Myndchat Acceptable Use Policy
This policy says what may not be done with Myndchat. It forms part of the Terms of Service, is accepted together with them at sign-up, and applies to everything you do on the platform and through it.
It does not exist out of caution on our part. Anyone operating as a technology provider for messaging channels is jointly and severally liable for what their customers do: one irregular message sent by you reaches our relationship with the channel, and can cost every other customer their access. We write the rules plainly because the alternative is finding them out later, together.
This document covers:
- the consent rule, which is the one that gets accounts shut down most often;
- what may not be sent, offered or collected;
- what may not be designed into an automation, even where it is technically possible;
- the limits on technical use of the platform;
- what happens when a rule is broken, step by step, and how to appeal.
The rule that sums up all the others. The conversation is yours, the contact is yours, and responsibility for what you send is yours. Myndchat is the tool. We do not read your conversations to check whether each message is compliant — we could not, and section 6 of the Data Processing Addendum exists precisely to prevent that kind of access. What we do is act on signals, reports, and determinations from a channel or an authority.
Beyond this policy, the rules of the channels you connect apply. They belong to third parties, change without telling us, and prevail over any summary we make of them. Section 5 explains how we deal with that.
Contents
- 1. Who this policy applies to
- 2. Consent: the rule that shuts down the most accounts
- 3. What is prohibited
- 4. What may not be designed into an automation
- 5. The rules of the channels you connect
- 6. Technical use of the platform
- 7. What happens when a rule is broken
- 8. How to report and how to appeal
- 9. Changes to this policy, and contact
1. Who this policy applies to
It applies to you, the account holder, and to everyone who uses the platform through your account.
- every member of your team you granted access to, whatever their role;
- any system you connect through a programming interface or an automatic trigger;
- anyone you pass access on to, even though passing it on is already prohibited by section 6;
- you yourself, as to the lists you import and the content you configure in an automation, even where someone else presses send.
An act by someone on your team is your act, for the purposes of this policy. From the outside we cannot tell who inside your organisation pressed which button — and neither can the channel.
It does not apply to your end contacts. Someone who talks to you never accepted this document and does not answer under it. If a contact uses the conversation for something unlawful, the problem is real, but it is handled under section 8.
2. Consent: the rule that shuts down the most accounts
If you read only one section of this document, read this one. It is the most common violation, the easiest to commit in good faith, and the one channels punish fastest.
You may only start a conversation with someone who gave you their own contact details and authorised you to message them. Both things, together. Having the number is not enough; having authorisation for another purpose is not enough. That is the channel's rule, written by the channel, not our reading of it.
The following are not valid consent, and using any of them is a direct violation:
- a list bought, rented, swapped or received from a partner;
- a database scraped from a website, social network, marketplace or public group;
- contacts collected for another purpose — an invoice record, a prize draw form, an attendance list — without specific authorisation to receive messages;
- a contact whose origin you cannot demonstrate;
- authorisation obtained through misleading wording, a pre-ticked box, or consent bundled into acceptance of something else.
Keep the evidence of authorisation. When a channel or an authority questions a send, you are the one who must show where the contact came from — and Myndchat cannot do that in your place.
Refusal is stricter still than authorisation: an unsubscribe request must always be honoured, immediately, and also when it arrives by another route. If the person asked by phone, by e-mail or in person to stop receiving messages, that request counts just the same. The platform keeps the opt-out record and it survives the deletion of that contact's other data, precisely so the person does not start receiving messages again on the next import.
3. What is prohibited
The conduct below is prohibited on any channel, at any volume, and regardless of whether the contact authorised the initial contact. Authorisation to receive messages is not authorisation to receive any message.
