Acceptable Use Policy
Version 2026.2 · Last updated July 24, 2026
Overview
Scope
This Acceptable Use Policy (the "AUP") governs your use of RevDesk. It is incorporated into the Terms of Service and applies to you, to everyone in your workspace, and to anyone you allow to use the Services on your behalf.
RevDesk connects to the public telephone network. That means some of the rules below are not ours: they come from carriers, from the CTIA, and from regulators, and we are obliged to enforce them. Where a rule has an external source, we say so, because it explains why we cannot make exceptions to it.
General Prohibitions
You may not use the Services to:
- Violate any law, regulation, or third-party right
- Infringe intellectual property rights
- Harass, abuse, threaten, defame, or harm anyone
- Impersonate a person or entity, or misrepresent your affiliation with one
- Interfere with or disrupt the Services, our infrastructure, or another customer's use
- Attempt to gain unauthorized access to any system, account, or data
- Probe, scan, or test the vulnerability of our systems without written authorization
- Scrape or access the Services by automated means outside our documented API
- Resell or white-label the Services except under an executed partner agreement
- Use the Services for fraudulent, deceptive, or misleading purposes
Calling and Messaging
Calling Rules
These rules apply to every outbound call you place through RevDesk, whether dialed by a person or by an AI agent.
You may not:
- Spoof or falsify caller ID. You may only display a number you own or are authorized to use, and only where the display is not intended to defraud or mislead. Falsifying caller ID with intent to defraud is a federal offense under the Truth in Caller ID Act.
- Evade STIR/SHAKEN attestation or any other call-authentication or traceback mechanism, including by rotating numbers to avoid reputation scoring.
- Engage in access stimulation or traffic pumping, or generate artificially inflated traffic of any kind.
- Commit toll fraud, or route traffic to premium-rate or high-cost destinations for revenue rather than a genuine business purpose.
- Make marketing calls without documented prior express written consent where the law requires it. AI-generated voice is treated as an artificial voice under the TCPA, which means AI marketing calls require that consent even where a live agent would not.
- Call numbers on the National Do Not Call Registry, on a state registry, or on your own internal do-not-call list, outside a recognized exemption.
- Call outside permitted hours. Federal rules allow 8:00 a.m. to 9:00 p.m. in the recipient's local time. Several states are narrower, and the stricter rule governs.
- Abandon calls beyond the rate permitted by the Telemarketing Sales Rule, or place silent calls.
- Record without the consent your jurisdiction requires. See Call Recording for the state-by-state position.
Disclosing that the caller is an AI
A growing number of jurisdictions require you to disclose that a caller is interacting with an AI, including California's bot-disclosure law and, from 2 August 2026, Article 50 of the EU AI Act. RevDesk provides localized disclosure phrasing you can place in your agent's greeting. Deciding whether a disclosure is required, and making sure it is actually present, is your responsibility.
Messaging Rules
These rules apply to every messaging channel you use through RevDesk. The consent, opt-out, and content rules below are channel-independent: they hold whether you are sending SMS, iMessage, WhatsApp, or anything else.
On top of them, each channel carries its own platform rules, and those are not ours to waive. US carriers govern SMS through A2P 10DLC. Apple and Meta each impose their own business-messaging policies, including limits on who you may message first and how long you have to reply. Where a channel restricts a message type we would otherwise permit, the channel's rule wins.
Registration (SMS)
- You must register your own brand and campaign for A2P 10DLC before sending, and the registration data you give us must be accurate and current. Submitting false or borrowed business details is grounds for immediate suspension.
- Your published opt-in flow, privacy policy, and message samples must match what you actually send. Carriers audit this.
- You may not snowshoe, meaning spread traffic across numbers or campaigns to dilute filtering, or send campaign traffic through a number registered for a different purpose.
Consent and opt-out
- Collect and retain proof of opt-in for every recipient, per channel.
- Honor STOP, UNSUBSCRIBE, CANCEL, END, and QUIT immediately, and honor HELP with a reply identifying you and giving a contact method.
- Never send to a recipient who has opted out, from any number.
- Identify yourself in your messages, and do not obscure who is sending.
Prohibited content
Carriers and messaging platforms block the following outright, commonly called SHAFT plus the high-risk categories:
- Sex, hate, alcohol, firearms, and tobacco or vaping content
- Cannabis and CBD, including in states where it is legal
- Illegal substances and paraphernalia
- Gambling, sweepstakes, and contests, absent an approved carrier exception
- High-risk financial services, including payday loans, debt relief, and debt collection
- Get-rich-quick offers, multi-level marketing, and work-from-home schemes
- Phishing and smishing, credential harvesting, malware links, and URL shorteners on shared domains
Some of these are permitted with a specific carrier approval. If you have one, contact us before you send.
Data and Enforcement
Data You Bring
For every contact, phone number, and list you upload or sync into RevDesk, you represent that:
- You have a lawful basis to hold and process it, and to contact the person on each channel
- You obtained it lawfully, and not from a purchased or scraped list you cannot document
- You have given the notices the applicable privacy law requires
- You will keep opt-outs and suppression current, and will not re-import a suppressed contact
You may not upload special-category or highly sensitive data, including protected health information, unless your workspace is configured for it under an executed agreement. HIPAA mode plus a signed BAA is required before any PHI enters the platform.
You may not use the Services, or their output, to build a competing product, to train a machine learning model, or to compile a database for resale.
Enforcement
Where circumstances allow, we will contact you and give you a chance to fix a problem before taking action. Often they do not allow it. Carrier and regulator mandates arrive with immediate effect, and a live spam or fraud incident harms recipients and every other customer sharing our routes.
We may, without prior notice:
- Throttle or block specific traffic, numbers, or campaigns
- Suspend a campaign, a number, or the workspace
- Terminate the account for a serious or repeated violation
- Preserve and disclose records where law, legal process, or a traceback requires it
When we act immediately
We suspend first and discuss afterwards when a carrier or regulator directs us to, when there is active fraud or a security incident, when traffic is causing recipient harm, or when continuing would put our platform registrations at risk.
Suspension for a violation does not entitle you to a refund. See the Subscription and Payment section of the Terms.
To report abuse originating from RevDesk, or to appeal an enforcement action, email compliance@revdesk.com. Security vulnerabilities go to security@revdesk.com.