Your model supplier’s rules reach you through us
PhoneBase’s copilot sends your instructions to a third-party model provider, OpenRouter, and runs the model’s replies against your phone. That means their rules apply to what you ask for here, not only to what we do. Your use of the copilot must comply with your model supplier’s usage policies. Those policies are theirs to write and to change, and we pass them on rather than restating them: read OpenRouter’s Terms of Service for the current text. This is the part people are most often surprised by. A request our own rules do not mention can still be refused upstream, and a refusal that arrives from the model provider is not a PhoneBase fault.Three things you may not use a phone for
These are ours, and they are about the device rather than the model.- Fraud. Do not use a phone to deceive a person or a service for gain. That includes payment fraud, fake engagement, fabricated identities and anything whose purpose is to make a counterparty act on a false belief.
- Taking accounts that are not yours. Do not use a phone to sign in to, recover, or hold an account you are not authorised to hold. Credential stuffing, SMS interception for somebody else’s login, and working through a list of accounts all fall here.
- Getting around a platform’s own protections. Do not use a phone to defeat another service’s security or integrity controls. Rate limits, device attestation, bot detection, region locks and account-linking protections are that service’s decisions about its own product.
What we do when this is broken
We may throttle, suspend, or terminate. That is the right this policy reserves. What that means in practice today is withdrawal of access. An API key can be revoked, and from its next request it is refused with the reason it was refused for, which is a sentence your client can print. A device can have its entitlement revoked, andoperator is one of the recorded reasons for that.
Withdrawing access is not a deletion. The receipt ledger is a separate record
and revoking a credential does not touch it, so what already happened stays
readable.