Acceptable Use Policy
Misar products can send messages, source contact data, and reach people at scale. This policy sets out what you may and may not do with them. It is not advisory: breaching it costs you your account.
Last updated: July 20, 2026 | Version: 2026-07-20
1. Scope and Acceptance
This Acceptable Use Policy (the "AUP") applies to every Misar AI product, website, API, SDK, and integration, including but not limited to misar.io, misar.dev, misar.blog, mail.misar.io and misarmail.com, reach.misar.io and misarreach.com, post.misar.io and misarpost.com, seo.misar.io and misarseo.com, and every other subdomain of misar.io (collectively, the "Services").
The AUP forms part of the Terms of Service and is accepted when you create a Misar account. Terms defined there have the same meaning here. Where this AUP and the Terms conflict, the Terms govern.
The AUP applies to you, to anyone you permit to use your account, and to anything sent, generated, or collected through your account — including by automation, agents, or API clients you operate. You are responsible for all of it.
2. Prohibited Conduct
You may not use the Services, or permit the Services to be used, to do any of the following.
Fraud, deception, and criminal activity
- Operate or promote any scam, confidence trick, advance-fee fraud, fake invoice, fake job offer, romance scam, cryptocurrency or investment fraud, pyramid or Ponzi scheme, or any other scheme designed to obtain money, credentials, or data by deception.
- Conduct phishing, spoofing, or impersonation of any person, business, brand, or government body — including falsifying sender names, reply-to addresses, headers, domains, or message provenance.
- Distribute malware, ransomware, spyware, credential harvesters, or links to any of the above.
- Engage in money laundering, sanctions evasion, trafficking, the sale of stolen data or credentials, or any other activity that is criminal under the law of any jurisdiction that applies to you or your recipients.
- Distribute child sexual abuse material, content that sexually exploits minors, or content promoting terrorism or violent extremism. We report this category to the relevant authorities without notice to you.
Harm to people
- Harass, stalk, threaten, defame, or incite violence or hatred against any person or group.
- Continue contacting a person after they have asked you to stop, by any channel, whether or not the request used the words "unsubscribe" or "stop".
- Target people on the basis of protected characteristics in a manner that is unlawful in the applicable jurisdiction.
Harm to systems
- Circumvent, disable, or interfere with any rate limit, quota, consent check, suppression list, quiet-hours window, unsubscribe mechanism, or other control built into the Services.
- Probe, scan, or test the vulnerability of any system without authorisation, or access any account or data that is not yours. Good-faith research conducted under our security disclosure policy is exempt.
- Resell, sublicense, or provide the Services to third parties as a bulk-sending or data-brokering service without our written agreement.
3. Email and Bulk Sending
This section applies wherever you send email through Misar, including MisarMail campaigns and any email sent from MisarReach sequences or automations.
You are the sender. Misar provides the tooling; you decide who is contacted, what is said, and on what basis. In data-protection terms you are the controller of your recipient lists and we act as processor on your instructions. You are responsible for having a lawful basis for every message you send.
You must:
- Have a lawful basis for contacting each recipient under the law that applies to them — including CAN-SPAM (US), CASL (Canada), GDPR and ePrivacy (EU/UK), the DPDP Act (India), the Privacy Act and Spam Act (Australia), and any other applicable regime. Where that law requires prior consent, obtain it before sending.
- Identify yourself accurately, including a valid sender identity and a physical postal address where required.
- Include a working, one-click unsubscribe in every commercial message, and honour opt-outs promptly — within ten (10) business days at the outside, and immediately where the law requires it.
- Keep records demonstrating how each recipient came to be on your list, and produce them on request.
- Send only to addresses you collected or sourced lawfully, and maintain list hygiene — remove hard bounces, spam complainants, and unsubscribes and never re-add them.
You must not:
- Send unsolicited bulk email — spam — by any definition applicable to the recipient.
- Upload or send to purchased, rented, scraped, appended, or otherwise third-party-sourced lists where the recipients have not agreed to hear from you and no other lawful basis exists.
- Use deceptive subject lines, preheaders, sender names, or "Re:"/"Fwd:" prefixes on messages that are not replies or forwards.
- Send to spam traps, role addresses harvested at scale, or addresses obtained from a data breach.
- Spread a single campaign across multiple accounts, domains, or sending identities to evade limits, reputation monitoring, or a prior enforcement action against you.
Complaint and bounce thresholds. We monitor spam-complaint rates, bounce rates, and blocklist signals. Sustained complaint rates above 0.3% or hard-bounce rates above 5% may trigger throttling, review, or suspension regardless of whether any other clause of this AUP has been breached — deliverability is a shared resource, and a sender who degrades it affects every other customer.
4. Lead Sourcing and Enrichment
MisarReach can search, enrich, and score business contact data from a range of sources. That a record can be retrieved does not mean you may lawfully contact the person it describes, and it does not mean you may use it for any purpose you like.
