Legal · Last updated 24 September 2026
Acceptable Use Policy
Contents
- 1. Who this policy applies to
- 2. You may use Warmerly to
- 3. You must not use Warmerly to
- 4. Restricted content
- 5. Sending-quality standards
- 6. LinkedIn, WhatsApp, Instagram and other connected platforms
- 7. Hosted mailboxes (OneMail) and the free sandbox mailbox
- 8. AI features and Warmi
- 9. Transactional email API
- 10. API, MCP and automated access
- 11. Monitoring, investigation and cooperation
- 12. Security research and responsible disclosure
- 13. Enforcement
- 14. Reporting abuse
- 15. Changes
- 16. Contact
Warmerly is built for legitimate business-to-business outreach teams that want to land in the inbox without being flagged as spam. Warmup, hosted mailboxes and our sending infrastructure are shared, so one customer's behaviour affects everyone else's deliverability. This Acceptable Use Policy ("policy") explains what you can and cannot do. It forms part of our Terms of Service, and words defined there have the same meaning here.
1. Who this policy applies to
This policy applies to you, to every member of your workspaces, to anyone else you allow to use your account, and to any software, script or AI agent you connect to Warmerly through our API or MCP server. If you are an agency, it also applies to use of the service for or by your clients. You are responsible for their compliance as if it were your own, and a breach by any of them is a breach by you.
This policy sets minimum standards. Complying with it does not mean your use is lawful: you remain responsible for complying with every law that applies to you and to the people you contact.
2. You may use Warmerly to
- Warm up mailboxes you own or are authorised to operate on behalf of your employer or client.
- Build sender reputation in advance of legitimate B2B outbound campaigns.
- Run business-to-business outreach campaigns to recipients you have a lawful basis to contact, from mailboxes and accounts you are authorised to use.
- Manage replies across your connected email, LinkedIn, WhatsApp, and Instagram accounts.
- Research companies and find business contact details for that outreach, subject to our Lead Database Use Terms.
- Send transactional email from your own verified domains, as described in section 9.
- Diagnose deliverability issues via inbox-placement and authentication monitoring.
3. You must not use Warmerly to
Unlawful, deceptive or harmful messages
- Send, prepare for, or facilitate any unsolicited bulk email that violates anti-spam laws including CAN-SPAM (US), CASL (Canada), PECR / UK GDPR (UK), or the ePrivacy Directive (EU).
- Send phishing, deceptive, fraudulent, or impersonation messages, or messages with false or misleading headers, sender names or subject lines.
- Send malware, ransomware, or links to malicious content.
- Send messages without a clear identification of yourself or your business.
- Send messages without a working unsubscribe mechanism where required by law.
- Remove, obscure, or falsify the sender identification or unsubscribe link in your campaign mail.
- Send content that is defamatory, discriminatory, obscene, threatening, or that infringes anyone's intellectual property, privacy or other rights.
- Use Warmerly to harass, threaten, stalk, or otherwise harm any person, or to keep contacting someone who has asked you to stop.
Lists and personal data
- Harvest, scrape, or otherwise collect email addresses unlawfully, or in breach of a site's terms or
robots.txt. - Send to lists bought or rented from third parties, or to people the law of their country does not let you contact without their prior consent or an existing relationship.
- Contact consumers (rather than businesses) without their consent, where the law of their country requires it.
- Upload or process special category data, criminal offence data, or data about children.
- Re-add, re-import or re-contact an address that has unsubscribed, objected or been suppressed, or take any step designed to get around a suppression list.
Accounts, limits and the platform
- Resell or sublicense Warmerly without prior written agreement.
- Warm up mailboxes you do not own or are not authorised to operate, or interfere with the warmup network (for example by reporting warmup mail as spam, auto-deleting it, or harvesting addresses from it). Our Warmup Network Participation Terms set out the full rules.
- Create extra accounts or workspaces to get around plan limits, sending limits, a suspension or a ban.
- Share one login between several people.
- Probe, scan, or attempt to bypass our security controls, except as permitted by section 12.
- Connect a mailbox or account under a false identity, or use Warmerly on behalf of a person or business you have been told we will not serve.
4. Restricted content
Because warmup, OneMail and the transactional API share reputation across customers, you must not use Warmerly to promote or sell the following without our prior written approval, which we may refuse for any reason:
- adult or sexual content, dating or escort services;
- gambling, betting or lotteries;
- weapons, ammunition, drugs, drug paraphernalia, tobacco, vaping or cannabis products;
- cryptocurrency, forex, penny stocks, "get rich quick" or other high-risk investment schemes;
- payday loans, debt relief or credit repair;
- pharmaceuticals, supplements or health claims;
- hacking tools, counterfeit goods, or anything that infringes someone else's rights;
- political campaigning.
