2. Prohibited activity
- illegal surveillance, interception, stalking, harassment, threats, discrimination, exploitation, or invasion of privacy;
- spam, robocalling, deceptive marketing, impersonation, phishing, credential theft, fraud, or manipulation;
- malware, vulnerability exploitation, denial of service, unauthorized access, or attempts to bypass safeguards and limits;
- uploading or distributing content the business does not have the right to collect, copy, analyze, or disclose;
- using the service to make high-impact decisions about employment, credit, housing, insurance, health care, legal rights, or essential services without required human review and legal authorization;
- reselling access, sharing tester credentials, or provisioning undisclosed customers through one sponsored grant; and
- using fabricated operational data in a way that could be mistaken for a real customer, call, lead, inventory record, or transaction.
3. Sensitive and regulated information
The private beta is not approved for protected health information, full payment-card data in forms or messages, bank credentials, government identity documents, biometric identification databases, children's information, intimate information, criminal-investigation records, or other specially regulated or highly sensitive content unless a separate written review explicitly authorizes the workflow and required safeguards.
The business must configure forms and greetings to discourage unnecessary sensitive information and must remove accidental collection according to its lawful retention process.
4. Calls, recordings and communications
Before recording or transcribing, the configured greeting must tell the caller what will happen, state the business purpose, and provide an appropriate alternative when required. Proceeding after a clear notice may support implied consent in some circumstances, but the business remains responsible for determining the rule that applies to its call and location.
A recording collected for intake and routing cannot silently be reused for advertising, profiling, biometric identification, discipline, or training. Caller access and correction requests must be handled through the responsible business and applicable privacy process.
Trace Intake must not be advertised, configured, or relied on for 911, emergency dispatch, crisis response, medical triage, alarms, public safety, or any situation where delay or failure could cause injury or serious harm.
5. Security, devices and credentials
- protect activation codes, passwords, API keys, authentication factors, and business storage access;
- use supported Windows security controls and restrict folder permissions;
- do not copy owner credentials or use one tester's provider resources for another;
- install updates and follow recovery instructions when supplied;
- do not disable signed-callback verification, spending limits, duplicate protection, review queues, or audit safeguards; and
- report a suspected compromise, exposed credential, misrouted record, privacy incident, or unusual provider charge promptly through the beta channel.
6. Provider rules and cost limits
Use of Cloudflare, Stripe, Twilio, OpenAI, and customer-selected storage must remain compatible with those providers' applicable terms and acceptable-use rules. Current official links are listed in the Third-Party Provider Directory. Tester projects, subaccounts, numbers, spend limits, usage triggers, and grants may not be circumvented.
A telephone-number preview is read-only. A paid number may be activated only after explicit owner approval and customer selection. A sponsored tester is limited to the approved number and funded limits.
7. Reporting, review and enforcement
Potential violations may be investigated using narrow account, security, provider-reference, and service-health information rather than customer business-file contents. Access may be limited or suspended when reasonably necessary to stop harm, control provider cost, comply with law, protect credentials, or preserve service integrity.
Where safe and lawful, the operator should notify the affected business of the concern and corrective step. Serious illegality, deliberate abuse, credential theft, or immediate harm may require suspension without advance notice and referral to a provider or authority.
Commercial enforcement, appeals, notice periods, and termination remedies must be reviewed and finalized with the Terms of Service.