Varren Acceptable Use Policy

Alpha Innovation Technologies - F.Z.C, a free zone company registered in Ajman Free Zone, United Arab Emirates, trading as AlphaIT Engineering ("Varren", "we", "us", "our")

Effective date: 22 September 2026 Version: 1.1 Applies to: varren.co, the Varren application, the Varren API, and every Varren service (together, the "Service")

1. Scope

Varren does not only generate content. It posts, sends, publishes, replies, researches, and drives a browser inside sessions you are signed in to.

This policy forms part of the Varren Terms of Service at https://varren.co/terms, and breach of it is breach of your contract. It binds you, everyone in your workspace, everyone you grant access to including your own clients, anyone using your credentials whether or not you authorised them, up to the point at which you notify us of unauthorised access under clause 14.5 of the Terms and we have had a reasonable opportunity to act, and everything Varren does under your Action Mandate, because an action within your mandate is your action. Where you provide Varren's capability to your own clients, their compliance is your responsibility.

2. The governing principle

The Service may be used only to do things you could lawfully and honestly do yourself, at the speed automation provides, without misrepresenting who you are. Automation is not a defence. The remainder of this policy states what that principle requires.

3. Prohibited content

You must not use the Service to generate, store, publish, transmit or act on content that:

3.1 Sexualises a minor, real or synthetic, drawn, described or generated.

3.2 Is sexual, intimate or pornographic imagery of any real, identifiable person. Consent does not change this. The Service is not available for adult content of any kind, generated or uploaded.

3.3 Incites, glorifies or instructs violence, terrorism, violent extremism or genocide.

3.4 Attacks a person or group with hatred or dehumanisation on the basis of race, ethnicity, national origin, religion, caste, sex, gender, gender identity, sexual orientation, disability or serious disease.

3.5 Harasses, stalks, doxxes or threatens a specific person, or coordinates others to do so, including by publishing a home address, private number, government identifier or location without consent.

3.6 Is defamatory, or states a serious accusation about an identifiable person or business as fact without a reasonable basis.

3.7 Gives operational instruction for serious harm, including chemical, biological, radiological or nuclear weapons, explosives, or weapons for mass casualties.

3.8 Facilitates trafficking, forced labour or child exploitation, or the sale of people, organs, endangered species or controlled substances.

3.9 Promotes self-harm, suicide or disordered eating, or supplies methods for any of them.

3.10 Is knowingly false and materially harmful, including fabricated health claims, fabricated emergency information and invented financial disclosures.

3.11 Infringes intellectual property or misappropriates a trade secret, including by prompting the Service to reproduce a specific protected work.

3.12 Breaches confidence, or is data you are not entitled to hold, including material from a breach, a leak or another person's account.

Fiction, satire, journalism, education, research and security work are legitimate purposes. They do not license clauses 3.1, 3.2, 3.7 or 3.8, and they do not license passing invented material off as fact.

4. Prohibited conduct

You must not use the Service to:

