Terms of ServicePrivacy PolicyAcceptable Use PolicyData Processing Agreement

Goro Acceptable Use Policy

Version 1.0 Effective date: 2026-08-01 Last updated: 2026-08-01

Applies to everyone who calls the Goro gateway, over the HTTP API with a goro_live_ key or over MCP. It forms part of the Terms of Service at https://usegoro.ai/legal/terms.

Break this policy and we can cut your access and close your account.


What Goro does with your call, and what that leaves to you

Goro is a pay-per-call gateway in front of third-party tools. Most of them are Apify actors. The image and video endpoints run on kie.ai and the voice endpoints on Fish Audio. For each call we:

  • check your JSON against the endpoint's schema,
  • fill in the defaults our schema declares,
  • on the Apify-backed endpoints, pass anything else you send through unchanged, including fields we do not declare,
  • send it to the provider, and return the tool's items untouched,
  • store nothing of what you sent, and hold what came back only until you collect it, and never longer than 24 hours.

Read those middle points again, because they cut both ways.

We do not filter anything, with one narrow exception. The schema check is a shape check, not a safety filter. Every Apify-backed endpoint's schema allows undeclared fields, so anything extra you put in the body is forwarded to a third-party tool as you wrote it. (The voice and generative endpoints are stricter and reject fields they do not declare.)

The exception is a short list of run-infrastructure fields we refuse outright, on every endpoint: customMapFunction, pageFunction, cookie, cookies, initialCookies, proxy, proxyConfig, proxyConfiguration, customHttpHeaders, authTokens and userAgent. These are not capability, they are control over the account the run executes on: code we would execute and pay for, credentials attached to our identity, or traffic routed through a host you choose. A request carrying one is rejected with a 400 naming the field, rather than being silently stripped, because a run that quietly ignored what you sent would still have charged you. Fields that merely resemble these, such as proxyCountryCode, are untouched. We do not pick your targets, rewrite your queries, or screen the output. You decide what gets collected, about whom, and what happens next, and you need a lawful basis for the call and for what you do with the results.

Some of our defaults decide how much personal data a call collects. If you leave a field out, you get the default we chose, not the smallest possible request. Today:

  • twitter.followers defaults getFollowers to true, and the smallest request the tool accepts is 200 followers per call. So the bare call returns a follower list, because of our default.
  • The three LinkedIn search endpoints (linkedin.search_name, linkedin.search_services, linkedin.company_employees) let you choose how much of each profile comes back. We default that to the least revealing option, Short. Full and Full + email search exist and are opt-in. That is still our choice rather than yours, and it is worth knowing which way it points.

inspect shows every default before you run anything, and setting a field yourself always wins.

Four more things you are agreeing to:

  • Every customer run executes under one Goro account with each execution provider. Your abuse lands on our account and on the tool authors, not only on you. That is why this policy is enforced rather than decorative.
  • Your run input is not stored by us, and that is not the same as private. It is passed to a third-party tool as you wrote it, and that tool's operator handles it. Do not send anything you are not entitled to send to a third party.
  • The RESULTS are held only until you collect them, and never longer than 24 hours. Goro writes a finished run's rows to its database so a slow run stays collectable, then deletes them shortly after your first fetch and unconditionally at the 24 hour mark. The window is deliberately the shortest one that makes a paid run reliably deliverable, because this catalog reaches personal data about people who have no relationship with us. It also means we cannot hand you results back after that window: once a result reaches you, it is yours to govern. Audio that voice.speak generates is held the same way, on the same clock, except that it sits in a private file store rather than in the database and reaches you as a link that stops working at the same deadline. Download it if you need to keep it. Images and video are different again: those files are hosted by the generative provider, which states a 14 day retention for them, so the URL we hand you outlives our own record of the run.
  • A CLONED VOICE IS THE ONE EXCEPTION, and it is deliberate. Everything else here is a call that leaves nothing behind. A voice model created by voice.clone is a durable object: it is kept at the provider, under Goro's account, until you delete it, because a voice you have to re-upload recordings for every time is not a reusable voice. The reference recordings themselves are not stored by Goro at all, only passed through. Clause 10 has the rest.

What we do keep about you, and for how long. Which endpoint you ran, when, what it cost, how many rows came back and whether it errored, kept for 10 years as part of the accounting record. Your wallet ledger, the same. Your account, workspace and API key records, for as long as the account exists. The raw text of a discover query that matched nothing, for 90 days. The Privacy Policy section 6 has the full table, including which of these a scheduled job enforces and which are still a person's job.

