Acceptable Use Policy
Acceptable Use Policy
Version: 1.2
Effective date: 3 August 2026
Replaces: version 1.1 of 2 August 2026
Service provider: Pedro Cantueso García de Vinuesa (NIF 45748777Y), Avenida de la Arruzafa 50, 14012 Córdoba, Spain — operating the Service under the brand kreawave
Abuse contact: [email protected]
1. Purpose, scope and how this Policy fits with the other documents
1.1 What this Policy is
This Acceptable Use Policy ("Policy") sets out, in an explicit and reasoned manner, which uses of the Service are prohibited, what the Service actually does to enforce those prohibitions, and what happens when a user breaches them.
It is published in compliance with Art. 14.1 of Regulation (EU) 2022/2065 (Digital Services Act, "DSA"), which requires providers of intermediary services to state in their terms and conditions any restrictions they impose on the use of their service, including their content-moderation policies, the tools used and any algorithmic decision-making involved. Section 9 of this Policy is the description that Art. 14.1 requires, and it describes the enforcement systems as they are actually deployed today, not as they are planned.
1.2 Who is bound by this Policy
This Policy binds every person who uses the Service in any way: registered account holders on any plan (Free, trial, subscription or hour pack), and anonymous visitors who use the public demo without registering. Acceptance of the Terms of Service constitutes acceptance of this Policy.
The account holder is responsible for all activity carried out through their account, including activity by third parties to whom they have given access, whether authorised by them or not.
1.3 Which content this Policy covers: audio, images and video
This Policy applies to all content generated through the Service, in any modality — audio, image or video — and to all input the user submits in order to generate it (text to be voiced, generation instructions, uploaded reference material).
What the Service actually offers today is AI text-to-speech audio generation from a catalogue of predefined voices. Voice cloning, image generation and video generation are not active features of the Service at this time; no user-uploaded voice sample, image prompt or video prompt is processed today.
The prohibitions in this Policy are deliberately drafted by reference to conduct and to the harm caused, not by reference to the technology used. A synthetic recording that puts words into the mouth of a real person is prohibited whether it is delivered as audio, as an image, as a video, or as a combination of the three. Consequently:
- Every prohibition in sections 3, 4, 5, 6 and 8 applies in full and immediately to the audio generation that is live today.
- Every prohibition in sections 3, 4, 5, 6 and 8 will apply automatically, with no gap in protection and without a new version of this Policy being required, to image content and to video content from the moment, if any, the Service enables those modalities.
- Section 7 contains the additional rules that are specific to voice cloning. Because cloning is not active, those specific rules have no current subject matter; they will take effect automatically if and when the feature is enabled.
The pricing page and the product interface are the authoritative source of which features are live at any given time.
1.4 Relationship with the other legal documents
| Document | What it governs | Prevails over this Policy? |
|---|---|---|
| Terms of Service (https://kreawave.com/legal/terms) | The contract: plans, volumes, daily limits, billing, ownership of output, liability, withdrawal | Yes. In the event of any conflict, the Terms prevail |
| Refund Policy (https://kreawave.com/legal/refunds) | Every question of money: what is charged, what is returned, and when | Yes, on economic matters |
| This Policy | Permitted and prohibited conduct, and the enforcement of that conduct | — |
| Notice and Takedown Procedure (https://kreawave.com/legal/takedown) | How anyone reports allegedly illegal content and how the Service handles it | Complementary |
| AI Disclosure (https://kreawave.com/legal/ai-disclosure) | How generated content is identified as AI-generated | Complementary |
| Privacy Policy (https://kreawave.com/legal/privacy) | Processing of personal data | Complementary |
| Cookie Policy (https://kreawave.com/legal/cookies) | Cookies and similar technologies | Complementary |
| Legal Notice (https://kreawave.com/legal/notice) | Provider identification, customer service and complaint channels (LSSI Art. 10) | Complementary |
In every case, and notwithstanding the order of precedence above, where two of our documents differ and one of them is more favourable to you as a consumer, the more favourable text applies (Art. 80.2 TRLGDCU). No rule of precedence in our documents may remove or reduce a right that Spanish or European consumer law gives you and that cannot be waived by contract (Art. 10 TRLGDCU).
