// Legal

Acceptable Use Policy

Effective date: July 13, 2026  ·  Company: Mahlum Innovations LLC d/b/a Chronos

This Acceptable Use Policy ("AUP") is incorporated into the Chronos Terms of Service. Capitalized terms have the meanings given there. Where your firm has signed a Business Associate Agreement (BAA), the BAA governs PHI obligations in the event of conflict.

Contents

  1. 1. Who may use Chronos
  2. 2. Only upload what you have authority to process
  3. 3. Security of the platform and others' data
  4. 4. No resale or misrepresentation
  5. 5. Professional-responsibility red lines
  6. 6. API, automation, and scraping limits
  7. 7. Account security duties
  8. 8. Enforcement

1. Who may use Chronos

The Service is for licensed legal professionals and their supervised staff — attorneys, paralegals, legal nurses/consultants, and legal-operations personnel — acting for a law firm or legal organization, for lawful legal-practice purposes in the United States. You must be at least 18, provide accurate registration information, and use the Service only under an account your firm authorizes. Attorneys remain responsible for supervising nonlawyer staff use of the Service consistent with ABA Model Rules 5.1 and 5.3 and applicable state bar guidance.

The Service is not offered to consumers, members of the public, or individuals acting outside of a professional legal-practice context.

2. Only upload what you have authority to process

You may upload records and case data only where your firm has the legal authority to possess and process them for the matter at hand — e.g., under a client authorization, HIPAA-permitted disclosure, subpoena, or discovery order. Specifically, you must not:

  • Upload PHI before your firm's BAA with Chronos is executed (it is presented at onboarding and included with every account).
  • Upload records of individuals your firm does not represent and has no lawful basis to process, or records obtained in violation of law, court order, or protective order.
  • Upload data whose processing would breach a confidentiality agreement, sealing order, or professional-conduct obligation binding your firm.
  • Upload PHI or case data into free-text fields not designed for it (e.g., support tickets, billing notes) or send PHI to Chronos by email.

Your firm — not Chronos — is responsible for client consents, HIPAA authorizations, and compliance with professional conduct rules governing its own use of client information, including obtaining any informed consent required by ABA Formal Opinion 512 (2024) and applicable state bar guidance.

3. Security of the platform and others' data

You must not:

  • Attempt to access, view, or extract another customer's data, another firm's workspace, or any account you are not authorized to use.
  • Probe, scan, penetration-test, or attempt to circumvent any security, access-control, tenant-isolation, or authentication feature of the Service. Coordinated disclosure of vulnerabilities to security@medchronosai.com is welcome; independent testing of production systems is not authorized.
  • Transmit malware or harmful code, or use the Service to stage attacks on any system.
  • Attempt to extract, reconstruct, or infer the Service's models, prompts, or source code (including via prompt-injection or model-extraction techniques), or reverse engineer or decompile the Service.

4. No resale or misrepresentation

You must not resell, sublicense, white-label, time-share, or provide the Service (or output generated at volume) to third parties as a competing or rebranded chronology service without Chronos's prior written consent. Serving your firm's own clients with Chronos-assisted work product is permitted and expected.

You must not misrepresent Chronos's compliance posture to courts or clients — Chronos is HIPAA-aligned with a signed BAA on every account and operates a SOC 2 readiness program; we do not hold government "HIPAA certification" (no such certification exists) or a SOC 2 report unless and until one is issued.

5. Professional-responsibility red lines

You must not use the Service to:

  • File, serve, or submit unreviewed AI output. Every chronology entry is an AI-generated draft carrying a per-line citation to its source page. A licensed attorney (or supervised staff under attorney review) must verify entries against their cited source pages before the work product is relied on, filed, served, produced, or presented to a court, tribunal, or opposing party. Filing unverified AI output may violate Fed. R. Civ. P. 11, court standing orders on AI, and Rules of Professional Conduct in your jurisdiction.
  • Violate court rules, standing orders, or protective orders — including AI-use disclosure or certification orders in force in your jurisdiction.
  • Generate or manipulate content for fraudulent, deceptive, or tortious purposes, including fabricating or altering medical evidence.
  • Practice law where not licensed, or provide the Service's output as legal or medical advice to the public.

6. API, automation, and scraping limits

  • Access the Service programmatically only through published APIs with issued credentials. API and automated access must not exceed 60 requests per minute per firm unless otherwise agreed in writing.
  • No scraping, crawling, bulk-downloading, or automated extraction of Service content outside the published API. No headless-browser automation against the web app.
  • No sharing of API keys outside your firm; keys must be stored securely and rotated on personnel departure.
  • Bulk export for legitimate case work and offboarding is supported in-app; contact support rather than scripting around limits.

7. Account security duties

  • MFA is mandatory for every user and must not be disabled, shared, or circumvented.
  • One person per login; no shared or role-based credentials. Firm admins must promptly deactivate departed personnel.
  • Use unique, strong passwords; report suspected compromise to security@medchronosai.com immediately.
  • Firms are responsible for all activity under their accounts and for keeping user roles and permissions current.

8. Enforcement

How we act. We may investigate suspected violations (using audit logs and telemetry — we do not read case files except as necessary to provide the Service, investigate a security incident, or as required by law) and may throttle, suspend, or terminate access for violations.

Notice and cure. For material violations, we will notify the firm's admin and, where the violation is curable and poses no security or legal risk to other customers, allow 10 business days to cure before suspension.

Immediate suspension. We may suspend immediately, without prior notice, where reasonably necessary to protect PHI, other customers, or the Service — e.g., credential compromise, attempted cross-tenant access, security probing, or a legal requirement.

Effect on data. Suspension does not delete your data; retention and return of PHI continue to be governed by your BAA and the Terms. Uploading PHI without a signed BAA is a material breach and grounds for suspension.

Reporting. Report abuse or violations to legal@medchronosai.com.

We may update this AUP with 30 days' notice for material changes.

See also: Terms of Service · Privacy Policy · SLA · Security overview