Acceptable Use Policy
Effective Date: July 25, 2026
Last Updated: July 25, 2026
This Acceptable Use Policy ("AUP") governs access to and use of the TextConvo platform, software, websites, applications, artificial intelligence functionality, application programming interfaces, communications tools, integrations, telecommunications capabilities, and related products and services provided by TextConvo, LLC ("TextConvo," "we," "us," or "our") (collectively, the "Services").
This AUP is incorporated into and forms part of the agreement governing a customer's access to or use of the Services, including the TextConvo Terms of Service, Master Services Agreement, Order Form, or other applicable written agreement (collectively, the "Agreement").
This AUP applies to each customer, account owner, authorized user, employee, contractor, agent, affiliate, service provider, developer, reseller, and other person or entity that accesses or uses the Services through a customer account (collectively, "Customer" or "you").
By accessing or using the Services, Customer agrees to comply with this AUP and ensure that all use of the Services through Customer's account complies with this AUP.
TextConvo may restrict, suspend, or terminate access to the Services, block communications, impose additional controls, or take other protective action if TextConvo reasonably believes that Customer has violated this AUP or that Customer's activity creates legal, regulatory, security, consumer-protection, network, carrier, deliverability, financial, or reputational risk.
Table of Contents
1. Purpose and Scope
The purpose of this AUP is to:
- promote lawful, responsible, transparent, and secure use of the Services;
- protect consumers, businesses, communications networks, service providers, and other users from spam, fraud, deception, harassment, and abuse;
- support compliance with telecommunications, privacy, consumer-protection, marketing, email, artificial intelligence, and data-protection requirements;
- protect the integrity, security, availability, reputation, and deliverability of the Services;
- support compliance with carrier, telephone-provider, messaging-provider, mailbox-provider, platform, and industry requirements; and
- prevent misuse of TextConvo's infrastructure, artificial intelligence systems, telephone numbers, email domains, messaging channels, APIs, integrations, and related resources.
This AUP applies to all communications and activities conducted through or facilitated by the Services, including:
- SMS and MMS;
- Rich Communication Services ("RCS");
- WhatsApp and other third-party messaging channels;
- commercial and transactional email;
- live, automated, artificial-intelligence-generated, synthetic, prerecorded, or artificial voice calls;
- voicemail and answering-machine messages;
- conversational and agentic artificial intelligence;
- call recording, transcription, summarization, analytics, and quality monitoring;
- APIs, webhooks, integrations, workflows, and automated sequences; and
- content, data, contact lists, prompts, scripts, models, knowledge bases, and other materials submitted to or generated through the Services.
2. Compliance With Applicable Requirements
Customer must comply with all laws, regulations, rules, orders, regulatory guidance, contractual obligations, and industry requirements applicable to Customer's access to or use of the Services ("Applicable Requirements").
Depending on the nature of Customer's activities, Applicable Requirements may include:
- the Telephone Consumer Protection Act and implementing Federal Communications Commission rules;
- the Telemarketing and Consumer Fraud and Abuse Prevention Act and Telemarketing Sales Rule;
- the CAN-SPAM Act and implementing rules;
- federal and state Do Not Call requirements;
- state telemarketing registration, calling-time, disclosure, consent, recording, and mini-TCPA laws;
- federal and state consumer-protection and unfair or deceptive practices laws;
- privacy, data-protection, breach-notification, wiretap, interception, recording, and biometric-privacy laws;
- laws governing artificial intelligence, automated decision-making, synthetic media, and digital replicas;
- laws applicable to financial services, insurance, healthcare, housing, employment, education, debt collection, political communications, charitable solicitations, and other regulated activities;
- communications-carrier, messaging-provider, mailbox-provider, telephone-provider, domain-registry, and platform rules;
- CTIA guidelines, messaging campaign-registration requirements, sender-verification requirements, and industry codes of conduct;
- international communications, privacy, anti-spam, and marketing laws where recipients are located outside the United States; and
- contractual restrictions imposed by third-party providers used to deliver the Services.
Customer is solely responsible for identifying and complying with the Applicable Requirements governing each communication, campaign, recipient, purpose, industry, jurisdiction, technology, and communication channel.
TextConvo does not provide legal advice, determine whether Customer's activities are lawful, or guarantee that use of the Services will make Customer compliant with any law or regulation. Registration, approval, technical enablement, or acceptance of a campaign, telephone number, sender identity, domain, template, use case, or account by TextConvo or a third-party provider does not constitute legal approval.