This Policy does not create, alter or restate any economic condition. It does not state prices, volumes, daily limits or refund rules; where conduct described here has an economic consequence (section 8.3), that consequence is governed exclusively by the Terms of Service and the Refund Policy.
2. General principle and eligibility
2.1 General principle
The Service is a content-creation tool for legitimate creators. Its use is restricted to lawful and ethical purposes that respect the rights of third parties. Any use that departs from this principle breaches this Policy, whether or not it is expressly listed below: the lists in this Policy are illustrative of the categories of harm, not an exhaustive catalogue of every possible abuse.
2.2 Eligibility
The Service is intended exclusively for users aged 18 or over, or the minimum legal age in the user's jurisdiction if higher (Terms of Service §3). It is prohibited to:
- Use the Service if you are below that age.
- Create or operate an account on behalf of a person below that age.
- Provide false information in order to circumvent this requirement.
2.3 The user's own compliance
The user is responsible for ensuring that their use of the Service, and the subsequent publication or distribution of the generated content, complies with:
- Spanish law and European Union law;
- the law of the user's own country of residence and of any country in which they publish the content;
- the terms of any third-party platform on which they publish it.
The Service being technically capable of producing a given output is never a representation that producing, publishing or distributing it is lawful.
3. Illegal content — absolute prohibitions
The following prohibitions apply to audio, images and video alike, to the input text or instructions submitted, and to any attempt, even an unsuccessful one.
3.1 Child sexual abuse material (CSAM)
This is the most serious possible infringement of this Policy and admits no exception, no artistic justification and no fictional framing.
It is prohibited to generate, request, attempt to generate, store or distribute through the Service:
- Any sexual or sexualised depiction of a person under 18 years of age, real or entirely AI-generated, in any modality — audio, image, video or text — and in any style, including photorealistic, illustrated, animated, anime, manga or cartoon.
- Audio that simulates a minor in a sexual context, or that sexualises a minor's voice.
- Any attempt to describe or elicit minors in sexual contexts through euphemism, coded terminology or evasive spelling ("young", "student", "small", "loli", "shota", or any equivalent).
- Any request designed to probe, deceive or circumvent the Service's detection systems for this category.
The mere attempt triggers, immediately and without prior notice: blocking of the request, suspension of the account, preservation of incident metadata, and reporting to the competent authorities — INCIBE, the National Police (Unidad Central de Ciberdelincuencia / BCIT) and the Guardia Civil (Grupo de Delitos Telemáticos) — in accordance with Arts. 189 and 189 bis of the Spanish Penal Code. Those articles are named because the Service is operated from Spain and that is the law under which we report; the equivalent criminal law of your own country applies to you in addition, not instead, and a report may be forwarded to the authorities of your jurisdiction through the applicable channels of international cooperation. Prohibited material is never stored: only the metadata strictly necessary to substantiate the report is preserved. The Service's internal handling of these incidents follows its CSAM protocol.
3.2 Terrorism and violent extremism
It is prohibited to generate content that:
- Constitutes propaganda, recruitment material, or a call to action for terrorist organisations or violent extremist movements.
- Publicly glorifies terrorism or humiliates its victims (Arts. 578 and 579 of the Spanish Penal Code).
- Reproduces the symbols or insignia of organisations that are illegal or proscribed in Spain or in the European Union.
Where relevant, Regulation (EU) 2021/784 on addressing the dissemination of terrorist content online also applies.
3.3 Hatred, discrimination and incitement to violence
It is prohibited to generate content that incites, promotes or facilitates hatred, hostility, discrimination or violence against a person or group on grounds of racial or ethnic origin, nationality, religion or belief, sex, sexual orientation, gender identity, gender expression, disability, illness, age, or any other protected characteristic (Art. 510 of the Spanish Penal Code).
