1. Purpose and scope
This Acceptable Use Policy ("AUP") applies to all access to and use of Paravane websites, APIs, dashboards, documentation, software, outputs, and related services, including the smtpRS API. This AUP is incorporated into the Paravane Terms of Service.
You are responsible for your users, systems, API keys, applications, customers, contractors, and downstream recipients that access or use the Services through your Account or credentials.
2. General rule
You may use the Services only for lawful, authorized, secure, and rights-respecting purposes. You may not use the Services to harm Paravane, other customers, end users, individuals, systems, networks, or third parties; to evade legal obligations; or to build or support abusive, deceptive, invasive, discriminatory, or unsafe systems.
3. Prohibited security and abuse activities
You may not use the Services to engage in, facilitate, enable, or support:
- Unauthorized access to systems, accounts, networks, data, or credentials.
- Credential stuffing, password spraying, account takeover, phishing, spear phishing, smishing, vishing, pharming, impersonation, or social engineering.
- Malware, ransomware, botnets, worms, trojans, spyware, keyloggers, exploit kits, malicious scripts, or command-and-control infrastructure.
- Denial-of-service attacks, stress testing without authorization, traffic amplification, scanning or probing systems without authorization, or attempts to degrade service availability.
- Evasion of rate limits, quotas, billing controls, subscription checks, entitlement checks, abuse controls, security controls, or access restrictions.
- Misrepresentation of request origin, fake accounts, fraudulent signup or evaluation requests, API key sharing, token leakage, request laundering, payment abuse, chargeback abuse, or unauthorized resale of the Services.
- Attempts to reverse engineer, extract, scrape, copy, or reconstruct Paravane models, datasets, scoring logic, features, endpoints, or proprietary technology except as expressly permitted by law.
- Use that interferes with the security, integrity, availability, or performance of the Services or third-party systems.
4. Prohibited unlawful, harmful, or rights-violating uses
- Violating any applicable law, regulation, rule, court order, sanction, export control, industry rule, or third-party right.
- Harassment, stalking, doxxing, intimidation, threats, abuse, hate, discrimination, or targeting individuals based on protected characteristics.
- Infringing intellectual property, privacy, publicity, contractual, confidentiality, or data protection rights.
- Collecting, processing, or disclosing personal information without required rights, notices, consents, lawful bases, or authorizations.
- Creating, enriching, selling, sharing, or using dossiers about individuals in a manner that violates law or reasonable privacy expectations.
- Sending spam, unsolicited bulk messages, deceptive marketing, illegal telemarketing, or communications that violate CAN-SPAM, TCPA, GDPR/ePrivacy, or similar laws.
- Supporting scams, fraud, identity theft, synthetic identity abuse, payment fraud, financial crime, or deceptive practices.
- Submitting false, misleading, unlawful, or unauthorized data to the Services.
5. Prohibited regulated, sensitive, and high-risk data
Unless Paravane expressly agrees in a signed written agreement, you may not submit or process the following through the Services:
- Protected health information or data subject to HIPAA or similar health privacy laws.
- Full payment card data, CVV codes, bank credentials, or PCI-regulated data.
- Government identification numbers, social security numbers, passport numbers, driver's license numbers, or taxpayer identifiers.
- Financial account numbers, credit reports, credit scores, payroll records, or debt-collection data.
- Precise geolocation, biometric identifiers, genetic data, or data collected from children.
- Special-category or sensitive data under GDPR or similar laws, unless specifically authorized.
- Data obtained unlawfully, through scraping that violates law or terms, from data breaches, from compromised accounts, or from sources you are not authorized to use.