Any approval we give is limited to what it states in writing, and we may withdraw it at any time.
5. Sending-quality standards
Everything you send through Warmerly must meet these standards, whichever channel or mailbox it goes from:
- Clean lists. Verify addresses before you send to them, remove addresses that bounce, and do not send to addresses you have reason to believe are invalid, role-based traps, or spam traps.
- Low bounces and complaints. Keep your bounce, complaint and unsubscribe rates low and within the sender requirements that mailbox providers publish. If a provider, a blocklist operator or we tell you a list or mailbox is causing problems, stop sending to that list or from that mailbox until you have fixed the cause.
- Authentication. Configure SPF, DKIM and DMARC on every domain you send campaign mail from, to the standard mailbox providers require.
- No evasion. Do not rotate domains, mailboxes or accounts to spread out complaints or bounces, to evade filtering or blocklisting, or to carry on sending a campaign we or a provider have paused. Do not send from a domain or mailbox you know to be blocklisted.
- Relevance. Send outreach only to people whose business role makes your message relevant to them, and keep volumes proportionate to that audience.
Automatic safeguards. Warmerly measures bounces on every campaign and sending mailbox over a rolling 7-day window. Once there are at least 25 sends in that window, a campaign is paused automatically if its bounce rate reaches 7%, or if 30% or more of the leads it tried to reach were rejected as undeliverable; a mailbox that still exceeds those rates afterwards has its campaign sending paused. We also apply daily limits, sending windows and gradual volume ramps. These safeguards protect shared infrastructure; they are a backstop and not a permitted level of bounces. Staying below them does not mean you have met this section, and you must not resume a paused campaign or mailbox without first dealing with the cause.
6. LinkedIn, WhatsApp, Instagram and other connected platforms
- You must comply with the terms, policies and messaging rules of every platform whose account you connect, including any rules restricting automation, bulk messaging or third-party tools. You connect each account at your own risk: a platform may restrict, suspend or close an account for activity carried out through Warmerly, and our Terms of Service exclude our liability for that.
- Warmerly applies its own daily caps, pacing, send windows and ramps to automated LinkedIn and WhatsApp activity. You must not try to get around them, for example by connecting the same account in several workspaces or by splitting one campaign across accounts.
- Connect only accounts that belong to you as a real person or to your business. Do not use fake, purchased, borrowed or shared profiles or numbers.
- Do not use automated WhatsApp or Instagram messaging to contact people who have not given you their number or handle in a business context, or to send them promotional messages where the law or the platform requires their consent.
- Stop messaging anyone who blocks you, reports you, or asks you to stop, on any channel.
7. Hosted mailboxes (OneMail) and the free sandbox mailbox
- Mailboxes, domains and servers we host for you remain ours or our providers'. Use them only for purposes this policy allows. We may throttle, pause or suspend sending from them, at the mail server, at any time to protect deliverability.
- Do not use a hosted mailbox, or a domain we provide, to impersonate another person, brand or organisation, or to send restricted content under section 4.
- Each person is entitled to one free sandbox mailbox. Do not create accounts or workspaces to obtain more.
- The sandbox mailbox is provided to warm up and to try the service. Its warmup cannot be switched off. Campaign sending from it stays locked until conditions we set are met, and is then capped at a low daily volume. We may change those conditions, lock sending again, or withdraw the sandbox mailbox at any time, including when its free period ends or it goes unused.
8. AI features and Warmi
- Do not use AI features to generate content that this policy prohibits, or content designed to deceive the recipient about who is writing to them or why.
- Do not use AI features to impersonate a real person or organisation, or to write messages that claim to come from someone who has not authorised them.
- Where a law requires you to disclose that a message or conversation is automated or AI-generated, you must make that disclosure. Do not present an automated conversation as a human one in those circumstances.
- Do not attempt to manipulate, jailbreak or inject instructions into Warmi (our support assistant) or any other AI feature, for example to extract its instructions, reach another customer's data, obtain credits, discounts or plan changes, or make it take actions you are not authorised to take. Nothing Warmi says changes these Terms, your plan or your price unless we confirm it in writing.
- Do not submit special category data or other sensitive personal data to AI features, and do not use AI output to train or improve a competing model or product.
- You must review AI output before relying on it or sending it; if you let a feature send without review, you are treated as having approved what it sends.
