Keldio
FeaturesPricingContactGet Started
Legal

Acceptable Use Policy

Rules for using Keldio responsibly, including email, checkout, content, privacy, security, integrations, APIs, MCP tools, automations, and connected agents.

Keldio Acceptable Use Policy

Last updated: 17 August 2026 Effective date: 6 May 2026 Document version: 1.0

This Acceptable Use Policy (the "AUP") forms part of the Keldio Platform Terms of Service. It explains what is not allowed on or through Keldio. It applies to Tenants, Admin Users, team members, contractors, agencies, connected agents, scripts, API consumers, MCP clients, and anyone acting through a Keldio Workspace.

Keldio gives businesses powerful tools: websites, funnels, checkout, CRM, email, member portals, automations, webhooks, APIs, MCP tools, and agent access. Those tools must be used responsibly. If activity creates legal, security, deliverability, privacy, reputational, payment, infrastructure, or platform risk, Keldio may restrict or stop it.

1. Core rule

You must not use Keldio to do anything unlawful, abusive, deceptive, unsafe, invasive, infringing, exploitative, or harmful to Keldio, other Tenants, End-Users, third-party providers, payment networks, email networks, ad networks, social platforms, or the public.

You are responsible for everything that happens through your Workspace, including activity by invited users, employees, contractors, agencies, scripts, automations, API keys, MCP keys, and external AI agents or operational agents connected by you.

1A. Cooperation and enforcement evidence

You must cooperate reasonably with Keldio when Keldio investigates suspected abuse, provider complaints, security issues, payment risk, rights complaints, unlawful content, or violations of this AUP. You must provide accurate information, preserve relevant records, stop or remediate risky activity when requested, and not delete, alter, conceal, or move activity for the purpose of evading investigation or enforcement.

Keldio may rely on metadata, complaints, provider notices, payment-provider signals, delivery/reputation signals, public content, support records, audit logs, automated detections, security telemetry, customer or End-User reports, and limited content review where reasonably necessary to assess risk. Keldio is not required to prove a legal violation beyond doubt before taking protective action where there is a reasonable risk to Keldio, other Tenants, End-Users, providers, payment networks, email networks, social platforms, regulators, or the public.

2. Illegal or regulated activity

You must not use Keldio for:

  • illegal goods, services, transactions, instructions, or content;
  • fraud, scams, pyramid schemes, deceptive offers, fake scarcity, fake testimonials, fake earnings claims, impersonation, or misleading identity claims;
  • evading sanctions, export controls, anti-money-laundering rules, tax obligations, payment-provider rules, or court/regulatory orders;
  • selling, facilitating, or promoting products or services that are illegal in the relevant jurisdiction;
  • regulated activity without the licences, registrations, disclosures, consents, and safeguards required for your business;
  • activity that would cause Keldio or its providers to violate law, contract, payment-network rules, platform policies, or regulatory duties.

Keldio may refuse or restrict businesses in high-risk sectors, including financial advice, credit repair, investment schemes, gambling, adult content, weapons, drugs, medical/health claims, political campaigning, surveillance, biometric identification, high-risk employment decisions, or other sensitive uses.

3. Spam, email, messaging, and deliverability abuse

You must not use Keldio to send spam or unlawful communications. This includes:

  • sending email, SMS, social messages, or other communications without the required lawful basis or consent;
  • using purchased, scraped, harvested, rented, or unlawfully obtained contact lists;
  • ignoring unsubscribe, suppression, bounce, complaint, or opt-out signals;
  • hiding sender identity or using misleading subject lines, domains, from names, reply-to addresses, or tracking links;
  • sending malware, phishing, credential-harvesting messages, deceptive invoices, fake payment requests, or impersonation messages;
  • attempting to bypass sending limits, throttles, suppression lists, domain checks, provider controls, or deliverability safeguards;
  • using Keldio in a way that damages Keldio's or another Tenant's sender reputation, domain reputation, IP reputation, payment standing, or provider relationships.
  • sending purchased-list campaigns, scraped-list campaigns, list-bombing messages, snowshoeing campaigns, misleading-header campaigns, spoofed-domain campaigns, unlawful affiliate or lead-generation campaigns, or campaigns designed to evade provider limits, suppression lists, complaint thresholds, throttling, or enforcement systems.

You are responsible for SPF, DKIM, DMARC, unsubscribe handling, consent records, message content, audience targeting, and compliance with applicable electronic-communications laws.

