Inovamail Legal
Acceptable Use Policy
This Policy sets the rules for using Inovamail. In short: use the Service lawfully, don't send spam, don't attack our systems or anyone else's, and only use the Outreach Tools for lawful, individualized outreach. You are responsible for everything done under your Account, and we may suspend or terminate access for violations. This summary is for convenience and does not replace the full text below.
1. Purpose & Scope
1.1 This Acceptable Use Policy (this "Policy") governs all access to and use of the Inovamail encrypted email service, including the web application, IMAP/SMTP access, mobile and desktop applications, email aliases, custom domains, Fortress mode, automated workflows and integrations, Organizations, the Outreach Tools (as defined in Section 5), APIs, and any related software or features (collectively, the "Service"). The Service is operated by [LEGAL ENTITY NAME], doing business as Inovamail ("Inovamail", "we", "us").
1.2 This Policy is part of, and incorporated by reference into, the Inovamail Terms of Service (the "Terms"). Capitalized terms used but not defined in this Policy have the meanings given in the Terms. If this Policy conflicts with the Terms, the Terms control except where this Policy is expressly stricter, in which case the stricter provision applies to the conduct it addresses.
1.3 This Policy applies to everyone who accesses or uses the Service: individual account holders ("Account" holders), trial and free-tier users, paying subscribers, Organization administrators ("Admins"), Organization members ("Members"), and anyone accessing the Service through your credentials, applications, integrations, or API keys. By using the Service, you agree to this Policy. If you do not agree, you must not use the Service.
1.4 This Policy works together with our Anti-Spam & Outreach Policy, which contains additional binding rules for all sending activity, and our Copyright/DMCA Policy for intellectual-property complaints.
2. Your Core Responsibilities
2.1 Comply with all laws. You must use the Service in compliance with all laws, regulations, and third-party rights applicable to you and to your use, including (without limitation) anti-spam laws (such as Canada's Anti-Spam Legislation ("CASL") and the U.S. CAN-SPAM Act), privacy and data-protection laws (such as PIPEDA, the EU/UK GDPR, and applicable provincial and state laws), export-control and economic-sanctions laws, criminal laws, and laws governing electronic communications. Where this Policy is stricter than the law, this Policy applies; where the law is stricter, the law applies. It is your responsibility — not ours — to determine which laws apply to your activity.
2.2 You are responsible for your Account and Organization. You are solely responsible for all activity that occurs under your Account and, if you are an Organization or its Admin, under your Organization and its Members' accounts, and for all messages, files, lists, addresses, automations, and other material stored in, sent through, or generated by means of your Account or Organization ("Content") — whether or not you personally initiated the activity, and whether the activity was performed through the web application, IMAP/SMTP, an application password or API key, an automation, or a connected third-party service.
2.3 Keep credentials secure. You must keep your passphrase, private keys, recovery codes, two-factor authentication factors, application passwords, and API keys confidential and secure, and you must notify us promptly at [ABUSE EMAIL] of any suspected unauthorized access. Because of Inovamail's zero-knowledge design, we cannot recover a lost passphrase or private key; safeguarding credentials is entirely your responsibility.
You own the consequences. Activity under your credentials is treated as your activity. Compromise of your credentials does not relieve you of responsibility under this Policy for activity that occurs before you notify us and we are reasonably able to act.
3. Prohibited Content
3.1 You must not create, store, upload, transmit, distribute, or solicit through the Service any Content that:
- Is illegal — Content that is unlawful under the laws of Canada, the laws applicable where you or your recipients are located, or that facilitates any illegal activity;
- Exploits children — child sexual abuse material ("CSAM") or any Content that sexualizes, exploits, or endangers minors. We maintain zero tolerance: we will terminate implicated accounts, preserve available evidence, and report to law enforcement and applicable child-protection authorities as required or permitted by law, without prior notice to you;
- Infringes intellectual property — Content that infringes any copyright, trademark, patent, trade secret, or other proprietary right of any person. See our Copyright/DMCA Policy for notice-and-takedown procedures;
- Is malicious or fraudulent — malware, ransomware, viruses, worms, trojans, or other harmful code; phishing, pharming, or credential-harvesting material; forged or spoofed messages; fraudulent schemes, scams, pyramid or Ponzi schemes, advance-fee fraud, or material intended to deceive or defraud any person;
- Is hateful, harassing, or violent — Content that promotes hatred against identifiable groups, harasses, stalks, bullies, or threatens any person, or that incites, glorifies, or threatens violence or terrorism;
- Violates privacy — Content that discloses another person's personal information, private communications, intimate images, or confidential data without lawful authority ("doxxing"), or that was obtained through unauthorized access or surveillance.
