Acceptable Use Policy
Version 2026-07-15. Applies to everyone using the X-com service and to any content sent through it.
1. Prohibited content
- Unlawful, infringing, defamatory, or fraudulent material.
- Child sexual abuse material (CSAM). Reported to the relevant authority (NCMEC / IWF) without notice and preserved for law enforcement.
- Content that promotes or facilitates terrorism, credible violence, or self-harm.
- Content that harasses, threatens, dehumanises, or targets a person or protected group.
- Sexually explicit content involving real people without their clear, verifiable consent.
- Personal data of others uploaded without a lawful basis (doxxing).
2. Prohibited conduct
- Sending malware, phishing links, or content used to attack any system.
- Probing, scanning, or testing the security of the service without our written permission. Coordinated disclosure is welcomed via security@connectandflow.app.
- Circumventing rate limits, plan limits, quotas, IP blocks, or access controls.
- Automated bulk activity (scraping, mass account creation, credential stuffing) not documented in an API contract.
- Impersonating another person or organisation, including deceptive "from" identities on connected channels.
- Using the service to build a competing product by copying features, UI, or workflows.
3. Regulated data restrictions
Do not upload the following to the service unless a signed order form or DPA explicitly authorises it and enables the corresponding controls:
- Payment card data (PAN, CVV, magnetic stripe / chip). Card capture is delegated to Stripe.
- Protected health information (PHI) under HIPAA or equivalent regimes.
- Government-issued identifiers at scale (SSN, national ID, driving licence, passport).
- Biometric identifiers (fingerprint, face templates, voiceprints).
- Special-category data under GDPR Art. 9 (racial or ethnic origin, religious beliefs, sexual orientation, trade-union membership, health, genetic or biometric data).
During the beta all of the above are prohibited regardless of any agreement (see the Beta programme notice).
4. Bulk messaging and connected channels
- Email: comply with CAN-SPAM, CASL, PECR, and any equivalent laws in the recipient's jurisdiction. Marketing sends must include a working unsubscribe link and honour opt-outs within 10 business days.
- SMS / voice: comply with TCPA, CTIA guidelines, and local do-not-call registries. Obtain express prior consent.
- Slack, Zendesk, Freshdesk, Intercom bridges: respect the underlying provider's terms of service. Suspensions upstream may cause us to suspend the bridge.
5. AI features
When you use AI features, the prompt and any attached content are sent to our model provider(s) listed in the subprocessor list. Do not submit content you are not permitted to disclose to a processor outside your jurisdiction. Do not use AI features to generate the prohibited content in §1.
6. Enforcement
We may take one or more of the following actions in response to a violation, proportionate to the severity and history: warning, content removal, feature disable, account suspension, workspace suspension, account termination, referral to authorities.
We will normally give notice and an opportunity to remedy, but for clear, serious, or ongoing violations (CSAM, active attack, credible threat) we may act immediately and notify afterwards.
7. Reporting abuse
Email abuse@connectandflow.app with a URL or account identifier and a description. For security vulnerabilities in the service itself, use security@connectandflow.app instead.