  1. Commit or facilitate fraud: phishing, confidence and advance-fee scams, fake invoices, business email compromise, pump-and-dump schemes, fake investment offers, or multi-level marketing recruitment.
  2. Manufacture inauthentic engagement: fake accounts, fake reviews or testimonials, bought followers, vote manipulation, astroturfing, brigading, or coordinated activity presented as independent voices.
  3. Conduct activity a platform classifies as spam, engagement farming or platform manipulation.
  4. Evade a ban, block, filter, age gate, geographic restriction, safety guardrail, approval gate or rate limit, ours or a third party's, including by creating replacement accounts.
  5. Deceive people about who or what they are dealing with, including by denying that an interaction is automated when someone sincerely asks.
  6. Surveil or profile a person without a lawful basis, or build a dossier on a private individual.
  7. Make or materially inform a decision about credit, employment, housing, insurance, education, immigration, benefits, healthcare, policing or essential services without competent human review by someone able and willing to override it.
  8. Operate, control, monitor or inform the operation of anything where a failure could kill or injure a person or cause serious damage to property or the environment, including power generation and distribution, water treatment, medical devices and clinical systems, emergency dispatch, aviation, rail, maritime and road traffic control, industrial control systems, telecommunications infrastructure and election systems. The Service is not certified, tested or insured for any of this, and no approval setting makes it suitable.
  9. Discriminate unlawfully in advertising, recruitment, lending, housing or pricing, including by targeting or excluding on a protected characteristic where the law forbids it.
  10. Market to, profile, build an audience from, or send automated messages to anyone you know or ought reasonably to know is under 18, or collect a child's personal data through the Service. The Service is for users aged 18 and over, as clause 4.1 of the Terms requires. Where a law gives children stronger protection, including the United States Children's Online Privacy Protection Act, the United Kingdom Age Appropriate Design Code, and state and national laws restricting the profiling of minors, that law governs and you must comply with it.
  11. Design, develop, refine, manufacture or source weapons, munitions, firearms, firearm components, untraceable or 3D-printed firearms, or systems intended to cause physical harm, or produce material that assists any of that.
  12. Attack, degrade or overload any system, ours or another party's.
  13. Resell or expose the Service as a general-purpose automation API beyond your plan, or use the Service, its output, its interfaces or any data derived from them to train, fine-tune, evaluate or benchmark a machine learning model, or to reverse engineer or reconstruct any part of the Service. This restricts what you may do with our product, not what business you may be in.
  14. Carry out any practice prohibited by Article 5 of Regulation (EU) 2024/1689, the EU AI Act, wherever you are. You must not use the Service to scrape facial images from the internet or from CCTV in an untargeted way to build or expand a facial recognition database; to infer emotions from a person in a workplace or an educational setting; to categorise people by biometric data in order to deduce race, political opinion, trade union membership, religious or philosophical belief, sex life or sexual orientation; to score or classify people by social behaviour or personal characteristics in a way that leads to detrimental treatment in an unrelated context; to exploit the vulnerability of a person by reason of age, disability or social or economic situation; or to use subliminal or purposefully manipulative techniques that materially distort a person's behaviour and cause or are likely to cause significant harm. Fines under Article 99(3) of that Regulation reach EUR 35,000,000 or 7% of total worldwide annual turnover, whichever is higher. This clause is enforced everywhere, not only in the European Union.
  15. Breach trade sanctions or export controls. Clause 37.4 of the Terms sets out the full obligation, and it reaches not only you but any person you direct the Service to contact.

5. Outreach, messaging and spam

The Service can send at volume. This section applies to that capability.

5.1 Every channel

5.2 Email

Send from a domain you control, with correct SPF, DKIM and DMARC, and include a valid physical postal address. Honour an opt out immediately where you can, and within ten business days at the outside. Do not use another organisation's domain, an open relay, disposable domains rotated to evade reputation, or a mailbox you accessed without authority. Do not send to addresses harvested from web pages, broker exports or breach dumps.

5.3 LinkedIn and professional networks

LinkedIn's User Agreement prohibits using software, scripts, robots, crawlers, browser plugins or extensions to scrape or copy the service, and prohibits bots or other unauthorised automated methods to access it, add or download contacts, send or redirect messages, or create, comment on, like, share or re-share posts. LinkedIn enforces that against accounts and against vendors.

Where an official API exists and we support it, Varren uses it. Where you instruct Varren to act through a browser session instead, you are choosing to act in a way the platform may treat as a breach, and the consequences, including permanent loss of your account and your network, are yours. We may restrict, throttle or withdraw browser automation for any platform, for any account, at any time and without notice, including where a platform requests it. Do not mass-connect, run untargeted connection or InMail sequences, auto-engage for reciprocity, or scrape profiles into a list.

5.4 WhatsApp and messaging apps

You may message a person on WhatsApp only where they gave you their number and opt-in permission to receive messages from you. Use approved templates where required, respect the customer service window, and provide a prompt, clear path to a human. Honour a block or opt-out request wherever it arrives. Do not use prohibited categories, consumer accounts, unofficial clients or grey-market gateways to send business messages at scale. The same applies to Telegram, Discord, Instagram direct messages and every other messaging surface: no cold bulk messaging into communities you joined for another purpose.

5.5 SMS, RCS and voice

Obtain prior express written consent for marketing, for the specific programme, with the sender identified and clear STOP handling. Register your campaign where the carrier requires it and send from the identity you registered. Respect quiet hours and do-not-call registries where your recipient is. Do not spoof a sender ID, use borrowed number pools to obscure who is sending, or place AI-voice calls without the consent the law requires for an artificial or prerecorded voice.

5.6 Volume, pacing and limits

Your plan carries rate limits and the Service paces itself to protect connected accounts. Do not circumvent either, split a campaign across accounts, workspaces, domains, numbers or tenants to defeat a limit, or rotate identities to spread volume. We may lower a limit on any account at any time. Bursts indistinguishable from a spam run may be throttled or stopped, whether or not the content is lawful.

6. Scraping, data collection and platform terms

You may collect data you are entitled to collect. You must not use the Service:

Signing in with your own credentials, or with credentials the account owner authorised you in writing to use, and then having Varren act in that session is not circumvention. Defeating a check that exists to establish that a human is present is circumvention, even in your own account.