You must not use Keldio-managed or Tenant-configured email infrastructure in a way that damages or threatens Keldio's sending reputation, provider relationships, IP/domain reputation, legal standing, platform availability, other Tenants, or recipients. Keldio may pause, throttle, block, review, or terminate sending and preserve evidence where we reasonably suspect email or messaging abuse.

You must not use inboxes, support channels, email replies, support bubble features, attachments, MCP/API inbox tools, or other communication features to upload, send, store, forward, or induce others to open malware, phishing material, credential-harvesting content, unlawful files, non-consensual intimate material, exploit payloads, abusive or harassing messages, deceptive invoices, fake payment requests, impersonation messages, or content that violates another person's privacy, intellectual-property rights, or confidentiality rights.

4. Privacy, tracking, pixels, and data misuse

You must not use Keldio to collect, import, enrich, combine, transmit, disclose, or otherwise process personal data unlawfully.

You must not:

  • upload data you are not authorised to process;
  • scrape, harvest, buy, sell, or share personal data unlawfully;
  • track people without required notice or consent;
  • configure pixels, cookies, server-side conversion events, or analytics without required consent and disclosures;
  • send hashed personal data to ad platforms unless you have a lawful basis and have provided required notices;
  • use Keldio to infer, expose, exploit, or target sensitive personal data unlawfully;
  • attempt to access another Tenant's data or bypass tenant isolation;
  • use Customer Personal Data for purposes inconsistent with your privacy notices, consents, customer contracts, or Data Protection Laws.
  • enable server-side conversion events, enhanced conversions, audience matching, or ad-platform data sharing without a lawful basis, required consent, required notices, and compliance with provider restricted-data rules;
  • use pixels, tags, scripts, UTM links, QR links, attribution flows, or provider tokens to deceive users, evade opt-outs, track people across contexts unlawfully, profile sensitive characteristics, or send sensitive, child-related, health, financial, employment, or other high-risk data to ad platforms without explicit legal authority and provider permission;
  • manipulate analytics, attribution, conversion events, deduplication IDs, click identifiers, or reporting data to mislead Keldio, providers, advertisers, affiliates, customers, regulators, or other third parties.

5. Content and intellectual property

You must not publish, host, upload, send, sell, or distribute content that:

  • infringes intellectual property, personality rights, privacy rights, confidentiality duties, or trade secrets;
  • is defamatory, threatening, harassing, hateful, exploitative, violent, or designed to incite harm;
  • contains malware, malicious scripts, exploit code, credential-harvesting forms, or deceptive downloads;
  • impersonates another person, business, brand, authority, or platform;
  • misleads End-Users about who they are contracting with, what they are buying, payment terms, refund terms, subscription terms, or expected outcomes;
  • contains unlawful health, financial, earnings, tax, legal, investment, or professional claims;
  • violates social-platform, payment-provider, ad-network, email-provider, hosting-provider, or app-store policies.

You must have all rights needed for your pages, funnels, images, videos, course content, member content, community content, copy, legal documents, tracking scripts, and downloadable files.

5A. Hosted pages, funnels, forms, and custom code

You must not use Keldio-hosted pages, funnels, forms, checkout flows, public legal pages, custom HTML, scripts, redirects, embeds, widgets, or A/B test variants to operate phishing pages, fake login pages, credential-harvesting flows, malware delivery, cloaked redirects, deceptive lead magnets, fake scarcity, fake testimonials, unsubstantiated earnings/health/financial/professional claims, hidden continuity offers, dark-pattern checkout flows, unlawful tracking, or third-party scripts that violate law, provider terms, End-User privacy, platform integrity, or Keldio's reputation. You must not hide the identity of the responsible business or mislead End-Users about who they are contracting with, what they are buying, how data is collected, whether a payment or subscription will occur, or what refund/cancellation rights apply.

5B. Member portals, courses, and communities

5C. Calendar bookings, appointments, and scheduling

You must not use calendar, booking, appointment, reminder, or scheduling features to create fake bookings, exhaust another party's availability, harass hosts or End-Users, send deceptive appointment communications, impersonate appointment participants, conceal the real provider of a service, collect unnecessary sensitive information, bypass cancellation or no-show rules, or interfere with another person's schedule, calendar account, meeting link, or communications.

You must not configure booking questions, appointment notes, reminders, calendar embeds, integrations, or connected agents to collect or process unlawful, excessive, misleading, special-category, child-related, health, financial, legal, employment, surveillance, or other high-risk data without the required lawful basis, notices, consents, safeguards, and professional compliance.

