Reading time
10 sections · approximately 10 minutes. This document is written in plain language to keep our practices transparent. Defined terms have their first meaning carried throughout.
Scope
This Acceptable Use Policy (“AUP”) applies to everyone who uses ChatinFlow, including workspace owners, invited team members, and anyone acting through our API. It forms part of our Terms of Service; where the two differ on a question of permitted use, this policy governs.
ChatinFlow sends messages through platforms we do not own, primarily Meta (Instagram and Messenger). Their policies apply to you as well as to us, and they apply to the account you connect, not just to ours. A breach on your side can get your Instagram or Facebook Page restricted by Meta directly, and repeated breaches across our customer base can cost every ChatinFlow customer access. That is why the rules below are strict and why we enforce them without waiting for a complaint.
Consent is the baseline
You may only message people who have a genuine, recent, and demonstrable relationship with the business sending the message. In practice that means one of the following:
- They messaged the connected account first, and you are replying inside the platform's messaging window.
- They commented on, reacted to, or mentioned content from the connected account, and your reply follows from that interaction.
- They explicitly opted in to receive messages, and you can show when and how.
Purchased, scraped, rented, or otherwise acquired contact lists are never an acceptable basis for messaging, regardless of how the list was described to you when you obtained it.
Opt-out must always work. Every contact who replies STOP, or uses an equivalent unsubscribe path, must stop receiving messages immediately. Attempting to suppress, reset, or route around an opt-out is a serious violation and is grounds for immediate suspension.
Prohibited content
You may not use ChatinFlow to send, solicit, or promote:
- Financial and investment scams: guaranteed returns, “free money”, cash giveaways, wire-transfer requests, recovery scams, or any offer whose appeal is that it pays out with no plausible underlying business.
- Cryptocurrency promotion of the fraudulent kind: airdrops, token pumps, paid “signal” groups, doubling schemes, and unlicensed investment advice. Legitimate, licensed financial businesses may operate here, but the burden of showing that is yours.
- Adult and sexual content, sexual solicitation, and links to adult subscription platforms.
- Phishing and credential harvesting: messages that imitate another brand, platform, or person in order to collect passwords, one-time codes, card numbers, or identity documents.
- Malware and harmful links, including shortened links that conceal a destination violating this policy.
- Regulated goods you are not licensed to sell: prescription drugs, recreational drugs, weapons, counterfeit goods, and forged documents.
- Hate speech, harassment, threats, and content that endangers minors.
- Misinformation designed to cause harm, including fabricated health or election claims.
This list describes categories, not an exhaustive enumeration. Content that is clearly designed to defraud or endanger the recipient is prohibited whether or not it appears above.
Prohibited behavior
Independently of what a message says, you may not:
- Send bulk unsolicited messages, or split one campaign across multiple workspaces or connected accounts to stay under a limit.
- Message the same contact repeatedly beyond the frequency caps described below, or build an automation whose effect is to do so.
- Operate accounts on behalf of others in order to evade a suspension, whether ours or a platform's.
- Create trial or duplicate accounts to obtain free capacity beyond what a single organization is entitled to.
- Impersonate ChatinFlow, Meta, a payment provider, a delivery company, or any other organization.
- Probe, scan, or load-test our infrastructure without written permission, or attempt to circumvent rate limits, quotas, or access controls.
- Resell access without a written reseller agreement.
Sending limits and automated safeguards
ChatinFlow applies automated limits on every workspace. They are not negotiable per-message, and they are deliberately set below the ceilings the underlying platforms enforce, so that our safeguard triggers before the platform's does.
- Per-contact frequency caps, so a single person cannot be messaged repeatedly by one workspace in a short window.
- Per-channel throughput limits, applied per connected account rather than per workspace.
- Plan quotas on automation runs, broadcasts, and connected channels.
- Anomaly detection on outbound volume and content. A sudden spike, or a burst of messages our content classifier flags, can pause a workspace's automations automatically while we review.
When a limit is reached we slow sending down rather than dropping messages, and we tell you in the dashboard. Deliberately engineering around these limits is itself a violation.
How we enforce this
Enforcement is graduated, and we skip steps when the conduct warrants it:
- Warning: we tell you what tripped and what to change.
- Throttle: sending is slowed or a specific automation is paused.
- Suspension: the workspace stops sending pending review.
- Termination and revocation: the account is closed and every connected channel token is revoked.
We may act immediately and without prior notice where there is a credible risk of harm to recipients, to a connected account, or to our platform standing. That includes phishing, content endangering minors, and coordinated spam.
We do not offer to review the content of your campaigns in advance, and passing our automated checks is not an approval. You remain responsible for what you send.
Your obligations to your contacts
You are the data controller for the people you message through ChatinFlow. That means you are responsible for having a lawful basis to contact them, for honouring their requests to access or erase their data, and for telling them who you are. ChatinFlow provides export and deletion tooling for contacts; using it is your obligation, not ours.
Do not send us, or store in ChatinFlow, categories of data the platform is not built for: payment card numbers, government identity documents, health records, or credentials.
Reporting abuse
If you received a message sent through ChatinFlow that you believe violates this policy, report it to abuse@chatinflow.com. Include the message content, the account that sent it, and the approximate time. We review every report.
For security vulnerabilities, use security@chatinflow.com instead, and see our Security page.
What this policy does not promise
Following this policy substantially reduces the risk of your connected account being restricted, but it is not a guarantee. Meta and other platforms make their own enforcement decisions, using signals we cannot see, and they can restrict an account without notice or explanation. Anyone who tells you a tool guarantees your account will not be actioned is not being straight with you.
What we do commit to: keeping our own limits conservative, telling you promptly when we detect a problem, and giving you the controls to disconnect and delete at any time.
Changes to this policy
We update this policy as platform rules and abuse patterns change. Material changes are announced in-product and by email to workspace owners before they take effect. Continuing to use the Services after the effective date means you accept the updated policy.
Questions about this document?
Reach our legal and privacy team directly. We respond to most requests within five business days.