Molecule API Acceptable Use Policy

Version 1.0

Effective date: 2nd of October 2026

This Molecule API Acceptable Use Policy (the "Policy") sets out the rules that apply to all use of the Molecule API provided by Molecule AG, Schaffhausen, Switzerland ("Molecule", "we", "us" or "our"). It forms part of, and is incorporated into, the Molecule API Terms of Service (the "API Terms"). Capitalised terms not defined in this Policy have the meanings given to them in the API Terms.

1. Scope

1.1 This Policy applies to every person who holds or uses a Credential and to every application, script, Agent and Model Context Protocol client that accesses the API using a Credential. You are responsible for ensuring that Your Application, any Agent using your Credentials and any person acting on your behalf comply with this Policy. Any conduct of an Agent using your Credentials that breaches this Policy is deemed to be a breach by you.

1.2 The examples set out in this Policy are illustrative and not exhaustive. If you are unsure whether a particular use is permitted, you should contact Molecule at [email protected] before proceeding.

1.3 This Policy is intended to prevent misuse and harm and not to restrict legitimate scientific research in any field, including research relating to infectious diseases, toxicology, clinical science and information security.

2. Unlawful Activity and Sanctions

You shall not use the API:

(a) in violation of any applicable law or regulation, or to facilitate any such violation by another person;

(b) if you, or any person owning or controlling you, are the subject or target of sanctions administered or enforced by Switzerland, the European Union, the United Kingdom, the United Nations or the United States, or from, in or for the benefit of any country or territory that is the subject of comprehensive sanctions;

(c) to send, receive or route funds or digital assets involving any sanctioned person or wallet, or to conceal the origin or destination of funds, including through services designed to evade sanctions screening;

(d) to transfer any data, technology or material subject to export control, sanctions, biosecurity or dual-use restrictions without all required authorisations; or

(e) in connection with fraud, money laundering, terrorist financing or any other financial crime.

3. Accounts and Credentials

You shall not:

(a) create accounts, wallets or Credentials in bulk or by automated means, or use disposable, false or misleading identities to obtain Credentials;

(b) create or use multiple accounts, wallets or Credentials in order to exceed any usage limit or any limit on the number of active Credentials, or to evade any suspension or termination;

(c) share, sell, rent, publish or otherwise transfer your Credentials, or use Credentials belonging to another person;

(d) embed a Consumer Credential in any software distributed to third parties, including web or mobile applications, public repositories and shared Agent configurations, in a manner that allows recipients to obtain it;

(e) impersonate Molecule, any Lab, researcher, institution or other user, or misrepresent your identity, your affiliation or the person on whose behalf you act; or

(f) issue a Credential through an Agent or any other automated means without the knowledge and authorisation of the account holder.

4. Service Integrity and Usage Limits

You shall not:

(a) circumvent, disable or interfere with any usage limit, cost limit, query complexity limit, pagination limit, firewall or other protective measure of the API;

(b) submit requests that are designed to consume excessive resources without legitimate need, including deliberately complex or deeply nested queries, unbounded pagination and repeated identical requests that could reasonably be cached;

(c) conduct denial-of-service attacks, flooding, or load or stress testing against the API, including the Test Environment, without Molecule's prior written consent;

(d) interfere with or disrupt the API, its underlying infrastructure or any other user's use of the API, including by introducing malicious code or by exploiting any defect for your own benefit; or

(e) disregard any rate-limiting response or retry interval communicated by the API, or repeatedly resubmit requests that have been refused for reasons that resubmission cannot cure.

Molecule does not publish the thresholds applied by its protective measures, which may change at any time without notice.

5. Access Controls and Confidential Content

Access to Lab data rooms is governed by roles granted onchain by each Lab. You shall not:

(a) access or attempt to access any content, encryption key or operation to which your wallet or Credential is not entitled, including by exploiting any misconfiguration or any role that has expired or been revoked;

(b) attempt to decrypt Confidential Content without the required role, or request any encryption key or passphrase for any purpose other than enabling an authorised person to read or write the relevant content;

(c) publish, sell or otherwise disclose Confidential Content outside the relevant Lab without the prior consent of the Lab owner, or retain Confidential Content beyond the period permitted by the API Terms;

(d) use any role granted to you for a purpose other than that for which it was granted, including deleting or overwriting the work of others without authority; or

(e) use the metadata of confidential files, including descriptions, tags, categories and searchable text, which is not encrypted, to reconstruct, profile or disclose the confidential content of those files.

6. Data Collection and Machine Learning

6.1 You may use the API to retrieve API Content for the purposes of Your Application, including search, analysis and Agent workflows for users who are entitled to access that API Content.

6.2 You shall not:

(a) scrape or crawl the Molecule Labs application or Molecule websites, or use headless browsers or other unofficial interfaces, as a substitute for the API;

(b) systematically download, copy or mirror the content of Labs or data rooms, other than your own or those whose owners have consented, for the purpose of creating a competing dataset or service or for resale;

(c) use Confidential Content to train, pre-train or fine-tune any machine learning model, or use other API Content for any such purpose except as permitted by the licence terms applicable to that API Content;

(d) collect, compile or infer information about identifiable individuals from API Content, including wallet holders, researchers and contributors, for the purposes of profiling, tracking, harassment or marketing; or

(e) combine API Content with other data in order to re-identify any individual in anonymised research data.