3. Customer Responsibility
Customer controls and is solely responsible for:
- selecting the recipients of communications;
- determining the purpose, timing, frequency, content, and communication channel;
- obtaining and documenting all required consents, permissions, registrations, licenses, and other legal authority;
- determining whether a communication is marketing, telemarketing, informational, transactional, servicing, authentication-related, or otherwise regulated;
- configuring campaigns, prompts, scripts, disclosures, operating hours, transfer logic, routing, suppression lists, knowledge sources, and automated workflows;
- reviewing and approving communications and AI-generated output;
- supervising Customer's employees, contractors, affiliates, agencies, lead providers, vendors, and downstream users;
- responding to complaints, access requests, deletion requests, opt-outs, do-not-call requests, disputes, and regulatory inquiries;
- maintaining appropriate privacy notices, terms, disclosures, and consent language; and
- ensuring that Customer's products, services, representations, offers, and business practices are lawful and not deceptive.
Customer may not represent that TextConvo has reviewed, approved, certified, endorsed, or determined the legality of Customer's campaign, content, consent process, business model, or use of the Services unless TextConvo expressly authorizes that representation in writing.
4. Authorization and Consent
Customer may communicate with a recipient through the Services only when Customer has a valid legal basis and all consent, permission, or other authorization required for that particular communication.
Customer must independently evaluate authorization based on:
- the recipient;
- the telephone number, email address, account, or communication endpoint;
- the identity of the sender or caller;
- the communication channel;
- the use of automation, artificial intelligence, prerecorded content, an artificial voice, or an automatic telephone dialing system;
- whether the communication is marketing, telemarketing, informational, transactional, or otherwise regulated;
- the products, services, brands, or entities promoted;
- the purpose and frequency of the communications;
- the jurisdiction in which the sender and recipient are located; and
- all other facts relevant under Applicable Requirements.
Permission to communicate through one channel does not automatically authorize communication through another channel. Permission for one purpose, seller, brand, product, service, affiliate, campaign, or frequency does not automatically authorize a materially different use. Customer may not:
- rely on vague, misleading, hidden, preselected, bundled, coerced, or deceptively obtained consent;
- materially expand the scope of consent after it is obtained;
- use consent obtained for another company, seller, brand, purpose, or channel unless the consent lawfully and clearly covers Customer's use;
- misrepresent the source, scope, age, language, or validity of consent;
- alter or fabricate consent records;
- use personal information after receiving notice that the information was obtained unlawfully; or
- treat an existing business relationship as authorization where additional consent is required.
5. Consent and Compliance Records
Customer must create, maintain, and preserve complete and verifiable records sufficient to demonstrate compliance with Applicable Requirements. Records should include, as applicable:
- the recipient's telephone number, email address, or other identifier;
- the date and time consent or authorization was obtained;
- the identity of the person or entity obtaining consent;
- the source, method, context, and purpose of consent;
- the exact disclosure and consent language presented;
- the webpage, form, advertisement, application, keyword, recording, or other mechanism used;
- screenshots, form versions, URLs, IP addresses, timestamps, and audit logs;
- the identity of each seller, caller, sender, brand, or affiliate covered;
- the communication channels, technologies, purposes, and frequency covered;
- call scripts, email templates, message templates, prompts, recordings, and campaign configurations;
- records of opt-outs, revocations, complaints, reassigned-number checks, suppression actions, and do-not-contact requests;
- campaign registration and sender-verification information; and
- any other documentation required by law, regulation, contract, carrier, provider, or TextConvo.
Customer must retain records for the period required by Applicable Requirements and, at minimum, for as long as needed to substantiate the legality of communications sent through the Services. Customer must provide requested records to TextConvo promptly. Unless TextConvo specifies a shorter period based on urgency, Customer must respond to a compliance request within two business days. Failure to provide sufficient records may result in blocking, restriction, suspension, or termination.
6. Contact Lists and Lead Sources
Customer may use only contact information that Customer lawfully obtained and is legally authorized to use. Customer may not use:
- scraped or harvested telephone numbers, email addresses, or account identifiers;
- lists generated through dictionary attacks, sequential-number generation, or random-address generation;
- unlawfully purchased, rented, leased, borrowed, or transferred contact lists;
- third-party leads lacking verifiable, legally sufficient permission;
- outdated or recycled consent that no longer reasonably supports the communication;
- data obtained through fraud, deception, malware, credential compromise, or unauthorized access;
- contact information associated with minors unless legally permitted and appropriately authorized;
- contact information subject to a suppression or do-not-contact request; or
- data that Customer knows or reasonably should know is inaccurate, reassigned, unlawfully obtained, or not authorized for the intended use.
