Last updated: 25 August 2026

Acceptable Use Policy

CollabFlow can send email from your address and runs on shared infrastructure and third-party APIs. These are the rules that keep that safe for you, your recipients, and everyone else using the Service.

01Scope

This Acceptable Use Policy applies to everyone who uses CollabFlow. It forms part of our Terms & Conditions, and breaching it is a material breach of that agreement.

The rules exist for a practical reason. CollabFlow can send email from your address and holds message content on your behalf, and it runs on infrastructure and third-party APIs shared by every user. Misuse by one account can get inboxes blocked, get our API access revoked by Google, and degrade the Service for everyone. We enforce this policy accordingly.

This list is illustrative, not exhaustive. If something is obviously abusive but not listed here, it is still prohibited.

02Email and Messaging

CollabFlow sends replies from your own connected mailbox, in threads that your keywords matched. It is a tool for responding to inbound collaboration enquiries. It is not a bulk email, cold outreach, or marketing platform, and must not be used as one.

You must not use the Service to:

  • send unsolicited bulk or commercial email, cold outreach campaigns, chain messages, or any communication that would be spam under CAN-SPAM, the EU ePrivacy Directive, PECR, or equivalent law where you or your recipient are located;
  • send to purchased, scraped, harvested, or otherwise non-consenting recipient lists;
  • forge headers, spoof a sender, or otherwise misrepresent who a message is from or on whose behalf it is sent;
  • ignore an opt-out, unsubscribe request, or a recipient's clear request to stop contacting them;
  • configure keywords or automated replies designed to trigger indiscriminately in order to reach a high volume of recipients;
  • send phishing, fraudulent, deceptive, or malware-bearing messages, or messages that impersonate a brand, agency, or person;
  • connect a mailbox you do not own or control, or one belonging to an employer or client without their documented permission.

You are responsible for the messages sent from your account, including those sent automatically by a feature you enabled.

03Content and Conduct

You must not use the Service to store, process, transmit, or generate content that:

  • is unlawful, or that promotes or facilitates unlawful activity;
  • infringes or misappropriates anyone's copyright, trademark, trade secret, publicity, or privacy rights;
  • is defamatory, harassing, abusive, threatening, or that incites violence or hatred against a person or group;
  • is sexually explicit, or that sexually exploits or endangers a minor;
  • contains malware, ransomware, or any code designed to disrupt, damage, or gain unauthorised access to a system;
  • is deliberately deceptive, including AI-generated content presented as verified fact or as the words of someone who did not write it;
  • you have no right to disclose, including another party's confidential information or personal data you have no lawful basis to process.

You must also not use the Service to violate the terms of a connected third-party service, including the Google Terms of Service, the Google API Services User Data Policy, or the Notion Terms of Service.

04Data the Service Is Not Built to Hold

CollabFlow is designed for creator pipeline and payment tracking. It has not been built, assessed, or certified for regulated categories of data, and we do not offer the contracts those categories require. Do not put the following into the Service:

  • Payment card data — full card numbers, CVV or security codes, or magnetic stripe data. We are not a PCI DSS cardholder data environment. Record amounts and payment status, not card details.
  • Health information subject to HIPAA or comparable law. We do not sign business associate agreements.
  • Government identifiers such as national identity numbers, Aadhaar, Social Security numbers, passport numbers, or driving licence numbers.
  • Bank credentials, full account and routing numbers, or passwords and API keys for other services.
  • Special category personal data under GDPR Article 9 — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, sex life, or sexual orientation — unless it is unavoidably present in an email you received and you have a lawful basis for it.
  • Data about children, or any data subject to sector-specific regimes such as FERPA, GLBA, or classified or export-controlled information.

If you put this data in anyway, you do so at your own risk and you are responsible for the consequences.

05Technical and Platform Restrictions

You must not:

  • probe, scan, or test the vulnerability of the Service, or breach or circumvent its authentication, authorisation, or security measures — except through a good-faith security disclosure to us, which we welcome;
  • access the Service by any automated means other than the interfaces we provide, or scrape or harvest data from it;
  • circumvent, disable, or artificially inflate plan limits, quotas, rate limits, or usage metering, including by creating multiple accounts to obtain additional free-plan allowances;
  • reverse engineer, decompile, or disassemble the Service, or attempt to derive its source code;
  • interfere with the Service or its infrastructure, including through denial-of-service attacks, excessive load, or overwhelming the third-party APIs we depend on;
  • introduce malware, or use the Service as a staging point for an attack on another system;
  • frame, mirror, or resell the Service, or use it to build or benchmark a competing product.

06Account Restrictions

  • Do not share sign-in credentials, or let people who are not covered by your plan use your account.
  • Do not sell, rent, sublicense, or transfer your account or your access to the Service.
  • Do not create an account using false information, on behalf of someone who has been suspended, or to evade a suspension.
  • Do not use the Service if you are under 18.

07How We Enforce This

If we reasonably believe you have breached this policy, we may take any of the following steps, choosing what is proportionate to the seriousness and the risk:

  • contact you and ask you to fix the problem;
  • throttle or restrict a feature, in particular outbound sending;
  • remove or disable access to specific content;
  • suspend your account, in whole or in part;
  • terminate your account and this agreement;
  • report the matter to law enforcement or to an affected third-party provider.

Where there is a risk of imminent harm — to another person, to our infrastructure, to our standing with a provider we depend on, or to the deliverability of other users' mail — we may act immediately and without notice. Otherwise we will notify you first and, where the breach can be fixed, give you a reasonable opportunity to fix it.

Suspension or termination for a breach of this policy does not entitle you to a refund. If you believe we acted in error, email us and we will review the decision.

08Reporting Abuse or a Security Issue

If you have received an abusive message sent through CollabFlow, believe an account is breaching this policy, or have found a security vulnerability, email support@getcollabflow.com. Include the full message headers or the steps to reproduce where you can — it makes the investigation much faster.

We investigate every report. We will not take legal action against a security researcher who reports a vulnerability in good faith, gives us a reasonable chance to fix it before disclosure, and does not access, modify, or delete other people's data in the process.

Contact

Report abuse, a security issue, or appeal an enforcement decision:

support@getcollabflow.com

Early access opening soon

Priority invites first