This includes content that trivialises, denies or glorifies genocide, crimes against humanity or war crimes, and content that glorifies torture or gratuitous violence.
3.4 Facilitation of other serious crimes
It is prohibited to use the Service to produce content that provides operational assistance for:
- The manufacture, acquisition or use of weapons, explosives, or chemical, biological, radiological or nuclear agents.
- The synthesis or trafficking of controlled substances.
- Attacks on information systems, distribution of malware, or any other activity punishable under Arts. 197 bis and 264 et seq. of the Spanish Penal Code.
- Trafficking in human beings, smuggling of migrants, or the sexual exploitation of any person.
3.5 Fraud, scams, phishing and vishing
It is prohibited to use the Service, and in particular the generated audio, to:
- Produce voice messages intended to deceive a victim into transferring funds, disclosing credentials or authorising a transaction (vishing), including "family emergency", "your bank is calling" and CEO-fraud scenarios.
- Generate voice or video content that circumvents, or attempts to circumvent, voice-biometric or liveness authentication systems.
- Produce audio tracks or voiceovers for phishing campaigns, fraudulent advertising, fake investment schemes or any other deceptive commercial practice prohibited by Directive 2005/29/EC and by Book II, Title IV of the Spanish TRLGDCU (Royal Legislative Decree 1/2007).
- Generate content constituting fraud under Arts. 248 et seq. of the Spanish Penal Code.
This is the single highest-risk misuse of a text-to-speech service. It is treated as a very serious infringement in every case (section 10), regardless of whether the fraud succeeded.
4. Impersonation, deepfakes and the rights of real persons
4.1 Identity, voice and likeness of real people
It is prohibited to generate content that reproduces, imitates or simulates the identity, voice, likeness, image or name of an identifiable real person — a public figure, politician, artist, athlete, journalist, business executive, or any private individual — without their explicit, documented and demonstrable consent.
"Identifiable" includes cases where the person is not named but is recognisable from context, timbre, characteristic turns of phrase, or accompanying material.
This prohibition protects rights that, under Spanish law, exist independently of any criminal offence: the right to honour, personal and family privacy and one's own image under Art. 18.1 of the Spanish Constitution and Organic Law 1/1982, whose Art. 7.6 expressly designates the use of a person's name, voice or image for advertising, commercial or analogous purposes as an unlawful interference. Impersonating a person may additionally constitute an offence under Art. 401 of the Spanish Penal Code (usurpation of civil status).
4.2 Deepfakes and synthetic misrepresentation
It is prohibited to generate content designed to make it appear that a real person said, did, endorsed, was present at or participated in something that did not happen. This includes, without limitation:
- Synthetic statements attributed to political figures, authorities, journalists or institutional representatives.
- Fabricated endorsements of products, services, investments or campaigns.
- Fabricated confessions, admissions, insults or discriminatory statements attributed to a real person.
- Manipulated recordings of real events (altering what was actually said in a genuine recording).
- Content produced for disinformation at scale, and in particular electoral disinformation, fabricated news, or the simulation of official announcements, emergency alerts or public-authority communications.
Satire, parody and legitimate criticism are protected forms of expression under Art. 20 of the Spanish Constitution, but they do not exempt the user from clearly identifying the content as synthetic (section 4.6) and never justify content that is deceptive, defamatory, sexual, or capable of causing material harm.
4.3 Non-consensual intimate content
It is prohibited to generate, in any modality, sexual or intimate content depicting or simulating an identifiable real person without their consent. This covers synthetic intimate imagery ("deepfake pornography"), synthetic intimate audio, and the manipulation of genuine material to give it sexual content.
Such conduct may constitute an offence under Arts. 197 and 173 of the Spanish Penal Code and, in any event, an unlawful interference with the rights protected by Organic Law 1/1982. Directive (EU) 2024/1385 on combating violence against women and domestic violence expressly requires Member States to criminalise the non-consensual production and dissemination of manipulated intimate material, with a transposition deadline of 14 June 2027.