Whether an automated collection is permitted is a question about the source and about you. Determine it before you instruct the Service.

7. Impersonation and identity

You must not impersonate any person, business, brand, government body, regulator, law enforcement or emergency service, or imply an affiliation or endorsement you do not have. You must not operate an account in another person's name without their written authority, hold yourself out as a licensed professional you are not, or use our name or marks to suggest we authored your content. Acting openly for a client whose authority you hold is agency, not impersonation, and is a normal use of the Service.

8. Synthetic media, likeness and voice

These rules apply whenever you upload a photograph, video, recording or voice sample of a real person, and whenever you ask the Service to generate content depicting, imitating or reproducing the appearance, voice or manner of a real person, living or dead.

8.1 Consent. For every identifiable person you must hold free, specific, informed and unambiguous written consent covering the media, the territories, the duration and whether the use is commercial. Consent for one campaign is not consent for the next. For a deceased person you need the written authorisation of whoever controls the estate's publicity rights.

8.2 Evidence. Keep the consent record for at least three years after the last use and produce it within five business days of our request. We may require proof before enabling a likeness capability, and may require the depicted person to complete a consent step directly with us. We are not obliged to verify, and not verifying does not move responsibility from you to us.

8.3 Prohibited, with or without consent.

8.4 Labelling. Article 50(2) of Regulation (EU) 2024/1689, the EU AI Act, requires the provider of a generative AI system to mark its output in a machine-readable format. Where the model we route to embeds such a marking, including an invisible pixel watermark, that marking travels with the file and you must not remove, alter or obscure it, and you must not use the Service to remove it from another person's content. Some formats and settings produce a file with no embedded metadata, in which case the file carries no marking and the audit trail in your workspace is the record that the output was generated by Varren. Where you publish a deep fake you are the deployer under Article 50(4) and must disclose that the content is artificially generated or manipulated, clearly and no later than the first time a person is exposed to it. Non-compliance can attract fines of up to EUR 15,000,000 or 3% of total worldwide annual turnover, whichever is higher. Which disclosure a given publication needs, and where it appears, is your judgement.

8.5 Withdrawal and takedown. Where a person withdraws consent, stop generating immediately, remove existing content from every channel you control within seven days, and notify us at [email protected]. We may disable reference material on credible notice from the person depicted, and we will inform you when we do.

8.6 The laws you are agreeing to comply with. These include, and are not limited to:

This clause extends automatically to further digital replica and synthetic media laws as they take effect.

9. Elections and political content

Political communication is permitted. Deceptive political communication is not. You must not:

Political advertising must meet the disclosure, labelling, sponsor identification and funding transparency rules that apply to you. In the European Union that includes Regulation (EU) 2024/900 on the transparency and targeting of political advertising, which requires a clear statement that an advertisement is political, a transparency notice, and a prohibition on targeting that profiles people using special categories of personal data. Comparable rules apply elsewhere.

We may require verification, decline political and issue advertising on any account, and restrict autonomous political publishing during an election period.

10. Financial, medical and legal content

The Service produces drafts. It does not produce advice and it is not a licensed professional.

You must not present its output as personalised financial, investment, tax, insurance, medical, mental health, legal or immigration advice, or hold yourself out as licensed where you are not. Content in these fields must be reviewed by a qualified person before publication, must carry any disclosure your regulator requires, and must not promise a specific financial return, clinical outcome, legal result or visa decision. Without that review, you must not use the Service to produce securities offering material, credit or underwriting decisions, diagnoses, treatment plans, dosing instructions, or filings for a court or regulator.

11. Security, malware and testing

You must not use the Service:

Defensive security work is permitted, including testing your own systems and testing a third party's under a written authorisation you can produce on request. The authorisation is the difference, and the burden of showing it is yours.

You must not attack the Service itself, extract our models, prompts or configurations, or work around our safety controls in order to abuse them.

Security research safe harbour. We will not treat security testing of the Service as a breach of this policy, and we will not pursue a claim or a report to law enforcement over it, where you test only your own workspace and your own data, stop as soon as you confirm a problem, take no more data than is needed to demonstrate it, do not degrade the Service for anyone else, do not access another tenant's workspace or data beyond the minimum needed to prove that access is possible, notify us at [email protected] with "Security" in the subject line before telling anyone else, and give us ninety days to fix it before publishing. Testing outside those bounds is not covered. Where you are unsure whether a test is covered, ask us first.