| Category | What is not allowed | Why |
|---|---|---|
| Fraud and deception | Scams, phishing, fake charges, offers that do not exist, fake prize draws, manufactured urgency and promises of guaranteed financial returns | It is unlawful, and it is the fastest way to lose access to the channel |
| Impersonation | Passing yourself off as another person, company, public body or as Myndchat itself; using a third party's brand without authorisation | Beyond being unlawful, it breaks the trust of whoever reads the message on the channel |
| Illegal content | Material the law prohibits, including anything involving children or adolescents, incitement to crime, hate speech and threats | There is no tolerance case, and there is a duty to report to the authorities |
| Harassment and abuse | Stalking, intimidation, persistence after a request to stop, and mass sending to people who already refused | A request to stop is the clearest expression of will there is |
| Misuse of data | Collecting personal data under a false pretext, using what was collected for a purpose other than the one disclosed, or processing sensitive data without a legal basis | You are the controller of that data and you answer for it |
| Content restricted by the channels | Offering a product or service prohibited by the commercial policy of the connected channel | That list belongs to the channel, changes without notice and prevails. See section 5 |
Regulated sectors are not prohibited, and it is worth saying so clearly: clinics, law firms, brokerages, schools and financial institutions may use the platform. What is required is compliance with your own sector's regulation — including the advertising rules of your professional body, where one exists.
An honest question has an address. If you are unsure whether your case fits, write to support@myndchat.com before sending, describing what you intend to do. Asking beforehand leaves no mark against you; finding out afterwards can mean suspension and loss of channel access.
4. What may not be designed into an automation
This section exists because the platform gives you design power, and some designs the tool will execute without complaint are nonetheless abusive. What follows is prohibited even where it is technically possible to build.
- an automation designed to stop someone reaching a human, ignoring an explicit request to speak to one;
- a flow that makes leaving harder — hiding the unsubscribe, requiring a long sequence of steps to get out, or answering a request to stop with a question instead of stopping;
- a message presenting itself as a person when it is an automation, if the person asks directly who they are talking to;
- automatic persistence after a request to stop, even with different wording or through another channel;
- capturing sensitive data — health, biometrics, racial origin, political opinion, children's data — through an automated flow, without a legal basis on your side and without saying what it is for;
- chaining designed to get around a channel's frequency limit by splitting the same send across windows, numbers or accounts.
A request to stop must stop that contact's entire flow, not just the step they were on. A sequence that continues after the request is a violation, even if the next step is about something else.
About the artificial intelligence layer. It answers within what you configured, and responsibility for what it sends is yours — the platform is a tool here too. It is prohibited to configure it to deny being an automation when asked, to promise results you cannot deliver, or to give individualised medical, legal or financial advice unless your business is properly licensed for that.
Contact memory is only written by explicit action of an automation or an agent, never by inference of the model. Using that memory to record information the person does not know is being kept, or that you could not lawfully keep, violates this policy and probably the law.
5. The rules of the channels you connect
Every connected channel has its own policy, written by the channel's owner. It applies to you in full, adds to this one, and prevails over any summary of ours.
Why we do not copy their list here. WhatsApp's messaging policy warns, in its own text, that it may be updated without prior notice. A copy pasted onto this page would age on its own and become false information the day after a change — and you would have relied on it. So we describe the types of restriction and send you to read at the channel, which is where the list is always correct.
Channels typically restrict the offering of weapons and controlled goods, substances and medical products, gambling, adult products and dating services, virtual assets, very short-term credit, live animals and protected species, and pyramid recruitment schemes. That is an indication of the kind of thing restricted, not the applicable list: the applicable list is the channel's, on the date you send.
Channels also impose rules on the service window, on approved message templates and on sending frequency. The platform respects those rules by design where it can, but it does not replace your reading of the channel's policy.
When a channel imposes a measure on your account — blocking a number, removing a template, restricting sending — we comply and tell you what was determined and by whom. We cannot reverse a channel's decision, and we say so rather than promising an intermediation we do not control.
6. Technical use of the platform
These rules protect the whole platform. A customer who breaks them degrades the service for everyone else, which is why the response here tends to be faster than in other cases.
- do not attempt to access another customer's data, account or organisation, nor probe the isolation between organisations outside a responsible security report;
- do not circumvent request, plan or quota limits, including by creating multiple accounts to split the same usage;
- do not reverse engineer, extract code, copy the interface, or use the platform to build a competing product;
- do not resell, sublicense or pass access on to an unidentified third party. An agency operating its clients' accounts is legitimate and expected use, provided each organisation belongs to the client and the client knows it;
- do not run bots, scrapers or undocumented automation against the product's interface;
- do not introduce malicious code, or use the platform as an intermediary to attack a third party.
