Acceptable Use Policy
This Acceptable Use Policy (the "AUP") describes prohibited uses of the Kontracks platform (the "Service") and the conduct standards every Customer and Authorized User must follow. It supplements, and is incorporated into, the Kontracks Terms of Service. If Customer uses SMS through the Service, the SMS Acceptable Use Policy applies in addition to this AUP.
Kontracks may modify this AUP at any time by posting an updated version at this URL. Material changes will be notified to account administrators by email or in-product banner. Violations may result in throttling, suspension, termination, or legal action.
1. Prohibited content
You may not upload, post, transmit, store, or share through the Service any content that:
- Is unlawful, defamatory, fraudulent, deceptive, threatening, harassing, hateful, or invasive of another's privacy or publicity rights;
- Constitutes or facilitates child sexual abuse material, non-consensual intimate imagery, or content that exploits minors in any way;
- Infringes any copyright, trademark, trade secret, patent, or other intellectual property right;
- Contains personally identifying information of a third party that you do not have lawful authority to process;
- Contains health information regulated by HIPAA, except where Kontracks has executed a Business Associate Agreement with Customer (Kontracks is not a HIPAA-covered entity or business associate by default);
- Contains payment card account numbers, full social security numbers, government-issued identification numbers, biometric identifiers, or precise geolocation data, except as expressly supported by Service features (e.g., addresses for service delivery);
- Contains controlled-substance, firearms, gambling, adult-services, or other content prohibited by U.S. wireless carriers from being transmitted via 10DLC SMS;
- Contains material that violates the terms of any Third-Party Service the content is routed through (e.g., Stripe's restricted businesses list, Telnyx's prohibited content list, Intuit's QuickBooks acceptable use rules).
2. Prohibited uses
You may not use the Service to:
- Send unsolicited communications, "spam", or any message that violates the TCPA, CAN-SPAM, CASL, the EU/UK e-privacy rules, or any U.S. state telemarketing law;
- Engage in any activity that would constitute or facilitate identity theft, phishing, smishing, vishing, fraud, money laundering, terrorism financing, or evasion of sanctions;
- Impersonate any person or entity, or falsely state or misrepresent your affiliation with a person or entity;
- Harvest or collect contact information of other users, or scrape any content from the Service;
- Distribute viruses, worms, trojan horses, ransomware, keyloggers, spyware, or any other malicious software, or attempt to disable, overburden, or impair any portion of the Service;
- Probe, scan, or test the vulnerability of the Service or any related system or network without our prior written consent through our security disclosure program at security@kontracks.com;
- Bypass, defeat, or attempt to bypass any technical limitation, rate limit, access control, authentication, or encryption mechanism;
- Use the Service to develop, train, or improve a competing product or service, or any large language model or machine learning model (other than for your own internal business operations on your own Customer Data);
- Sell, rent, lease, sublicense, or otherwise transfer your account, login credentials, API keys, or any portion of the Service to a third party;
- Use the Service to make available to a third party any function of the Service through proxying, white-labeling, or wrapping it as your own service, except as expressly authorized by a separate written agreement with Kontracks;
- Use the Service to operate a service bureau or shared-tenancy environment in which multiple unrelated businesses use a single Kontracks tenant.
3. Communications-specific requirements
If you send communications through the Service (email, SMS, voice, or otherwise), you must:
- Obtain valid consent under all applicable laws and the U.S. wireless carriers' 10DLC requirements before contacting any recipient, and produce that consent on demand within 48 hours of a Kontracks request;
- Honor opt-out / unsubscribe / STOP requests immediately (within five (5) minutes of receipt for SMS, within ten (10) business days for email under CAN-SPAM, immediately upon consent withdrawal under CASL and GDPR);
- Identify yourself accurately as the sender (no spoofed "From" addresses, no misleading display names);
- Avoid sending non-emergency messages during quiet hours (before 8:00 a.m. or after 9:00 p.m. in the recipient's local time, or as further restricted by state law);
- Maintain a working reply path to receive responses, including STOP/HELP for SMS;
- Cooperate promptly with carrier or regulator inquiries.
4. Resource & security obligations
- Do not exceed published API rate limits. We may throttle, queue, or refuse requests that exceed limits to protect platform stability.
- Do not store or cache more Service data on your own systems than necessary to run your business. Do not redistribute Service output as a data product.
- Use strong, unique passwords. Enable multi-factor authentication where available. Deprovision Authorized Users promptly when they leave or change roles.
- Report security vulnerabilities to security@kontracks.com. Do not publicly disclose unpatched vulnerabilities, and do not access or modify data belonging to other Customers.
5. AI feature use
When you use AI features in the Service (the in-app assistant, pricing math, draft email, supplement writer, photo material identification, and others), you remain responsible for the output. AI features are tools that aid your judgment, not a replacement for it. You must review AI-generated content for accuracy before sending it to End Customers, submitting it to insurers, relying on it for pricing or legal decisions, or representing it as final work product. You may not feed an AI feature any content prohibited by Section 1.
6. Reporting violations
If you become aware of conduct that violates this AUP, please report it to abuse@kontracks.com. We investigate every credible report and act on confirmed violations.
7. Enforcement
Kontracks may, at its sole discretion and without prior notice:
- Investigate suspected violations;
- Remove or refuse to display content;
- Throttle, queue, or temporarily restrict access to one or more features;
- Suspend Customer's account in whole or in part;
- Terminate Customer's subscription as set forth in the Terms;
- Cooperate with law enforcement and regulators, and disclose information as required by law or as reasonably necessary to protect Kontracks, other Customers, End Customers, or the public.
For violations that affect carrier-regulated services (SMS), Kontracks may be required by the carriers to suspend service even where Customer disputes the underlying complaint.
8. Contact
Abuse / AUP reports: abuse@kontracks.com.
Security: security@kontracks.com.
Legal: legal@kontracks.com.
KONTRACKS