Legal

Acceptable Use Policy

Last updated July 2026

Gridwork sends messages to real people on platforms we do not own. If a workspace abuses that, the consequences land on the customer, on us, and sometimes on every other business using the same messaging infrastructure. This policy is the line. It forms part of our Terms of Service.

Messaging and consent

  • Only send proactive messages to contacts whose consent status permits it. Do not import a purchased list and mark it opted in.
  • Honour opt-outs immediately and permanently. “Stop” means stop, in either language.
  • Follow the rules of every platform you connect — including WhatsApp's Business Messaging Policy, its customer-service window, and its template approval requirements; and Meta's Platform Terms for Instagram.
  • Identify your business honestly. Do not present your workspace as a business you do not operate.

Prohibited content and conduct

You may not use Gridwork to:

  • Send spam, chain messages, or bulk unsolicited marketing.
  • Deceive people — including fake scarcity, fabricated reviews, impersonation, phishing, or fraud of any kind.
  • Promote or transact in anything unlawful where you or your customer are located, or anything restricted by the connected platforms: illegal drugs, weapons, counterfeit goods, or unlicensed financial, medical or legal advice.
  • Harass, threaten, or target individuals, or produce content that is hateful or sexually exploitative.
  • Collect payment card numbers, passwords, government ID numbers or similar credentials through an agent conversation.
  • Attempt to break workspace isolation, probe our infrastructure, or extract another customer's data.
  • Reverse-engineer the service, resell access without a partner agreement, or use it to build a competing product.

Being straight about AI

Agent replies go out under your business's identity, which is normal and expected — a business answering its own WhatsApp is not a disclosure event. What you may not do is affirmatively lie about it: if a customer asks whether they are talking to a person, the honest answer is required, and you must not configure your agents to deny it.

Do not configure agents to state prices, availability, medical or legal outcomes, or guarantees that you cannot honour. The product is built not to invent these; do not instruct it to.

Automated actions and spend

Approval settings and spend caps are your safety controls, not ours. If you set an action to run automatically, you own the consequences. Do not use automation to circumvent a platform's rate limits, its review processes, or its advertising policies.

How we enforce this

Where we become aware of a breach — through a platform complaint, an abuse report, or our own monitoring — we may pause outbound messaging on the workspace, restrict a specific capability, or suspend the workspace entirely. Where it is safe and lawful to do so, we will tell you what happened and give you a chance to fix it first. Severe cases — fraud, targeting of individuals, or anything that jeopardises our platform access — may be actioned immediately and reported to the relevant platform or authority.

Reporting abuse

If you have received a message from a business using Gridwork that breaches this policy, tell us at abuse@bygridwork.com. Include the sender and the message and we will investigate.