Customer is responsible for conducting reasonable due diligence on lead generators, list providers, publishers, affiliates, agencies, brokers, and other sources of contact information. The fact that a lead provider supplies a consent certificate, transaction identifier, timestamp, or other record does not relieve Customer of responsibility for evaluating whether the consent is genuine, complete, applicable, and legally sufficient.
7. Opt-Outs, Revocation, and Suppression
Recipients must be able to revoke consent or request that communications stop through any method required by Applicable Requirements. Customer must:
- honor valid opt-out, unsubscribe, revocation, and do-not-contact requests promptly and within any legally required time;
- recognize reasonable variations of opt-out language, not solely exact keywords;
- honor oral do-not-call and revocation requests made during voice calls;
- maintain accurate internal suppression and do-not-contact lists;
- ensure opt-out mechanisms are clear, conspicuous, accessible, functional, and not misleading;
- prevent additional communications after an opt-out, except for a legally permitted confirmation or other communication expressly authorized by law;
- not charge a fee or impose unreasonable steps as a condition of honoring an opt-out;
- not require a recipient to provide unnecessary personal information to opt out;
- not use an AI agent, representative, or automated workflow to argue with, obstruct, delay, or pressure a recipient after a clear opt-out request;
- propagate revocations and suppression instructions across campaigns, systems, vendors, channels, brands, and business units when required by Applicable Requirements;
- preserve records of each request and the action taken; and
- obtain new legally sufficient consent before resuming communications where new consent is permitted.
For text messaging, Customer must support all opt-out terms required by law, carriers, messaging providers, or TextConvo. These may include terms such as STOP, END, CANCEL, UNSUBSCRIBE, REVOKE, OPT OUT, and QUIT, together with reasonable natural-language equivalents. For commercial email, Customer must provide a clear and functioning unsubscribe method and comply with all requirements governing the availability and processing of that mechanism. For voice calls, Customer must promptly terminate or appropriately conclude the call after a clear do-not-call request and ensure that the number is added to all legally applicable suppression lists.
8. Sender and Caller Identification
Communications must clearly and accurately identify the person or business responsible for the communication whenever required by Applicable Requirements.
Customer may not:
- conceal or misrepresent the identity of a sender, caller, seller, advertiser, or business;
- use a false, misleading, or unauthorized caller ID, telephone number, email address, display name, domain, subdomain, Reply-To address, routing field, brand, logo, or account;
- spoof or manipulate caller identification or email transmission information;
- falsely imply affiliation with or endorsement by another person, company, regulator, government agency, financial institution, healthcare provider, employer, insurer, utility, nonprofit, or other organization;
- falsely claim that a communication is urgent, legally required, government-authorized, security-related, or connected to an existing account;
- impersonate a real person through text, email, AI-generated content, synthetic media, or voice cloning without valid authorization; or
- use a sender identity, telephone number, domain, voice, likeness, or trademark that Customer does not own or have authority to use.
Where required, Customer must promptly disclose:
- the identity of the caller or sender;
- the identity of the business on whose behalf the communication is made;
- the commercial or telemarketing purpose;
- the nature of the goods, services, or request;
- that an automated, artificial, prerecorded, or AI-generated system is being used; and
- any other information required by Applicable Requirements.
9. SMS, MMS, and RCS
Customer's use of SMS, MMS, and RCS must comply with Applicable Requirements and all carrier, messaging-provider, registration, campaign, and sender-verification requirements.
Customer must:
- use accurate and approved campaign-registration information;
- send only traffic consistent with the registered use case;
- use approved telephone numbers, short codes, toll-free numbers, sender IDs, and brand identities;
- provide all legally and contractually required disclosures during opt-in;
- maintain required HELP and opt-out functionality;
- honor message-frequency disclosures;
- identify the sender as required;
- avoid misleading, excessively abbreviated, or obscured disclosures;
- maintain accurate campaign and consent records;
- comply with carrier throughput, content, formatting, and traffic-quality rules; and
- prevent prohibited content from being transmitted through shortened URLs, images, attachments, redirects, or linked landing pages.
Customer may not use shared, unregistered, improperly registered, or unauthorized sender identities to evade registration requirements, filtering, blocking, throughput restrictions, complaint controls, or carrier enforcement.
10. WhatsApp and Third-Party Messaging Channels
Customer's use of WhatsApp or another third-party messaging channel must comply with:
- this AUP;
- Applicable Requirements;
- the third party's terms, commerce policies, business messaging policies, template requirements, consent requirements, and technical rules; and
- any geographic, content, timing, or account restrictions imposed by the third party.
Customer may not use a third-party messaging channel to send communications that would be prohibited through another channel or to circumvent a restriction imposed by TextConvo, a carrier, a mailbox provider, or another service provider.
