version | Date | What changed |
|---|---|---|
| 1.0 | 2026-08-20 | First publication. |
LobiPlan for organizations · LobiPlan for households · bsimba6@gmail.com