4.4 Harassment, threats, defamation and digital violence
It is prohibited to use the Service to produce content that:
- Harasses, intimidates, threatens, humiliates or coerces any person.
- Constitutes defamation, insult or calumny against an identifiable person.
- Constitutes digital gender-based violence, as recognised in Art. 3.4 of Organic Law 10/2022 on the comprehensive guarantee of sexual freedom.
- Facilitates doxxing, stalking or the targeting of a private individual.
- Is directed at a minor with the aim of contacting, grooming, humiliating or coercing them.
4.5 Deceased persons, minors and vulnerable groups
The prohibitions in this section apply with the same force to:
- Deceased persons, whose memory is protected under Arts. 4 to 6 of Organic Law 1/1982; consent must be obtained from the person designated in their will or from their surviving relatives.
- Minors, whose image and voice enjoy reinforced protection under Art. 4 of Organic Law 1/1996 on the legal protection of minors; the consent of a parent or guardian does not make lawful any use that harms the minor's interests.
- Persons in a situation of vulnerability, including patients, victims of crime, and persons who lack capacity to consent.
4.6 The user's own disclosure obligation under the AI Act
Regulation (EU) 2024/1689 (AI Act) allocates transparency duties to two different parties, and both apply from 2 August 2026 (Art. 113):
- The Service, as provider, must ensure that its outputs are marked in a machine-readable format and detectable as artificially generated (Art. 50.2). The Service does this on every generation; see section 9.5 and the AI Disclosure document.
- The user, as deployer, must disclose that content constituting a deep fake has been artificially generated or manipulated (Art. 50.4), and must disclose the artificial nature of AI-generated text published to inform the public on matters of public interest.
That second duty is the user's own and the Service cannot discharge it on the user's behalf. Removing, degrading, obscuring or failing to make that disclosure where it is required is a breach of this Policy, in addition to being a breach of the user's own obligations under the AI Act.
5. Sexual and adult content
The absolute prohibitions in section 3.1 (minors) and section 4.3 (real persons without consent) apply in every case and are never displaced by anything in this section.
In addition, and in every modality — audio, image and video — it is prohibited to use the Service to generate sexually explicit or pornographic content, including explicit or suggestive nudity and sexual audio.
The Service does not operate age verification and is neither designed nor licensed for adult-content production. This prohibition is therefore absolute: it does not depend on the law of the user's own jurisdiction, and it is not lifted by the content being lawful where the user lives or by the absence of any real person in it. It is consistent with the image and video rules in Terms of Service §7, which prohibit the same material in those modalities.
The following are, in addition and always, very serious infringements, dealt with under section 3.1 and section 10: any content that sexualises a minor or evokes a minor sexually, in any style; "borderline" or ambiguous content designed to test or circumvent the Service's filters; content depicting non-consensual sexual acts presented as real; and content involving bestiality or the sexualisation of extreme violence.
This is a contractual restriction, not a statement about the capabilities of our automated screening: section 9.1 explains what the screening layer does and does not detect, and the fact that a generation completes is never an authorisation.
6. Intellectual property and third-party rights
It is prohibited to use the Service to:
- Submit as input, or generate as output, content that infringes third-party copyright or related rights protected by the Spanish Consolidated Text of the Intellectual Property Act (Royal Legislative Decree 1/1996), including reproducing protected works or substantial parts of them without authorisation.
- Reproduce a performer's distinctive vocal performance in a way that trades on their reputation, which engages both Art. 7.6 of Organic Law 1/1982 and the performers' rights in Book I, Title I, Chapter II of the TRLPI.
- Use third-party registered trade marks in a manner liable to cause confusion in the market or to take unfair advantage of their reputation (Ley 17/2001 on Trade Marks).
- Circumvent technological protection measures of any other system or service.
- Generate content that discloses trade secrets or confidential information belonging to a third party.
The user warrants that they hold all rights, consents and authorisations necessary over every text, instruction and reference material they submit (Terms of Service §8), and is solely responsible for that material.