12. Accounts, credentials and access

Seats are personal. Do not share a login, access link, API key, session token, recovery code or two-factor secret, pass a seat around a team, sell or rent access, or create accounts to obtain trials, credits or capacity you are not entitled to.

Connect only accounts you own or are authorised in writing to operate, and not an employer's, a client's or a former client's account once your authority has ended. Revoke access when a person leaves or an engagement ends. Notify us within twenty four hours of discovering any actual or suspected unauthorised access.

13. Supervising autonomous action

The approval spine is your control surface, and the level of autonomy you run at is your decision.

14. Enforcement

14.1 What we may do. Depending on severity: warn you, throttle or pause an action, disable a capability or a connected account, remove or quarantine content, require proof of consent, suspend your account, or terminate it. Where we restrict or remove your content we will tell you what we removed and why, unless a law or valid legal process prevents us.

14.2 Immediate suspension or termination, without notice and without refund. For the conduct in clause 3.1 or clause 8.3, for criminal activity, and for activity that harms or endangers a person, threatens the Service or another customer, or exposes us to legal or regulatory risk, we act immediately. Fees already paid are not refunded, unspent Varren Credits are cancelled without refund, and clause 21.4 of the Terms applies. Where a law that applies to you requires a refund, we will make it. Where you are a consumer, nothing in this clause takes away a right your national consumer law gives you and does not permit you to give up.

14.3 What suspension does not do. It does not pause your billing where the cause is your breach, release you from fees you owe, or affect your indemnity under clause 19 of the Terms.

14.4 Reporting and preservation. We report child sexual abuse material and credible threats to life to the authorities. We report other unlawful activity where a law that applies to us requires it, or where we reasonably believe disclosure is necessary to prevent serious harm to a person. We may preserve evidence, including content and audit records, for as long as an investigation, legal obligation or dispute requires. Where a third-party platform asks us about activity on an account you connected, we will inform you before we respond unless a law or the platform's valid legal process prevents us, and we will disclose no more than the request requires. What we disclose, to whom, and on what legal basis is set out in the Privacy Policy at https://varren.co/privacy.

14.5 Appeals. Where you consider that we acted wrongly, write to [email protected] with your account and what you want reviewed. We will tell you what we found and why we acted, and we will answer within ten business days. An appeal does not lift a suspension while it is considered, and we do not reinstate for the conduct in clause 14.2.

14.6 Detection. We use automated systems, and human review where an automated signal warrants it, to detect and investigate breaches of this policy in content, prompts, outputs, connected-account activity and audit records, to keep the Service, its customers and the public safe, on the legal bases and within the limits set out in the Privacy Policy at https://varren.co/privacy. We do not use this access to read your material for any other purpose, and nothing detected in one workspace is surfaced in another.

14.7 Discretion. Not enforcing once does not waive our right to enforce later and does not make the conduct permitted.

14.8 Consumer rights. Where you use the Service as a consumer, nothing in this policy excludes or limits a right you have under the consumer law of the country you live in that cannot be excluded or limited by agreement. Where a term of this policy conflicts with such a right, the right prevails and the rest of this policy continues in force.

15. Reporting abuse

State what happened, where you saw it, and how to reach you. We acknowledge every report within two business days and tell you the outcome within fourteen days, or tell you why it is taking longer. We do not retaliate against a good-faith report.

16. Survival

These obligations continue after your account ends, for as long as they can still matter: the consent records you must keep and produce under clause 8.2, the withdrawal and takedown duties in clause 8.5, your responsibility for content you published while you were a customer, the cooperation and preservation provisions in clause 14.4, the security research safe harbour in clause 11, and clause 14.8. Everything else ends when your right to use the Service ends.

17. Changes to this policy

This policy is a separate document incorporated into the Terms by reference. Prior versions are available from the company on request to [email protected]. For a change that materially reduces what you are permitted to do we will give thirty days notice by email, except where a shorter period is needed to comply with law or stop active harm. Continuing to use the Service after a change takes effect constitutes acceptance of it. Where a change materially reduces what you are permitted to do and you do not accept it, notify us at [email protected] before it takes effect and terminate under clause 21.1 of the Terms, and we will refund prepaid fees for the unused remainder of your term together with the value of unspent unexpired Credits. This refund right is an exception to clauses 21.1 and 21.4 of the Terms and prevails over them.


Varren is operated by Alpha Innovation Technologies - F.Z.C, Ajman Free Zone, Ajman, United Arab Emirates, trading as AlphaIT Engineering. Read this policy together with the Terms of Service at https://varren.co/terms and the Privacy Policy at https://varren.co/privacy.