Safety
Keep your keys secret. Review data before sending. Your team controls case access. Templ checks legal authority before acting. Use the Safety form for legal requests, required notices, urgent reports and appeals.
1. Who runs Templ
templ.fun Ltd runs Templ. Customers run their support workspaces.
templ.fun Ltd is a BVI Limited Company, company number 2191511. It registered on 28 October 2025. Its registered and mailing address is Quijano Chambers, P.O. Box 3159, Road Town, British Virgin Islands.
A Customer is the team that uses Templ for support. A user asks that team for help through Templ. Customers usually supply the people who answer. A signed order form may include done-for-you work by Templ staff. They act under Customer instructions after its manager grants explicit team access.
Read the Terms, Privacy Policy and DPA with these rules.
2. Protect your wallet
Keep keys secret. Use the sign-in card to prove wallet control.
Never share a private key, recovery phrase or seed phrase. Templ and authorized staff must never ask for them. Keep them out of messages, screenshots, files and knowledge sources.
Wallet sign-in uses an authentication message. Check the website, wallet and message before signing. Use the sign-in card. A sign-in proof authorizes no payment, token approval or transaction. It does not prove your name or company authority.
Templ binds each challenge to its domain, URI, chain, nonce and expiry. Widget challenges also bind the workspace. Nonces are single-use. Templ checks replay, expiry and revocation.
A connected wallet alone remains unverified. A wallet reported by the host app also remains unverified without proof. Email confirmation grants no wallet, team or app authority.
Chat cannot start signing, token approvals or transfers. Staff may ask for a past public transaction hash or signature. That request does not ask you to sign anything new.
3. Share case details
Review what the team will receive before sending.
Read the widget's sharing notice. Remove unrelated personal details from text and screenshots. Share public transaction references only when they help your case.
Templ screens messages for recognized private keys and recovery phrases before storage. Detection can miss secrets. Do not rely on it to protect data you send.
Some hexadecimal values can be public references or secrets. Templ hides ambiguous values from AI, bots, webhooks and exports unless shared as typed transactions. The user and authorized team may still see them. A support lead can redact them.
Wallet addresses and transaction references can reveal a person's activity. Public blockchain records can be copied or linked to people. Templ cannot erase them or reverse a final transfer. Deleting a Templ case does not delete blockchain data.
Privacy explains case retention, exports, legal holds and separate improvement copies. A de-identified copy may still be personal data.
4. Case access
Users read their own cases. Team members need current permission.
A widget session belongs to one approved origin and workspace. It grants access only to that user's thread. It grants no team access or general app session.
A guest's own session credential must redeem a wallet proof to link their thread. Someone else's proof cannot take over that thread.
Only the Customer manager grants team permissions. Templ's done-for-you staff need that grant too. Payment, billing rights, token ownership and display names grant no case access. Ordinary assignment grants none.
Specialists need a current qualifying follow-up or mention. Their access ends when that basis ends. They cannot reply to users or export cases.
Templ checks current permission on private reads, writes, searches, files, exports and events. Newly authorized staff may read retained history within their role. Revoking access stops future access through Templ. It cannot retrieve copies someone already exported lawfully. User exports exclude internal notes.
A legal report grants no team access and opens no Customer inbox.
5. AI answers
AI may be wrong. Ask the team when you need a person.
AI can produce wrong, incomplete, biased or outdated answers. It may invent facts and sources. Check important instructions and relevant sources before acting.
| Case mode | What the agent may do |
|---|---|
| AI answers | Send answers while the case's reply and handoff rules allow it. |
| AI drafts only | Read the case and create internal drafts. It cannot send user-facing text. |
| AI off | It cannot read or act on the case through the agent interface. |
The Customer manages case modes. An agent cannot change its own mode. A person who sends a draft takes responsibility for that reply.
You can ask for a person on your own thread. The request hands the case to the team. It adds no charge or permission. It promises no immediate reply or continuous staffing.
Customers must supervise their agents and high-risk answers. Done-for-you staff follow agreed Customer instructions and scope.
6. Checks and payments
Transaction checks are read-only. Use payment instructions in the authenticated app.
Checks explain available blockchain records. Providers or networks can delay them or return incomplete data. A check does not prove that a protocol, token, contract or wallet is safe.
Templ holds no Customer or user private keys. It does not control their wallets or sign for them. It provides no custody, brokerage or exchange service. It provides no financial, investment, tax or legal advice.
Stablecoin payments buy Templ services. Prepaid balance is service credit, not custody or an investment.
Payments use the stablecoins and networks shown in the app. Supported tokens include USDC and USDT where official on configured EVM networks and Solana. Payments are direct stablecoin transfers. Each method stays closed until its release checks and verification pass. Pay to the address shown in the app. Chat cannot change that address or start a payment.
Check the asset, network, address and amount before paying. Wrong-network or wrong-address transfers may be lost. A wallet signature or screenshot proves no receipt. The Terms explain verified credits, billing disputes and eligible refunds.