Where a third party brings a claim against the Service arising from material a user submitted, the user shall cooperate with the defence of that claim and, where the user acted in breach of this Policy or of the law, shall be liable for the loss actually caused, in accordance with general Spanish law and up to the amount of that loss. This Policy imposes no indemnity beyond what the law provides, does not apply to loss caused by the Service's own act or omission, and — as stated in section 1.4 — creates no economic condition of its own. Ownership of the generated output is governed by Terms of Service §9; this Policy does not alter it.
7. Voice cloning — additional rules
Status: voice cloning is not active on the Service. The /api/tts/clone/* endpoints are not mounted in production. No user-uploaded voice sample is processed today, and no cloned voice exists in the Service. The rules below are kept in force so that they apply automatically, without a new version of this Policy, from the moment the feature is enabled.
In addition to every prohibition in sections 3 to 6, it is prohibited to:
- Clone the voice of any person without their explicit, documented and demonstrable consent. A voice is biometric data; its processing requires an explicit legal basis under Art. 9.2.a GDPR.
- Clone the voice of a minor, of a deceased person without the authorisation described in section 4.5, or of a person unable to give valid consent.
- Upload as a reference sample any recording the user does not hold the rights to (broadcast material, podcasts, films, video calls, recordings made without the speaker's knowledge).
- Generate, using a cloned voice, any statement attributed to the real speaker that they did not make (sections 4.1 and 4.2).
- Access, use, copy, extract or reproduce another user's cloned voice, by reverse engineering, identifier enumeration, unauthorised API access or any other means. Each cloned voice is exclusive to the account that created it; unauthorised access to another user's cloned voice is a very serious infringement of this Policy and may constitute an offence under Art. 197 of the Spanish Penal Code (discovery and disclosure of secrets).
- Transfer, assign, sell, sublicense or share access to one's own cloned voice with any third party outside the user's account.
The exclusivity guarantees, the deletion right and the revocation of biometric consent applicable to cloned voices are set out in Terms of Service §11 and in the Privacy Policy.
8. Integrity of the AI mark, of the Service and of the account
8.1 The AI identification mark must not be removed
Every audio file produced by the Service carries a mandatory AI identification mark that the user may not disable, remove, degrade or conceal. It is prohibited to:
- Strip, overwrite or falsify the provenance metadata embedded in the generated file.
- Process the audio with the specific purpose of destroying or defeating the inaudible watermark (adversarial filtering, targeted re-synthesis, deliberate degradation).
- Present content generated by the Service as an authentic human recording where the AI Act, or any other applicable rule, requires the opposite (section 4.6).
- Falsely claim that content not produced by the Service carries its mark.
Normal editing, mixing, format conversion and lossy compression of the audio for legitimate production purposes are permitted and are not a breach of this section; the watermark is designed to survive them.
8.2 Models, infrastructure and automated access
It is prohibited to:
- Reverse engineer, decompile, disassemble or attempt to extract the Service's AI models, weights, voice embeddings or prompts.
- Use the Service's output to train, fine-tune, distil or evaluate a competing speech, image or video synthesis model.
- Systematically harvest the voice catalogue, the preview samples or any other resource of the Service (scraping, enumeration of identifiers, mass automated downloading).
- Access the Service by automated means outside the interface provided, or generate volume through scripted or headless clients, without express written authorisation.
- Probe, scan, load-test or attack the Service's infrastructure, or attempt to access other users' accounts, jobs, generated files or data.
- Submit input designed to manipulate the processing pipeline (template or prompt-injection payloads). The Service's text-to-speech engine treats the submitted text strictly as data to be voiced, not as instructions to be executed, so such payloads do not affect generation; they are nevertheless recorded and reported as abuse signals (section 9.2).
8.3 Circumvention of limits and fraudulent consumption
It is prohibited to:
- Circumvent, or attempt to circumvent, the daily usage limit, the plan volume or any other quota, in the manner described in Terms of Service §4-bis.
- Create multiple accounts, or use disposable email addresses, multiple identities, proxies or VPNs, in order to obtain repeated free allowances, repeated trial offers or repeated demo usage.