3.2 End-to-end encryption does not exempt Content from this Policy. Encrypted Content remains subject to this Policy even though Inovamail cannot read it; violations may be established through metadata, recipient complaints, law-enforcement information, or any other lawful means.
4. Prohibited Conduct
4.1 You must not, and must not permit or enable any third party to:
- Send spam or unsolicited bulk messages — send unsolicited bulk or commercial electronic messages, or otherwise violate our Anti-Spam & Outreach Policy, which is incorporated into this Policy and applies to all sending through the Service;
- Attack or probe systems — conduct unauthorized security testing, vulnerability scanning, port scanning, or penetration testing of the Service or of any third-party system; access or attempt to access any account, system, or data without authorization; or intercept communications not intended for you;
- Reverse engineer — reverse engineer, decompile, disassemble, or attempt to derive the source code, cryptographic implementations, or underlying design of the Service, except to the limited extent such restriction is prohibited by applicable law;
- Scrape or automate access to the Service — use robots, crawlers, scrapers, or other automated means to access the Service or extract data from it, except through the documented APIs and features we provide, and then only within their documented limits;
- Circumvent controls — bypass, disable, or interfere with rate limits, sending quotas, plan limits, Fortress mode, sender-verification challenges, authentication, encryption enforcement, or any other security or abuse control of the Service, or assist anyone in doing so;
- Overload the Service — take any action that imposes an unreasonable load on our infrastructure, or launch, relay, or facilitate denial-of-service attacks, mail bombs, or similar disruptive activity against the Service or any third party;
- Deceive as to sender identity — impersonate any person or entity, forge headers, spoof sender addresses or domains you are not authorized to use, or otherwise misrepresent the origin of any message. Use of aliases and custom domains is permitted only for addresses and domains you control or are authorized to use, and does not excuse compliance with sender-identification requirements under applicable law;
- Violate sanctions or export controls — use the Service in violation of Canadian, U.S., EU, UK, or other applicable economic-sanctions or export-control laws, or use the Service if you are located in a comprehensively embargoed territory or are a sanctioned or denied party;
- Resell without authorization — resell, rent, lease, sublicense, or provide the Service to third parties as a service bureau or managed offering, except as expressly permitted by the Terms (for example, administering Members within your own Organization) or a separate written agreement with us;
- Build a competing product — access or use the Service to build, benchmark for, or improve a product or service that competes with the Service, or copy its features, functions, or user interface for that purpose.
5. Outreach Tools & Email Discovery
5.1 The Service includes features that discover publicly available email addresses from the public web at a rate-limited pace and allow you to send messages to them individually, one at a time (the "Outreach Tools"). The Outreach Tools are provided as a neutral technical instrument for lawful, individualized professional outreach. Inovamail does not select your recipients, compose your messages, or direct your outreach in any way.
You are the sender. For every address you discover, upload, import, or contact using the Outreach Tools, you are the sole sender of the resulting messages and the sole data controller (or equivalent responsible party under applicable law) for those addresses and any associated personal information. Inovamail acts, at most, as a technical intermediary and processor acting on your instructions.
5.2 You may use the Outreach Tools only for lawful, individualized outreach for which you have a lawful basis — and, where required, the consent — mandated by every law applicable to you and each recipient, including CASL, the CAN-SPAM Act, the GDPR/UK GDPR and ePrivacy rules, and all other applicable anti-spam, privacy, and marketing laws. You represent and warrant to us, each time you use the Outreach Tools, that this is true for every message and every address.
5.3 You must not use the Outreach Tools (or any other part of the Service) to harvest, compile, or aggregate email addresses for bulk or unsolicited messaging; to build, sell, rent, or share marketing lists; or to generate addresses by guessing or dictionary techniques. Address harvesting and the use of harvested address lists are prohibited by this Policy and by law (see the Anti-Spam & Outreach Policy, including its discussion of section 82 of CASL).
5.4 All use of the Outreach Tools is subject to the Anti-Spam & Outreach Policy, including its requirements for consent, sender identification, unsubscribe mechanisms, suppression lists, and rate limits.