7. Biosecurity and Dual-Use Research

You shall not use the API, or any content stored or retrieved through it, to:

(a) develop, produce, enhance, acquire, stockpile or deploy biological, chemical, radiological or nuclear weapons, or their precursors or means of delivery;

(b) enhance the transmissibility, virulence, host range or immune evasion of any pathogen, or enable any pathogen or toxin to evade detection, diagnostics or medical countermeasures, other than within a lawful research programme that has obtained all required institutional, biosafety and regulatory approvals and operates under appropriate containment;, and that has obtained any export authorisation required for the submission or retrieval. An institutional approval is not that authorisation.

(c) disseminate protocols, sequences, methods or compilations of information where a principal use or effect, or a reasonably foreseeable material effect, is to enable or materially facilitate the causing of mass harm;

(d) assist any person in obtaining controlled pathogens, toxins or precursors in circumvention of applicable regulatory controls, screening procedures or export restrictions; or

(e) present any of the foregoing as legitimate research, including through intermediaries, funding applications or misrepresentation of institutional affiliation.

Where Molecule believes that any content presents a serious biosecurity risk, Molecule may restrict access to that content with immediate effect and may report the matter to the competent authorities. You may request a review of that restriction at [email protected]. Molecule will identify, in the Documentation, the contact responsible for imposing a hold and for reviewing a report that a hold was applied in error. Encryption of content, a statement that the use is research, and an intention to publish do not by themselves satisfy this Section 7 or Section 20 of the API Terms.

8. Personal Data and Human-Subject Data

Molecule Labs is limited to anonymous or irreversibly anonymised data. You shall not use the API to:

(a) submit personal data to any Lab, data room, file metadata or announcement, or in any Onchain Action;

(b) submit health, genetic, biometric or other special categories of personal data relating to identifiable individuals, including pseudonymised data that can be attributed to an individual;

(c) submit data derived from human participants unless it has been irreversibly anonymised and you hold all consents and ethics approvals required for its disclosure; or

(d) record personal data onchain in any form, including in token metadata, decentralised identifier documents or content identifiers that reference personal data.

If you become aware that personal data has been submitted, you shall promptly restrict further access to it through the API, request deletion of any copy Molecule holds outside a decentralised storage network, and notify Molecule at [email protected]. Content that has been stored on decentralised storage networks or recorded onchain may not be capable of removal, as described in Sections 9.5 and 11.2 of the API Terms. Your obligation under this Section 8 is to take the steps that remain available, not to achieve a deletion that the API Terms state Molecule cannot perform.

9. Research Integrity

You shall not use the API to:

(a) publish fabricated, falsified or plagiarised data, results or research outputs, or attribute your work to another person or the work of another person to yourself;

(b) make false or misleading statements concerning research results, clinical efficacy, regulatory status, peer review, or the participation or endorsement of any researcher, institution or authority;

(c) misrepresent the ownership or control of any intellectual property, or mint, tokenize or link any intellectual property that you are not entitled to deal with; or

(d) publish announcements or activity intended to mislead others as to the progress or status of any Lab.

10. Market Integrity

You shall not use the API, API Content or any Onchain Action to:

(a) manipulate or attempt to manipulate the price, trading volume, number of holders or apparent activity of any IP-NFT or IP Token, including by wash trading, spoofing, coordinated trading or pump-and-dump schemes;

(b) trade, or enable any other person to trade, any IP NFT or IP Token on the basis of material non public information obtained through the API, including Confidential Content and advance knowledge of announcements, where you know or ought to know that the information is not public and that it would be reasonably likely to have a significant effect on the price of that IP NFT or IP Token. This paragraph does not restrict a transaction that the Lab owner has authorised in writing and that is disclosed to the persons entitled to the relevant Confidential Content before it is submitted;

(c) front-run the transactions of other users on the basis of information obtained through the API;

(d) publish announcements, metadata or research updates that are false, misleading, or omitted in a manner that makes them misleading. A truthful announcement is not a breach of this paragraph because it may affect a price; or

(e) promote any IP-NFT or IP Token as an investment or represent that it will generate any return.

11. Agents and Automated Systems

If you operate an Agent using the API, you shall:

(a) ensure that an identified natural person or legal entity is accountable for the Agent and can be contacted by Molecule;

(b) where practicable, assign each Agent its own Consumer Credential, labelled so that requests made by that Agent can be identified;

(c) ensure that the Agent does not represent itself as a natural person, as Molecule or as a member of any Lab of which it is not a member;

(d) ensure that a natural person reviews and approves before the Agent performs any Onchain Action that transfers, mints or otherwise disposes of a digital asset, makes any payment above any threshold stated in the Documentation, deletes or overwrites data room content, changes access to any content, or discloses Confidential Content outside the relevant Lab, and that the approval is specific to the action. For any other Onchain Action, payment, deletion, access change or disclosure covered by Section 6.3 of the API Terms, ensure that a natural person reviews and approves the action, or that documented controls appropriate to the risk are in place, including spend limits, allow lists and a means to suspend the Agent;

(e) treat API Content as untrusted input and protect the Agent against instructions embedded in files, metadata or announcements;

(f) prevent Credentials from being included in prompts, logs, tool outputs or any other material that the Agent may disclose; and

(g) monitor the Agent for repeated, looping or otherwise unintended behaviour and suspend it where such behaviour occurs.