- Deliberately submit defective input — misspelled, corrupted or intentionally malformed text — with the purpose of subsequently obtaining generation, correction or re-generation of that content without it being charged. Regeneration of a segment re-synthesises that segment in full and consumes the same resources as the original generation; how regeneration is charged is set out in the Terms of Service and the Refund Policy, and this Policy adds no economic condition of its own. What this Policy prohibits is the conduct: engineering an apparent defect in order to obtain output at no cost.
- Request refunds or initiate payment disputes on grounds the user knows to be untrue.
8.4 Accounts, credentials and resale
It is prohibited to:
- Share account credentials among several persons or entities, or operate a single account on behalf of multiple end users, without the Service's written authorisation.
- Resell, sublicense or provide access to the Service, or offer the Service's generation capability to third parties as a service of the user's own, without express written authorisation. This does not restrict the user's normal commercial use of the generated content itself, which is governed by Terms of Service §9.
- Transfer an account to a third party without the Service's consent.
9. How the Service enforces this Policy (DSA Art. 14.1)
This section describes the moderation measures actually in operation. It is deliberately precise, because an inaccurate description of moderation systems is itself a breach of DSA Art. 14.1.
9.1 Screening of submitted text — blocking, fail-closed
Every text submitted for generation — through the public demo, through the registered-user interface and through the regeneration flow alike — is passed through an automated screening layer before any GPU resource is committed. The layer performs two operations:
- Sanitisation: removal of ASCII control characters, which can be used to hide content from logs or to inject data into the output file.
- Blocklist matching: case-insensitive pattern matching against a curated list of terms that clearly indicate CSAM, racial and ethnic slurs, explicit incitement to mass violence, terrorist attack planning and weapons-manufacturing instructions.
If a pattern matches, the request is rejected outright (HTTP 400) and no audio is produced. The rejection message is deliberately generic and does not indicate which pattern matched, so that it cannot be used to reverse-engineer the list.
The limits of this layer, stated honestly: it is a keyword-based first line of defence, not a machine-learning classifier of meaning. It reliably catches unambiguous abuse; it does not, and is not represented to, detect every prohibited use listed in this Policy. The fact that a generation completes is never an authorisation, an approval, or evidence that the content complies with this Policy or with the law.
9.2 Abuse-signal detection — reported, not blocked
Submitted text is also scanned for template and prompt-injection payloads ({{...}}, {% ... %}, special model tokens, instruction tags, "ignore previous instructions" constructions, role-reassignment jailbreak phrasing). These are not blocked, because the speech engine does not interpret the text as instructions and such strings are harmless to synthesis — blocking them would produce false positives for legitimate creators narrating code or writing about AI. They are recorded and reported to the provider as a signal that the Service is being probed.
9.3 Strikes, suspension and temporary blocking
When a submission is blocked under section 9.1, the Service does not merely return an error. It:
- Notifies the provider, with the account identifier, the originating IP address and a truncated excerpt of the offending text (limited to 200 characters) sufficient to assess the incident without dumping entire scripts into an internal mailbox.
- Records a strike against the identity, on a sliding 24-hour window.
- On the third strike within 24 hours:
- Registered users: the account is suspended (status set to
suspended), all active sessions are invalidated in the same transaction so that generation cannot continue with tokens already issued, the associated email address is placed on the abuse blocklist pending manual review, and the user is notified by email that the suspension is temporary and pending review, with an invitation to reply if they believe it is an error. - Anonymous / demo users: the originating IP address and device fingerprint are blocked temporarily (24 hours by default), with a
Retry-Afterresponse header. The block is temporary by design: a false positive self-heals on expiry. Loopback and internal addresses are exempt.
A suspended account or a blocked identity is rejected before any queue or GPU resource is committed, with HTTP 403.
These thresholds and windows are configuration values and may be adjusted to respond to an active abuse pattern.