You determine the purpose. We surface data; you decide what to do with it, and you are the controller of every record you retain, export, or contact. The lawfulness of that processing is yours to establish — including, where applicable, the legitimate-interest assessment, the balancing test, and the notice you owe the individual.
- Use sourced data only for legitimate business-to-business purposes, and only where you have a lawful basis to contact the individual.
- Provide the privacy notice the applicable law requires when you obtain personal data from a source other than the individual, and identify your source on request.
- Honour access, correction, deletion, and objection requests from individuals in your lists, and suppress anyone who objects.
- Compile, sell, license, or broker sourced data as a dataset, or build a competing contact database from the Services.
- Use sourced data to make decisions about credit, employment, housing, insurance, or eligibility for any benefit — the data is not verified for those purposes and is not a consumer report.
- Target individuals in a private capacity, or knowingly source data on minors.
- Breach the terms of any third-party platform whose data you reach through the Services, including by scraping in violation of that platform's terms.
5. Messaging Channels
MisarReach can send through channels other than email, including SMS, WhatsApp, Telegram, LinkedIn, X, Instagram, Facebook, Threads, Discord, and direct mail. Each of these has its own legal regime and its own operator rules, and they are stricter than email — several of them permit no cold outreach at all.
The rules of the channel apply in full. When you connect an account or a number to Misar, you remain bound by that provider's terms, and you authorise us to enforce their limits on your traffic. Where a channel is configured in the Services as consent-only or reply-only, that configuration reflects a legal or contractual requirement and must not be circumvented.
- Obtain prior express consent before sending SMS or WhatsApp messages where the applicable law requires it — the TCPA in the US, and equivalent regimes elsewhere. Statutory damages under the TCPA are assessed per message.
- Complete and maintain any registration the channel requires, including US A2P 10DLC brand and campaign registration, and keep the registered use case accurate.
- Honour STOP, UNSUBSCRIBE, and every equivalent opt-out immediately and across all channels — an opt-out on one channel is an opt-out for that person, not for that channel.
- Respect quiet hours and local time-of-day restrictions for the recipient's location.
- Send cold, unsolicited direct messages on any channel that prohibits them, or use a reply-only channel to initiate contact.
- Automate a personal social account in breach of that platform's terms, or operate multiple accounts to raise effective sending limits.
Using more channels does not dilute responsibility across them. Each message you send is your message, on every channel, and the obligations attach to each one independently.
6. AI-Generated Content
Several Misar products generate text, code, or media. Generated output can be wrong, biased, or unintentionally similar to existing work. You are responsible for reviewing anything you send or publish, and the fact that a model produced it is not a defence.
You may not use our AI features to:
- Generate content that impersonates a real person or organisation, or that presents synthetic media as genuine.
- Produce disinformation, election interference material, or content designed to deceive at scale.
- Generate material that infringes copyright, trademark, or other rights.
- Provide medical, legal, or financial advice presented as professional advice without appropriate qualification and disclosure.
7. Enforcement
We investigate reports of misuse and we act on them. Depending on the severity, the history of the account, and the risk to recipients or to the Services, we may take any of the following steps, in any order, with or without prior notice:
- Throttle, pause, or queue your sending.
- Require verification of your identity, your domain, or the provenance of a list.
- Remove content, disconnect a channel, or revoke API access.
- Suspend the account pending investigation.
- Terminate the account permanently and refuse all future service to you and to any account we reasonably associate with you.
Immediate permanent termination. Confirmed scams, fraud, phishing, distribution of malware, child sexual abuse material, and deliberate circumvention of consent, suppression, or opt-out controls result in permanent termination on first instance. There is no warning step for these categories, and no reinstatement.
Fees and credits. Termination for a breach of this AUP does not entitle you to a refund of prepaid fees or unused credits, and does not relieve you of amounts already owed.
Appeals. If you believe an enforcement action was made in error, write to abuse@misar.io. We will review the decision. Categories listed above as permanent are not subject to reinstatement, but we will correct a misidentification.
Cooperation with authorities and providers. We may preserve and disclose account records, message content, and traffic data to law enforcement, regulators, or an affected upstream provider where we are legally required to, or where we reasonably believe it necessary to investigate suspected fraud or a serious crime, or to protect the rights and safety of any person. We do this without notice to you where notice would prejudice an investigation or is prohibited by law.
Report Misuse
If you received a message sent through Misar that you believe breaches this policy, or you have been targeted by a scam involving our Services, tell us. Reports are actioned.
Abuse reports: abuse@misar.io
Legal notices: legal@misar.io
Privacy requests: privacy@misar.io
Include the message headers or a screenshot where you can. It is what lets us identify the sending account.
This policy sits alongside our Terms of Service and Privacy Policy. We may update it as products, laws, and abuse patterns change; material changes are notified as described in the Terms.