Acceptable Use Policy
Last Updated: April 30, 2026
Jump to section…
Last Updated: April 30, 2026 Effective Date: May 1, 2026
This Acceptable Use Policy ("AUP") describes activities that are prohibited on the FORMD Services. It is incorporated into and forms part of the Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.
This AUP applies to all Users — Athletes, Coaches, Authorized Users, and any other person who accesses or uses the Services.
The intent of this AUP is to keep the Services safe, lawful, and useful for the people who depend on them. We will read every report and act in good faith. If you are unsure whether a planned use is acceptable, contact us at legal@tryformd.com before proceeding.
1. General Principles
You may not use the Services in any manner that:
- Violates any applicable local, state, federal, or international law or regulation;
- Infringes the intellectual property, privacy, publicity, contract, or other legal rights of any person or entity;
- Is fraudulent, deceptive, or misleading;
- Endangers the health or safety of any person, including by giving unqualified medical advice or representing FORMD-generated content as medical advice;
- Could reasonably be expected to cause harm to FORMD, the Services, other Users, or the public.
This is the floor. The specific prohibitions below are illustrative, not exhaustive.
2. Prohibited Conduct
You agree not to do any of the following, and not to permit, encourage, or knowingly enable any other person to do any of the following:
2.1 Security and Integrity
- Probe, scan, or test the vulnerability of the Services or any related system without FORMD's prior written authorization (a coordinated disclosure to security@tryformd.com is welcome — see Section 7);
- Circumvent, disable, or otherwise interfere with security-related features of the Services, including authentication, rate limits, content filters, age gates, entitlement checks, or audit logs;
- Introduce viruses, worms, ransomware, trojans, spyware, keyloggers, or any other malicious code or harmful component into the Services or to other Users;
- Conduct or participate in a denial-of-service attack, distributed denial-of-service attack, or any similar volumetric or protocol attack against the Services or its infrastructure;
- Interfere with or disrupt the integrity, performance, or availability of the Services for any User.
2.2 Account, Credentials, and Seat Use
- Share your account password, API key, access token, magic link, invite link, coach code, or any other credential with any person who is not authorized to use the Services on your behalf;
- Permit two or more individuals to share a single Authorized User seat on the Coach Platform (Coach Customers must purchase additional coach seats for each individual; see Section 11.9 of the Terms of Service);
- Sell, lease, transfer, or assign your account or credentials to any third party except as permitted by the Terms of Service;
- Create accounts using automated means, false identities, disposable email services, or for the purpose of evading suspension or trial-eligibility rules;
- Impersonate any other person or entity, or misrepresent your affiliation with any person or entity, in connection with the Services.
2.3 Data and Privacy
- Access, attempt to access, collect, store, or use personal data of any other User except (a) your own data, (b) data you are authorized to access under the Terms of Service or DPA (e.g., a Coach accessing Connected Athletes' data on the Coach's instructions), or (c) as expressly permitted by these documents and applicable law;
- Use the Services to process personal data unlawfully, including in violation of GDPR, CCPA/CPRA, the Florida Digital Bill of Rights, the Washington My Health My Data Act, the Virginia VCDPA, the Colorado CPA, COPPA, or any other applicable data protection law;
- Disclose personal data of another User to any third party without that User's lawful consent;
- Re-identify or attempt to re-identify any aggregated, pseudonymized, or de-identified data made available through the Services;
- Use the Services to collect data about minors under thirteen (13) years of age. Coaches must not invite or maintain rosters that include minors under thirteen (13). For minors aged thirteen (13) to the local age of majority, the Coach must obtain and document verifiable parental or guardian consent before inviting the Athlete and provide that documentation to FORMD on request.
2.4 Content and Communications
- Submit, transmit, or publish through the Services any content that is unlawful, harassing, threatening, abusive, defamatory, hateful, harmful to minors, sexually explicit, violent, or otherwise objectionable;
- Use the Services to bully, intimidate, dox, or stalk any person;
- Use the Services to send unsolicited commercial messages ("spam"), bulk messages, chain messages, pyramid scheme content, or any messaging in violation of the CAN-SPAM Act, TCPA, GDPR ePrivacy rules, or analogous laws;
- Use the FORMD messaging or notification systems to communicate with any person who has not opted in to receive your communications, or after they have requested that you stop;
- Misrepresent FORMD-generated training content, race predictions, or analytics as medical advice, diagnosis, treatment, or as the work of any licensed healthcare provider you are not;
- Post or promote misleading claims about HYROX events, race results, or FORMD's platform.
