01Overview
This Acceptable Use Policy (the “Policy”) forms part of our Terms of Service. It applies to everything done with your account — by you, your team, and any AI agent or software using your keys. Where an agent breaks these rules, you have broken them.
The Service enforces some of these rules in code: suppression cannot be bypassed, no campaign launches without human approval, and sending limits are applied per mailbox. The rest depend on you.
02Lawful business outreach
You may use the Service only for business-to-business outreach to people in their professional capacity. You must:
- have a lawful basis to contact each recipient, and comply with every marketing and privacy law that applies to you and to them — including UK PECR and GDPR, the EU ePrivacy rules and GDPR, the US CAN-SPAM Act, Canada’s CASL, and Australia’s Spam Act;
- identify yourself truthfully in every email: a real sender name, a real business, a working reply address and, where the law requires it, a postal address;
- use accurate subject lines and headers; never disguise the origin, the sender or the purpose of a message;
- give recipients a clear way to opt out, and never contact anyone who has opted out, replied asking to stop, or bounced — the Service suppresses them for you, and you must not work around it; and
- keep volume reasonable: respect the sending limits on each mailbox and the warming schedule, and do not attempt to raise them by rotating accounts or workspaces.
You must not contact consumers at personal addresses, purchase or upload consumer lists, or contact anyone under 18.
03Prohibited content
You must not send, draft, host or promote through the Service any material that:
- is unlawful, defamatory, fraudulent, deceptive or misleading, including phishing, impersonation, fake invoices and advance-fee schemes;
- promotes or facilitates malware, credential theft, unauthorised access or any attack on a person or system;
- promotes illegal goods or services, counterfeit goods, unlicensed pharmaceuticals, unregistered securities, or investment schemes that are unlawful where the recipient is;
- is sexually explicit, or promotes gambling to jurisdictions where that is unlawful;
- harasses, threatens or incites hatred or violence against any person or group;
- infringes the intellectual property, privacy or publicity rights of any person; or
- is sent on behalf of a business you are not authorised to represent.
04Prohibited uses
You must not, and must not permit any agent or third party to:
- use the Service in breach of any applicable law or regulation, or of these rules;
- resell, redistribute or sublicense the Service or any data returned by it, or use returned data to build, train, enrich or validate a database or product for third parties;
- use the Service for surveillance, stalking, doxxing, background checks, credit or employment decisions, or any purpose other than your own business outreach;
- submit special category data, or data about children, to the Service;
- attempt to bypass suppression, human confirmation, scopes, spend limits, rate limits or sending limits;
- introduce malware, or attack, overload, probe or otherwise disrupt the API, the Console or our providers;
- attempt to access data, workspaces or systems you are not authorised to access;
- reverse engineer, decompile or disassemble any part of the Service except to the extent that applicable law prohibits that restriction;
- use the Service to develop a competing product, or to benchmark it on behalf of a competitor; or
- scrape, crawl or use automated means to extract data from the Console or documentation, except with our prior written consent. (Calling the API with your own key is, of course, exactly what it is for.)
05Agents and automation
We built the Service for agents, and we hold you to the same standard whether a human or an agent presses the button. You must:
- scope every key to the verbs it needs and set a spend limit where one is sensible;
- review what an agent has drafted before you approve a launch — approval means you have read it;
- not delegate the human confirmation step to another automated system; and
- revoke any key whose agent behaves in a way you did not intend.
06What we do when these rules are broken
Depending on severity we may: pause one or more campaigns; pause or retire a mailbox; suspend Sending Capacity; suspend or close the workspace; withhold refunds where the breach caused the loss; and report unlawful activity to the relevant authorities. Where it is reasonable to do so, we will tell you first and give you a chance to fix it. Where recipients, other customers or our providers are at risk, we act first and tell you afterwards.
Our providers and the mailbox hosts we send through run their own abuse systems. If they suspend a domain, mailbox or account because of your sending, that suspension is your responsibility, and we may pass on any cost it causes us.
To report abuse of the Service, or to be suppressed from a GTMRouter customer’s outreach, email founders@gtmrouter.dev with the address that received the email.
07Changes to this policy
We may amend this Policy from time to time, for example when a law or a provider’s rules change. The date of the most recent revision appears at the top of this page. Material changes are notified by email at least 14 days before they take effect.