Policy overview
1. General use requirements
1. General use requirements
You must use the HoopAI platform in compliance with all applicable laws, regulations, and industry standards. By using our services, you agree to:
- Use the platform only for lawful business purposes
- Maintain accurate and current account information
- Keep your login credentials secure and confidential
- Maintain all necessary business licenses, permits, and insurance required for your operations
- Obtain all required permissions, consents, and authorizations before collecting, processing, or storing personal data through the platform
- Comply with all applicable accessibility laws and standards
Best practice: Conduct periodic reviews of your account activity, user permissions, and data processing practices to ensure ongoing compliance with this AUP and applicable regulations.
2. Prohibited activities
2. Prohibited activities
The following activities are strictly prohibited on the HoopAI platform:
2.1 Platform integrity
- Reverse engineering — Decompiling, disassembling, reverse engineering, or otherwise attempting to extract the source code, underlying algorithms, or data models of the platform
- Derivative works — Creating derivative works based on the platform or any of its components
- Proprietary notices — Removing, altering, or obscuring any proprietary notices, labels, trademarks, or branding on the platform
- Unauthorized access — Accessing or attempting to access accounts, systems, or data without proper authorization
- Non-standard interfaces — Accessing the platform through any non-standard or unauthorized interface, tool, or automated means not provided or approved by HoopAI
- Security circumvention — Bypassing, disabling, or interfering with any security features, access controls, or content-filtering mechanisms
- Platform interference — Engaging in any activity that disrupts, degrades, or interferes with the normal operation of the platform, including denial-of-service attacks
- Robots.txt violations — Bypassing or ignoring robots.txt directives or other access-restriction mechanisms
- Scraping — Automated scraping, crawling, or harvesting of platform content or data without express written authorization
2.2 Competitive misuse
- Competitor access — Using the platform by or on behalf of a competitor for the purpose of gaining competitive intelligence, benchmarking, or replicating platform features
- Misrepresentation — Misrepresenting your identity, affiliation, or the purpose of your use of the platform
2.3 User conduct
- Harassment — Engaging in harassing, threatening, intimidating, predatory, or stalking conduct toward any individual
- Impersonation — Impersonating HoopAI employees, officials, or representatives, or any other person or entity
- Content tampering — Deleting, revising, or modifying content created by other users without authorization
- Attribution modification — Modifying, removing, or falsifying author attributions on content
- Unauthorized registration — Creating accounts or subscriptions without proper authorization or through fraudulent means
2.4 Data export restrictions
- Do not export or transmit data in violation of applicable export control laws, including the Export Administration Regulations (EAR) and the International Traffic in Arms Regulations (ITAR)
- Do not provide platform access to individuals or entities in restricted jurisdictions or on sanctioned-party lists
3. Content standards
3. Content standards
All content created, uploaded, stored, or distributed through the HoopAI platform must comply with the following standards:
- Illegal content — Any content that violates applicable local, state, national, or international laws
- Hate speech — Content that promotes hatred, discrimination, or violence against individuals or groups based on race, ethnicity, religion, gender, sexual orientation, disability, or other protected characteristics
- Malware — Viruses, trojans, worms, ransomware, spyware, or any other malicious software or code
- Fraudulent content — Content designed to deceive, defraud, or mislead users, including phishing schemes
- Intellectual property violations — Content that infringes on copyrights, trademarks, patents, trade secrets, or other intellectual property rights of third parties
- Explicit or exploitative material — Obscene, pornographic, or sexually exploitative content, particularly any content involving minors
- Defamatory content — Content that is knowingly false and damages the reputation of individuals or organizations
Best practice: Implement internal content review processes before publishing or distributing content through the platform. Designate a team member responsible for content compliance.
4. Data privacy and compliance
4. Data privacy and compliance
You are responsible for ensuring that your use of the HoopAI platform complies with all applicable data protection and privacy laws. This includes but is not limited to:
4.1 Applicable regulations
| Regulation | Scope | Key requirements |
|---|---|---|
| GDPR | EU/EEA residents | Lawful basis for processing, data subject rights, DPA required |
| CCPA / CPRA | California residents | Consumer rights disclosure, opt-out mechanisms, data inventory |
| HIPAA | Protected health information (US) | BAA required, encryption, access controls, audit trails |
| PCI DSS | Payment card data | Secure handling, no storage of CVV, compliance validation |
| PIPEDA | Canadian residents | Consent-based processing, data breach notification |
4.2 Your obligations
- Lawful basis — Maintain a lawful basis for all data processing activities conducted through the platform
- Notice and consent — Provide clear and conspicuous privacy notices and obtain all required consents before collecting or processing personal data
- Consent records — Maintain accurate and auditable records of all consents obtained from data subjects
- Jurisdiction compliance — Comply with notice and consent obligations specific to each jurisdiction in which you operate or where your contacts reside
- Data minimization — Collect and process only the personal data that is necessary for your stated purposes
- Contact data — Ensure you have all necessary permissions and consents for any Contact Data processed through the platform
Best practice: Maintain a data processing register that documents the categories of data processed, legal bases, retention periods, and any third-party sharing. Review and update this register quarterly.
5. Email and messaging compliance
5. Email and messaging compliance
All electronic communications sent through the HoopAI platform must comply with applicable laws and industry standards.