The short version

  • Do not collect data about people without a lawful reason.
  • Do not turn the output into a data product about people.
  • Do not use it to target, track or harass anyone.
  • Do not use it to get into things, or around things.
  • Do not message people in ways their law does not allow.
  • Do not use an endpoint in a way the source platform forbids.
  • Do not fake a real person's voice, and do not use a synthetic one to deceive anybody.

Prohibited uses

1. Personal data without a lawful basis. If a call returns data about identifiable people, you must have a lawful basis for collecting it and for the purpose you collect it for, under GDPR, UK GDPR, CCPA/CPRA or whatever applies to you. "It was public" is not a lawful basis on its own. Request the smallest set of fields and rows that does your job.

2. Turning the output into a data product about people. You may use Goro to research a market, fill your own CRM, source candidates or build your own prospect list, if clause 1 and clause 5 are satisfied. You may not:

  • sell, license, broker, syndicate or publish personal data obtained through Goro, in raw or enriched form,
  • feed it into a people-search service, a contact or lead database, or a data-broker inventory that others query,
  • re-identify pseudonymous data, such as tying a Reddit or TikTok username to a real identity,
  • train or fine-tune a model that reproduces profiles of identifiable people, or build a facial recognition or other biometric database from scraped images.

The line is your own use versus supplying others. Crossing it is the fastest way to lose the account.

3. Harassment, stalking, doxxing and surveillance of individuals. No monitoring a named person's posts, comments, likes, followers, event attendance or location over time. No publishing or circulating someone's home address, phone number or personal email. No dossiers on private individuals, journalists, activists, ex-partners or anyone who did not sign up for it. No covert monitoring of people on behalf of a state or security service. Lawful, documented investigative work by a party that is entitled to do it is a different thing, and if we ask, you should be able to show which one you are.

4. Credential stuffing and unauthorized access. Do not use Goro against accounts you do not own or are not authorized to access. Do not pass credential lists, session cookies, tokens or stolen logins as endpoint input, in a declared field or an undeclared one. Anything you send is forwarded to a third-party tool, so it leaves your control the moment you send it.

5. Circumventing access controls. Do not use Goro to get around a platform's login wall, paywall, rate limit, IP block, bot detection, robots directives or contractual API limits. Do not create extra accounts to dodge a limit applied to you, and do not farm the signup credit with plus-addressed emails, disposable domains or duplicate accounts. The promo is one per person, whether or not our checks catch you.

6. Unlawful and unsolicited messaging. Contacts sourced through Goro come with the sender's obligations attached. You must:

  • meet the marketing and communication law that applies to you and to the recipient, including GDPR and ePrivacy, CAN-SPAM, CASL and local equivalents,
  • identify yourself honestly and give a working opt-out in every message,
  • honour every opt-out and keep a suppression list across campaigns,
  • not run automated DM, connection-request or follow bots, which also breaks the source platform's terms and therefore clause 7.

The rules differ by country, and by whether the recipient is a private individual, a sole trader or a company. In the EU and the UK, a published address is not consent. Sole traders and one-person businesses are usually treated as individuals. Working that out is your job, not ours.

This bites hardest on the LinkedIn "full + email search" modes, on linkedin.profile, and on any endpoint that returns a prebuilt contact database rather than a live scrape. Every row those return is a contact record carrying a business name, an email address, a phone number, a business address and a registration and VAT number, so clauses 1, 2 and 6 apply to all of it.

Receiving a contact record is not a licence to message the person it describes. Two things in particular:

  • Many marketplace sellers are sole traders or one-person companies. Under EU and UK law those are usually treated as individuals, not as businesses, so the stricter rules apply to them.
  • A published business address is not consent. It never has been in the EU or the UK.

If you cannot say which lawful basis covers your intended use of a row, do not send the message.

7. Anything that violates the source platform's terms. Every data endpoint hits a real platform with its own terms of service. If your use breaches theirs, it breaches ours.

8. Sensitive uses. No collecting or inferring special-category data (health, religion, politics, sexual orientation, union membership, ethnicity), including via group membership or engagement history. No targeting children, and do not submit data about children as input. No using Goro output to decide credit, employment, housing, insurance or benefits. Goro is not a consumer reporting agency, output from the gateway is not a consumer report, and it must not be used for any purpose regulated by the US Fair Credit Reporting Act or its equivalents. No discriminatory targeting.