You must not use Keldio courses, member portals, communities, memberships, lesson attachments, downloadable files, community uploads, posts, replies, likes, videos, embeds, or member-access features to host, publish, distribute, or facilitate unlawful, infringing, defamatory, harassing, hateful, exploitative, unsafe, deceptive, privacy-invasive, malware-bearing, credential-harvesting, or rights-violating content. You must not use those features to evade membership gates, distribute pirated materials, expose confidential information, mislead members about access, outcomes, qualifications, accreditation, refunds, or support, or operate communities that lack legally required moderation, safeguarding, age controls, parental consent, professional review, or member notices.

6. Payments, checkout, refunds, subscriptions, and consumer protection

You must not use Keldio checkout, payment links, coupons, subscriptions, payment plans, invoices, refund tools, tax tools, provider connections, payout-readiness workflows, or billing tools to:

  • misrepresent pricing, currency, tax/VAT treatment, trial terms, renewal dates, subscription terms, installment schedules, cancellation rights, refund rights, delivery, guarantees, scarcity, product identity, seller identity, merchant identity, beneficial owner, payment recipient, payout recipient, provider account holder, or expected outcomes;
  • create unauthorised charges, hidden continuity programs, deceptive upsells, forced add-ons, dark-pattern checkout flows, cancellation obstruction, or misleading dispute evidence;
  • issue misleading coupons, fake discounts, expired discounts, unauthorised discounts, or discount terms that are inconsistent with what End-Users see at checkout;
  • avoid chargeback rules, payment-provider reviews, fraud checks, reserves, payout holds, tax obligations, sanctions checks, consumer-protection laws, or provider terms;
  • use false VAT numbers, false reverse-charge claims, incorrect tax settings, misleading invoice data, or tax configurations that you know or should know are inaccurate;
  • sell products or services prohibited by Stripe, Mollie, card networks, banks, regulators, or other payment providers;
  • route transactions through a provider account you are not authorised to use, process payments for another business where provider rules do not permit it, split or disguise transactions to avoid provider review, launder payments, hide the responsible seller, or use Keldio in a way that causes or is likely to cause excessive chargebacks, fraud reports, provider monitoring, account termination, or payment-network action.

Tenants are responsible for their own End-User contracts, checkout disclosures, refund and cancellation policies, subscription notices, trial notices, consumer-rights notices, tax settings, invoices, product delivery, access fulfilment, payment-provider compliance, provider account use, dispute handling, chargebacks, fraud controls, payout holds, provider reserves, and payout timing.

7. Security, systems, and platform integrity

You must not:

  • probe, scan, test, attack, overload, disrupt, or bypass Keldio systems without written permission;
  • attempt to access, extract, modify, delete, or infer another Tenant's data;
  • abuse APIs, MCP tools, webhooks, forms, checkout endpoints, authentication flows, rate limits, or infrastructure;
  • introduce malware, backdoors, worms, botnets, ransomware, cryptominers, exploit payloads, or harmful code;
  • use Keldio to operate phishing pages, fake login pages, credential collection, or social-engineering flows;
  • create excessive load, storage, bandwidth, queue, email, webhook, or API usage that threatens platform stability or provider limits;
  • bypass plan limits, workspace limits, usage limits, authentication, authorisation, or audit controls;
  • create, provision, or maintain duplicate, disposable, synthetic, misleading, unauthorised, or account-farmed Workspaces to bypass limits, evade enforcement, impersonate another party, resell access, or obscure the responsible operator;
  • share credentials, API keys, MCP keys, webhook secrets, OAuth tokens, or admin access insecurely.
  • use Keldio, APIs, MCP tools, agents, automations, public pages, webhooks, integrations, or provider connections to bypass tenant boundaries, probe or access another Workspace, harvest credentials, scrape or export data without authority, evade rate limits or logging, mask the source of abusive activity, test security controls without permission, interfere with monitoring, or use an agent or script to perform actions that would violate this AUP if performed by a human user;
  • misuse team-management, role-assignment, invitation, account-switching, API-key, MCP-key, support-access, impersonation-like, or credential-management features to obtain unauthorised access, hide the responsible operator, evade audit or enforcement, retain access after authority ends, or give an agent or third party more access than the Tenant is authorised to grant;

You must not use Keldio in a way that damages or threatens Keldio's cloud, hosting, storage, email, messaging, carrier, payment, authentication, DNS, CDN, social, calendar, analytics, webhook, AI, or other provider accounts or provider relationships, including by causing excessive complaints, bounces, chargebacks, fraud signals, abuse reports, takedowns, moderation actions, carrier filtering, account restrictions, infrastructure load, sanctions screening, provider investigations, or provider termination risk.

