# Acceptable Use Policy

> Draft rules for using MobileValidate: fraud-prevention and deliverability uses, prohibited uses such as enumeration, stalking and spam, and enforcement.

Canonical: https://mobilevalidate.com/legal/acceptable-use · Last updated: 2026-09-25

> **Draft — pending legal review.**

This policy is part of the [Terms of Service](/legal/terms). It covers every use of the MobileValidate API, SDK, command-line tool, MCP server and any AI agent acting with your keys. We built the service for fraud prevention, deliverability, sign-up and passcode protection, and lead verification. Any use outside that purpose needs our written approval first.

## What is the service for?

The service is for checking contact data you already hold for a legitimate business reason. Typical examples:

- screening sign-ups and one-time-passcode requests for fake or unreachable numbers;
- cleaning a customer list before a transactional or consented campaign;
- choosing the channel a customer who opted in can actually receive;
- checking that a web-form lead is plausible before a salesperson calls;
- screening inbound or outbound call numbers against spam-reputation signals.

## What is prohibited?

You must not use the service, or let anyone else use it, to:

1. **Send unsolicited messages or calls** in breach of the law, including marketing rules such as the TCPA, PECR, the ePrivacy rules, CAN-SPAM and their equivalents. The same applies to finding recipients for such messages.
2. **Enumerate identifiers.** This means checking sequential or generated number ranges, or generated lists of e-mail addresses, to discover who uses a platform. It includes attempts to "find all users" of any app or service.
3. **Scrape, harvest or resell results** to build contact databases, or offer the service or its results as a competing product.
4. **Stalk, harass, monitor or locate** a person, or find out whether a specific private individual uses an app without a legitimate business reason.
5. **Build profiles of private individuals**, or combine results with other data to identify people who have not dealt with you.
6. **Make eligibility decisions** about credit, employment, housing, insurance or similar matters, or use results as a consumer report.
7. **Discriminate** against anyone on the basis of results, or infer sensitive characteristics.
8. **Get around our controls**, including rate limits, daily caps, spend caps, anti-enumeration rules, suppression and opt-outs, or entitlement to services. This covers splitting requests or spreading them across keys or accounts to avoid limits.
9. **Test or attack** the service's security without written permission, or use test keys to probe live behaviour.

## What do you promise us?

You confirm that:

- you have a lawful basis for every phone number and e-mail address you submit;
- you have given the people concerned any notice the law requires;
- you will honour opt-outs and objections.

You understand that results are signals observed at a point in time (`checked_at`). They are not proof of identity or ownership and cannot replace KYC or AML checks. A spam-reputation level of `no_reports` does not mean a number is safe. Checks never return names, photos or profiles, and you must not try to obtain them through the service.

## How do we enforce this policy?

We monitor for abuse automatically. Requests that look like sequential number ranges or generated e-mail lists are rejected, and patterns such as repeated checks of the same person are reviewed.

If we reasonably suspect a breach, we may:

- ask you for information about your use case and lists;
- reduce limits;
- disable services for your account;
- suspend or revoke API keys;
- close the account.

We may act without notice where there is a risk to other people. Serious or repeated breaches can lead to termination. We may also report unlawful activity to the authorities. Credit used on prohibited activity is not refunded ([refund terms — pending]).

To report abuse of the service, contact info@broadnet.me.
