Draft — pending legal review.
This policy is part of the Terms of Service. It covers every use of the MobileValidate API, SDK, command-line tool, MCP server and any AI agent acting with your keys. We built the service for fraud prevention, deliverability, sign-up and passcode protection, and lead verification. Any use outside that purpose needs our written approval first.
What is the service for?
The service is for checking contact data you already hold for a legitimate business reason. Typical examples:
- screening sign-ups and one-time-passcode requests for fake or unreachable numbers;
- cleaning a customer list before a transactional or consented campaign;
- choosing the channel a customer who opted in can actually receive;
- checking that a web-form lead is plausible before a salesperson calls;
- screening inbound or outbound call numbers against spam-reputation signals.
What is prohibited?
You must not use the service, or let anyone else use it, to:
- Send unsolicited messages or calls in breach of the law, including marketing rules such as the TCPA, PECR, the ePrivacy rules, CAN-SPAM and their equivalents. The same applies to finding recipients for such messages.
- Enumerate identifiers. This means checking sequential or generated number ranges, or generated lists of e-mail addresses, to discover who uses a platform. It includes attempts to "find all users" of any app or service.
- Scrape, harvest or resell results to build contact databases, or offer the service or its results as a competing product.
- Stalk, harass, monitor or locate a person, or find out whether a specific private individual uses an app without a legitimate business reason.
- Build profiles of private individuals, or combine results with other data to identify people who have not dealt with you.
- Make eligibility decisions about credit, employment, housing, insurance or similar matters, or use results as a consumer report.
- Discriminate against anyone on the basis of results, or infer sensitive characteristics.
- Get around our controls, including rate limits, daily caps, spend caps, anti-enumeration rules, suppression and opt-outs, or entitlement to services. This covers splitting requests or spreading them across keys or accounts to avoid limits.
- Test or attack the service's security without written permission, or use test keys to probe live behaviour.
What do you promise us?
You confirm that:
- you have a lawful basis for every phone number and e-mail address you submit;
- you have given the people concerned any notice the law requires;
- you will honour opt-outs and objections.
You understand that results are signals observed at a point in time (checked_at). They are not proof of identity or ownership and cannot replace KYC or AML checks. A spam-reputation level of no_reports does not mean a number is safe. Checks never return names, photos or profiles, and you must not try to obtain them through the service.
How do we enforce this policy?
We monitor for abuse automatically. Requests that look like sequential number ranges or generated e-mail lists are rejected, and patterns such as repeated checks of the same person are reviewed.
If we reasonably suspect a breach, we may:
- ask you for information about your use case and lists;
- reduce limits;
- disable services for your account;
- suspend or revoke API keys;
- close the account.
We may act without notice where there is a risk to other people. Serious or repeated breaches can lead to termination. We may also report unlawful activity to the authorities. Credit used on prohibited activity is not refunded ([refund terms — pending]).
To report abuse of the service, contact [email protected].