9. Abusing the gateway itself. Do not share, publish or embed your API keys in client-side code. Do not resell, sublicense or white-label access without a written agreement with us. No probing other workspaces, no attacks on our infrastructure or on an execution provider, no fraud, malware or other unlawful activity. Do not evade the rate limits, the concurrency cap or a budget block, including by spreading traffic across extra keys or extra accounts.

10. Voice. A person's voice identifies them the way their face does, and a convincing synthetic one can be used against them by anyone who has it. The voice endpoints (voice.speak, voice.transcribe, voice.clone, voice.list, voice.delete) come with their own rules:

  • Do not clone, imitate or synthesise a real person's voice without that person's documented consent, given for this use. Documented means you can produce it if we ask. A recording being public is not consent, and neither is owning the rights to the recording: those are two different permissions and you need the one from the person.
  • Do not pass a real person's voice as reference audio or as a voice model unless that same consent covers it.
  • Do not present synthetic speech as a genuine recording or as a real person speaking. If a listener could reasonably take it for the real thing, say that it is generated.
  • Do not use a synthetic voice to impersonate anyone, real or invented, in order to obtain money, credentials, access or a decision. That covers calls to banks, employers, helpdesks, family members and any system that treats a voice as proof of who is speaking.
  • Do not submit someone else's recorded voice for transcription without a lawful basis for holding it, and do not use transcription to monitor a named person over time. Clause 3 already says that, and recordings make it easier to do, so it is worth saying twice.
  • Do not synthesise a child's voice, and do not submit one as input.

Cloning is available. voice.clone takes recordings of a person speaking and produces a reusable voice model. voice.speak will then speak in it. Three things about how it works are worth stating plainly, because two of them protect you and one of them does not.

  • Consent is asked for on every single call. voice.clone will not run unless you set consent_attested to true. What that flag means is the first rule above, in full: the person whose voice the recordings capture has given documented consent to have their voice cloned and synthesised for this use, and you can produce that consent if we ask. There is no default and it is not remembered between calls. What you attested, and when, is recorded against the voice and stays with it.
  • The attestation is a record of what you told us. It is not verification. We cannot hear who is in an uploaded recording and we do not try to. Nothing in the flow checks whether the consent exists, whether the speaker is who you say, or whether the voice is a real person's at all. Setting the flag does not transfer responsibility to us and it is not a defence: it is a statement you made, timestamped, that we will produce if a person whose voice was cloned comes to us, and that we will act on under the enforcement section below.
  • A cloned voice belongs to the workspace that created it and to no other. Nothing else can reach it. A voice id from another workspace is refused in exactly the same way as one that does not exist, so no customer can use, discover, confirm the existence of, or delete another customer's voice. voice.list shows only your own. This is enforced in our database on every call, not by the provider.

Deleting a voice with voice.delete, or from the Resources page in the app, removes it from the provider as well as from Goro. If the person whose voice it is withdraws consent, that is the thing to do, and it is not reversible.

Extra conditions on people-data endpoints

These endpoints serve legitimate research, recruiting, sales ops and market analysis. They are also the ones that get accounts closed: the LinkedIn set (linkedin.profile, linkedin.search_name, linkedin.search_services, linkedin.company_employees, linkedin.profile_posts, linkedin.post_search, linkedin.jobs), twitter.followers, twitter.profile, amazon.sellers_eu, and the Facebook, Instagram, TikTok, Reddit, YouTube and Maps endpoints that return comments, reviews, followers or profile detail. maps.reviews belongs on that list: its output carries the reviewer's display name, profile URL and review history, not just the review.

Before you call them:

  • Be able to state your lawful basis and purpose in one sentence if we ask.
  • Request the minimum. On linkedin.search_name, linkedin.search_services and linkedin.company_employees the fuller modes are opt-in, so leave profileScraperMode on Short unless you actually need more, and never select the email mode unless you genuinely need contact details.
  • Know that linkedin.profile has no such switch. It takes profile URLs only, and the tool returns a contact email or phone whenever it can resolve one. If you call it, assume you are collecting contact details, and have a basis for that before the call, not after.
  • If GDPR applies to you, you owe the people in that dataset an Article 14 notice, and you must honour access, objection and erasure requests. Goro does not do this for you.
  • Delete what you no longer need. Do not treat a run output as a permanent asset. We hold ours for at most 24 hours; after that the only copies are yours and the execution provider's.

