Legal
Acceptable Use Policy
What you may not do with this product, and the two sets of obligations that are yours rather than ours: our AI provider's rules, and the law governing the mail you send.
- Effective
- 6 September 2026
- Last updated
- 6 September 2026
Who this applies to
This policy is part of the terms of service and applies to everyone who uses the product: the account owner, every person on a seat, and anybody they let use their sign-in.
What you must not do
Do not use the product to break the law, to infringe somebody's rights, or to handle information you have no right to hold.
Do not attempt to reach another customer's workspace, probe the service for weaknesses without our written permission, or interfere with how it runs for anybody else.
Do not resell the product, share one seat between several people, or automate the product in a way that is really a second product.
Do not upload malware, and do not use the product to store or distribute it.
Using the AI features
These obligations come from our AI provider's usage policy and they bind you because we pass them on. Breaking them puts our access at risk as well as yours.
Do not use AI features to generate spam, bulk unsolicited messaging, or content designed to deceive the person who receives it about who is writing to them or why.
Do not present AI output as something it is not. If a message was drafted by a model, do not claim a person wrote it from scratch, and do not use the product to impersonate a real person or organisation.
A person reviews every AI draft before it is sent. The product is built that way and this policy requires it: nothing this product generates goes to a recipient without somebody reading it first.
Do not use AI features for decisions that materially affect somebody's rights, safety, employment, credit or health without a person reviewing the decision.
Do not use AI features to produce content that harasses, defames, or sexualises anybody, or that promotes self harm or violence.
The mail you send, and the law that governs it
When you send outreach through this product, you are the sender. The obligations below are yours under the CAN-SPAM Act and its equivalents elsewhere, and the law is explicit that you cannot contract them away, including to us.
Your headers and your subject line must be honest. The from address, the reply address and the routing must identify you, and the subject must reflect what is in the message.
Every message must carry a valid physical postal address for you. Ours is not yours, and this product will not substitute one for you.
Every message must carry a clear and conspicuous way to opt out, and you must honour an opt-out within ten business days. The product adds an unsubscribe link and records what it receives; acting on it in time is still your obligation.
Say clearly when a message is an advertisement, and keep your own records of consent where the law where your recipient lives requires it.
The records you load
Only load records about people you are entitled to hold and to contact. You are the controller of those records and you decide what is collected and why; we process them for you.
Do not load special category information, payment card numbers, government identifiers, or health information into a workspace. The product is not built to hold them and this policy forbids it.
Fair use of the service
The product applies rate limits, sending limits and daily caps. Do not work around them, and do not run the service at a volume that degrades it for other customers. If you need more headroom, ask us.
How we enforce this
Where we can, we ask you to fix a problem before we do anything else. Where a problem is urgent, or where it puts other customers or our providers at risk, we may suspend a capability or an account first and tell you immediately afterwards. Serious or repeated breaches end the agreement.