TextConvo does not control the approval, rejection, filtering, suspension, classification, delivery, or availability decisions of third-party platforms.
11. Email
Customer must comply with all laws and provider requirements applicable to commercial, transactional, and relationship email.
Customer may not:
- use false or misleading From, To, Reply-To, domain, display-name, or routing information;
- use deceptive, misleading, or materially inaccurate subject lines or preview text;
- conceal the identity of the person or business initiating the email;
- omit a valid physical postal address when required;
- omit required advertising or promotional disclosures;
- send commercial email without a clear and conspicuous unsubscribe mechanism;
- use an unsubscribe mechanism that is hidden, misleading, defective, unreasonably complicated, conditioned on payment, or dependent on unnecessary personal information;
- continue sending commercial email after a valid opt-out request;
- sell, rent, transfer, or use an email address contrary to an opt-out request, except as legally permitted to support suppression;
- harvest email addresses, conduct dictionary attacks, perform list bombing or mail bombing, or generate addresses algorithmically;
- use open relays, open proxies, compromised accounts, or unauthorized systems;
- manipulate email authentication, engagement, headers, domains, IP addresses, reputation signals, or complaint metrics;
- evade spam filters, blocklists, sending limits, mailbox-provider restrictions, or domain-reputation controls;
- use a domain, subdomain, mailbox, display name, or sender identity Customer does not control or have authority to use;
- send malware, malicious attachments, deceptive links, credential-harvesting content, or phishing communications; or
- classify a commercial email as transactional or relationship email to evade marketing requirements.
Customer must properly configure and maintain applicable authentication and security controls, including SPF, DKIM, DMARC, domain access, account credentials, and suppression systems. Customer is responsible for email sent by TextConvo, Customer's vendors, agencies, affiliates, contractors, or other persons on Customer's behalf.
12. Voice Calls and AI Voice
Customer may use TextConvo's voice functionality only when Customer has all legally required authority to place the call and use the applicable technology. This requirement applies to:
- live-agent calls;
- automated calls;
- predictive or power-dialed calls;
- artificial or prerecorded voice calls;
- AI-generated or synthetic voice calls;
- voice agents that conduct interactive conversations;
- voicemail drops;
- answering-machine messages;
- outbound call sequences; and
- calls that transfer or connect recipients to a person, agent, business, or third party.
Customer must:
- obtain the level and form of consent required for each call;
- account for the use of an artificial, prerecorded, synthetic, or AI-generated voice;
- comply with national and state Do Not Call requirements;
- maintain applicable entity-specific do-not-call lists;
- comply with calling-hour and time-zone restrictions;
- provide prompt and accurate caller disclosures;
- transmit accurate and authorized caller identification;
- provide legally required automated opt-out functionality;
- promptly honor oral and automated opt-out requests;
- comply with abandoned-call, call-duration, ring-time, dead-air, call-attempt, and disconnect requirements;
- comply with applicable telemarketer-registration, bonding, licensing, script, and recordkeeping requirements;
- maintain required copies of scripts, recordings, call-detail records, consent records, and campaign materials;
- ensure that transfer destinations and downstream agents comply with Applicable Requirements;
- provide a reasonable means to reach a human representative when legally required or appropriate for the use case; and
- implement controls to prevent the AI agent from making unauthorized representations, transactions, decisions, or commitments.
Customer may not use AI voice or automated calls to:
- impersonate another person without documented authorization;
- mislead a recipient into believing the recipient is speaking with a specific real person;
- disguise the artificial, synthetic, prerecorded, or automated nature of a call where disclosure is required;
- contact emergency lines, public-safety answering points, healthcare emergency lines, or similar protected numbers except where expressly authorized and lawful;
- place calls to numbers on applicable suppression or do-not-call lists;
- deliver unlawful voicemail drops or ringless voicemail;
- create excessive abandoned calls, dead air, hang-ups, repeated attempts, or harassment;
- make false claims regarding an account, debt, application, approval, eligibility, emergency, deadline, government action, legal obligation, prize, or financial consequence;
- obtain payment information, authentication credentials, or sensitive information through deception;
- pressure vulnerable individuals or exploit confusion caused by an AI-generated voice; or
- evade call labeling, blocking, traceback, caller authentication, or provider enforcement.
