Acceptable Use Policy

Version 1.0 · Effective 11 August 2026

d754e0c68e24e7e9e422c55a88bfc65a

1. PURPOSE AND SCOPE

This Acceptable Use Policy ("AUP") governs your use of the Gloora AI platform and services. It is incorporated into and forms part of the Terms of Service. Capitalised terms have the meaning given there.

This AUP applies to you, your staff, and anyone accessing the Services through your account. You are responsible for their compliance.

Why this matters: we deliver messaging, voice, and email through third-party providers — including Meta, telephony carriers, and email infrastructure. Misuse by one client can result in the suspension of infrastructure shared by all our clients. Our enforcement here is necessarily strict.

2. GENERAL PROHIBITIONS

You must not use the Services to:

  • (a) violate any applicable law, regulation, or industry code in any jurisdiction where you or your End Customers are located;
  • (b) infringe any intellectual property, privacy, publicity, or other right of any person;
  • (c) transmit content that is defamatory, obscene, harassing, threatening, hateful, or that incites violence or discrimination;
  • (d) transmit content that sexualises, endangers, or exploits minors — we report such activity to the relevant authorities without notice;
  • (e) impersonate any person or entity, or misrepresent your affiliation, identity, or the origin of a communication;
  • (f) engage in fraud, deception, phishing, pretexting, or any scheme to obtain money, credentials, or data by false pretences;
  • (g) operate or promote a pyramid scheme, multi-level marketing scheme, "get rich quick" offer, or investment scheme;
  • (h) distribute malware, ransomware, spyware, or any malicious or destructive code;
  • (i) transmit or facilitate the sale of illegal goods or services, including controlled substances, unlicensed pharmaceuticals, weapons, counterfeit goods, or stolen data;
  • (j) promote or facilitate gambling where it is unlawful for the recipient; or
  • (k) engage in any activity that would bring Gloora AI into disrepute.

3. MESSAGING, MARKETING, AND ANTI-SPAM

This is the most important section of this policy and the most common cause of account suspension.

3.1 Consent is mandatory

You may only contact individuals who have given you consent as required by the law applicable to them. You must be able to evidence that consent, including its date, method, and scope.

3.2 Prohibited sending practices

You must not:

  • (a) send to purchased, rented, scraped, harvested, appended, or otherwise non-consented lists — this is prohibited in all cases, without exception;
  • (b) send unsolicited commercial messages of any kind (spam);
  • (c) send to any individual who has opted out, unsubscribed, or requested no further contact;
  • (d) fail to honour an opt-out promptly, and in any event within the period required by applicable law;
  • (e) omit a clear and functional opt-out mechanism where the law requires one;
  • (f) disguise, falsify, or obscure the sender identity, originating number, return address, or routing information;
  • (g) use misleading subject lines, sender names, or message previews;
  • (h) send outside permitted calling or messaging hours in the recipient's local time zone;
  • (i) use the Services for cold outreach to individuals who have no existing relationship with your business;
  • (j) send to recipients in a jurisdiction where your messaging programme is not lawful; or
  • (k) engage in "snowshoeing", number rotation, content variation, or any technique intended to evade spam filtering or carrier detection.

3.3 Jurisdiction-specific obligations

You are responsible for compliance with all laws applicable to your recipients, including:

RegionKey obligations
United StatesTCPA — prior express written consent for SMS and automated/AI voice calls. CAN-SPAM. State telemarketing and auto-dialer laws. National and internal Do Not Call lists. Calling-hour restrictions.
CanadaCASL — express or valid implied consent, sender identification, functional unsubscribe.
EU / UKGDPR and UK GDPR lawful basis; ePrivacy/PECR rules on electronic marketing; soft opt-in limits.
UAE / GCCUAE PDPL; TDRA rules on direct marketing and bulk messaging; registration requirements for promotional SMS.
AllWhatsApp Business Messaging Policy and Meta commerce policies; carrier codes of conduct; 10DLC / sender-ID registration where applicable.

TCPA note: statutory damages are USD 500–1,500 per message or call. A single non-compliant campaign can generate claims far exceeding the value of your subscription. This is the largest legal risk in the Services and it is yours to manage.

3.4 Content restrictions

Regardless of consent, you must not use the Services to send messages relating to:

  • (a) regulated or restricted categories where prohibited by carrier or platform policy — including cannabis and CBD, tobacco and vaping, firearms, alcohol where restricted, prescription pharmaceuticals, adult content, payday and high-cost lending, debt relief, credit repair, and cryptocurrency solicitation;
  • (b) health claims that are false, unsubstantiated, or that you are not licensed to make;
  • (c) before-and-after imagery or treatment claims in breach of applicable health authority advertising rules; or
  • (d) any content prohibited by the WhatsApp Business Messaging Policy or your carrier.

4. AI SERVICES

You must not:

  • (a) disable, suppress, remove, or obscure any AI disclosure we provide, or configure an AI agent to deny that it is an AI system when asked;
  • (b) use AI Services to provide medical, dental, veterinary, legal, or financial advice, diagnosis, or treatment recommendations;
  • (c) configure AI agents to make binding commitments, guarantees, or representations you are not willing to honour;
  • (d) use AI Services to generate content that is deceptive, defamatory, discriminatory, or unlawful;
  • (e) generate deepfakes, voice clones, or synthetic likenesses of any real person without their documented consent;
  • (f) use AI Services to make automated decisions producing legal or similarly significant effects on an individual without appropriate safeguards and human review;
  • (g) attempt to jailbreak, prompt-inject, or otherwise manipulate the AI Services to bypass safety controls or extract system prompts, model weights, or training data;
  • (h) use output from the AI Services to train, fine-tune, or evaluate any competing AI model; or
  • (i) deploy AI Services without a means for an End Customer to reach a human.

