Evil ASF

API acceptable use

Effective 14 August 2026. This is the whole policy. There is no second document, no appendix, and nothing here is decided case by case.

Evil ASF sells an uncensored model. That is the product, not a side effect of one, and this page exists so that the exact edge of it is knowable before you build against it rather than discovered by a 403 in production.

What we do not restrict

The API does not refuse, soften, water down, or add warnings to:

  • profanity, insults, and abrasive tone
  • sexual content between consenting adults, including explicit content
  • offensive, extreme, unpopular or wrong political and religious opinions
  • graphic violence in fiction, journalism or analysis
  • conspiracy analysis, contested history, and arguments against official accounts
  • criticism, ridicule and accusation directed at public figures, companies, governments and institutions
  • the full contents of the document archive, however graphic — including released material describing the sexual abuse of real people and of children

That last line is not an exception we tolerate. It is the primary use of this product. Asking what a document says, quoting it, summarising it or analysing it is always allowed, and we have deliberately built the safety floor so that it cannot fire on research.

If a filtered model refuses something and we do not, that is the thing you are paying for.

The floor

Two things are refused. Both are stated as law rather than taste, and there is nothing else on the list.

1. Sexual content involving a minor. Any framing, real or fictional, including roleplay, fan fiction, and "aged-up" framings of a character established as a child. There is no artistic, satirical or research exemption.

2. Sexual content depicting a real, identifiable, living person. Writing a sex scene starring a named real person is refused. Discussing, reporting or quoting the documented record of what happened to a real person is not — that is the distinction, and it is the difference between generating and describing.

A third rule is contractual rather than automatic:

3. Targeted harassment, threats, or doxxing of a named private individual. No classifier screens for this, because one that tried would become the general refusal layer this product exists not to have. It is enforced by account termination after the fact, on report or on review.

How the floor is enforced

One classifier, on the request you send and on the output we generate. It is never run in shadow mode — if it flags something, we act on it in the same request. We do not keep a quiet score against your account.

It screens what you wrote, not what we retrieved. Archive documents injected into your prompt are never passed to it. This is what makes rule 2 safe for research: our own retrieval layer supplies the graphic material, and screening it would refuse the question that caused it.

If the classifier is unavailable, your request is served. We record that it was not screened. We do not fail your request because a dependency of ours is down.

A refusal is billed

A refused request answers 403 CONTENT_REFUSED and is charged at the price it would have cost.

This is deliberate and it is the only place where credits do not track inference. A free refusal turns the endpoint into a free oracle for mapping the exact boundary at 60 requests a minute, at no cost to whoever is mapping it. Charging is not a penalty; it is the only thing that makes probing cost something. We also did the work.

The refusal body names which of the two rules applied and links back to this page. It will never say only "content policy".

Three refusals suspends the key

Three refused requests on one key within 24 hours suspends that key automatically and alerts a person. This is a rule, not a heuristic, which is why it is allowed to be automatic.

GET /api/v1/key reports your refusal count, so this is visible before it happens rather than after.

If your key is suspended and you believe the refusals were wrong, reply to the notification. Wrongly refused requests are refunded and the key is restored. We would rather hear about a bad refusal than not — a classifier that refuses research is broken in the direction that costs us customers, and we want to know.

Attribution

Every chat request carries end_user: an opaque, stable identifier for whoever inside your product caused the call. We store only a peppered HMAC of it, never the value, so an internal user id or an account number identifies nobody to us.

It exists so that when something goes wrong we can stop one of your users rather than your whole integration. A rotating identifier — a fresh UUID per request — defeats that, and leaves suspending your key as the only action available to us. We measure the ratio of distinct identifiers to requests and will contact you before doing anything about it.

Reporting

To report content produced through this API, or non-consensual intimate imagery anywhere on the platform: [email protected], read by a person. Reports of non-consensual intimate imagery are acted on within 48 hours.

Changes

Material changes to the floor are announced by email to every account with a live key at least 30 days before they take effect. We are not going to quietly widen this list — the whole value of a published floor is that it is the same one you built against.

This page covers the API only. The general terms of service cover accounts, subscriptions and billing.