ALYT
Home Legal

Acceptable Use Policy

Version 1.0  |  Effective: September 6, 2026

This policy sets out what you may not do with ALYT. It is incorporated by reference into our Terms of Service — a violation of this policy is a violation of those Terms. We wrote it in specific, concrete terms rather than only abstract legal language, because a rule you can actually picture is a rule you are more likely to follow, and because ALYT sits in an unusual position: it is simultaneously a home automation product, a device with a microphone in your living room, and a platform with a real API surface that a determined bad actor could try to abuse. Each of those needs its own guardrails.

1. Compliance with Law

You must use ALYT in compliance with every law that applies to you, wherever you are and wherever your home is. This includes, without limitation, laws concerning:

  • Computer fraud and unauthorized access (in the U.S., the Computer Fraud and Abuse Act and equivalent state laws; internationally, equivalent computer-misuse statutes)
  • Wiretapping and eavesdropping, including single-party and all-party consent recording laws, which vary significantly by state and country
  • Stalking, harassment, and coercive control
  • Privacy and data protection (GDPR, CCPA/CPRA, and similar)
  • Children's protection (including COPPA in the U.S.)
  • Export control and economic sanctions
  • Intellectual property

2. Unauthorized Access and Account Security

2.1 You may not attempt to access anything that is not yours

  • Another household's account, home configuration, or devices
  • Data belonging to another ALYT tenant, customer, or user
  • ALYT's internal systems, infrastructure, or source code beyond what is publicly documented
  • Private network addresses (for example, addresses in the 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16 ranges) reachable only from ALYT's own infrastructure, which are never a legitimate target for a request through ALYT's public API

2.2 You may not compromise account security

  • Sharing your password, API keys, or MFA recovery codes with anyone outside your own household
  • Using someone else's login credentials
  • Attempting to bypass, disable, or circumvent multi-factor authentication
  • Leaving an authenticated session open on a shared or public device

2.3 You may not reverse-engineer or hack ALYT itself

  • Decompiling, disassembling, or reverse-engineering the ALYT app, console, or firmware, except to the limited extent applicable law expressly permits despite this restriction
  • Probing, scanning, or testing ALYT's infrastructure for vulnerabilities outside the good-faith research process described in our Security & Responsible Disclosure policy
  • Exploiting a known vulnerability rather than reporting it responsibly

3. Surveillance and Recording Abuse

ALYT will not be used as a tool for unlawful surveillance. This is not a formality — a product with a microphone that can be placed in a bedroom, and that (through integrations) can drive cameras, carries a real risk of misuse that we take seriously.

3.1 Prohibited

  • Using voice, camera, or sensor features to monitor a partner, family member, roommate, employee, or anyone else without the consent required by law where you are located
  • Placing a microphone- or camera-equipped device to observe a bathroom, a changing area, or any other space with a clear expectation of privacy
  • Using motion sensors, presence detection, or automation history to track a specific person's movements or schedule as a form of controlling or intimidating them
  • Recording anyone's voice or image without the consent required in your jurisdiction — many U.S. states require the consent of every party to a conversation, not just the person operating the device
  • Sharing recordings, transcripts, or footage of people outside your household without their consent
A concrete example of what this rule is for: a person configuring an ALYT hub with a hidden voice recording automation aimed at a partner or ex-partner, to secretly capture what is said in a shared home, is exactly the kind of use this policy prohibits and will result in account termination and, where warranted, a report to law enforcement.

3.2 What this does not prohibit

Ordinary household use — a shared voice assistant everyone in the home knows about and uses, a video doorbell that records visitors at your own front door, a security camera covering your own driveway — is the intended use of the product and is not what this section restricts. The line is consent and reasonable expectation of privacy, not "recording exists at all."