9.4 Volume and rate controls
The public demo is subject to per-request character limits and to sliding-window request limits applied per IP address, per device fingerprint and per visitor identifier, together with a global cap on concurrent demo jobs. Registered accounts are subject to the plan concurrency limits and daily volume limits described in Terms of Service §4-bis. These controls exist to protect availability for all users and to prevent the free tiers being harvested; they are not, in themselves, content moderation.
9.5 Marking of the generated output
Every audio file produced in production carries:
- An inaudible watermark embedded in the audio signal (AudioSeal, Meta, MIT licence), applied on every production path. The mark is never disabled: a synthesis worker that cannot load the watermarking model refuses to start, and the assembled file is re-checked with the detector before delivery and marked again if the mark is not found. The Service does not deliver unmarked audio. The mark survives MP3 re-encoding. No watermark is technically impossible to remove; removing it, or attempting to, is prohibited by section 8.1.
- A provenance stamp written into the file metadata (generator, model, licence of the model weights, voice identifier, seed, date) together with a SHA-256 fingerprint of the audio, which allows a file to be traced back to its generation even if it is renamed.
This is how the Service discharges its own obligation under AI Act Art. 50.2, and it is what allows a disputed file to be attributed. The user's separate disclosure obligation under Art. 50.4 is described in section 4.6. Full detail is in the AI Disclosure document.
9.6 What the Service does not do
The Service does not carry out general monitoring of user content, and is under no obligation to do so: DSA Art. 8 expressly excludes any general obligation on providers of intermediary services to monitor the information they store or to actively seek facts indicating illegal activity.
In particular, and contrary to what earlier versions of this Policy stated, the Service does not currently operate: multimodal classification of generated images, facial-similarity or celebrity-matching gates, hash-matching against external CSAM databases, or C2PA marking. Those systems relate to the image and video modules, which are not deployed. They will be described here accurately, and this Policy updated with a new version number, before any such module is enabled.
9.7 Circumventing enforcement
The existence of automated moderation does not diminish the user's own responsibility in any way. It is an independent breach of this Policy to attempt to evade, deceive, probe or manipulate these systems, including by obfuscating prohibited terms, splitting prohibited content across multiple requests, or rotating identities after a block.
10. Consequences of non-compliance
10.1 Principle of proportionality
The Service applies the measures below in a diligent, objective and proportionate manner, with due regard to the rights and legitimate interests of all parties involved, including the fundamental rights of the user, as required by DSA Art. 14.4. The measure applied depends on the seriousness of the breach, on whether it was intentional, on whether it caused harm to a third party, and on whether it is repeated.
10.2 Scale of measures
| Level | Conduct | Measure |
|---|---|---|
| Minor | Isolated breach with no apparent intent to cause harm and no third-party harm | Warning; blocking of the specific request; possible temporary restriction |
| Serious | Deliberate generation of prohibited content; deepfakes or impersonation; hate content; circumvention of limits or fraudulent consumption (§8.3); repeated minor breaches | Temporary suspension or permanent termination of the account |
| Very serious | CSAM or any attempt at it; fraud, vishing or impersonation used to deceive; non-consensual intimate content; terrorism; unauthorised access to another user's data or cloned voice | Immediate and permanent termination + preservation of evidence + report to the competent authorities |
10.3 Measures applicable to serious and very serious breaches
- The account is suspended precautionarily and with immediate effect, and all active sessions are invalidated.
- The metadata of the incident is preserved for the purposes of reporting and of defending any subsequent claim. Content in the CSAM category is never stored; only the metadata strictly necessary for the report is retained.
- The affected content is removed or access to it is disabled.
- The Service may pursue civil and/or criminal proceedings, and will report the matter to the competent authorities where the conduct so requires.
10.4 Statement of reasons and right to contest
Where the Service removes content or restricts an account for breach of this Policy, it provides the affected user with a clear and specific statement of reasons, in accordance with DSA Art. 17, stating the measure taken, the facts relied on, whether automated means were used, the contractual or legal ground, and how to contest the decision.
