1. The short version
- Use the Service lawfully, on data you have the right to submit.
- Keep direct identifiers and sensitive data off the event stream; use the supported mechanisms for identity and special-category data.
- Don’t distribute malware, don’t mislead people with your links or messages, don’t probe what isn’t yours.
- When something looks wrong, tell us: hello@pharen.ai.
2. Prohibited data
The event stream — track() and screen() events, crash and performance context, session data — is designed to carry pseudonymous data only, and the Service enforces that server-side: an event carrying a field the platform classifies as identifying is rejected, not quietly cleaned. The SDKs additionally drop a short list of obvious identifying key names from track() properties as a convenience — a courtesy, not a filter you may rely on, and it does not cover screen views, crash or performance context, or data you attach elsewhere. These safeguards are defense in depth, not permission: you must not submit the following to the event stream at all:
- direct identifiers — names, email addresses, phone numbers, physical addresses;
- government-issued identification numbers (Social Security, passport, driver’s license, or equivalents);
- payment-card or financial-account data (PAN, CVV, bank account numbers);
- authentication secrets — passwords, API keys, tokens, private keys;
- special-category data — health information, biometric or genetic data, and data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sex life, or sexual orientation;
- precise geolocation, or any continuous location tracking of an identified person.
The supported mechanisms. Identity belongs in identify(): traits route to a restricted attribute store, separate from events, never inlined into properties or logs. Health-adjacent special-category data (for example, a vision-test result) may be stored only through the restricted attribute store, only under an explicit, runtime end-user consent to the health purpose, and only where your own disclosures to that End User cover it. There is no other supported path for special-category data anywhere in the Service.
Two categories are prohibited outright, with no supported mechanism during Early Access:
- Protected health information regulated under HIPAA. We do not offer a business associate agreement; do not submit PHI created or received by or for a HIPAA-covered entity.
- Children’s data. Do not use the Service with an App directed to children under 13, and do not knowingly submit personal data of children under 13, without our prior written agreement. Where your App serves minors at all, compliance with children’s-privacy law (COPPA and its equivalents) is your responsibility.
3. Abuse of the platform
- No unlawful use, and no content or data that infringes anyone’s rights.
- Distribution: no malware, spyware, or deceptive software through the Service’s build-distribution infrastructure; distribute only builds you have the right to distribute, signed under credentials you are entitled to use.
- Links: no phishing, no misleading destinations, and no link-cloaking of prohibited content through the Service’s link infrastructure.
- Messages: if you deliver communications to End-User devices through the Service, no spam, no deception about the sender or purpose, and honor opt-outs. Compliance with messaging and electronic-communications law is yours.
4. Security & integrity
- Do not attempt to access another customer’s data, probe or test the Service’s isolation against data that is not yours, or interfere with the Service or other customers’ use of it.
- Do not circumvent rate limits, quotas, consent enforcement, or other technical safeguards, and do not falsify the origin of data you submit.
- Do not share, sell, or misuse credentials, and do not resell or provide the Service to third parties as a service bureau without our written agreement.
- Good-faith security research is welcome when it is performed against your own account and data, respects rate limits and other users, and is reported to hello@pharen.ai before public disclosure. We confirm receipt within five business days — automation may send that confirmation, and a person always follows up as soon as practicable — and agree a disclosure timeline with you; absent agreement, 90 days from your report is reasonable. Research within those bounds will not be treated as a breach of the Terms, and we will not bring or support legal action against you for it — including under the Computer Fraud and Abuse Act or analogous computer-crime laws — nor ask that you be prosecuted. Anything beyond those bounds — including any test that touches data that is not yours — requires our prior written permission.
5. Copyright complaints
The Service hosts builds our customers upload and serves install pages and links for them. If you believe material distributed through the Service infringes your copyright, send a notice with the substance of 17 U.S.C. § 512(c)(3) — identification of the work, the location of the material, your contact details, the required good-faith and accuracy statements, and your signature — to hello@pharen.ai (subject “Copyright complaint”) or by mail to the address at the foot of this page. On a valid notice we disable access to the material and notify the customer who distributed it; we accept counter-notices and restore material where the law provides; and we terminate the access of repeat infringers in appropriate circumstances.
6. Enforcement
Violations are handled under the Terms (Section 18): where suspension is necessary we suspend the narrowest slice practicable, with notice where practicable, and suspended ingestion fails with explicit errors rather than silently discarding data. Material violations of Section 2 or 4 may lead to immediate suspension or termination. To report abuse of the Service — including a link or build you believe is malicious — contact hello@pharen.ai.
Version history
- 1.0 — September 2, 2026 — initial publication.
The Pharen platform is operated by Lucubra LLC, a Washington (USA) limited liability company, operating the Pharen platform. 522 W Riverside Ave, Ste N, Spokane, WA 99201-0581, USA · hello@pharen.ai