13. Call Recording, Transcription, and Monitoring
Customer must comply with all laws governing call recording, interception, monitoring, transcription, storage, analysis, disclosure, and use. Customer must determine whether notice, one-party consent, all-party consent, employee notice, union consultation, or another form of authorization is required. Where required, Customer must provide a clear disclosure and obtain legally valid consent before recording, monitoring, or transcribing a communication. Customer may not:
- record, monitor, or transcribe a communication unlawfully;
- obscure or omit a required recording disclosure;
- continue recording after consent has been lawfully withdrawn where withdrawal must be honored;
- use recordings or transcripts for an undisclosed or incompatible purpose;
- disclose recordings or transcripts to unauthorized persons;
- retain recordings or transcripts longer than legally permitted or reasonably necessary;
- use recordings to create a voice clone or biometric profile without specific authority;
- record authentication credentials, payment-card data, government identifiers, or other restricted information unless an approved secure process is used; or
- use call recordings, transcripts, or analytics to unlawfully discriminate, profile, manipulate, or make regulated decisions.
Customer is responsible for configuring pause, redaction, masking, retention, access-control, and deletion functions appropriate to Customer's use case.
14. Voice Cloning, Digital Replicas, and Synthetic Media
Customer may not create, upload, generate, or use a digital replica, synthetic voice, cloned voice, likeness, image, or other simulation of an identifiable person unless Customer has documented authorization sufficient for the intended use.
Customer must not use synthetic media to:
- impersonate a government official, political candidate, executive, employee, celebrity, customer, family member, healthcare provider, financial institution, or other identifiable person;
- commit fraud, deceive a recipient, solicit funds, obtain credentials, influence voting, or misrepresent identity;
- falsely imply endorsement, approval, affiliation, or sponsorship;
- create defamatory, exploitative, abusive, or nonconsensual content;
- circumvent identity-verification or authentication controls; or
- interfere with legal, electoral, financial, employment, healthcare, or public-safety processes.
TextConvo may require proof of authorization before enabling or continuing any voice-cloning or digital-replica use case.
15. Artificial Intelligence and Automated Systems
Customer is responsible for all AI-generated output, automated actions, and agentic workflows initiated through Customer's account.
Customer must:
- conduct appropriate testing before deployment;
- define and enforce the permitted scope of the AI system;
- provide accurate, lawful, and appropriately licensed prompts, content, data, and knowledge sources;
- review AI-generated content for accuracy, legality, safety, and suitability;
- implement human review, escalation, override, and shutdown controls appropriate to the risk;
- prevent hallucinations, fabricated claims, unauthorized offers, and unsupported representations from reaching recipients;
- monitor performance, complaints, opt-outs, failures, bias, and anomalous behavior;
- promptly correct or disable unsafe or noncompliant workflows;
- protect personal, confidential, proprietary, and sensitive information submitted to AI systems; and
- disclose the use of artificial intelligence where required by law or where failure to disclose would be deceptive.
Customer may not use the Services or any AI functionality to:
- generate or distribute unlawful, fraudulent, deceptive, defamatory, threatening, harassing, or abusive content;
- falsely present an AI system as a human or as a particular person where doing so is unlawful or misleading;
- create fabricated testimonials, reviews, endorsements, credentials, qualifications, approvals, prices, terms, or material facts;
- make final decisions regarding credit, lending, insurance, employment, housing, healthcare, education, legal rights, public benefits, or another high-impact matter without all legally required controls and human involvement;
- provide individualized legal, medical, investment, tax, insurance, or financial advice without appropriate authorization, disclosures, supervision, and safeguards;
- manipulate individuals through coercion, threats, manufactured urgency, emotional exploitation, or deceptive personalization;
- target individuals based on protected characteristics in violation of law;
- infer, generate, or exploit sensitive personal characteristics unlawfully;
- suppress or override opt-outs, objections, safety instructions, or escalation requests;
- facilitate surveillance, stalking, credential theft, identity theft, malware, phishing, or unauthorized access;
- generate harmful instructions or content intended to facilitate illegal conduct;
- make emergency-service, public-safety, or life-critical decisions; or
- train, fine-tune, or operate a model using data Customer is not authorized to use.
16. Privacy, Personal Information, and Sensitive Data
Customer must collect, use, disclose, store, and delete personal information through the Services only as permitted by Applicable Requirements and Customer's agreements and privacy notices.
Customer must not submit or process sensitive information through the Services unless:
- the use is supported by a lawful and disclosed purpose;
- Customer has all required consent or authorization;
- the applicable TextConvo service is designed and approved for that information;
- appropriate contractual and security safeguards are in place; and
- the use complies with all Applicable Requirements.