9. Transactional email API
The transactional API runs on dedicated mail servers, kept separate from outreach so that mail people are waiting for (a password reset, a receipt) is not held back by anyone's cold outreach. To keep it that way:
- Send only transactional messages: messages a recipient needs because of an account, purchase, request or relationship they have with you, such as sign-in links, password resets, receipts, invoices, order and delivery updates, security alerts and service notifications.
- Do not send marketing, newsletters, promotions, cold outreach, re-engagement or other bulk commercial messages through the transactional API. Promotional content in a transactional message must be no more than incidental, such as your logo or a footer link.
- Send only to people who gave their address to you directly. Never send transactional mail to a purchased, rented, scraped or lead-database list.
- Send only from domains you own or control and have verified with us, and do not use a sending key for any domain it is not issued for.
- Hard bounces are added to your suppression list automatically, and suppressed addresses are not sent to. Do not re-send to them by another route or take steps to get around suppression.
We may suspend transactional sending immediately if we reasonably believe it is being used for anything other than transactional mail.
10. API, MCP and automated access
- Access the service by automated means only through our documented API and MCP server, and only within the rate limits and plan limits we apply. Do not load-test the service or run anything that degrades it for others.
- Keep API keys, sending keys and OAuth grants secret. Do not share them outside your organisation or embed them in code others can read. Revoke any key you think has been exposed, and tell us.
- You are responsible for every action taken through a key or grant you create, including actions taken by an AI agent or other client you authorise through the MCP server. Authorise only clients you trust, with no more access than they need.
- Do not register or operate an OAuth client that misrepresents who it is, or that asks our users to authorise access for a purpose they have not been told about.
11. Monitoring, investigation and cooperation
We may monitor use of the service for compliance with this policy, including signals such as bounces and undeliverable rates, blocklist listings, sending patterns and reports from recipients, mailbox providers and other third parties. Where we reasonably need to in order to investigate a possible breach or a credible abuse report, authorised Warmerly staff may review account data, campaign content and messages, as our Data Processing Agreement allows.
If we ask, you must promptly give us the information we reasonably need to assess your compliance, such as where a list came from, the lawful basis you rely on, any consent records, and how you handle opt-outs. Failure to respond fully within the time we reasonably set is itself a breach of this policy.
We may preserve information and disclose it to law enforcement bodies, regulators (including the Information Commissioner's Office), courts or other public authorities where we are required to by law, or where we reasonably believe it is necessary to prevent fraud, abuse, harm to any person or harm to the service, to the extent the law allows. We may also cooperate with mailbox providers and blocklist operators to resolve abuse affecting our infrastructure.
12. Security research and responsible disclosure
You must not scan, probe, penetration-test or attack the service without our prior written permission. If you believe you have found a security vulnerability, report it to hello@warmerly.com with enough detail for us to reproduce it. While you do so, you must:
- access no more data than the minimum needed to demonstrate the issue, and never access, change, delete or keep another customer's data;
- not degrade or disrupt the service, send mail through it, or use social engineering, physical attacks or denial-of-service testing;
- not disclose the issue to anyone else until we have fixed it or told you we do not intend to, and give us a reasonable time to do so.
We will not treat good-faith research that follows these rules as a breach of this policy. We do not currently run a paid bug bounty programme.
13. Enforcement
We may, in our sole discretion and without prior notice, throttle, pause, suspend or terminate any account, workspace, mailbox, sending key, campaign or feature that we reasonably believe breaches this policy or puts our infrastructure, the warmup network or other customers' deliverability at risk. We may also remove a mailbox from the warmup network, remove access to the lead database, or require you to delete data obtained through the service. We choose the measure; we are not required to warn you first or to escalate step by step.
Breaches may result in immediate termination without refund. You must reimburse our reasonable costs of dealing with a breach, including the cost of getting our domains or IP addresses removed from blocklists, and the indemnity in our Terms of Service applies. Our allowing a campaign or account to run does not mean we consider it lawful or compliant with this policy; that remains your responsibility, and our not acting on a breach is not a waiver of it.
14. Reporting abuse
If you have received what appears to be abusive or unwanted mail sent through Warmerly, use our abuse report form or email hello@warmerly.com with the full message headers. We review credible reports and act on them where appropriate. We do not tell reporters who owns a reported account unless the law requires us to. If you want your details removed from our business-contact database, see our Prospect Privacy Notice.
15. Changes
We may update this policy. Material changes are notified by email at least 14 days before they take effect. Changes we need to make for legal, security or abuse-prevention reasons may take effect immediately.
16. Contact
Warmerly. Email hello@warmerly.com.



