UTC --:--:--

Goable — Acceptable Use Policy (AUP)

Version: 2026-06-26.

This Acceptable Use Policy ("AUP") governs your use of the Goable Service (the API, SDKs, console, documentation, and any related artefacts published by Goable, a brand operated by Fabio Carucci, an Italian sole proprietor, "Goable"). It supplements the Terms of Service; capitalised terms used here that are not defined inherit the meaning given in the Terms.

By accessing or using the Service you agree to the restrictions below. Goable may update this AUP from time to time; the current version is always published at https://goable.io/legal/acceptable-use and is the version that applies to your continued use.

1. Misrepresentation of the Service

You agree NOT to:

  • Present suitability scores, recommendations, or any other Goable output as a safety certification, guarantee, regulatory clearance, or substitute for qualified local judgement. Examples of qualified judgement that Goable does not replace include but are not limited to: avalanche safety bulletins issued by national avalanche services, coastguard / maritime authority advisories, medical or occupational-health advice, professional mountain-guide or instructor judgement, and aviation meteorological clearances. Scores are decision-support model outputs.
  • Strip, alter, or misstate the maturity (provisional / reviewed / calibrated), methodology, confidence intervals, hard-gate disclosures, or sample-size caveats that accompany scores and research artefacts.
  • Imply endorsement, certification, partnership, or affiliation with Goable that does not exist.
  • Re-brand the Service as your own (white-label resale) without a written reseller agreement signed by both parties.

2. Platform integrity

You agree NOT to:

  • Circumvent or attempt to circumvent rate limits, plan gates, daily quotas, scope restrictions, IP-based throttles, or any other authentication or authorisation mechanism.
  • Share API keys across unrelated tenants, organisations, or business units. Each tenant must use its own credentials; pooling keys is grounds for immediate suspension.
  • Resell raw API access, that is, re-expose the Service as an unbranded or differently-branded API endpoint, without a written reseller agreement signed by both parties.
  • Probe, scan, fuzz, port-scan, denial-of-service, or otherwise attempt to disrupt, degrade, or gain unauthorised access to the Service, its underlying infrastructure, or any other tenant's resources.
  • Reverse-engineer, decompile, or disassemble the Service, except to the extent this restriction is prohibited by applicable law (for example, mandatory interoperability or error-correction exceptions), and noting that the artefacts Goable publishes openly (the catalogue under CC BY 4.0, the forecast-verification metrics, the SPC drift charter, the research dataset, the scientific bibliography on the Science page) are available for use under their own licences.
  • Use automated tools (scrapers, headless browsers, multi-account farms) to extract data beyond what the documented API contracts return per call.
  • Submit content that contains malware, exploit payloads, or material designed to attack downstream consumers of your application.
  • Use the Service or non-public Service Data to circumvent access controls, extract proprietary model logic, or create a substantially substitutive service in breach of applicable law or these Terms. Bona fide research collaboration under a signed agreement is exempt.

3. Data and privacy

You agree NOT to:

  • Attempt to re-identify individual users, named operators, named businesses, or precise physical sites from the aggregated, disclosure-controlled research dataset (k-anonymised contributors with k≥10, 1 km² grid generalisation, 90-day publication lag).
  • Submit raw personal identifiers (real names, government IDs, email addresses, phone numbers, IP addresses, free-text biometric data) to endpoints that accept a user reference, including in the optional free-text outcome comment. Only the documented pseudonym (a keyed hash over your internal user-id keyed by a salt you hold) plus non-identifying attributes are permitted.
  • Use the Service to facilitate unlawful surveillance, stalking, harassment, discrimination on a protected basis, or any activity that violates applicable data-protection law (including GDPR Articles 5, 6, 9 special categories, and Chapter V international-transfer rules). You remain responsible for your own compliance obligations as controller of your end users' data; this clause does not transfer to you any obligation that rests with Goable.
  • Bypass the GDPR Article 17 deletion cascade (DELETE /v1/decision/user-data/:pseudonym) by re-introducing data under an alternative pseudonym after a user has requested erasure.

4. Environmental integrity and ESG

The sustainability data, the Goable Sustainability Index, and the per-activity environmental signals Goable publishes are informational inputs accompanied by their methodology and uncertainty bounds. They are not a certification and do not, on their own, establish compliance with any regulatory framework. You agree NOT to:

  • Use these signals to greenwash: published figures must retain their methodology + sample-size caveats and may not be presented as a certification we did not issue (e.g. badge, kitemark, score-derived rating).
  • Present Goable data in claims under the EU Green Claims Directive, CSRD, GRI, GSTC, Travelife or analogous frameworks without preserving the source methodology and uncertainty bounds we publish alongside the data. You remain responsible for the accuracy and legal compliance of any claim you make; Goable does not certify your compliance with these frameworks.

5. Underwriting, insurance, and parametric products

If you use Goable's underwriting endpoints (/v1/underwriting/quote, /bind, /evaluate), the SPC drift charter, or any T2 surface, you additionally agree NOT to:

  • Use the output as the sole pricing or binding signal without your own qualified actuarial review.
  • Bind risk to a Goable score in a jurisdiction where you do not hold the requisite insurance, MGA, broker, or reinsurance authority.
  • Misrepresent the calibration maturity (provisional cells cannot be used to bind retail risk; calibrated cells require the cohort hash to be reproducible by your auditor).

6. Activities that we will not knowingly support

Goable will not knowingly provide the Service to applications whose primary purpose is:

  • Military targeting or kinetic operations.
  • Mass surveillance of civilian populations.
  • Discrimination against a protected class under EU or applicable national law.
  • Evasion of weather-related regulatory safety obligations (e.g. presenting a Goable score as a substitute for an avalanche bulletin in a jurisdiction where the avalanche service has legal primacy).

If your use case touches any of these, please disclose it before signup; we will discuss with you and decline the engagement if the disclosure proves accurate.

7. Enforcement

Goable may rate-limit, suspend, or terminate API keys, individual users, or entire tenants that violate this policy. Where practicable we will give notice and a remediation window. Security-critical violations, ongoing data exfiltration, or material breaches of clause 6 may be actioned immediately and without prior notice.

The enforcement ladder, in escalating severity:

  1. Soft warning — written notice via the contactEmail on the tenant record + a banner in the console.
  2. Rate-limit clamp — daily quotas reduced for a stated period.
  3. Scope revocation — specific scopes (e.g. underwriting:write, decision:write) removed while score-read remains.
  4. Key revocation — affected API keys revoked; the tenant retains the right to issue new keys.
  5. Tenant suspension — login and API access blocked pending investigation.
  6. Termination — tenant archived per the Terms; final invoice issued; export period begins.

You may appeal an enforcement action by replying to the notice email; a real human reviews each appeal.

8. Reporting

Report abuse, security vulnerabilities, or suspected violations:

  • General abuse + AUP violations: contact@fabio-carucci.com
  • Security vulnerabilities: security@goable.io — see also https://goable.io/security for the responsible-disclosure policy.
  • Privacy / GDPR requests: privacy@goable.io

We acknowledge reports within one working day and triage within five.


Last updated: 2026-06-26. This document is published at https://goable.io/legal/acceptable-use. The canonical version that applies to your account is the one stored in legal_documents and accepted at signup; see also the Terms of Service for the version-acceptance contract.