If you discover a security issue, report it responsibly and do not exploit it, access data that is not yours, disrupt the platform, or publicly disclose it before Keldio has had a reasonable opportunity to investigate and remediate.

8. Agents, MCP, APIs, automations, and connected AI systems

Keldio does not provide a built-in large language model as part of the platform by default. Keldio allows Tenants to connect external agents, scripts, automations, MCP clients, or AI systems to act through Tenant-issued credentials.

If an API, MCP client, script, or external agent creates or configures a Workspace, issues credentials, changes owner/admin details, or connects providers, that activity is treated as Tenant-authorised activity when performed with valid credentials. You are responsible for supervising those clients and for promptly revoking credentials that should no longer be trusted.

If you connect an external agent or AI system, you are responsible for that connection. You must not use agents, MCP tools, APIs, webhooks, or automations to:

  • take unlawful, deceptive, harmful, or unauthorised actions;
  • send messages, refunds, cancellations, publications, exports, deletions, or payment actions without appropriate authority and safeguards;
  • expose Customer Personal Data to AI providers, tools, logs, prompts, memories, vector stores, or third-party systems without a lawful basis and appropriate contracts;
  • bypass human review where human review is legally or operationally required;
  • create mass actions, loops, runaway workflows, duplicate sends, duplicate charges, or destructive changes;
  • configure workflows, triggers, retries, webhooks, agents, or automations to evade consent requirements, unsubscribe or suppression signals, rate limits, provider policies, audit controls, or Keldio safety controls;
  • intentionally create automation loops, repeated customer-impacting actions, excessive webhook calls, repeated sends, repeated access changes, or other automated behavior that creates legal, deliverability, payment, security, infrastructure, reputational, or End-User risk;
  • use workflows or agents to make legally or similarly significant decisions about individuals without the notices, lawful basis, safeguards, human review, and appeal or correction rights required by applicable law;
  • hide agent identity, evade audit logs, rotate keys to avoid enforcement, or circumvent safety controls.

If you grant an agent, MCP client, API client, implementation partner, contractor, or automation tool access to team-management, settings, credential, export, publication, messaging, billing, payment, refund, subscription, legal-document, or similar sensitive tools, you must supervise that access and ensure the tool is authorised, secure, and appropriately scoped. You must not use such tools to obscure who controls a Workspace, to create unauthorised users, to retain access after a relationship ends, or to bypass Keldio's safety, billing, legal, or security controls.

You must not misuse guided onboarding features, including onboarding credentials, guided first missions, mission proposals or approvals, connection checks, or onboarding support channels, to obtain unauthorised access, automate unrelated or abusive activity, evade credential scoping or safety controls, manufacture fake activation signals, or present onboarding progress, mission completion, or connection status as Keldio review, certification, or endorsement of your content, configuration, or business.

You must not use agents, APIs, MCP clients, scripts, imports, or automations to mass-publish course/community content, grant or revoke member access, unlock drip content, send portal invitations, delete posts/replies, alter member progress, or upload files in a way that is unauthorised, deceptive, abusive, unlawful, inconsistent with member rights, or designed to evade Tenant moderation, consent, access-control, or Keldio safety controls.

External AI providers or agent runtimes connected by you are your responsibility unless Keldio has separately engaged them as Keldio Subprocessors. You must assess their terms, data-retention, training-data, security, and compliance posture before sending data to them.

You must not route personal data, confidential information, credentials, prompts, files, media, message content, or customer records to an external AI system, mailbox, messaging provider, social platform, webhook endpoint, or other provider unless you have authority, a lawful basis, required notices, appropriate contracts, and suitable provider settings for that transfer.

9. Social media and ad-platform integrations

Where you connect social media profiles, ad platforms, or social publishing tools, including Bundle.social and platform APIs, you must comply with the applicable platform terms and laws. You must not use Keldio to:

You must not use Keldio integrations, social connectors, webhooks, APIs, MCP tools, automations, redirects, or connected providers to:

  • connect, publish from, send through, or configure accounts, pages, profiles, domains, mailboxes, payment accounts, ad accounts, calendars, or provider credentials that you do not own or lawfully control;
  • impersonate a person, business, public figure, brand, agency, platform, provider, or customer, or misrepresent authority over a social profile, page, ad account, domain, payment account, mailbox, or webhook endpoint;
  • evade provider restrictions, bans, rate limits, consent requirements, unsubscribe rules, payment-provider rules, advertising policies, social-platform policies, or platform review processes;
  • publish or schedule unlawful, deceptive, infringing, defamatory, harassing, regulated, unsafe, adult, political, financial, health, employment, housing, credit, testimonial, giveaway, or promotional content without the notices, approvals, rights, disclosures, and compliance controls required for that content;
  • use integrations or redirects for phishing, credential harvesting, malware delivery, deceptive link routing, fake support flows, fake login flows, or unauthorised data collection;
  • route personal data, customer data, event data, media, or content to a provider, webhook endpoint, agent, or external system without the required authority, lawful basis, notice, consent, contract, or security controls.