4. Interference and Abuse of Other Users

  • Attempting to control, disrupt, or interfere with another person's devices or home
  • Sending unsolicited notifications, messages, or commands to accounts you do not own or have not been granted access to
  • Creating automations specifically intended to harass, annoy, or harm another person
  • Generating load, traffic, or requests intended to disrupt the Service for other users

5. Malware and Malicious Automation

  • Uploading, distributing, or attempting to execute malware through ALYT
  • Building automations designed to exploit a vulnerability in ALYT or a connected device
  • Injecting malicious code, scripts, or payloads into any part of the Service

6. API and Service Abuse

6.1 Rate limits and quotas

  • Exceeding published rate limits through automated or scripted requests
  • Attempting to evade a rate limit — for example, by splitting requests across accounts or credentials to exceed what any one of them permits
  • Bulk-scraping or bulk-downloading ALYT data outside documented, intended API usage

6.2 Denial of service

  • Sending traffic intended to overwhelm ALYT's infrastructure or degrade service for other users
  • Participating in, coordinating, or facilitating a denial-of-service attack against ALYT or against another user's home network via ALYT

6.3 Credential abuse

  • Attempting to guess passwords or API keys, including via credential-stuffing using leaked password databases
  • Reusing, selling, or distributing ALYT API keys or credentials

7. Unlawful or Harmful Content

  • Distributing content that violates any law through the Service, including in automation names, voice interactions, or any text field
  • Distributing child sexual abuse material — this results in immediate account termination and a report to the National Center for Missing & Exploited Children (NCMEC) or the equivalent authority in your jurisdiction, without exception
  • Distributing non-consensual intimate imagery
  • Using ALYT to send phishing communications or to impersonate another person or organization

8. Device and Hardware Abuse

  • Intentionally damaging ALYT hardware, whether your own (for warranty fraud) or another user's
  • Attempting to install unauthorized or modified firmware in a way that disables safety features, attacks ALYT's infrastructure, or attacks another user
  • Building automations that could reasonably be expected to cause fire, injury, or significant property damage — for example, an automation that repeatedly cycles a heating appliance in a way inconsistent with its safe operation
  • Distributing cracked, pirated, or unauthorized copies of ALYT firmware

9. Third-Party Integration Abuse

  • Sharing third-party integration credentials (Sonos, Ring, Alexa, and so on) with anyone unauthorized to access them
  • Using an ALYT integration to gain access to a third-party account or service you are not authorized to access
  • Exporting data obtained through a third-party integration and using it for a purpose unrelated to operating your own home
  • Using ALYT's connection to a third-party service to scrape or bulk-extract that service's own data outside its own terms

10. Unauthorized Commercial Use

Unless you have a separate commercial agreement with Fizzify Inc., you may not:

  • Resell access to ALYT, or offer it as a service to your own customers
  • Deploy ALYT in a commercial rental property, hospitality setting, or business premises for guest or employee monitoring without a commercial agreement covering that use
  • Use ALYT to develop a directly competing product, or analyze its internals for competitive purposes (beyond good-faith security research conducted under our Security policy)

11. Enforcement

11.1 How we learn about violations

Through automated anomaly detection (unusual traffic patterns, suspicious authentication attempts), reports from other users, our own security research, integration partners, and — where applicable — law enforcement.

11.2 What we may do

Depending on the severity and nature of a violation, we may: issue a warning; temporarily suspend your account; permanently terminate your account; remove specific content or automations; delete data associated with the violation; report the conduct to law enforcement, NCMEC, or another relevant authority; and pursue legal remedies to recover damages caused by the violation.

11.3 Appeals

If your account is suspended or terminated and you believe this was in error, email support@alyt.co with your account email and an explanation. We review appeals within 30 days. Termination for the most serious violations — hacking, malware distribution, unlawful surveillance, distribution of unlawful content — is final and is not subject to appeal.

12. Reporting a Violation

If you believe another ALYT user is violating this policy — including, especially, concerns about unlawful surveillance affecting you or someone you know — email support@alyt.co or privacy@alyt.co. We take reports of surveillance abuse and stalking-related misuse of ALYT particularly seriously and will prioritize investigating them. If you are in immediate danger, contact local emergency services first — ALYT is not a substitute for emergency response.

13. Responsible Security Disclosure

If you discover a security vulnerability, please report it through our Security & Responsible Disclosure process rather than exploiting it or disclosing it publicly. Good-faith security research conducted under that policy is not a violation of this Acceptable Use Policy, even where it necessarily involves the kind of probing that Section 2.3 above otherwise prohibits.

14. Questions

If you are unsure whether a planned use falls within this policy, ask first: email support@alyt.co describing what you intend to build or do. We respond within 10 business days.

15. Contact

Report a violation: support@alyt.co or privacy@alyt.co

Fizzify Inc.
30 N Gould St STE N
Sheridan, WY 82801
United States


Last updated: September 6, 2026