Acceptable Use Policy
Last updated: 2026-07-07
1. Scope and purpose
This Acceptable Use Policy ("AUP") applies to all use of Hail, the developer platform operated by Hail HQ ("we," "us"), by any Developer. "Developer" means the organization or individual whose account is used to trigger outbound communications through Hail's API, MCP interface, or CLI. "Recipient" means any person who receives a call, SMS, or email that a Developer triggers via Hail. Recipients are not Hail's customers.
This AUP applies only to Hail's hosted cloud product. It does not apply to self-hosted deployments of Hail's open-source software, which are licensed under AGPLv3. A party that self-hosts Hail is an independent data controller and operator of its own instance; Hail HQ has no processor or controller relationship to, no visibility into, and no liability for self-hosted deployments or how they are used.
This AUP is incorporated into, and forms part of, Hail's Terms of Use. Terms not defined here have the meaning given in the Terms of Use. In the event of a conflict between this AUP and the Terms of Use, this AUP governs with respect to acceptable use.
2. Your responsibility as a Developer
Hail is a platform: Developers programmatically trigger outbound voice calls, SMS/text messages, and email to Recipients they choose. Hail does not select Recipients, does not draft Developer content, and — except as described in Section 6 — does not verify in advance that a Developer has a lawful basis or valid consent to contact a given Recipient.
You, the Developer, are solely responsible for:
- ensuring you have all consent required by law from each Recipient before contacting them through Hail;
- ensuring you have a lawful basis to process Recipient data and to contact each Recipient;
- the content of every call, message, and email you trigger through Hail; and
- complying with all applicable law, including the telecommunications and marketing laws described in Section 4.
Hail performs limited compensating controls today (such as email verification at signup and account velocity caps on outbound volume). These controls are fraud- and abuse-mitigation measures for Hail's own risk management. They are not, and must not be relied upon as, a substitute for the Developer's own consent and compliance obligations.
3. Hard bans — absolutely prohibited uses
The following uses of Hail are prohibited without exception. Violation of any item in this section is grounds for immediate suspension or termination under Section 7, regardless of intent or whether harm resulted.
You may not use Hail, or permit Hail to be used, to:
- Commit or facilitate fraud or scams, including but not limited to advance-fee fraud, investment or financial scams, fake prize or lottery notifications, tech-support scams, or any scheme intended to deceive a Recipient for financial or material gain.
- Conduct phishing or vishing — attempting to induce a Recipient, through calls, SMS, or email, to reveal passwords, one-time passcodes, payment card details, bank credentials, or other sensitive credentials or personal data under false pretenses.
- Impersonate any person or entity, including impersonating a government agency, bank, law enforcement, healthcare provider, or any real business or individual without authorization, or otherwise misrepresenting your identity or affiliation to a Recipient.
- Harass any Recipient, including repeated unwanted contact after a request to stop, threatening or abusive communications, or communications intended to intimidate, alarm, or degrade a Recipient.
- Send robocalls or telemarketing communications without the consent required by applicable law. This includes any prerecorded or AI-generated voice call, autodialed call, or marketing message sent to a Recipient who has not given the consent required under the laws described in Section 4, or who has opted out or is on a suppression list as described in Section 5.
- Call emergency service numbers or emergency lines (including numbers such as 911, 112, 999, or their local equivalents in any jurisdiction), or otherwise target Hail-triggered communications at emergency services.
- Deceive Recipients about the AI nature of a call or message. Where a call or message is generated or delivered by an AI system (including Hail's own AI voice agent), you may not represent to the Recipient, or allow the Recipient to reasonably believe, that they are speaking with a human when they are not. You must not instruct or configure the AI voice agent to deny its automated nature if asked, or to otherwise conceal that the interaction is automated, where disclosure is required by applicable law or is directly asked by the Recipient.
4. Compliance with telecommunications and marketing law
You must comply with all laws applicable to your communications and your Recipients, including without limitation:
- The Telephone Consumer Protection Act (TCPA) and its implementing regulations, for calls and messages to Recipients in the United States, including requirements around prior express consent, calling hours, and do-not-call registries.
- The ePrivacy Directive and, where applicable, the UK Privacy and Electronic Communications Regulations (PECR), for calls and messages to Recipients in the United Kingdom or the European Union, including consent requirements for direct marketing by electronic means.
- The CAN-SPAM Act, for email sent to Recipients in the United States, including accurate header and subject-line information, identification of the message as an advertisement where required, disclosure of a valid physical postal address, and a working opt-out mechanism.
This list is illustrative, not exhaustive. You are responsible for identifying and complying with every law applicable to each Recipient based on their location and the channel used, including any law not listed above.
5. Opt-out and suppression requests
You must honor, promptly and without exception, any opt-out, unsubscribe, or suppression request from a Recipient, regardless of the channel on which it is received. This includes:
- immediately ceasing further calls, messages, or emails to a Recipient who has asked to stop, opted out, or requested to be placed on a do-not-contact or suppression list; and
- not circumventing, re-adding, or otherwise contacting a Recipient through Hail (or attempting to reach the same Recipient through a different channel) after an opt-out request, except where the Recipient affirmatively re-opts in.
Hail implements platform-level suppression mechanisms (for example, an unsubscribe/do-not-contact list checked before a call, message, or email is sent). Use of these mechanisms does not relieve you of your independent obligation to maintain and honor your own suppression records.
See our SMS Terms & Opt-Out for the SMS-specific keywords and disclosures.
6. Prohibited destinations
You may not use Hail to:
- place calls or send messages to premium-rate numbers or other destinations designed to generate per-call or per-message charges to the called party or to Hail; or
- call or message emergency services numbers, as described in Section 3(6).
Hail provisions all outbound telephone numbers through its own Twilio account; Developers may not bring their own carrier account, and may not attempt to route Hail-triggered communications through unauthorized carriers or numbers to evade the restrictions in this AUP.
7. Enforcement
Hail takes violations of this AUP seriously. Depending on the nature, severity, and recurrence of a violation, Hail may take any of the following actions, in its discretion and without prior notice where warranted by risk of harm:
- Warning — notice to the Developer identifying the violation and requiring corrective action within a specified period.
- Suspension — temporary suspension of some or all of the Developer's ability to trigger calls, messages, or email through Hail, pending investigation or corrective action.
- Termination — permanent suspension or termination of the Developer's account and access to Hail.
- Cooperation with law enforcement — where Hail reasonably believes a violation may involve criminal conduct (including fraud, phishing, or impersonation as described in Section 3), Hail may preserve relevant records and cooperate with law enforcement or regulatory authorities, including by providing information about the Developer and the communications in question where legally required or permitted.
These enforcement actions are in addition to, and do not limit, Hail's suspension and termination rights under the Terms of Use. Nothing in this AUP obligates Hail to take any particular enforcement action, or to take action within any particular time frame, and Hail may act immediately and without warning for violations of Section 3.
8. Reporting violations
If you believe a Developer is using Hail in violation of this AUP, including to contact you without consent or in a manner described in Section 3, contact hi@hail.so.
9. Changes to this policy
Hail may update this AUP from time to time. Material changes will be communicated to Developers in accordance with the notice provisions of the Terms of Use. Continued use of Hail after an update constitutes acceptance of the revised AUP.