1. Who this covers
This policy is part of our Terms of Service (section 7) and uses the same definitions. It applies to your account, your team members, clients you authorize, and every agent, automation, API key, website form and connected copy of AttackDesk acting for you.
You are responsible for their compliance. Make the people who use AttackDesk through your account aware of these rules, including the rules of the providers behind each service. Having a tool that can do something does not make it permitted.
2. Never allowed
Do not use AttackDesk for unlawful activity; fraud, phishing, scams or deceptive practices; spam; harassment, threats or abuse; content that sexually exploits or endangers children; malware or other harmful code; or infringing anyone's intellectual property, privacy or publicity rights.
Do not impersonate a real person, business or authority to mislead people, and do not disguise who is contacting someone. This includes AI-generated voices, text, images or video used to deceive. Content that is clearly labeled, consented to or not misleading is not prohibited by this rule alone; the service-specific rules below still apply.
3. Access, security and limits
Do not access, or try to access, accounts, data, systems or companies you are not authorized to use, including other AttackDesk customers' data. Do not probe, scan or load-test our services without our written permission.
Do not bypass or try to defeat access restrictions, permission checks, spending controls, service limits, rate limits, license checks, protected or sealed components, or security protections. Do not create or combine accounts to get around a limit. Keep API keys, form tokens and sign-in credentials secret, and do not resell or share them outside the people and systems you have authorized.
4. Texting
Text only people who agreed to receive texts from your business about that subject: express consent for informational texts and express written consent for marketing texts. Someone texting you first agrees only to your replies. Consent cannot be bought, sold, shared or transferred, and a purchased, rented or scraped list is never consent. Keep a record of each consent (when, how, the wording shown and the number) and provide it to us or our providers on request.
Identify your business in your texts, include opt-out instructions such as "Reply STOP to unsubscribe" in the first message of a program, and honor opt-out requests in any reasonable wording. After someone opts out, send at most one confirmation. AttackDesk records opt-out keywords sent to your AttackDesk numbers; you must also honor opt-outs you receive another way. Send only the kinds of messages covered by the consent and by your carrier registration.
Carriers and our messaging provider restrict some businesses and content on US and Canadian numbers. These rules apply to texting through AttackDesk, not to the rest of your account. Some are not allowed on any US or Canadian number, including payday and other high-interest short-term loans, third-party lending, lead generation that sells or shares consumer data, third-party debt collection, debt relief and credit repair, cannabis, CBD, kratom, vaping products, fireworks, gambling, firearms, sexual or hateful content, phishing, and get-rich-quick schemes. Others are allowed only with conditions, such as a date-of-birth age gate for alcohol, or only on a particular number type, such as tobacco on short codes only, and some programs need extra vetting or carrier approval, such as political, charity, school and emergency programs. In Canada, age-restricted content needs a carrier exemption. The current rules of our messaging provider and the carriers control where they differ from this summary.
Do not try to get around carrier filtering: no spreading messages across numbers to avoid limits, rotating numbers or links, misspelled or disguised opt-out language, or public link shorteners (use links on your own domain). Do not send simulated phishing or other security tests by text.
Carriers can fine our messaging provider for some violations, such as phishing or content sent without a required age gate. If traffic from your account causes a fine, we will pass that fine on to you.
5. Calls and recording
Follow the laws on calling people: get prior consent where required, say who you are and why you are calling at the start of the call, honor requests not to be called and applicable do-not-call registries, and call only at permitted times. Call from your AttackDesk numbers or caller IDs verified as yours, and never use misleading caller identification.
In the US, the FCC has ruled that AI-generated and cloned voices are artificial voices under the Telephone Consumer Protection Act, so calls that use them need the called person's prior express consent, and prior express written consent for telemarketing, unless an exemption applies. Do not place large numbers of unwanted, very short or unanswered calls that carriers treat as abusive. Recording and transcribing calls follow section 6 of the Terms: give the required notices and get every participant's consent where the law requires it.