6. smtpRS-specific restrictions
smtpRS outputs are intended to support technical risk analysis, fraud and abuse prevention, email/domain quality evaluation, account security workflows, and internal operational triage. They are not intended to be consumer reports, background checks, or regulated eligibility determinations.
| Restricted area | Rule |
|---|---|
| Credit and lending | Do not use the Services to determine eligibility for credit, loans, financing, deferred payment, credit limits, collections, or credit risk of a consumer. |
| Insurance | Do not use the Services to determine eligibility, pricing, risk, underwriting, renewal, cancellation, or benefits for insurance. |
| Employment and contractors | Do not use the Services to screen, hire, fire, promote, demote, reassign, retain, discipline, or evaluate employees, contractors, volunteers, or applicants. |
| Housing and tenancy | Do not use the Services for tenant screening, housing eligibility, rental decisions, eviction decisions, or real-estate eligibility. |
| Government benefits and licenses | Do not use the Services to determine eligibility for public assistance, benefits, licenses, permits, education, immigration, or similar government-related rights or opportunities. |
| Healthcare | Do not use the Services for diagnosis, treatment, healthcare eligibility, coverage, triage, or patient decisions. |
| Law enforcement and evidentiary use | Do not use the Services as evidence that a person is associated with an identifier, email, domain, IP address, account, event, or activity; for watchlists; or for criminal prosecution decisions. |
| Sole adverse decisions | Do not use the Services as the sole basis for suspending, blocking, denying, terminating, or taking adverse action against a person or organization without appropriate independent review. |
| Discrimination | Do not use the Services to infer, target, exclude, or discriminate based on protected characteristics or sensitive attributes. |
7. Required safeguards for permitted uses
For permitted uses, you must implement safeguards appropriate to your use case, including:
- Use outputs as one signal among multiple indicators, not as an automatic final decision unless the decision is low-risk and legally permissible.
- Set thresholds carefully and monitor false positives, false negatives, drift, and disparate impact where relevant.
- Provide legally required notices, consents, opt-outs, human review, appeals, and explanations to individuals affected by your decisions.
- Maintain records sufficient to show lawful use, data source authorization, and compliance with this AUP.
- Use data minimization and submit only the fields reasonably necessary for the endpoint and purpose.
- Secure API keys, logs, outputs, and downstream systems and restrict access to personnel with a legitimate need.
- Delete or de-identify outputs when no longer needed for the permitted purpose, unless law requires retention.
8. API, performance, and operational restrictions
- Do not exceed or circumvent Usage Limits, quotas, rate limits, concurrency limits, or billing controls.
- Do not use multiple accounts, workspaces, payment methods, proxies, API keys, checkout sessions, or customer portal sessions to evade limits, subscriptions, billing, enforcement, or account review.
- Do not generate excessive, abusive, or unnecessary requests that degrade service availability or increase costs unreasonably.
- Do not cache, resell, sublicense, or redistribute API responses except as permitted in your Order or Documentation.
- Do not benchmark, publish performance tests, or compare outputs publicly in a misleading way or without appropriate context and permission where required.
- Do not use the Services to build a substantially similar or competing service, dataset, scoring product, or API.
9. Vulnerability disclosure and security testing
If you discover a vulnerability, please report it to security@paravane.io. Do not exploit, access, exfiltrate, modify, destroy, or disclose data; do not disrupt the Services; and do not test against accounts, systems, or data that you do not own or have permission to test.
Security testing requires prior written authorization unless Paravane publishes a separate vulnerability disclosure policy or bug bounty scope that expressly permits specific testing.
10. Monitoring and enforcement
Paravane may monitor usage for security, reliability, abuse prevention, billing, and policy enforcement. If Paravane reasonably believes that you have violated this AUP, Paravane may warn you, request remediation, rate-limit requests, remove data, disable API keys, suspend features, suspend or terminate Accounts, notify affected parties, preserve evidence, or report activity to authorities where appropriate.
Paravane may consider factors such as intent, severity, risk, actual harm, repeat violations, cooperation, remediation, and legal obligations when deciding enforcement actions.
11. Reporting abuse
To report abuse of the Services, contact security@paravane.io with details, timestamps, API identifiers if available, and evidence that will help Paravane investigate. General information requests may be sent to contact@paravane.io. Do not include sensitive personal data unless necessary.
12. Changes to this AUP
Paravane may update this AUP from time to time. Updated versions apply as described in the Terms of Service. Continued use of the Services after an update becomes effective constitutes acceptance of the updated AUP.