Tracya
EN FR
← tracya.io
Legal

Acceptable Use Policy

Last updated: May 25, 2026

1. Purpose

This Acceptable Use Policy ("AUP") defines the permitted and prohibited uses of the Tracya platform, API, and embeddable widget (collectively, the "Service") operated by Athivia Labs SAS. By accessing or using the Service you agree to comply with this AUP. Violations may result in suspension or termination of your account.

2. Permitted uses

You may use the Service to:

  • Create, publish, and iterate on in-app onboarding flows for your own web application(s).
  • Embed the Tracya widget snippet on domains you own or control.
  • Collect anonymised, aggregated analytics data on user progression through your flows.
  • Invite team members to collaborate on flow design within your workspace.
  • Use the Tracya API to programmatically manage flows, retrieve analytics, and integrate with your CI/CD pipeline.
  • Export your flow data and analytics for your own business reporting.

3. Prohibited uses

You must not use the Service to:

3.1 Illegal or harmful content

  • Create or distribute content that is unlawful, defamatory, obscene, or that infringes any third-party intellectual property rights.
  • Deploy onboarding flows that collect personal data without adequate legal basis, notice, or consent in violation of applicable privacy law (GDPR, CCPA, etc.).
  • Promote, facilitate, or solicit illegal activities.

3.2 Security and infrastructure abuse

  • Attempt to reverse-engineer, decompile, or extract source code from the Tracya widget, API, or dashboard.
  • Probe, scan, or test the vulnerability of Tracya systems without prior written authorisation from Athivia Labs SAS.
  • Introduce malware, viruses, or any malicious code into your flows or via the widget.
  • Attempt to bypass authentication, rate limits, or access controls.
  • Conduct denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks against Tracya or any third party.
  • Scrape, crawl, or systematically extract data from the Tracya platform beyond what the official API permits.

3.3 Platform misuse

  • Embed the Tracya widget on domains you do not own or are not authorised to modify.
  • Use the Service to build a competing product or to benchmark Tracya's systems for a competitor's benefit without written permission.
  • Resell, sublicense, or redistribute access to the Service or your Tracya API key to third parties.
  • Create multiple accounts to circumvent plan limits or the geographic restrictions set out in the Terms of Sale.
  • Use the Service from a blocked territory (see §4 below).

3.4 Deceptive or manipulative flows

  • Design onboarding flows intended to deceive end-users (e.g., hidden fees, false urgency, dark patterns that prevent cancellation).
  • Use the highlight or tooltip components to obscure critical information or mislead end-users.
  • Collect end-user credentials, financial data, or other sensitive information through Tracya flow steps.

4. Geographic restrictions

The Service may not be used by individuals or entities located in, or acting on behalf of governments of: the United States, Canada, Russia, Belarus, Iran, North Korea, Syria, Myanmar, Cuba, Sudan, South Sudan, Central African Republic, Mali, Guinea-Bissau, Haiti, Nicaragua, Venezuela, or Zimbabwe. Full details are in the Terms of Sale §17.

5. End-user data responsibilities

You are the data controller for any personal data collected by your flows from your end-users. You are solely responsible for:

  • Providing an appropriate privacy notice to your end-users before deploying any Tracya flow.
  • Obtaining legally required consent where applicable.
  • Responding to end-user data subject requests relating to data collected through your flows.
  • Ensuring your flows do not instruct Tracya to process special-category personal data (health, biometric, financial account data, etc.).

Athivia Labs SAS acts solely as a data processor for flow-level analytics and has no visibility into what personal data your end-users may enter into form fields within your flows.

6. Content moderation

Athivia Labs SAS does not proactively review the content of your flows. However, we reserve the right to investigate and remove flows, or suspend accounts, when we receive credible reports of AUP violations or when our automated systems detect anomalous behaviour (e.g., unusually high API request rates, widget injected on domains not matching your registered domains).

7. Reporting violations

If you believe another user is violating this AUP, please report it to support@tracya.io with as much detail as possible. We investigate all credible reports and aim to respond within 5 business days.

8. Enforcement

Depending on the nature and severity of the violation, Athivia Labs SAS may take one or more of the following actions without prior notice:

  • Issue a warning and request remediation within a defined timeframe.
  • Temporarily suspend specific features or the entire account.
  • Permanently terminate the account without refund.
  • Report the violation to relevant law enforcement authorities.
  • Seek injunctive relief or other remedies available under French law.

9. Changes to this policy

Athivia Labs SAS may update this AUP at any time. Material changes will be notified by email to the account holder at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated AUP.

10. Contact

Questions about this policy: support@tracya.io

Legal home Legal notice Terms of sale Privacy policy DPA Security Accessibility FAQ Contact us Cookie preferences
Legal notice Terms of sale Privacy policy DPA Security Acceptable use Accessibility FAQ Contact us Cookie preferences

© 2026 Athivia Labs SAS - All rights reserved.