If someone whose data you collected complains to us, we will come to you and expect a straight answer. Data subject and takedown requests reach us at hello@usegoro.ai and are answered within the one month the GDPR allows. In most cases the answer will be that we no longer hold anything, because of the retention above.

What we can see

We do not store your run input, so we cannot read it after the fact, and neither can anyone who compromises us. What we can read is the RESULT of a run while it is still inside the 24 hour window, and the metadata of every run for as long as we keep it: which endpoint, when, what it cost, how many rows, and any error.

Our server code runs with a database key that bypasses row level security, so an operator with that key can read any workspace's results during that window. There is no audit log recording when it is used. If a complaint arrives, or an execution provider or a source platform escalates, we will read the actual results of the runs in question, not only the metadata, and we may share the relevant records with the provider, the affected platform, or law enforcement under "What we do when you break this".

Two consequences for you. Do not send anything into Goro that you could not stand to have read by us. And if you are the controller of the data you collect, your own privacy notice has to account for us holding it, briefly, on your instruction. The Data Processing Agreement at https://usegoro.ai/legal/dpa is the contract that covers it.

Who can use Goro

Goro is for business use. By using it you confirm you are acting for a business, trade or profession and not as a consumer, and that you are over 18. We do not verify this at signup, so that confirmation is a warranty from you rather than a check on our side. If you are a consumer anyway, the mandatory consumer law where you live applies to you whatever this says, and Terms section 7.4 says the same thing.

Reporting abuse

Email hello@usegoro.ai with the details, and the run id or key prefix if you have one.

What we do when you break this

We do not pre-screen runs. We act on complaints, on reports from an execution provider or a source platform, and on our own review of your runs. Depending on severity, in any order, with or without prior notice, we may:

  • ask what your use case is, and hold off while we wait for an answer
  • revoke every API key on your workspace, which also kills the OAuth tokens issued against them and cuts MCP access in the same moment
  • cancel in-flight runs, which releases the hold and charges you nothing for them
  • delete any stored run output before its deadline
  • close the account, which means revoking every key and removing the account itself
  • refuse future signups
  • pass information to the execution provider, to the affected platform, or to law enforcement where we are legally required to or where someone is at risk

Serious cases go straight to closing the account: stalking or targeting an individual, credential attacks, selling scraped personal data, anything illegal.

Enforcement today is manual, and here is exactly how blunt the tools are. We do not promise real-time detection and nothing in this section is a commitment to monitor. There is no per-workspace disable switch and no per-endpoint restriction, so revoking keys is the only control that lives inside the product, and a signed-in user can mint a replacement key immediately. That is why "closing the account" means removing the account at the identity provider, by hand, rather than flipping a flag. We would rather describe the ladder we actually have than one that sounds better.

On money: runs we block or cancel are not charged, and failed runs are never charged. The wallet is prepaid, is not withdrawable, and unused cash is refundable on request under Terms section 7. If we close your account because you breached these rules, the unused balance is forfeited.

To appeal, email hello@usegoro.ai and quote your key prefix. If we got it wrong we will say so and restore access.

Changes

We may update this policy. The version in force is always the one published at https://usegoro.ai/legal/acceptable-use, with the version number and date at the top. A material change takes effect 14 days after we publish it and any other change takes effect when published. Publication is the notice, because the product has no outbound email and we will not promise a channel we do not have. Continuing to use Goro after a change takes effect means you accept it. The Terms, the Privacy Policy and the DPA carry the same clause, the same period and the same channel.

Who you are contracting with

PROMPTIFY S.R.L. Strada Prof. Nicolae Oblu, Nr. 24A, Bloc B2A, Etaj 2, Ap. 22, Municipiul Iasi, Judetul Iasi, Romania Trade register number J22/1745/06.06.2023, CUI 48270068, EUID ROONRC.J22/1745/2023, VAT RO48310979

Contact: hello@usegoro.ai

Related documents. Terms of Service (https://usegoro.ai/legal/terms), Privacy Policy (https://usegoro.ai/legal/privacy), Data Processing Agreement (https://usegoro.ai/legal/dpa).