Acceptable Use Policy

Last updated: September 2026

This Acceptable Use Policy (โ€œAUPโ€) describes the rules that apply to any party using any Iterable Products and Services. The AUP are incorporated into the Iterable Master Services Agreement (MSA) available at https://iterable.com/legal/master-services-agreement, https://iterable.com/legal/iterable-ireland-master-services-agreement, or a similar agreement executed between Iterable and Customer, as applicable (collectively, the โ€œAgreementโ€).

You understand that you are responsible for any of your usersโ€™ compliance with this AUP. The examples described in this AUP are not exhaustive. Inquiries regarding this policy should be directed to abuse@iterable.com. Channel-specific requirements may apply as set forth in the Product-Specific Terms at https://iterable.com/legal/product-specific-terms

For purposes of this AUP, โ€œMessagesโ€ means any electronic communication sent through the Services, including email, SMS, MMS, RCS, push notifications, in-app messages, web push, WhatsApp messages, embedded messages, and any other messaging channel supported by the Services. 

Capitalized terms not defined herein will have the meanings outlined in the Agreement. If there is a conflict between any of the documents that form part of the Agreement, the order of precedence shall be: (1) the applicable Enterprise Order; (2) the Product-Specific Terms; (3) this Acceptable Use Policy; and (4) the MSA.ย 

1. No Abuse

You may not use Iterableโ€™s Services to engage in, promote, or facilitate illegal, abusive, or irresponsible behavior, including:

  1. any activity or conduct that is likely to breach any applicable laws, codes, or regulations, including data protection and privacy laws, digital harm laws, and laws relating to unsolicited commercial electronic messages or wireless communications;
  2. collecting or using information, including email addresses, screen names, or other identifiers, by deceit (such as phishing, Internet scamming, password robbery, spidering, and harvesting);
  3. unauthorized access to or use of data, systems, or networks, including any attempt to probe, scan, or test the vulnerability of a system or network or to breach security or authentication measures without express authorization of the owner of the system or network;
  4. monitoring data or traffic on any network or system without the express authorization of the owner of the system or network;
  5. introducing intentionally, knowingly, or recklessly any virus or other contaminating code into the Services;
  6. distributing software that covertly gathers or transmits information about a user;
  7. any conduct that is likely to result in retaliation against Iterable or its employees;
  8. any action which directly or indirectly results in any of our IP space being listed on any abuse database;
  9. conducting any gambling or lottery activity in violation of any required licenses, codes of practice, or necessary technical standards required under the laws or regulations of any applicable jurisdiction;
  10. any action that is otherwise illegal or solicits conduct that is illegal under laws applicable to you or to Iterable; or
  11. any conduct that generates multiple direct abuse complaints for any sustained amount of time.

2. Anti-Spam Policy

You agree that your use of the Services is subject to Iterableโ€™s Anti-Spam Policy (https://iterable.com/legal/anti-spam-policy/) and those terms are incorporated here by reference.

Without limiting the application of any other provisions of this AUP or the Anti-Spam Policy, with respect to any of the Servicesโ€™ features or functionality, you may not:

  1. use the Services to verify the email address(es) of any person who has not directly and affirmatively consented (i.e., opted-in) to receiving email communications from you;
  2. use the Services to validate email addresses that were purchased, rented, or similarly obtained from a third party (i.e., third-party email lists);
  3. use the Services to harvest email addresses or otherwise determine the existence of unknown email addresses;
  4. use the Services to send any electronic mail message or wireless communication to any person who has opted out or otherwise objected to receiving such messages from you or anyone acting on your behalf; or
  5. use co-registration networks, lead brokers, list rental or resale services, traffic or post-conversion offer monetization platforms, or similar third-party acquisition methods where recipient consent is indirect, bundled, transferred, inferred, or unclear.

Any use of affiliate marketing or lead generation services is prohibited. All recipients must have provided direct, explicit, and informed opt-in consent to receive Messages from the customer by brand at the time of signup. Any practice that obscures the true source of consent, prevents recipients from reasonably understanding why they are receiving Messages or unsubscribing from them, or results in complaints directly to Iterable, Inc. is prohibited. Use of such services may result in immediate suspension or termination of Services.

3. Compliance with Laws and Regulations

You must comply with the laws and regulations applicable to Messages in your jurisdiction and the jurisdiction in which the recipient is located. In addition to complying with such laws and regulations, you agree that the following shall be included in your electronic communications through the Services:

a. Email-Specific Requirements.ย 

    1. You must be the sole or designated โ€œsenderโ€ of any email message you send using the Services.
    2. The โ€œfromโ€ line of any email message sent will accurately and in a non-deceptive manner identify you or your organization, product, or its services, and you must not obscure the source of your emails.
    3. The โ€œsubjectโ€ line of any email message sent will not contain any deceptive or misleading content regarding the overall subject matter of the email message.
    4. Every email message sent for marketing purposes using the Services must contain an โ€œunsubscribeโ€ link that allows subscribers to remove themselves from your mailing list, and a link to the then-current privacy policy; such links must remain operational for a period of 30 days after the date the message is sent.
    5. In the event โ€œunsubscribeโ€ is selected, you must be clear with the individual as to the details of the unsubscribe, and in the event you cannot or do not provide a detailed preference center, you must unsubscribe them from all channels and projects. You are responsible for configuring unsubscribe functionality within your use of the Services and ensuring it remains operational.
    6. You must have a privacy policy posted for each domain associated with the mailing.
    7. You must post an email address for complaints in a conspicuous place, you must promptly respond to messages sent to that address, and you must have the means to track anonymous complaints.
    8. Your intended recipients have given their consent to receive email via some affirmative means, such as an opt-in procedure.
    9. You must honor revocations of consent and notify recipients of the same. You are responsible for configuring and maintaining opt-out handling mechanisms within your use of the Services, and you must honor any reasonable attempt by a recipient to revoke consent or opt out, regardless of the method used.

    b. SMS, RCS, and Other Messaging Requirements.

    1. You have obtained express written consent (as defined under the TCPA or equivalent applicable law) from each recipient before sending any SMS, MMS, or RCS marketing message. You must make clear to the individual they are agreeing to receive messages of the type you intend to send, and you must keep a record of the consent (e.g., form signed, message signed, timestamp of completed signup flow).
    2. You understand that consent applies only to you and the specific use, project, or channel that the recipient has consented to; you cannot treat consent as blanket consent allowing you to send messages from other brands or companies you may have, or messages about other uses or campaigns.
    3. You must respect the message recipientโ€™s preferences in terms of frequency of contact.
    4. Every message you send must clearly identify you as the sender.
    5. Messages must include the ability to opt out and recipients must also have the ability to revoke consent at any time by replying with a standard opt-out keyword; for SMS and RCS messages, you must honor standard opt-out keywords (including STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, and QUIT) and process opt-outs promptly in compliance with applicable law and carrier requirements. You are responsible for configuring and maintaining opt-out handling mechanisms within your use of the Services, and you must honor any reasonable attempt by a recipient to revoke consent or opt out, regardless of the method used.
    6. You must ensure that no message recipient is younger than the legal age of consent based on where the recipient is located.
    7. You must ensure that the message content complies with all applicable laws of the jurisdiction in which the message recipient is located or applicable communications industry guidelines or standards.
    8. You must complete and maintain all carrier, platform, and industry registrations required to send Messages through the Services, including A2P 10DLC registration for SMS and agent verification for RCS, and you must not send Messages through the Services until such registrations are complete and approved.
    9. Your SMS and RCS message content and sending regions must comply with Iterableโ€™s Restricted SMS Content and Regions policy as described in the Documentation.

    4. Infringement of Laws or Standards

    You must not infringe any laws, regulations, industry standards, governmental orders, telecommunications providersโ€™ requirements, or carrier guidance (including without limitation privacy and export control laws) in any applicable jurisdiction in relation to Messages, including any of the preceding that require:

    1. consent be obtained prior to transmitting, collecting, processing, recording, or monitoring data or communications; and/or
    2. compliance with opt-out requests.

    These policies apply to any Messages sent using the Services, or, if applicable, to any Messages sent from any network by you or any person on your behalf that directly or indirectly reference or utilize the Services. These requirements apply to distribution lists created by third parties to the same extent as if you created the list. You must be able to provide proof that you have in place measures to ensure compliance with these restrictions.

    5. Use Guidelines

    Your use of Iterable Services is subject to the following:

    1. you will not use the Services to send unsolicited electronic or wireless communications (โ€œspamโ€);
    2. you will not use the Services to host content, including images and documents, that infringe on the intellectual property rights of others or otherwise include any obscene or libelous material or other material that violates any applicable law or regulation;
    3. you will import, access or otherwise use only lists for which all listed parties have legally consented to receive correspondence from you in connection with your use of the Services;
    4. you will not use the Services to send any commercial electronic mail messages or any wireless communications to any person who has opted out or otherwise objected to receiving such messages from you or another sender acting on your behalf;
    5. you will not use the Services to provide, sell, or offer to sell any of the following products or content (or services related to the same): pornography or illicitly pornographic sexual products, including but not limited to magazines, video, and software; escort services; dating services; adult โ€œswingerโ€ promotions; illegal goods; illegal drugs; illegal drug contraband; pirated computer programs; instructions on how to assemble or otherwise make bombs, grenades, or other weapons;
    6. you will not use Services to display or market material that exploits or harms children, or otherwise exploits children under 18 years of age, and you will not post or disclose any personally identifying information or private information about children without their consent (or their parentsโ€™ consent in the case of a minor);
    7. you will not market to third-party voter registration lists;
    8. you will not sell or promote any products or services that are unlawful in the location at which the content is posted or received;
    9. you will not use the Services to send Messages that violate the Telephone Consumer Protection Act or any other applicable telephone consumer protection law or regulation;
    10. you will not use the Services to send Messages without first completing all applicable carrier, platform, or industry registrations required for the applicable messaging channel; and
    11. you will not use the Services to send content that violates applicable carrier, aggregator, or platform provider content policies or that is identified as prohibited or restricted content under CTIA guidelines or equivalent industry standards.