7. Lawful use
Do not use support access to harm people or bypass security.
These rules apply to Customers, teams, agents, integrations and users. Do not:
- Ask for private keys, recovery phrases, seed phrases or stolen credentials.
- Use chat to start signing, token approvals or transactions.
- Impersonate a person, protocol, Templ employee or legal authority.
- Use phishing, fraud, malware, harassment, threats or child sexual exploitation material.
- Share another person's private data without lawful authority.
- Read another user's case or workspace without permission.
- Bypass grants, session limits, revocation, safety screens or a suspension.
- Use prompt injection to obtain secrets or unauthorized access.
- Disrupt the service, send spam or test systems without permission.
- Break applicable sanctions, export controls or other law.
Customers must manage their team and agents. They need lawful rights to submitted content and user data. Customer instructions cannot override applicable law or Templ's safety checks.
8. Applicable sanctions
Follow sanctions that apply to the people, location and service involved.
Do not use Templ when an applicable sanction prohibits that service. Do not act for a prohibited person or evade applicable ownership, control or location restrictions. Tell Templ if a change makes your use unlawful.
As a BVI company, templ.fun Ltd follows sanctions in force in the British Virgin Islands. These include UK and UN measures extended there through applicable law. The BVI sanctions guidance explains that framework.
US, UK and EU rules can apply through their own territorial and personal scope. Templ checks the law that applies and any valid exemption or licence. Crypto payments receive no exemption from applicable sanctions.
Templ may request data needed to check a legal restriction. It may refuse prohibited service or payments. It may preserve or report data when law requires it. These rules promise no continuous screening or sanctions certification.
9. Report routes
Use the Safety form for its listed reports. Your team handles ordinary support.
The form accepts:
- Requests from legal authorities. Identify the agency, official contact, instrument, jurisdiction and requested action.
- Notices required by law. Cite the law, provision, jurisdiction, content location and evidence. Include your name, contact email and good-faith statement.
- Child sexual exploitation or abuse reports. Give the exact location and facts. You may omit your name, email and legal citation.
- Immediate threats to life or serious injury. Give the exact location and facts. You may omit your name, email and legal citation.
- Appeals of platform decisions. Explain the error and include an earlier report ID if available.
A mandatory notice needs no government authority unless its law requires one. Templ checks whether the claimed duty applies. The form accepts ordinary illegal-content claims only where an applicable law requires that intake. Customers handle protocol support, spam and ordinary case disputes in their own workspaces.
Do not upload, copy or send illegal sexual material. Do not include keys, invitation secrets or unrelated personal data. A message report can capture only stored content the reporter may currently read.
10. Verified review
A receipt confirms intake. It grants no access and proves no claim.
An operator checks claimed authority through independent official sources. The operator checks the contact, instrument, legal basis, jurisdiction and scope. An official-looking email or title proves no authority.
A new legal hold or Safety suspension needs stored validation. It must establish competent authority, an applicable notice duty or an urgent legal duty. Ordinary reports and appeals cannot authorize a new restriction. Report volume alone decides nothing.
No report automatically discloses private data, grants access or restricts anyone. Preservation and disclosure need separate authorized legal review. Applicable emergency and reporting duties remain.
When acting as a processor, Templ follows the DPA's notice and instruction rules. It tells the Customer about binding disclosure demands unless law prohibits notice. It limits disclosure to the valid duty's scope.
Templ may restrict a workspace, account or file where verified authority or applicable law requires it. Restrictions cannot rewrite blockchain records. Existing recipients may retain lawful copies.
11. Retention and appeals
Routine reports expire after 90 days. Documented legal duties may require longer retention.
Routine reports stay for 90 days. Documented legal holds and active enforcement can require longer retention. Active enforcement carries a 30-day review marker. It does not promise that a restriction ends after 30 days.
A message report can preserve a restricted review copy after the original is deleted. Its legal basis and scope limit preservation. Legal holds never extend improvement or evaluation copy retention.
Choose the appeal option to request review. Explain the error and provide relevant new facts. An operator reviews the original decision before restoring access. Do not create another account to bypass it.
Payment does not excuse prohibited conduct or prevent lawful restrictions. A restriction creates no automatic refund right. The Terms and mandatory law control remedies.
12. Emergencies and contact
Contact local emergency services for immediate danger. Use Templ's widget for other help.
Do not wait for Templ when someone faces immediate danger. Contact local emergency services. Templ offers no emergency dispatch, continuous monitoring, response deadline or fund recovery.
Legal notices opens Templ's widget for legal questions or an unavailable Safety form. Formal legal notices may also go to legal@usetempl.com. Use Privacy requests for data requests. These requests may also go to privacy@usetempl.com. Use Security reports for vulnerability reports. These reports may also go to security@usetempl.com.
Give enough facts to locate the issue. Do not test other people's data or disrupt the service. This page grants no testing permission and promises no bounty. Ordinary protocol questions go to that protocol's team.