Legal
Acceptable Use Policy
Effective date: June 8, 2026
This Acceptable Use Policy ("AUP") supplements our Terms of Service and applies to all users of Cloutbox. Violating this AUP may result in immediate suspension or termination of your account.
1. General Prohibitions
1.1 Illegal Activity
- Violate any applicable local, national, or international law or regulation.
- Engage in fraud, identity theft, or impersonation of any person or entity.
- Facilitate unlicensed gambling, regulated weapons sales, controlled substance distribution, or other restricted activities.
- Engage in money laundering or violate anti-money laundering (AML) laws.
1.2 Sanctions and Export Controls
- Use the Service if you are located in or acting on behalf of a person or entity in a US-embargoed country or territory (including Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions).
- Use the Service if you are listed on the OFAC SDN list, the BIS Entity List, or any other applicable restricted-party list.
- Export, re-export, or transfer Service data or technology in violation of US Export Administration Regulations (EAR) or other applicable export laws.
1.3 Harmful or Offensive Content
- Publish, schedule, or distribute content that is defamatory, harassing, threatening, abusive, or incites hatred based on protected characteristics.
- Distribute spam — unsolicited bulk messages, chain letters, or commercial messages to people who have not opted in.
- Publish or distribute content that sexually exploits, endangers, or sexualises minors (CSAM). We report all such content to NCMEC and cooperate fully with law enforcement.
- Distribute malware, ransomware, phishing materials, or any malicious code via connected social media platforms.
- Publish false or misleading content designed to defraud, manipulate financial markets, or interfere with elections.
1.4 Intellectual Property
- You represent and warrant that all content you publish through the Service does not infringe any third-party copyright, trademark, patent, trade secret, or other proprietary rights. This representation applies to text, images, video, audio, and any other media.
- You must not use the Service to circumvent any digital rights management (DRM) or other technical protection measure.
- If you receive a DMCA takedown notice related to content published through Cloutbox, you must notify us at abuse@cloutbox.ai promptly. See our DMCA Policy.
1.5 System Abuse
- Attempt to gain unauthorised access to the Service, other users' accounts, or connected social platforms.
- Probe, scan, or test the vulnerability of the Service without our written authorisation.
- Conduct denial-of-service (DoS/DDoS) attacks against the Service or any connected platform.
- Reverse engineer, decompile, or disassemble any part of the Service.
- Use scrapers, bots, or automated agents against the Service beyond its published API and documented rate limits.
- Attempt to circumvent rate limits, security controls, or platform API restrictions.
2. Platform API Compliance
2.1 All Connected Platforms
- Do not use data received from any platform API to train AI or machine learning models.
- Do not conduct coordinated inauthentic behaviour (fake engagement, astroturfing, vote manipulation, or bot networks).
- Do not publish content that violates the relevant platform's community guidelines or content policies.
- Do not use automated mass-action tools (mass follow, mass like, mass DM) that violate platform rate limits.
Platform policy changes: each platform may change its API terms, acceptable use policies, or community guidelines at any time. You are responsible for monitoring and complying with current platform policies. If a platform change makes a previously permissible activity prohibited, you must immediately cease that activity. Cloutbox will attempt to provide guidance on significant platform policy changes affecting the Service, but bears no liability for your non-compliance with updated platform policies.
2.2 X (Twitter)
- You may not use X API data obtained through Cloutbox to create datasets, train models, or for any purpose not permitted by the X Developer Agreement.
- You may not operate multiple coordinated accounts performing the same actions.
2.3 LinkedIn
- All LinkedIn publishing via Cloutbox must be triggered by explicit user action within the session — do not configure automations that post without per-post user confirmation.
- Do not store LinkedIn member data beyond the 48-hour API retention limit.
2.4 TikTok
- You must review and may edit any preset captions before publishing to TikTok. Pre-filled captions are suggestions only; TikTok requires that users can edit them.
2.5 Meta
- Connect only Pages, Instagram accounts, and ad accounts that you own or are legally authorised to manage.
- Do not use Cloutbox to run ad campaigns that violate Meta's Advertising Policies.
2.6 Google and YouTube
- YouTube data accessed through Cloutbox may only be used for your own account management within the Service.
- Do not publish content that violates YouTube's Community Guidelines or Google's Terms of Service.
3. Email and Communication Compliance
- Comply with CAN-SPAM, CASL, GDPR Article 6, and all other applicable email marketing laws for any outbound communications facilitated through the Service.
- All commercial emails must include a physical mailing address and a working unsubscribe mechanism.
- Unsubscribe requests must be honoured within 10 business days.
- Do not use deceptive subject lines or sender names.
4. Enforcement
We reserve the right to investigate suspected AUP violations. We may take any of the following actions:
- Issue a formal warning.
- Temporarily suspend your account or specific features.
- Permanently terminate your account without refund.
- Report the activity to law enforcement, platform operators, NCMEC, or applicable regulators.
- Pursue civil legal remedies for damages.
We are not obligated to provide advance notice before acting in cases of severe, ongoing, or legally mandated intervention. We will use commercially reasonable efforts to provide notice and an opportunity to cure for non-severe, first-time violations.
5. Reporting Violations
Abuse / content violations
abuse@cloutbox.aiSecurity vulnerabilities
security@cloutbox.aiGeneral enquiries
support@cloutbox.aiWe acknowledge abuse reports within 2 business days and security vulnerability reports within 24 hours. See our Security Policy for responsible disclosure details and our bug bounty programme information.
6. Updates to This Policy
We may update this AUP to reflect new platform requirements, legal obligations, or changes to the Service. Material changes will be communicated by email at least 30 days before taking effect. Continued use after the effective date constitutes acceptance of the updated AUP.