6. Email
Send marketing and other non-transactional email only to people who gave your business affirmative consent. Never send to purchased, rented, scraped or harvested lists, or to generic addresses such as info@ without consent, and reconfirm consent after a long period without engagement. Send only from domains you own or control and have verified in AttackDesk.
Every message must identify you accurately, with truthful headers and a subject line that is not misleading. Non-transactional email must include your physical mailing address, a working unsubscribe link and a link to your privacy policy. Honor unsubscribe requests promptly, and within 10 days at most. Keep bounce and complaint rates low; senders with high rates may be slowed or paused. Do not try to get around spam filtering, and do not send simulated phishing.
Our email provider does not carry sexually explicit material, escort, mail-order-bride or marriage-broker services, unapproved health claims, prescription-drug advertising, phishing, or pyramid schemes. Email about alcohol, tobacco, cannabis, firearms, gambling or adult content requires age verification.
7. Address lookups
AttackDesk includes Google Maps features and content, such as address suggestions and details. Use of Google Maps features and content is subject to the then-current versions of the Google Maps End User Additional Terms of Service (https://maps.google.com/help/terms_maps/) and the Google Privacy Policy (https://policies.google.com/privacy).
Use address results to fill in the address someone chose. Do not scrape, bulk-download, store or export Google Maps content beyond that, use it to create other data or to train AI models, or show it on a non-Google map. If you make AttackDesk's address lookup available to your own customers or website visitors, your terms must include the same Google Maps notice.
8. AI and automated agents
You are responsible for what your agents and automations do, including the messages they send, the money they spend, the records they change and the code they write. Give them only the permissions and budgets they need, keep human confirmation steps in place, and supervise them. Do not use agents to do anything this policy prohibits.
When an AI agent communicates directly with people for you, by text, email, phone or chat, do not present it as a human, and tell people they are interacting with AI where the law or the model's provider requires it. Do not use AI to impersonate a real person or organization, or to use someone's voice or likeness without their consent, in a way that could mislead people, and do not pass off AI-generated content as entirely human-made to deceive.
Do not use AI output to make decisions with legal or similarly significant effects on people, such as credit, employment, housing, insurance, education, legal, medical or government-service decisions, without review by a qualified person. Do not try to bypass a model's safety measures or test them adversarially without the provider's written approval.
AI provided through AttackDesk is part of AttackDesk and is for use within its features, such as the assistant, agents and other AI functions of your installation. Do not extract or use AttackDesk-provided AI keys, credentials or endpoints to reach models outside those features, share or resell that access, or use it to build a competing AI service. Tools you run against your installation, such as a coding agent, may use AttackDesk's AI features, but not the keys themselves for other purposes.
AI use through AttackDesk is also subject to the usage policy of the model's provider, which may be stricter than this policy, including Anthropic (https://www.anthropic.com/legal/aup), OpenAI (https://openai.com/policies/usage-policies/), Google (https://policies.google.com/terms/generative-ai/use-policy), DeepSeek (https://cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html) and BytePlus (https://docs.byteplus.com/en/docs/legal/acceptable_use_policy_byteplus_genai).
9. Reporting abuse
Report suspected abuse, spam, unauthorized access or a security problem involving AttackDesk using the contact address at the end of this page. Include what happened, when, and any identifiers you have, such as the phone number, sending domain, message or web address involved. Do not include passwords, API keys or other secrets.
Security researchers must not access other customers' data, disrupt services or keep data they encounter. Tell us promptly and give us a reasonable opportunity to fix the problem before disclosing it.
10. What we may do
If we reasonably believe this policy or the Terms are being broken, we may act in proportion to the risk. We may ask you to fix the problem, limit or pause a specific service, number, sender, key or feature, remove access for a person or agent, or suspend the account. Where there is a risk of harm to people, to other customers, to our providers or to legal compliance, we may act first and explain afterward.
Carriers and providers can also block traffic, suspend numbers or senders, or require changes under their own rules, independently of us. When we restrict something, we will tell you what was affected and what is needed to restore it when we reasonably can. You can ask us to review a restriction using the contact address at the end of this page.
Questions? support@attackdesk.com