Reminder: you remain responsible for all AI-generated content sent under your name, as if you had written it yourself.

5. DATA AND PRIVACY

You must not:

  • (a) upload protected health information (PHI) or GDPR Article 9 special category data — including health, biometric, genetic, racial or ethnic origin, religious belief, political opinion, sex life, or sexual orientation data — without a separate written addendum with us;
  • (b) upload payment card data other than through our designated payment processor;
  • (c) upload data relating to children under 16 without verifiable parental consent;
  • (d) upload data you do not have a lawful basis and all necessary consents to process;
  • (e) use the Services to conduct surveillance, tracking, profiling, or monitoring of individuals without their knowledge and lawful basis;
  • (f) attempt to re-identify de-identified or aggregated data; or
  • (g) access, or attempt to access, data belonging to another Gloora AI client.

This applies to free-text fields too. Client notes, appointment reasons, visit history, internal comments, and message content are all covered. Do not record clinical observations, diagnoses, treatments, medications, or medical history anywhere in the Services.

If you run a clinic, dental practice, medical spa, veterinary practice, physiotherapy practice, or similar business, use Gloora AI for booking, scheduling, contact management, and marketing — and keep clinical records in a system built and certified for that purpose.

If your business handles health data, contact support@gloora.ai before uploading it. Enhanced terms may be available. Uploading it without them is a material breach.

6. PLATFORM INTEGRITY AND SECURITY

You must not:

  • (a) reverse engineer, decompile, or disassemble the Services, or attempt to derive source code, model weights, system prompts, or architecture;
  • (b) use the Services to build, train, market, or operate a competing or substantially similar product;
  • (c) access the Services for benchmarking, competitive analysis, or feature or interface copying;
  • (d) resell, sublicense, rent, or share access, or operate the Services as a service bureau, except with our prior written consent;
  • (e) share account credentials, or permit access by anyone other than your authorised staff;
  • (f) circumvent or attempt to circumvent any usage limit, rate limit, quota, paywall, or access control;
  • (g) scrape, crawl, or use automated means to extract data, other than through our documented APIs and within their limits;
  • (h) conduct penetration testing, vulnerability scanning, or security research without our prior written consent — to request authorisation, email support@gloora.ai;
  • (i) impose an unreasonable or disproportionate load on our infrastructure, or interfere with any other client's use;
  • (j) probe, scan, or test the vulnerability of any system or network, or breach any security or authentication measure; or
  • (k) use the Services to attack, disrupt, or gain unauthorised access to any third-party system.

7. SANCTIONS AND RESTRICTED TERRITORIES

You must not use the Services:

  • (a) to transact with, or send communications to, any person listed on a sanctions list maintained by the UAE, United Nations, United States (including OFAC's SDN list), European Union, or United Kingdom;
  • (b) to send communications into a comprehensively sanctioned territory; or
  • (c) in breach of any applicable export control law.

8. REPORTING VIOLATIONS

If you become aware of any violation of this AUP, or of any security vulnerability, report it immediately:

TypeContact
Abuse, spam, AUP violationsupport@gloora.ai
Security vulnerabilitysupport@gloora.ai
Legal or data protection concernsupport@gloora.ai

We investigate all credible reports. We do not pursue good-faith security researchers who report vulnerabilities responsibly and do not access or exfiltrate data belonging to others.

9. ENFORCEMENT

9.1 Our rights

If we reasonably believe this AUP has been breached, we may — at our discretion, with or without prior notice, and in any combination:

  • (a) investigate, including by reviewing message content, metadata, and account activity to the extent lawful;
  • (b) require you to provide evidence of consent or remediate within a stated period;
  • (c) remove or block specific content or campaigns;
  • (d) throttle or restrict sending volume or specific features;
  • (e) suspend your account in whole or in part;
  • (f) terminate your account and these Terms;
  • (g) report the activity to law enforcement, a regulator, or an affected third-party provider; and
  • (h) pursue any other remedy available at law.

9.2 Immediate action without notice

We will act immediately and without prior notice where we reasonably believe there is: risk of harm to individuals; risk to the security or integrity of the Services; risk of legal or regulatory liability to us; risk to our relationship with a third-party provider such as Meta or a carrier; content involving minors; or activity that is clearly fraudulent or criminal.

9.3 No refund

Suspension or termination for breach of this AUP does not entitle you to any refund, and does not relieve you of fees accrued to the date of termination.

9.4 Your liability

You remain liable for all consequences of a breach, including under the indemnity at §19.1 of the Terms of Service. Your indemnity obligations are not subject to the liability cap.

9.5 Reinstatement

Where we suspend rather than terminate, we will explain what is required for reinstatement and restore access promptly once we are satisfied the issue is resolved. Repeat breaches will result in termination.

10. CHANGES TO THIS POLICY

We may update this AUP to address new abuse patterns, legal developments, or third-party provider requirements.

  • Material changes: at least thirty (30) days' notice by email.
  • Changes required by law or a third-party provider, or to address active abuse: effective immediately, with notice as soon as practicable.

The current version is always at gloora.ai/aup. Previous versions: gloora.ai/aup/archive.

11. QUESTIONS

If you are unsure whether a use is permitted, ask before you send. Email support@gloora.ai. We would much rather answer a question in advance than suspend an account afterwards.

GLOORA AI FZC LLC · AMC Boulevard-A Building, Ajman Media City, Ajman, UAE Trade Licence No. 50100 · VAT TRN 105295069600003

Acceptable Use Policy v1.0 — effective 11 August 2026.

Acceptable Use Policy | Gloora AI