You shall not operate any Agent that creates accounts or Credentials in bulk, coordinates multiple identities to evade usage limits, or performs actions on behalf of any wallet holder who has not authorised them.

12. Harmful Content and Third-Party Rights

You shall not use the API to submit, publish or distribute any content that:

(a) infringes any intellectual property right, right of confidentiality, right of privacy or other right of any person;

(b) contains malware, exploit code directed at others, or links designed to compromise users, devices or wallets, including phishing and wallet-draining schemes;

(c) constitutes unsolicited bulk communications;

(d) harasses, threatens or incites violence against any person, or promotes hatred on the basis of any protected characteristic; or

(e) sexually exploits or endangers minors. Molecule will report any such content to the competent authorities.

13. Security Research

13.1 Molecule welcomes good-faith security research. You may test the API for security vulnerabilities provided that you:

(a) use only accounts, wallets, Labs and data that you own or are expressly authorised to test, and use the Test Environment wherever possible;

(b) cease testing and report to Molecule immediately upon accessing any data that does not belong to you, and do not retain, use or disclose such data;

(c) do not degrade the availability of the API for others, including through denial-of-service testing, flooding or high-volume automated scanning;

(d) do not perform any Onchain Action that could cause loss to any other person;

(e) report any vulnerability to [email protected] with sufficient detail to allow it to be reproduced, and allow Molecule a reasonable period to remediate it before any public disclosure; and

(f) comply with any vulnerability disclosure policy that Molecule may publish.

13.2 Molecule will regard security research conducted in accordance with Section 13.1 as authorised by Molecule under this Policy, will not initiate legal action against you in respect of it, and will not suspend your access to the API on account of it. This Section 13.2 binds Molecule only. It does not bind any other person, and it does not prevent Molecule from taking the minimum action reasonably necessary to contain an apparent ongoing risk to the API or to another user while Molecule reviews your report. Molecule will not treat that containment, of itself, as a finding that you breached this Policy.

13.3 Testing that does not comply with Section 13.1 may constitute a breach of Sections 4 and 5 of this Policy. An accidental deviation that you report promptly under Section 13.1(b) or 13.1(e), and that you do not exploit, will be reviewed under Section 15.6 and is not of itself grounds for termination.

14. Reporting

14.1 You may report any suspected breach of this Policy, any security vulnerability, any personal data found in a Lab or data room, or any exposed Credential to Molecule at [email protected]. If a Credential has been exposed, you shall also revoke it immediately in the Molecule Labs application.

14.2 If you become aware that Your Application, any Agent using your Credentials or any person acting on your behalf has breached this Policy, you shall notify Molecule without undue delay and cooperate with any resulting investigation.

15. Enforcement

15.1 Molecule may investigate any suspected breach of this Policy, including by reviewing request logs, usage patterns, onchain activity and content.

15.2 Molecule will respond to breaches of this Policy in a manner proportionate to their nature, seriousness and recurrence and to whether they were deliberate. Such measures may include, individually or in combination:

(a) restricting or reducing your usage limits;

(b) issuing a warning and requiring remediation within a specified period;

(c) revoking one or more Credentials or refusing to issue further Credentials;

(d) suspending your access to the API or to particular operations; and

(e) terminating your access to the API and blocking associated accounts, wallets and decentralised identifiers.

15.3 Molecule may take any of the measures described in Section 15.2 with immediate effect and without prior notice where the breach involves a biosecurity risk, sanctions, a compromised Credential, an ongoing attack, market manipulation, personal data or content that Molecule is legally required to remove, or where prior notice would be unlawful or would defeat the purpose of the measure.

15.4 Where Molecule takes action in respect of content in a Lab or data room, it may restrict access to that content through the API. Molecule cannot remove content from decentralised storage networks or blockchains that it does not control.

15.5 Molecule may report conduct to, and cooperate with, law enforcement and regulatory authorities where required by law or where Molecule believes that there is a risk of serious harm.

15.6 If you believe that Molecule has taken action against you in error, you may request a review of that decision by contacting [email protected]. Molecule will consider your request within a reasonable period and, where lawful, inform you of the reasons for its decision. A review under this Section 15.6 is also the route for a review of a biosecurity hold under Section 7, a sanctions screening decision notified to you, and a containment step taken during security research under Section 13.2.

15.7 Any failure by Molecule to enforce this Policy in any instance shall not constitute a waiver of its right to enforce it in any other instance.

16. Amendments

Molecule may amend this Policy from time to time in accordance with Section 22 of the API Terms. Each version of this Policy remains available at its published location.