Sensitive information may include:
- Social Security numbers and government-issued identifiers;
- financial-account and payment-card information;
- authentication credentials and security codes;
- health, medical, genetic, and biometric information;
- precise geolocation;
- information concerning children;
- information concerning race, ethnicity, religion, sexual orientation, citizenship, immigration status, political beliefs, or union membership;
- protected educational or employment records;
- criminal-history information;
- insurance, credit, lending, and financial-eligibility information; and
- other information classified as sensitive or regulated under Applicable Requirements.
Customer may not use the Services to unlawfully sell, share, profile, enrich, reidentify, or disclose personal information.
17. Prohibited Conduct and Content
Customer may not use the Services to create, transmit, facilitate, promote, advertise, sell, solicit, or support:
- illegal activity, products, or services;
- fraud, deception, scams, identity theft, or misrepresentation;
- phishing, smishing, vishing, credential harvesting, malware, ransomware, spyware, or malicious code;
- unlawful financial schemes, investment scams, pyramid schemes, or deceptive earnings opportunities;
- predatory lending, unlawful payday lending, unlawful credit repair, or deceptive debt-relief services;
- unlawful debt collection, threats of arrest, false legal claims, or abusive collection practices;
- unlawful controlled substances, illegal drugs, or drug paraphernalia;
- unlawful firearms, weapons, explosives, or related transactions;
- illegal gambling, unlawful sports betting, or unlawful sweepstakes;
- explicit sexual services, nonconsensual sexual content, sexual exploitation, or content involving minors;
- human trafficking, exploitation, or facilitation of prostitution;
- hate speech, unlawful discrimination, threats, violence, harassment, stalking, or intimidation;
- election interference, voter suppression, false voting instructions, or deceptive political impersonation;
- counterfeit goods, stolen goods, piracy, or infringement of intellectual-property rights;
- unauthorized pharmaceutical sales or deceptive healthcare products;
- fake charities or deceptive charitable solicitations;
- unlawful surveillance, tracking, monitoring, or data brokerage;
- fabricated emergencies, account alerts, security warnings, government notices, or legal demands;
- false or misleading claims about products, services, pricing, performance, availability, affiliation, licensing, or approval; or
- any content or conduct that TextConvo reasonably determines is abusive, dangerous, deceptive, harmful, or likely to expose TextConvo or another party to material risk.
18. Restricted and Regulated Use Cases
The following activities may require TextConvo's prior written approval, enhanced diligence, additional contractual terms, technical restrictions, or proof of compliance:
- consumer lending, mortgage lending, credit, credit repair, and debt-relief services;
- debt collection and account recovery;
- banking, securities, cryptocurrency, investments, and other financial services;
- insurance marketing, quoting, enrollment, and servicing;
- healthcare, prescription drugs, medical services, and protected health information;
- employment, recruiting, background screening, and workforce communications;
- housing, real estate, tenant screening, and property-related solicitations;
- legal services and legal claims;
- political, campaign, advocacy, and election-related communications;
- charitable and nonprofit solicitations;
- education, student recruitment, and student-financial-aid services;
- alcohol, tobacco, nicotine, cannabis, gambling, and other age-restricted products or services;
- sweepstakes, contests, prize promotions, and negative-option offers;
- biometric identification, voiceprints, and facial or voice recognition;
- communications directed to or involving minors;
- emergency, healthcare, utility, government, and public-safety communications;
- collection of payment information or execution of financial transactions;
- voice cloning and digital replicas;
- high-volume outbound AI voice campaigns; and
- other use cases identified by TextConvo as presenting heightened legal, consumer-protection, security, network, or reputational risk.
Approval by TextConvo does not constitute legal advice or relieve Customer of responsibility for compliance. TextConvo may revoke or modify approval at any time based on changes in law, provider requirements, complaint rates, risk, use-case changes, or Customer conduct.
19. Age-Restricted Products and Services
Customer may not market or promote age-restricted products or services unless the activity is lawful in every applicable jurisdiction and Customer has implemented appropriate age-verification, audience, consent, content, timing, and geographic controls.
Customer may not direct age-restricted content to a person who is not legally eligible to receive, purchase, use, or participate in the applicable product or service.
TextConvo may prohibit or restrict age-restricted content even where the underlying product or service is lawful.
20. Message and Call Frequency
Customer must maintain reasonable communication frequency consistent with:
- recipient expectations;
- the consent obtained;
- the disclosed campaign frequency;
- the nature and urgency of the communication;
- Applicable Requirements;
- industry norms; and
- carrier, mailbox-provider, telephone-provider, and TextConvo requirements.
Customer may not:
- repeatedly contact recipients who do not respond;
- use excessive call attempts, messages, or emails;
- spread substantially similar communications across multiple numbers, domains, accounts, brands, or channels to evade frequency limits;
- restart a sequence after an opt-out or complaint;
- coordinate channels in a manner that creates harassment or unreasonable pressure;
- send communications at prohibited or unreasonable hours; or
- generate abnormal complaint, blocking, unsubscribe, bounce, spam-report, or opt-out rates.
