Acceptable use

Acceptable Use Policy

The rules that protect your customers, your numbers, and the other merchants who share the same Platform — and what happens when they are broken.

Last updated: 15.09.2026

1. Who this policy applies to

This policy applies to you as a merchant, to every member of your team, and to every message, campaign, automation, or agent reply that leaves your account through the Platform — WhatsApp, Instagram, Messenger, X, the chat widget, and email. Anything a member of your organization does, or the agent does under your settings, is attributed to you.

The policy is part of the Terms & Conditions and complements them. Where it conflicts with a channel policy, the stricter rule applies. The detailed rules for each channel are in the Channel Policies, and the rules for the agent in the AI Policy.

3. Prohibited content

You may not use the Platform — yourself or through the agent — to sell, promote, or send:

  • Goods or services that are illegal in your country or in the customer's country.
  • Fraud, deceptive financial schemes, or false claims about a product (guaranteed results, therapeutic properties without a licence, a fake "original" price).
  • Counterfeit products or content that infringes someone else's intellectual property.
  • Hate, harassment, threats, or discrimination against any person or group.
  • Adult content where the channel's policy prohibits it (Meta, X, or the email provider).
  • Malware, phishing links, or any attempt to steal login credentials or card details.
  • Any content that violates Meta's policies (WhatsApp Business, Instagram, Messenger), the X rules, Stripe's terms, or your store platform's policies.
  • Regulated goods (medicines, supplements, tobacco, alcohol, weapons, financial services, and so on) without the licence required in the market you sell into.

If your product is allowed in one place and prohibited in another, you are responsible for restricting sending to the permitted markets.

4. Impersonation and deception

  • The agent does not claim to be human. When a customer explicitly asks whether they are talking to a bot, the agent answers honestly. You may not write rules or instructions that make it deny being an AI. You can give it a name and a personality, but not a fake human identity.
  • No impersonating another business or body. Do not present your store as someone else's brand, a government body, a bank, the payment provider, or even our Platform.
  • No fake reviews. Do not use the agent or campaigns to generate or solicit fake reviews, or to write reviews of your own products posing as a customer.
  • No false urgency. "Last one in stock" or "the offer ends in an hour" must be true. The agent reads inventory and coupons from your store, so do not instruct it to invent scarcity or deadlines that do not exist.

5. Misuse of the agent

The agent is built to serve your store's customers within clear limits. You may not use it, or attempt to use it, to:

  • Extract another organization's data on the Platform. Every query we run is scoped to the store, and an attempt to get around that scoping is a serious violation whether or not it succeeds.
  • Jailbreak the model or inject instructions through product descriptions, the knowledge base, or customer messages in order to change its behaviour.
  • Generate any of the prohibited content listed above.
  • Deliberately bypass the guardrails: raising the autonomy level or the discount and refund caps so that the agent makes financial commitments you would not have approved had they gone through a person, or working around the approval queue. The hard caps exist to protect you, not to be broken.
  • Use Capi (the manager agent) to execute an action without the human approval it asks for. Capi only proposes; the decision is yours.

How the agent works and what reaches the model provider is explained in the AI Policy.

6. Platform integrity

  • No probing or penetration testing without written permission. You may not scan, probe, pen-test, or send abnormal load against the Platform or our providers' infrastructure without our prior written consent. If you stumble on a vulnerability, report it to security@capiagent.com following the responsible-disclosure route on the Security page — we do not pursue researchers who report in good faith.
  • No bypassing limits. You may not circumvent plan limits, rate limits, or AI usage metering, whether through automation, multiple accounts, or any other means.
  • No scraping. You may not automatically extract data or content from the Platform outside the exports we provide in the dashboard.
  • No sharing credentials. Every member of your team signs in with their own account. You may not share passwords, two-factor codes, or API keys, and you may not hand your account to an outside party.
  • No reselling. You may not resell the Platform or offer it as a service to third parties without a written agreement with us.

7. Your third-party accounts

Your accounts with Meta, X, and your store platform are your responsibility, but their effects reach us: the WhatsApp, Instagram, and Messenger channels run through a single Meta app shared by all our merchants, and the quality of your WhatsApp number affects everyone's ability to send.

  • Keep your accounts in good standing: Meta, X, and store-platform policies respected, and business details accurate.
  • We monitor Meta's quality rating for every WhatsApp number every 6 hours, and we automatically throttle or defer sending when it drops. That slowdown protects your number; it is not a penalty.
  • If your use puts our shared app, number quality, or our relationship with Meta, X, or Stripe at risk, we suspend the channel or the account immediately and without prior notice, and tell you why afterwards.
  • If Meta, X, or your store platform restricts or bans your account, we cannot lift that restriction for you; we can only help with the information we have.

8. Data handling

  • Collect data lawfully only. You must have a legal basis (under the Saudi PDPL, the Turkish KVKK, or the EU GDPR as applicable) for every piece of customer data you enter into or sync to the Platform, and you must publish your own privacy notice naming us as a processor.
  • No sensitive data categories in conversations. Do not ask for or store, through the agent or campaigns, health data, detailed financial data, religious beliefs, or any other sensitive category — unless it is lawful and necessary to provide your product, in which case you are responsible for the legal basis and for configuring the agent accordingly.
  • No card numbers in chat. You may not ask a customer to type their card number, security code, or payment details on any channel. Payment happens on your store or through official payment links.
  • Respect data-subject rights. When a customer asks to delete, correct, or receive a copy of their data, act from the Customers page in the dashboard; if you need our help, we assist within 30 days at most.

The details are in the Privacy Policy and the Data Processing Agreement.

9. Monitoring and enforcement

How do we know? We do not read your conversations proactively. What we watch are automated signals: opt-out rate, Meta's quality rating for your numbers, spam complaints and reports that reach us from customers or providers, and rate-limit hits. We look at the content of a conversation only when we receive a specific report, when you ask us for support, or when the law requires it.

What do we do? Actions are graduated by severity and repetition:

  1. A warning by email and an in-dashboard notice explaining the violation and what is required.
  2. Feature limitation: pausing campaigns, lowering the sending cap, or disabling a specific channel.
  3. Account suspension: your data stays readable and exportable, but the agent, sending, and automations stop.
  4. Account termination under the termination section of the Terms & Conditions.
  5. Reporting to the competent authorities where the law requires it.

In severe cases — fraud, phishing, an attempt to reach another organization's data, or a risk to our shared Meta app — we go to suspension immediately, without passing through the first steps.

10. Reporting abuse

If you see the Platform being abused — whether you are a merchant, a customer of a store that uses us, or a security researcher — report it:

Tell us the store, number, or address the message came from, and attach a copy of the content if you can. We reply within 5 business days at most, and we do not share your identity with the reported party unless you agree or the law requires it.

11. Appealing an action

If we take an action against your account or channel and you believe it is a mistake, write to legal@capiagent.com from the email registered on your account, naming the action you received and the reason you see. A person on our team — not an automated system — reviews the appeal, and we reply within 5 business days at most. If the action turns out to be wrong, we restore your account to its previous state.

Throughout the appeal your data stays readable and exportable from the dashboard, unless continued access is itself the risk.

12. Changes to this policy

We may amend this policy when channel policies, laws, or Platform features change. We notify you of material changes by email or by an in-dashboard notice 30 days before they take effect. Changes imposed by Meta, X, or a change in the law may take effect sooner, and we explain why. The last-updated date is at the top of the page.

This page describes our actual enforcement practice and does not constitute legal advice. For any question or appeal, email us at legal@capiagent.com.