Devoku Legal Official document

Devoku AI and Agent Terms

Effective: 18 September 2026 Last updated: 16 September 2026

These supplemental terms apply whenever you use AI models, coding hands, agents, automations, computer workspaces, browser control, voice processing, model gateways, plug-ins, MCP servers, or related tools. The Devoku Terms of Service control if there is a conflict.

1. You are interacting with AI

Devoku agents and model responses are generated by AI unless clearly stated otherwise. Do not assume an agent or message is a human. If you expose an agent to another person, you must give that person the same clear disclosure no later than their first interaction.

Preserve machine-readable provenance or content credentials that accompany AI-generated media. Clearly disclose deepfakes and AI-generated public- interest content where required by law.

2. Output limitations

Models predict outputs; they do not know whether an answer is true or suitable for your situation. Output can contain factual, reasoning, coding, security, licensing, privacy, bias, or safety errors and can change between runs. Different users may receive similar output.

Never rely on output without independent review appropriate to the risk. A qualified human must review any use affecting health, safety, legal rights, employment, credit, housing, education, insurance, public services, or other high-impact decisions. Devoku is not a substitute for a licensed professional.

3. Agents take real actions

Depending on permissions, an agent can:

  • read, create, modify, move, expose, or permanently delete files;
  • run shell commands and installed software with user or root privileges;
  • browse websites, submit forms, download files, and communicate externally;
  • use secrets, APIs, plug-ins, MCP servers, and third-party accounts;
  • deploy code or infrastructure and change production systems;
  • send messages or process other people’s data; and
  • create usage, cloud, provider, subscription, or transaction charges.

An approval prompt reduces risk but is not a guarantee that an action is safe or that every side effect is described. “Autonomous,” “managed,” “isolated,” or similar product language does not mean consequence-free or perfectly sandboxed operation.

4. Your required safeguards

Before enabling an agent, use safeguards proportionate to its access and the consequences of error. For an agent that can affect production, irreplaceable data, other people, external systems, or paid resources, you must where applicable:

  1. verify that you may provide the data, credentials, and access;
  2. use the least privilege and narrowest workspace and network scope;
  3. remove unnecessary secrets and personal or regulated data;
  4. maintain independent, tested backups and version control;
  5. use non-production environments and test fixtures where feasible;
  6. set review gates and spending or resource limits;
  7. review commands, diffs, destinations, dependencies, and licenses;
  8. monitor the run and stop it if activity is unexpected; and
  9. independently test and security-review output before deployment.

You are responsible for configurations, prompts, approvals, and decisions to use output or permit actions. Coded remains responsible where mandatory law or an express written commitment makes it responsible; these terms do not excuse defective controls, misleading product behavior, or failure to use legally required professional diligence.

5. Data sent to providers

The selected provider may receive prompts, message history, files, code, workspace context, tool results, audio, identifiers, and technical metadata. The provider can be selected by you, your organization, or Coded.

If you use your own API key or provider account, your agreement with that provider applies directly. If Coded supplies access, the provider acts under Coded’s agreement where applicable, but provider-specific use restrictions still apply. Provider retention, human review, model training, data location, and abuse monitoring vary. Do not send sensitive data until you have checked the selected route.

Revoking an optional consent does not erase data already sent to a provider and may require switching to a local model or disabling the feature.

6. Code, licenses, and third-party rights

Output may reproduce or depend on open-source or other third-party material. It may not be unique or patentable and may be subject to attribution, copyleft, export, usage, or provider restrictions. You must scan, test, and review dependencies and licenses. Coded does not clear output for your use.

You may not use content you lack rights to provide. Do not ask an agent to evade licenses, confidentiality, access controls, or safeguards.

7. Security and data loss

AI-generated code and actions can introduce vulnerabilities, outages, corruption, irreversible deletion, credential exposure, or supply-chain risk. Backups, snapshots, version control, previews, or rollbacks may be incomplete or unavailable. Keep recoverable copies outside the affected environment and test restoration.

Do not use preview or beta agents for production, safety-critical, or irreplaceable data. No service-level or recovery commitment applies unless a signed order expressly provides one.

8. Prohibited agent uses

The Acceptable Use Policy applies. In particular, do not permit an agent to operate beyond authorization, autonomously make prohibited high-impact decisions, evade human review, spread or persist without consent, acquire additional privileges, hide its AI identity, or continue after authorization is withdrawn.

9. Reporting

Report unsafe output or actions through the in-product control where available or to abuse@devoku.com. Include the run or message identifier and a safe description; do not email credentials or illegal content. Security vulnerabilities should go to security@devoku.com.