TextConvo may impose campaign-specific or account-specific volume, frequency, throughput, concurrency, and attempt limits.
21. Traffic Manipulation and Communications Abuse
Customer may not manipulate, inflate, fabricate, or interfere with communications traffic, engagement, deliverability, reputation, billing, or provider systems.
Prohibited activity includes:
- SMS pumping or traffic pumping;
- artificial traffic generation;
- artificially generated calls, texts, opens, clicks, replies, or conversions;
- traffic designed to generate fees, credits, rebates, commissions, or carrier charges;
- call looping, auto-answer manipulation, or artificial call duration;
- list bombing, mail bombing, or coordinated spam complaints;
- rotating telephone numbers, domains, subdomains, IP addresses, accounts, brands, or identities to evade enforcement;
- snowshoe spam or distributed low-volume abuse;
- manipulating caller reputation, attestation, authentication, call labeling, or traceback systems;
- evading filtering, blocking, throttling, registration, or complaint controls;
- unauthorized reselling, sublicensing, traffic aggregation, or traffic brokering; and
- using the Services primarily to test whether contact information is valid.
22. Security and Platform Abuse
Customer may not:
- access or attempt to access an account, system, network, data set, or resource without authorization;
- probe, scan, test, exploit, or circumvent vulnerabilities or security controls without TextConvo's prior written authorization;
- introduce malware, malicious code, destructive payloads, or harmful files;
- interfere with the security, availability, integrity, performance, or operation of the Services;
- bypass authentication, authorization, access-control, rate-limit, usage, billing, or technical restrictions;
- reverse engineer, decompile, disassemble, scrape, or copy the Services except as expressly permitted by law or the Agreement;
- share account credentials in an unauthorized manner;
- use compromised credentials, stolen payment methods, false identities, or fraudulent account information;
- conceal the origin of traffic or impersonate another account;
- use the Services to conduct denial-of-service attacks, credential stuffing, enumeration, or automated abuse;
- access data belonging to another customer;
- interfere with an investigation, audit, traceback, or security process;
- test production communications against recipients without authorization;
- use the Services to benchmark or develop a competing product in violation of the Agreement; or
- remove or circumvent technical safeguards, disclosures, or compliance controls.
Customer must implement reasonable administrative, technical, and physical safeguards appropriate to Customer's use of the Services.
23. APIs, Integrations, and Automated Workflows
Customer must use TextConvo APIs, integrations, webhooks, and automation tools in accordance with documentation, access permissions, technical limits, and the Agreement. Customer is responsible for:
- all activity initiated through Customer's credentials, tokens, integrations, and connected systems;
- securing API keys and credentials;
- limiting access according to least-privilege principles;
- validating data and instructions received from connected systems;
- preventing duplicate, runaway, recursive, or unauthorized workflows;
- monitoring integration failures and unexpected behavior;
- ensuring that connected systems propagate consent, suppression, deletion, and correction instructions;
- terminating access for former personnel and compromised systems; and
- promptly rotating exposed or compromised credentials.
Customer may not use integrations to bypass a restriction that applies directly to the Services.
24. Carrier, Provider, and Third-Party Requirements
Communications carriers, telephone providers, messaging providers, mailbox providers, domain registries, application platforms, and other third parties may impose their own requirements and may block, filter, label, throttle, reject, suspend, or terminate communications or accounts. Customer must comply with all applicable third-party requirements. TextConvo does not control and is not responsible for:
- message, call, or email delivery;
- filtering, blocking, call labeling, spam classification, or carrier treatment;
- sender, campaign, number, domain, or template approval;
- delays, outages, routing, or provider availability;
- changes to third-party policies;
- third-party termination or suspension decisions; or
- the availability of a telephone number, email domain, sender identity, integration, or communication channel.
Customer may not use the Services to evade or circumvent a third party's lawful restriction or enforcement action.
25. Monitoring, Auditing, and Quality Controls
To protect the Services and support compliance, TextConvo may, subject to Applicable Requirements and the Agreement:
- monitor account activity, traffic patterns, complaints, opt-outs, error rates, and deliverability;
- review communications, templates, prompts, scripts, recordings, transcripts, campaign settings, and AI output;
- review consent records, lead sources, registration information, and suppression practices;
- use automated systems to detect fraud, abuse, security threats, prohibited content, and anomalous activity;
- request compliance certifications, legal opinions, policies, training records, or other documentation;
- conduct audits or require an independent audit;
- test opt-out, disclosure, suppression, and escalation functions;
- require Customer to modify a campaign, use case, workflow, prompt, model, script, or configuration;
- require additional registration, verification, identity validation, security, or consent controls; and
- share relevant information with providers, carriers, regulators, law enforcement, industry traceback organizations, or affected parties as permitted or required by law.
