Acceptable Use Policy
Rules and guidelines for the safe and appropriate use of GPguide.
This Acceptable Use Policy sets out rules for using GPguide. It is designed to protect clinicians, patients, and the GPguide platform. By accessing or using GPguide, you agree to comply with this AUP and our Terms of Use.
1. Intended use (what GPguide is for)
2. Absolute prohibition: do not enter patient identifying information
GPguide is designed for non-identifying inputs. You must not enter any patient identifying information into GPguide.
This includes (without limitation):
- Patient name (first/last), initials when combined with other identifiers
- Date of birth
- Address
- Phone number or email address
- Medicare number, DVA number, IHI
- Medical record number / UR number
- Any images, attachments, or free text containing identifiers
- Any combination of details that could reasonably identify a patient
This approach aligns with OAIC guidance recommending organisations avoid entering personal (especially sensitive) information into publicly available generative AI tools and to take a cautious, privacy-by-design approach.
3. No high-risk or unsafe clinical reliance
You must not use GPguide:
- As a substitute for professional judgement
- To generate outputs that are used without clinician review and editing
- To diagnose, triage, prescribe, or make automated clinical decisions
- To create emergency instructions (e.g., “what to do right now for chest pain/stroke symptoms”) for patient-facing use
If a situation is urgent or high-risk, follow standard clinical pathways and local emergency processes.
4. Prohibited content (what you must not input or generate)
You must not use GPguide to input, generate, upload, transmit, or store content that:
- Is unlawful, defamatory, harassing, hateful, or threatening
- Facilitates wrongdoing (e.g., identity theft, fraud)
- Includes malware, malicious code, or instructions intended to compromise systems
- Infringes intellectual property rights (e.g., copying/publishing copyrighted templates you do not have rights to use)
- Attempts to reveal another person’s private information
5. Prohibited technical activities (protecting the platform)
You must not:
- Attempt to bypass security, authentication, rate limits, or access controls
- Probe, scan, or test vulnerabilities without written permission
- Scrape, crawl, or bulk-export the service or its outputs
- Reverse engineer, decompile, or attempt to extract source code, prompts, models, or system logic
- Use automated tools/bots to generate excessive traffic or disrupt the service
- Interfere with other users’ access to GPguide
These restrictions reflect standard “licence restrictions and prohibited use” clauses common in Australian SaaS terms.
6. Account integrity
You must:
- Keep your login credentials secure
- Not share accounts (unless your plan explicitly allows multi-user access)
- Promptly notify us if you suspect unauthorised access to your account
7. If you accidentally include patient identifiers
If you believe you have entered patient identifying information:
- Stop and do not reuse that output.
- Remove identifiers from your workflow and re-create the prompt using de-identified context only.
- Contact us at support@gpguide.com.au so we can assist and assess whether further steps are appropriate.
8. Enforcement
We may take reasonable steps to enforce this AUP, including:
- Warning you and requesting corrective action
- Suspending or terminating access (especially for repeated or serious breaches)
- Restricting usage where we reasonably believe use is unsafe, unlawful, or poses a security/privacy risk