Acceptable Use Policy

Last updated: August 30, 2026

This page exists because security and procurement reviewers ask for an acceptable-use policy by name and should not have to read a whole contract to find one. The rules below are the same four in section 5 of the terms, rendered from the same source — there is no second set of rules here.

1. What you agree not to do

You agree not to:

  • upload anything you do not have the right to hold, or anything unlawful;
  • upload malware, or deliberately attempt to break, overload or circumvent the service’s limits;
  • try to access another workspace’s data, probe the service for vulnerabilities outside a good-faith disclosure, or resell access;
  • use the service to send unsolicited messages to people who have no relationship with you.

That list is deliberately short. It is not a catalog of everything we would rather you did not do; it is the set of things that put other people at risk — another workspace’s data, a subcontractor’s inbox, or the service everyone else is relying on.

2. The messaging rule, specifically

The fourth rule is the one worth expanding, because Sealinn is a product that sends mail and texts on your behalf. When a reminder goes out it carries your company’s name and Sealinn’s opt-out instructions, so the audience and permission behind each contact matter.

So: use it for people you actually work with, or are actively engaging. Every email we send a subcontractor carries a working unsubscribe link, every text carries STOP, and once somebody opts out by either route we stop sending to them from every workspace, not just yours. That is not a setting you can turn off — it is how the do-not-contact list is built. The messaging program sets out exactly which texts the product sends, in the wording it sends them.

The part worth being blunt about is whose permission is whose. Agreeing to the terms is your consent for us to contact you. It is not, and cannot be, consent on behalf of a subcontractor. Your working relationship determines who belongs in the workspace; it is not permission to text them. Sealinn sends an SMS only after a current preference is submitted through that subcontractor record’s bearer upload page for the exact number being texted. The upload link does not verify who submitted the preference or who owns the number. You cannot switch the preference on from the contractor-facing app, and changing the phone number does not carry the old choice across.

Two consequences follow. Uploading a purchased or scraped contact list and calling it your subcontractor roster is a breach of this policy, regardless of how the list was described when you bought it. And a phone number is not reusable permission: if you are unsure who owns it, correct the record and require a fresh upload-page preference. The final send check blocks a number with no current, number-matched preference and also blocks any number that has replied STOP.

3. What this policy is not about

It is worth saying what will not get you a message from us, because a policy that could be read as covering ordinary use is one nobody trusts.

  • Heavy but ordinary use. Plan limits are a commercial matter, handled in section 6 of the terms and enforced by the product, not by us writing to you. Hitting one is not misuse.
  • Disagreeing with a compliance decision. You set your own requirements and you can approve a document over a flagged violation. That is the product working as designed — your reviewer compares the COI with your requirements and you decide. Automated requirement checks are currently unavailable. What you require of your subcontractors is between you and them.
  • Using the supported COI workflow for ordinary project records. New document collection currently supports certificates of insurance and their endorsement pages only. Authorized historical files remain readable. Stored custom-document configuration is not permission to upload a new file type, and the restrictions below still apply to every record.
  • Telling us we got something wrong. Including in public.

4. Automated access

There is no public API today, so there is nothing to build against and no key to request. Driving the application with a script or a browser automation tool instead is not a supported way to use it: it bypasses the limits that keep the service up for everybody and it breaks without warning, because the interface it drives is not a contract.

Ordinary bulk work is supported and is not this. Importing several hundred subcontractors from a spreadsheet, generating a report over your whole book, exporting every certificate at once — those are features, and hitting a rate limit while using them is the system pacing you, not accusing you.

5. Security research is welcome

Testing your own workspace for problems, and telling us what you find, is not a breach of the third rule. Good-faith research is explicitly carved out. What is not carved out is reaching for another customer’s data, or continuing to probe after you have proved a point.

Report anything you find to security@sealinn.com. Our coordinated disclosure practice is on the security page, and the machine-readable version is at /.well-known/security.txt.

6. Reporting a problem

If a Sealinn message reached somebody who should not have had it, or a workspace is being used for something on the list in section 1, write to hello@sealinn.com. Include the message or the workspace name if you have it, and roughly when — a report we cannot locate is a report we cannot act on.

You do not need an account to report anything, and you do not need to be the person affected. If you received a Sealinn email you did not want, use its unsubscribe link. For a text, reply STOP. Either route takes effect immediately and across every workspace for that contact channel.

A report may concern somebody else’s workspace. Account actions and private account details are not disclosed to a reporter simply because they submitted the report.

7. What happens if a rule is broken

Almost always: we email you and ask. The overwhelmingly likely explanation for anything on that list is a mistake — a list imported from the wrong source, a departing employee’s credentials still in use, a script left running.

Where something is actively harming another party or the service itself, we may suspend the workspace first and contact you immediately after. Suspension is not deletion: your data stays where it is, exports keep working, and the retention windows on the privacy page are unchanged. If the relationship ends, the ordinary termination terms in section 9 apply — including that you keep your records and can export them.

In order, then: we ask; if that goes nowhere we limit the specific capability being misused, which for a messaging problem means outbound mail and texts rather than the whole account; and only then do we suspend. Immediate suspension is reserved for the case where waiting for a reply would let the harm continue. Nothing here is automatic — no score, no threshold, no bot deciding.

If you think we got it wrong, say so. Reply to the notice you received or write to hello@sealinn.com with the earlier message and the facts you want considered. There is no separate appeal form or ticket number.

8. Changes to this policy

The four rules in section 1 come from section 5 of the terms and change only when the terms do, with the version and date recorded there. If we change them in a way that narrows what you are allowed to do, we will write to your workspace owner before it takes effect rather than relying on you re-reading this page.

Everything else here — the enforcement ladder, the reporting route, the examples — is how we apply those rules, and we may sharpen it as we learn what actually comes up. The date at the top of the page moves when it does.

9. Questions

Anything about this page, and abuse reports: hello@sealinn.com. Security specifically: security@sealinn.com. Anything about the data itself — what is held, or a request to delete it — goes to the privacy page, which has its own address for exactly that.

This policy describes how we apply section 5 of the terms. Where the two could be read differently, the terms are the agreement — this page has no clause the terms do not already contain, and it is not a second thing you agreed to.

Looking for a different document? They are all listed on the Legal page.