5.1 Messaging compliance requirements
| Requirement | Email (CAN-SPAM) | SMS/MMS (TCPA) | A2P 10DLC |
|---|---|---|---|
| Prior consent | Implied or express | Express written consent required | Campaign registration required |
| Sender identification | Accurate From header and physical address | Registered business identity | Brand and campaign verified |
| Opt-out mechanism | Unsubscribe link in every message | STOP keyword support | STOP keyword support |
| Opt-out processing | Within 10 business days | Immediate | Immediate |
| Content restrictions | No deceptive subject lines | No prohibited content categories | Content must match registered use case |
| Record keeping | Maintain consent and opt-out records | Written consent records | Registration documentation |
5.2 Prohibited messaging practices
- Spam — Sending unsolicited bulk messages or communications to individuals who have not opted in
- Purchased lists — Using purchased, rented, or third-party contact lists where recipients have not provided direct consent to receive communications from you
- Scraped contacts — Sending messages to contacts obtained through scraping, harvesting, or other unauthorized collection methods
- Opt-out violations — Failing to honor opt-out requests or continuing to send messages after a recipient has unsubscribed
- Missing unsubscribe — Sending marketing communications without a clear and functioning unsubscribe or opt-out mechanism
- Deceptive messaging — Using misleading sender information, subject lines, or message content
Best practice: Implement double opt-in for all marketing lists, regularly clean your contact lists to remove inactive or bounced addresses, and maintain suppression lists across all communication channels.
6. AI agent and automation rules
6. AI agent and automation rules
The HoopAI platform provides AI-powered agents, chatbots, and automation tools. The following rules govern their use:
6.1 Transparency and disclosure
- AI disclosure — You must clearly disclose to end users when they are interacting with an AI agent, chatbot, or automated system rather than a human
- No deceptive bots — AI agents must not be designed or configured to deceive users into believing they are communicating with a human
- Accurate responses — You are responsible for ensuring that AI-generated content and responses are accurate and not misleading
6.2 AI usage restrictions
- Do not use AI agents to generate or distribute spam, phishing content, or malicious communications
- Do not use AI agents to harass, threaten, or intimidate individuals
- Do not use AI agents to impersonate real individuals without their explicit consent
- Do not train or configure AI agents to produce content that violates the Content Standards (Section 3) of this AUP
- Do not use AI automation to circumvent rate limits, security controls, or other platform restrictions
Best practice: Regularly review AI agent conversations and outputs. Establish human oversight processes for sensitive use cases such as healthcare, financial advice, or legal guidance.
7. API usage and fair use
7. API usage and fair use
Access to the HoopAI API is subject to the following usage policies:
7.1 Rate limits and quotas
- Respect all published API rate limits and usage quotas
- Do not attempt to circumvent rate limiting through multiple accounts, IP rotation, or other evasion techniques
- Implement proper error handling and exponential backoff for rate-limited requests
7.2 API usage restrictions
- API access is for building integrations that complement your use of the HoopAI platform
- Do not use the API to build competing products or services
- Do not redistribute API access or resell API data to unauthorized third parties
- Do not use the API to perform bulk data extraction or scraping beyond your authorized use case
- Include proper attribution when required by the API terms
7.3 Authentication and security
- Keep API keys, tokens, and credentials secure and confidential
- Rotate API credentials regularly and immediately revoke compromised credentials
- Do not share API credentials across organizations or embed them in client-side code
- Use HTTPS for all API communications
Best practice: Use environment variables or a secrets manager for API credentials. Monitor your API usage dashboards regularly to detect anomalies or unauthorized access.
8. Enforcement actions
8. Enforcement actions
HoopAI reserves the right to take enforcement action against any account that violates this AUP. Enforcement actions are applied progressively based on the severity and frequency of violations.
8.1 Enforcement progression
| Level | Action | Trigger |
|---|---|---|
| Level 1 — Warning | Written notice of violation with remediation guidance | First minor violation or unintentional policy breach |
| Level 2 — Restriction | Temporary limitation of specific features or services | Repeated minor violations or failure to remediate after warning |
| Level 3 — Suspension | Temporary suspension of account access | Serious violation, repeated policy breaches, or threat to platform integrity |
| Level 4 — Termination | Permanent termination of account and all associated services | Severe or willful violations, illegal activity, or repeated suspensions |
8.2 Immediate action
HoopAI may bypass the progressive enforcement process and take immediate action (including suspension or termination) in cases involving:- Illegal activity or violations of criminal law
- Threats to the security or integrity of the platform
- Activity that poses risk of harm to other users or third parties
- Activity that exposes HoopAI to legal liability
8.3 Appeals
If you believe an enforcement action was taken in error, you may submit an appeal to legal@hoopai.com within 30 days of the action. Appeals will be reviewed and a response provided within 10 business days.9. Reporting violations
9. Reporting violations
If you become aware of any activity that violates this Acceptable Use Policy, we encourage you to report it promptly.
How to report
- Email: legal@hoopai.com
- Subject line: AUP Violation Report
What to include
- Your name and contact information
- Description of the violation
- Relevant account names, URLs, or identifiers
- Screenshots or other supporting evidence (if available)
- Date and time of the observed violation
Good faith reporting: HoopAI will not take adverse action against users who report violations in good faith, even if the investigation determines no violation occurred.