Keldio may suspend, disconnect, throttle, disable, quarantine, remove, delay, or refuse integrations, provider connections, social posts, media uploads, webhooks, redirects, API/MCP access, or automation activity where Keldio reasonably believes the activity is unauthorised, abusive, provider-prohibited, unlawful, insecure, likely to trigger provider sanctions, or likely to harm Keldio, other Tenants, End-Users, providers, recipients, or the public.

  • post spam, misleading claims, impersonation content, or prohibited ads;
  • scrape or misuse social-platform data;
  • bypass platform rate limits, account restrictions, review processes, or ad policies;
  • transmit ad-conversion data without required consent, notice, and lawful basis;
  • operate fake engagement, bot activity, deceptive amplification, or coordinated inauthentic behaviour.

10. Enforcement

Keldio may investigate suspected violations and may take action with or without prior notice where reasonably necessary. Actions may include:

  • warning you;
  • requesting information or remediation;
  • throttling, pausing, or disabling sending, publishing, checkout, automations, agents, MCP keys, APIs, webhooks, or integrations;
  • removing or disabling content;
  • suspending or terminating a Workspace;
  • blocking domains, endpoints, forms, checkouts, or accounts;
  • preserving evidence;
  • notifying providers, payment processors, hosting providers, law enforcement, regulators, or affected parties where legally required or reasonably necessary;
  • refusing future service.

Keldio may act immediately where activity creates legal risk, security risk, abuse risk, deliverability risk, payment risk, infrastructure risk, reputational risk, risk to other Tenants, or risk to End-Users.

Keldio may open, maintain, and retain abuse, security, provider-risk, payment-risk, or enforcement records. Keldio may use those records to decide restrictions, document remediation, respond to provider or legal requests, protect platform integrity, support dispute handling, and defend legal claims. Keldio may refuse to disclose internal risk methods, detection rules, provider communications, or security-sensitive evidence where disclosure would compromise security, enforcement, another party's rights, provider confidentiality, legal privilege, or Keldio's legitimate interests.

You must not retaliate against complainants, End-Users, Keldio personnel, providers, or other Tenants; move abusive activity to another Workspace, domain, provider, credential, account, agent, or integration; or create replacement accounts, Workspaces, pages, domains, automations, webhooks, API keys, MCP keys, or provider connections to evade enforcement.

Keldio may preserve and review relevant security, access, delivery, provider, content, and configuration evidence when investigating suspected security abuse, privacy abuse, credential compromise, provider complaints, or violations of this AUP.

Keldio may scan, review, throttle, disable, unpublish, remove, quarantine, preserve evidence relating to, or require changes to hosted pages, custom code, forms, redirects, scripts, tracking, domains, funnels, variants, checkouts, or public content where Keldio reasonably believes they may violate this AUP or create legal, security, privacy, payment, provider, deliverability, reputational, End-User, or platform risk.

Keldio may inspect metadata and, where reasonably necessary, message or attachment content to investigate abuse, security incidents, deliverability risk, provider complaints, legal requests, or threats to Keldio, other Tenants, End-Users, providers, or the public. Keldio may preserve evidence, restrict access to messages or attachments, suspend sending, block channels, revoke API/MCP access, or remove content where appropriate.

11. Reporting abuse

To report abuse, security issues, impersonation, spam, privacy concerns, or unlawful content involving Keldio, contact:

  • legal@keldio.com
  • support@keldio.com

Include the relevant URL, workspace, message, sender, domain, evidence, and a short explanation of the issue.

12. Changes

Keldio may update this AUP from time to time. Material changes will be handled according to the Platform Terms. Continued use of the Services after an update means the updated AUP applies.

Keldio

The agent-first platform for building and scaling your online business.

Product
FunnelsEmailCRMBillingLMS
Resources
ContactPricing
Legal
Legal TermsAcceptable Use PolicySubprocessor ListPrivacy PolicyPlatform TermsData Processing AgreementWebsite Terms
© 2026 Keldio. All rights reserved.