AI Inbx

Responsible email

Acceptable Use Policy

Rules that protect recipients, customers, and the email infrastructure we share. This policy forms part of the Terms of Service.

Last updated: 21 September 2026

1. Recipient permission and sender identity

Send only messages you are legally entitled to send. Marketing email requires prior consent wherever the applicable law requires it, unless a specific statutory exception applies. In Germany, the rules in Section 7 UWG apply to business recipients as well as consumers. A public email address, a purchased or scraped list, or a GDPR legitimate interest alone does not establish permission to send advertising email.

  • Keep evidence of consent or the specific exception you rely on and provide it when reasonably requested during an abuse review.
  • Identify the actual sender and use domains and mailboxes you own or are authorized to use. Do not falsify headers or impersonate another sender.
  • Provide a working, easy way to stop marketing messages and act on opt-outs without undue delay and within any applicable legal deadline.
  • Honor complaints, hard bounces, suppression lists, and withdrawn consent. Do not move recipients between accounts or domains to evade a suppression.
  • Use transactional messages for their stated purpose. Do not disguise marketing as a security alert, receipt, or personal reply.

You are responsible for privacy notices and any consent needed for open or click tracking. An AI classification or automated opt-out detector does not replace your responsibility to review and honor a recipient's request.

2. Prohibited activity

  • Unlawful unsolicited email, phishing, fraud, deceptive impersonation, credential theft, or distribution of malware.
  • Illegal goods or content, child sexual abuse material, unlawful threats or harassment, and content that infringes another person's rights.
  • Unauthorized access to accounts, mailboxes, or personal data; disclosure of secrets; or attempts to defeat tenant isolation.
  • Disrupting services, evading sending limits or sanctions, rotating accounts to avoid enforcement, or manipulating usage records.
  • Security testing against our systems without prior authorization, except activity expressly permitted by applicable law.

You must comply with applicable export controls and sanctions. A permitted business purpose does not excuse unlawful message content or sending practices.

3. Account security and delivery quality

Protect API keys, OAuth credentials, and webhook endpoints; give users only the access they need; and revoke compromised credentials promptly. Configure sender authentication and monitor delivery failures and complaints. Do not repeatedly send to addresses known to be invalid or to recipients who have objected.

We may slow, hold, or stop traffic that creates a material security, complaint, bounce, or reputation risk. Appropriate limits depend on the sending context and upstream requirements. We may request relevant information about list sources, recipient permission, or the affected traffic. No plan guarantees delivery to an inbox.

4. Enforcement, reports, and review

We assess reports and service signals and may restrict affected messages, features, or accounts as described in the Terms. Our response takes account of severity, urgency, recurrence, and the rights of affected people. Where practical, we notify you and allow you to correct the issue; urgent risks may require immediate action.

Report abuse or challenge a restriction at me@paukraft.com. Include a message or resource identifier, relevant headers where available, and the reason for your report. Avoid sending unrelated personal data or credentials. The Terms explain the information needed for illegal-content notices and the decision review route. Enforcement does not remove statutory refund or appeal rights.