    6. No Offensive Content or Materials

    You may not publish, transmit, or store on or via the Services any content or links to any content that Iterable reasonably believes:

    1. is violent, incites or threatens violence, contains harassing content or hate speech, creates a risk to a personโ€™s safety or health, or to public safety or health, compromises national security, or interferes with a law enforcement investigation;
    2. is unfair or deceptive under the consumer protection laws of any jurisdiction, including pyramid schemes or multi-level channel and network marketing (MLM) businesses, including personal work-at-home offers promoting liquidating retirement funds or other accounts, โ€œhot stocks,โ€ โ€œget rich quick,โ€ โ€œbuild your wealth,โ€ and โ€œfinancial independenceโ€ offerings;
    3. engages in any libelous, defamatory, scandalous, threatening, or harassing activity;
    4. provides material that is grossly offensive, abusive, bigoted, prejudiced, racist, hateful, profane, obscene, lewd, lascivious, filthy, excessively violent, harassing, inflammatory, or otherwise objectionable;
    5. constitutes, depicts, promotes, or relates in any manner to child pornography, bestiality, non-consensual sex acts, or otherwise unlawfully exploits persons under 18 years of age;
    6. provides content, including images, of authors, artists, photographers, or others without the express written consent of the content owner;
    7. is otherwise malicious, fraudulent, deceptive, misleading, or morally repugnant; or
    8. promotes any illegal activity, or advocates, promotes, or assists any unlawful act.

    7. AI-Generated Content

    If you use AI Features within the Services to generate or suggest message content, you remain solely responsible for reviewing, approving, and ensuring that all AI-generated content complies with this AUP, applicable laws, and platform policies before sending. AI-generated content is subject to the same restrictions as any other content sent through the Services.

    8. No High Risk Use

    You may not use the Services in any situation where failure or fault of the Services could lead to death or serious bodily injury of any person, or to physical or environmental damage. Without limiting the foregoing, the Services are not designed, intended, or authorized for use in connection with life support systems, emergency response systems, nuclear facilities, air traffic control, weapons systems, or any other application where service interruption or malfunction could result in loss of life, personal injury, or significant property or environmental harm.

    9. No Vulnerability Scanning and No Excessive Use

    You may not attempt to probe, scan, penetrate, or test the vulnerability of Iterable systems, networks, or Services, or to breach Iterable security or authentication measures, whether by passive or intrusive techniques.

    You may not use any shared system provided by Iterable in a way that unnecessarily interferes with the normal operation of the shared system, or that consumes a disproportionate share of the resources of the system.

    You agree that we may quarantine or delete any data stored on a shared system if the data is infected with a virus, or is otherwise corrupted, and has the potential to infect or corrupt the system or other customersโ€™ data that is stored on the same system.

    10. Export Controls

    The Services may not be used in violation of export laws, controls, regulations, or sanction policies of the United States or your applicable jurisdiction.

    The Services may not be used by persons, organizations, companies, or any such other legal entity or unincorporated body, including any affiliate or group company, which is involved with or suspected of involvement in activities or causes relating to: illegal gambling; terrorism; narcotics trafficking; arms trafficking or the proliferation, development, design, manufacture, production, stockpiling, or use of nuclear, chemical, or biological weapons, weapons of mass destruction, or missiles; in each case including any affiliation with others whatsoever who sponsor or support the above such activities or causes.

    11. Third Party Conduct

    You are responsible for violations of this AUP by anyone using the Services on your behalf or on an unauthorized basis as a result of your failure to use reasonable security precautions. You must use reasonable efforts to secure any device or network within your control against being used in breach of applicable laws against spam and unsolicited communications, including where appropriate by the installation of antivirus software, firewall software, and operating system and application software patches and updates. Our right to suspend or terminate your Services applies even if a breach is committed unintentionally or without your authorization, including through a Trojan horse or virus.

    If you use your own third-party messaging provider account (e.g., Telnyx or Twilio) in connection with the Services, you are also responsible for compliance with that providerโ€™s acceptable use policies.

    12. Mutual Conduct

    Both Parties will treat each otherโ€™s personnel with respect and dignity. This includes, without limitation, the following obligations:

    • No verbal or physical abuse of any kind directed at the other Partyโ€™s personnel;
    • No intrusive behavior toward the other Partyโ€™s personnel;
    • Respecting the physical integrity of all individuals; and
    • No harassment of personnel in any form.

    13. Changes to AUP and Consequences of Violation

    Digital, electronic, and wireless communication as well as privacy requirements are still evolving. Therefore, we may from time to time amend this AUP to further detail or describe reasonable restrictions on your use of our Services by publishing a revised version of the AUP.

    When a violation of this AUP is identified, where possible, we will work with you in good faith to restore compliance with this policy. However, to protect the continued ability of all our customers to freely use the Services for legitimate purposes, we reserve the right to immediately suspend or terminate your use of the Service(s) in the event you breach the AUP. We may intercept or block any content or traffic belonging to you or to users where Services are being used unlawfully or not in accordance with this AUP. To the extent credit is applicable for interruptions of service, no credit will be available for interruptions of service resulting from any AUP violation.