2.5 Reverse Engineering, Scraping, and Automation
- Reverse engineer, decompile, disassemble, or attempt to derive the source code, algorithms, model weights, or AI prompts underlying the Services, except to the extent this restriction is prohibited by applicable law;
- Use any robot, spider, crawler, scraper, or other automated means to access, query, or harvest data from the Services other than through FORMD-published APIs in accordance with the API documentation;
- Exceed published or reasonable rate limits, evade rate limits via account multiplication or proxy networks, or perform mass automated requests likely to degrade Service performance;
- Use the Services or its outputs (including AI-generated training plans, predictions, and analytics) to train, fine-tune, or evaluate any machine-learning model that is not operated by FORMD, except for use of your own User Content for your personal, non-commercial purposes.
2.6 White-Labeling, Reselling, and Sublicensing
- White-label, rebrand, repackage, or resell the Services or any output of the Services as your own product or as the product of any third party, except (a) under the white-label feature included in Gym Pro and Enterprise tiers, used in accordance with Section 12.8 of the Terms of Service, or (b) under a separate written agreement with FORMD;
- Provide the Services on a service-bureau, time-sharing, or subscription basis to any third party who has not entered into FORMD's Terms of Service;
- Embed the Services into a competing product or use the Services to assist in the development of a competing product;
- Remove, alter, or obscure FORMD's name, logo, copyright notices, or other proprietary notices, except as permitted by the white-label feature.
2.7 Marketplace and Sales Conduct (When Marketplace Is Active)
- Publish programs to the Marketplace that you do not own or have rights to, that infringe a third party's rights, or that contain misleading claims about results;
- Engage in fake-review, review-manipulation, or self-purchase schemes to inflate Marketplace metrics;
- Circumvent FORMD's payment processor (Stripe Connect) by directing buyers off-platform to avoid the FORMD commission for transactions sourced from the Services.
2.8 Coach-Specific Conduct
- Knowingly invite an Athlete who is under thirteen (13) or who you reasonably suspect to be under thirteen (13);
- Use the Coach Platform to coach Athletes for activities outside the scope of fitness training that require specialized credentials you do not hold (e.g., licensed physical therapy, regulated nutrition counseling, medical care);
- Misuse the Coach Platform's analytics or messaging features to surveil, harass, or coerce an Athlete who has disconnected from your roster.
3. Reporting Violations
If you become aware of any violation of this AUP, please report it to abuse@tryformd.com. Where possible, include:
- The nature of the violation;
- The User involved (account email or display name);
- The specific content, message, or behavior;
- Any supporting evidence (screenshots, links, dates).
We will investigate every credible report. We do not disclose the identity of reporters to the reported User except where required by law or court order.
For security vulnerabilities, please use security@tryformd.com and follow the responsible disclosure process described at tryformd.com/security (when published).
4. Enforcement
FORMD's responses to AUP violations are proportional to the severity, repetition, and willfulness of the violation, and may include any one or more of the following:
| Severity | Possible Actions |
|---|---|
| Minor / first-time | Warning, content removal, request for corrective action. |
| Moderate / repeated | Feature restriction, temporary suspension, mandatory remedial action (e.g., consent collection). |
| Severe / willful / illegal | Immediate suspension or termination, true-up of unauthorized use fees, forfeiture of refund rights, escalation to law enforcement, permanent ban. |
We may suspend or terminate accounts immediately and without prior notice where a violation poses a security risk, legal risk, or risk of harm to other Users (Section 17.1 of the Terms of Service). Where prior notice and opportunity to cure can be provided without increasing risk, we will provide them.
5. Appeal of Suspension or Termination
If you believe your account was suspended or terminated in error, you may appeal by following the process in Section 17.4 of the Terms of Service:
- Email legal@tryformd.com within thirty (30) days of the action;
- Include the email address on the affected account, the specific decision you are appealing, the alleged violation as you understand it, and any facts or evidence you wish FORMD to consider;
- We will review and respond within fifteen (15) business days.
Our determination on appeal is final.
6. Changes to This AUP
We may update this AUP at any time to address new threats, new features, or changes in law. Material changes are communicated under the change-notice process in Section 1 of the Terms of Service. Continued use of the Services after the effective date of an updated AUP constitutes acceptance.
7. Coordinated Security Disclosure
We welcome reports from security researchers acting in good faith. If you believe you have found a security vulnerability:
- Email security@tryformd.com with details and proof-of-concept (no exfiltrated personal data);
- Give us a reasonable opportunity to remediate before public disclosure (typically 90 days, or sooner by agreement);
- Do not access, modify, or delete data belonging to other Users beyond the minimum needed to demonstrate the vulnerability.
We commit to (a) acknowledging your report within five (5) business days; (b) keeping you informed of remediation progress; and (c) refraining from legal action against good-faith security research that complies with this Section 7.
8. Contact
Reports of abuse: abuse@tryformd.com Security disclosures: security@tryformd.com General legal inquiries: legal@tryformd.com General support: support@tryformd.com
Use the Services like the people on the other end matter. Because they do.