5.5 No warranty on discovered addresses. Inovamail does not verify, and makes no representation or warranty whatsoever, that any address returned by the Outreach Tools is accurate, current, deliverable, associated with any particular person, or lawful for you to contact. Discovered addresses are raw material from the public web; the decision to contact any address — and all legal consequences of that decision — are yours alone.
6. Automated Workflows & Integrations
6.1 The Service allows you to configure automated workflows, triggers, and integrations with third-party applications and services. Anything an automation or integration does under your Account is deemed done by you. You are solely responsible for the configuration, behaviour, and output of your automations and for any third-party service you connect, including that service's security, availability, data handling, and terms.
6.2 Automations and integrations must respect the Service's rate limits, quotas, and technical controls, and must not be used to send unlawful messages or bulk unsolicited messages, to circumvent Section 4 or 5, or to multiply sending in a way that defeats the individualized-sending design of the Outreach Tools.
6.3 Inovamail is not responsible for third-party applications or services, does not endorse them, and may suspend or disable any integration that we reasonably believe is causing harm, abuse, or a violation of this Policy.
7. Organizations
7.1 If you create or administer an Organization, you and the Organization are responsible for ensuring that every Member complies with this Policy, the Terms, and the Anti-Spam & Outreach Policy. Admins must configure Member accounts, addresses, and permissions responsibly and must promptly disable access for Members who violate this Policy or who leave the Organization.
7.2 A breach by any Member is attributable to the Organization. We may take enforcement action under Section 9 against the individual Member account, the Organization, or both, and the Organization remains responsible under the Terms (including indemnification obligations) for its Members' acts and omissions.
8. Reporting Abuse
8.1 If you believe the Service is being used in violation of this Policy — including to send spam, phishing, malware, threats, or CSAM — please report it to [ABUSE EMAIL]. Include the full message headers and any other information that may help us investigate. We review abuse reports but cannot guarantee a response to every report.
8.2 For copyright complaints, use the process in our Copyright/DMCA Policy. For privacy concerns, see our Privacy Policy or contact [PRIVACY EMAIL].
9. Enforcement
9.1 We may — but are not obligated to — investigate suspected violations of this Policy. Because of the Service's end-to-end encryption and zero-knowledge design, we cannot read E2E-encrypted Content; investigations may rely on traffic and volume metadata, delivery and bounce data, recipient complaints, information from law enforcement or anti-abuse organizations, unencrypted Content, and other lawful sources.
9.2 If we believe, in our sole discretion acting in good faith, that you or your Organization has violated this Policy, we may take any action we consider appropriate, including one or more of the following, with or without notice:
- remove, disable access to, or refuse to transmit any Content;
- throttle, rate-limit, or restrict sending or other features (including the Outreach Tools);
- suspend or terminate your Account, Organization, or any Member account;
- preserve, and where lawful or required disclose, evidence and account records;
- cooperate with, and report violations to, law enforcement, regulators (including the CRTC), and industry anti-abuse bodies; and
- pursue any other remedy available under the Terms or at law.
No liability for good-faith enforcement. To the maximum extent permitted by applicable law, Inovamail will have no liability to you or any third party for any action taken in good faith under this Section 9, including suspension or termination of access, removal of Content, throttling of sending, or disclosure to authorities — even if the action later proves to have been based on incomplete or incorrect information. Fees are not refunded for periods of suspension or following termination for breach, except where required by law or the Refund Policy.
9.3 No obligation to monitor. We do not undertake to monitor Content or use of the Service, and nothing in this Policy creates such an obligation. We reserve the right (but have no duty) to monitor use of the Service to the extent technically possible and legally permitted, to operate and protect the Service and to verify compliance with this Policy.
9.4 Enforcement in one instance does not obligate us to enforce in any other. Our failure to act on a violation is not approval of it and is not a waiver of our rights.
10. No Waiver; Changes to This Policy
10.1 No waiver. No failure or delay by Inovamail in exercising any right or remedy under this Policy operates as a waiver of that right or remedy, and no single or partial exercise precludes any further exercise. Any waiver must be express and in writing to be effective, and applies only to the specific instance for which it is given.
10.2 Changes. We may update this Policy from time to time, for example to address new features, new forms of abuse, or changes in law. The "Last updated" date above reflects the current version. Material changes will be notified as described in the Terms of Service. Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy; if you do not agree, you must stop using the Service.
10.3 Questions about this Policy may be sent to [LEGAL EMAIL].