Security research is welcome and has a route of its own. If you find a flaw, write to seguranca@myndchat.com. We take no action against anyone reporting in good faith, without exploiting the flaw beyond what is needed to demonstrate it and without accessing third-party data. What separates research from violation is exactly that: stopping at the point where the flaw has been demonstrated.
The cost of messages is charged by the channel provider directly to you and does not pass through Myndchat. Attempting to manipulate the count of active contacts or conversations in order to reduce your own plan violates this policy, and any investigation is carried out against the platform's records.
7. What happens when a rule is broken
The response is proportionate and progressive. We do not go from zero to eighty. This is the same ladder described in section 13 of the Terms of Service, and the two documents must not diverge.
| Step | What happens | Who decides |
|---|---|---|
| 1. Observation | The signal is recorded internally. Nothing changes for you | Automatic |
| 2. Warning | You receive a message saying what was detected, which rule applies, what to do and by when | Automatic |
| 3. Temporary limit | Reduced sending volume or a paused campaign. You carry on serving people who already talked to you | Automatic, with review |
| 4. Outbound sending suspended | Campaigns, sequences and sends are blocked. The inbox and replies within the service window keep working | A person, with their name and the reason recorded |
| 5. Account suspended | Access restricted, channels disconnected and data preserved | A person, with their name and the reason recorded |
A serious and unambiguous violation — a scam, illegal content or payment fraud — may go straight to the last step, and even then the decision goes through immediate human review and is recorded.
No suspension deletes data, and no artificial intelligence decides a suspension. Automated systems may flag and prioritise; the decision to suspend is always a person's, with their name and reason recorded. Suspension preserves your data; deletion is a deliberate act, with a deadline, and is described in the Terms of Service.
Repeat conduct hardens the response, and that is said here from the outset precisely so it is not a surprise. The same behaviour repeated after a warning does not start again at step one.
8. How to report and how to appeal
Both have an address, and both get an answer from a person.
| Situation | Where to write | What happens |
|---|---|---|
| You received an abusive message from a Myndchat customer | abuso@myndchat.com | We investigate and apply the ladder in section 7. You do not need to be a customer to report |
| You want to appeal a warning or a suspension of your account | The appeal channel inside the platform | Review by a person, with a recorded and reasoned decision. A successful appeal fully restores the previous state |
| You found a security flaw | seguranca@myndchat.com | We review every report and take no action against anyone reporting in good faith |
| You want to know why a measure was taken | support@myndchat.com | Every warning and every suspension states what was detected, which rule applies, when it happened and what to do |
A report from an end contact about one of our customers is taken seriously even when it comes without evidence. We investigate using what the platform records, without opening conversations outside the cases in the Data Processing Addendum, and the response is proportionate to what the investigation finds.
A report is not automatic access to conversations. A report on its own does not authorise us to read the content of a customer's conversations. Internal access to content is exceptional, requires a written justification, is logged, and appears in that organisation's own audit trail — including when the reason is an abuse investigation. The two things coexist: we investigate, and the investigation leaves a trace visible to whoever was investigated.
9. Changes to this policy, and contact
This policy changes when practice changes, when a channel's rule changes materially, or when a real case shows that a piece of wording was ambiguous.
A change that restricts what you were previously allowed to do is communicated at least 30 days in advance, at the account contact address, and takes effect after that. A change that merely clarifies, corrects wording or adds an example takes effect on publication.
A change to a channel's policy does not depend on us and applies to you when the channel publishes it, not when we reflect it here. That is why section 5 sends you to read at the channel.
| Subject | Address |
|---|---|
| Reporting abusive use | abuso@myndchat.com |
| Questions about what is allowed, before sending | support@myndchat.com |
| Security flaws | seguranca@myndchat.com |
| Contractual matters | juridico@myndchat.com |
Myndchat is MYNDCHAT TECNOLOGIA LTDA, company number (CNPJ) 65.434.606/0001-80, registered at Avenida Brigadeiro Faria Lima, 1811, Sala ESC 1119, Jardim Paulistano, São Paulo/SP, 01452-001, Brazil. The Portuguese version of this policy prevails in case of divergence with the English version.