Acceptable Use Policy

What you may not do with the platform, and what happens if you do.

Version 1.0 In force since Aug 21, 2026 Updated Aug 21, 2026

This policy is part of the Terms of Service. It exists because the platform sends email in your name and shares delivery reputation across customers: one sender’s abuse lands in another customer’s spam folder.

1. Email and outreach

  • Send only to people you have a lawful basis to contact. Purchased, scraped or rented lists are not allowed, and neither is importing a list you cannot explain the origin of.
  • Honour opt-outs promptly. The product records them; ignoring the record is a breach of this policy and, in most places, of the law.
  • Do not falsify sender identity, headers or reply addresses, and do not disguise who you are.
  • Do not use the platform for phishing, malware distribution, or any message designed to deceive the recipient about who is writing.

2. Content and data

  • No unlawful content, no content that infringes someone else’s rights, and no material that harasses or endangers a person.
  • Do not load special categories of data the platform was not built for: health records, biometrics, government identity documents, payment card numbers, or anything covered by HIPAA or PCI DSS.
  • Do not use the platform to build a product that competes with it, and do not resell access without a written agreement.

3. Technical limits

  • Do not attempt to reach another workspace’s data, to bypass isolation or authentication, or to interfere with anyone else’s use of the service.
  • Do not overload the API beyond published limits, and do not automate the interface to work around them.
  • Security testing against your own workspace is welcome, and unwelcome anywhere else. Report what you find to [email protected]: we answer researchers, and we do not threaten them.

4. Enforcement

We would rather warn you than shut you down. For most breaches we contact you first and give you a chance to fix it. Where the abuse is severe, ongoing, or puts other customers at immediate risk — active phishing, malware, an attack on isolation — we suspend first and explain immediately after. Your ability to export your data survives any suspension. Report abuse to [email protected].

Cookies, in one screen.

We use cookies to keep you signed in and to remember your language and theme. Nothing here tracks you across the web, and no analytics runs today. Read the cookie policy.

Preferences

Essential cookies keep sign-in and security working, so they cannot be switched off. Everything else stays off until you say otherwise, and you can change your mind at any time.