Any user may contest a measure by writing to [email protected]. The Service will review the case with human involvement — no measure is confirmed on the basis of an automated decision alone where it is contested — and will reply within a maximum of 15 days, the period established by Art. 21.3 of the TRLGDCU. Where the review shows that the measure was unfounded, it is reversed and the account is reinstated. This internal route does not affect the user's right to bring the matter before the competent consumer authorities or courts, as set out in the Terms of Service and the Refund Policy.
10.5 Effect on amounts paid
Termination of an account for a serious or very serious breach attributable to the user does not entitle the user to the return of amounts corresponding to volume already consumed, because the service corresponding to that volume was supplied. The unexpired part of the paid period, and any purchased top-up hours not used, are refunded: the Service does not retain money for a service it is not going to provide, and applies no forfeiture of amounts paid. Any loss caused by the breach is set out to the user in writing and claimed separately, and is never deducted unilaterally from the user's balance. The terms that govern this question are Terms of Service §13 and the Refund Policy §11, and this Policy adds nothing to them.
This does not affect any right that the applicable consumer-protection legislation confers on the user and that cannot be waived in advance — in particular Art. 10 of the TRLGDCU (Royal Legislative Decree 1/2007), under which the advance waiver of consumer rights is void. Nor does it affect the refund powers that Paddle.com Market Ltd., as Merchant of Record and legal seller of record, exercises at its own discretion.
11. Reporting abuse
If you become aware of abusive use of the Service, or you have received content generated by the Service that breaches this Policy or that you consider illegal, you may report it through any of the following channels. All channels receive equal treatment; using the technical endpoint confers no priority.
- Abuse email: [email protected]
- Notice endpoint (DSA Art. 16):
POST https://kreawave.com/api/takedown— a public endpoint that requires no registration, intended for automated or technical reporting. It accepts up to 5 reports per hour per IP address and returns a report identifier for follow-up. - Postal address: Avenida de la Arruzafa 50, 14012 Córdoba, Spain
- Telephone: +34 621 34 26 94 (Monday to Friday, 10:00-14:00 CET)
To be actionable, a notice should identify the content as precisely as possible (report identifier, job identifier, URL or file), explain why it is considered illegal or in breach, and provide contact details for follow-up. Full requirements, deadlines and the procedure that follows are set out in the Illegal Content Notice and Takedown Procedure: https://kreawave.com/legal/takedown. Reports of CSAM activate the emergency protocol with absolute priority.
Reports are handled confidentially to the extent possible. The Service acknowledges receipt and carries out an initial assessment within the deadlines stated in the Takedown Procedure. Manifestly unfounded or abusive notices, submitted repeatedly and in bad faith, may lead to the reporting identity being restricted.
12. Changes to this Policy
This Policy may be updated to address new threats, new technologies, new modalities of the Service or regulatory changes. Changes are announced with 30 days' notice, except where a shorter period is necessary to respond to an active abuse pattern or to comply with a legal requirement, in which case the change takes effect immediately and is communicated as soon as possible.
Every substantive change results in a new version number and a new effective date recorded in the table below. The version in force is always available at https://kreawave.com/legal/acceptable-use.
| Version | Effective date | Summary of changes |
|---|---|---|
| 1.0 | 22 June 2026 | Initial version |
| 1.1 | 2 August 2026 | English translation and consolidation |
| 1.2 | 3 August 2026 | Prohibitions restructured by conduct so that they cover audio, image and video without gaps; impersonation and deepfakes given their own section; sections on illegal content, fraud and vishing, non-consensual content, the AI mark and its integrity, and circumvention of limits added or expanded; section 9 rewritten to describe only the moderation systems actually deployed, removing the descriptions of image classification, facial-similarity gating, CSAM hash-matching and C2PA marking, none of which is in operation; enforcement measures aligned with DSA Arts. 14.4 and 17 with a statement of reasons and a right to contest |
13. Contact
Questions about this Policy, and requests to review a measure taken under it: [email protected].
Provider identification and full contact details: https://kreawave.com/legal/notice