TextConvo's monitoring does not transfer responsibility for Customer's activities to TextConvo and does not create an obligation to detect every violation.
26. Investigations and Cooperation
TextConvo may investigate suspected or alleged violations of this AUP, the Agreement, Applicable Requirements, provider policies, or third-party rights. Customer must cooperate fully and promptly with an investigation. Cooperation may include:
- preserving records and evidence;
- providing consent records, contact sources, campaign materials, scripts, prompts, recordings, transcripts, call-detail records, email data, and system logs;
- identifying relevant employees, contractors, vendors, lead providers, and downstream recipients;
- suspending or modifying affected activity;
- responding to complaints and regulatory requests;
- providing written explanations or certifications;
- implementing remediation; and
- participating in carrier, provider, regulator, law-enforcement, or traceback inquiries.
Customer may not conceal, alter, fabricate, destroy, or delete relevant evidence after becoming aware of a complaint, investigation, anticipated dispute, or legal hold.
Failure to cooperate may result in immediate restriction, suspension, or termination.
27. Enforcement
TextConvo may take any action it reasonably determines necessary to protect recipients, customers, providers, networks, the public, or TextConvo.
Enforcement actions may include:
- issuing a warning or remediation requirement;
- requiring additional consent, verification, or compliance documentation;
- rejecting or disabling a campaign, prompt, script, workflow, sender, number, domain, integration, or use case;
- blocking or quarantining messages, emails, calls, content, attachments, URLs, destinations, or traffic;
- limiting call concurrency, attempts, throughput, volume, features, destinations, or channels;
- applying spending limits, reserves, or additional fees;
- suspending a campaign, user, integration, feature, channel, or account;
- removing content or disabling access to data;
- requiring Customer to notify affected persons;
- terminating the Agreement or access to the Services;
- reporting activity to carriers, providers, regulators, law enforcement, industry organizations, or affected parties;
- preserving and disclosing records as permitted or required by law; and
- pursuing any other legal or equitable remedy.
TextConvo may act without prior notice when TextConvo reasonably believes immediate action is necessary to prevent or mitigate harm, legal exposure, fraud, abuse, security risk, provider action, network disruption, consumer injury, or reputational damage.
TextConvo is not obligated to restore suspended traffic, campaigns, resources, or accounts.
28. Costs, Penalties, and Responsibility for Violations
Customer is responsible for all activity conducted through Customer's account and all consequences arising from Customer's violation of this AUP, the Agreement, Applicable Requirements, provider rules, or third-party rights.
To the extent permitted by the Agreement and Applicable Requirements, Customer is responsible for:
- carrier, provider, registry, platform, regulatory, and governmental penalties;
- fines, assessments, chargebacks, credits, and pass-through costs;
- investigation, audit, traceback, response, and remediation expenses;
- costs associated with complaints, claims, disputes, subpoenas, and regulatory inquiries;
- costs arising from blocked, rejected, suspended, or terminated traffic or resources; and
- other losses caused by Customer's conduct.
Any indemnification obligations are governed by the applicable Agreement. Nothing in this AUP limits any rights or remedies available to TextConvo under the Agreement or Applicable Requirements.
29. No Circumvention
Customer may not use another provider, account, telephone number, domain, integration, affiliate, contractor, or technical method to continue activity that TextConvo has blocked, restricted, suspended, rejected, or terminated.
Attempts to circumvent enforcement constitute a separate material violation of this AUP.
30. Policy Updates
TextConvo may update this AUP periodically to account for changes in:
- the Services;
- Applicable Requirements;
- communications technologies;
- carrier, provider, platform, or industry rules;
- security, fraud, abuse, and consumer-protection risks; or
- TextConvo's operational requirements.
The updated AUP will be posted on TextConvo's website with a revised "Last Updated" date.
Unless a different effective date is stated, changes become effective when posted. Continued access to or use of the Services after an updated AUP becomes effective constitutes acceptance of the updated AUP.
31. Reporting Abuse and Contact Information
Suspected violations, security issues, or abusive activity should be reported to:
Reports should include sufficient information to identify the communication, sender, caller, campaign, date, time, telephone number, email address, or other relevant circumstances.
Questions concerning this AUP may also be submitted through TextConvo's Contact Us form.