Acceptable Use Policy

Last updated: 2026-04-14

DRAFT — AI-generated, not reviewed by counsel. This document is a working draft and does not constitute legal advice or a binding policy. It will be reviewed and revised by Truepost, LLC and its attorneys before it takes effect.

Truepost exists because email got loud, ugly, and full of liars. Our tagline — Email Messaging — But No, REALLY! — is a promise: no fake senders, one-click report-and-block, and a service that treats your inbox like it matters. This Acceptable Use Policy ("AUP") describes what you may and may not do when using Truepost. It applies to everyone who uses Truepost — free or paid, individual or organization — and is part of our Terms of Service.

If you break these rules, we may warn you, suspend your account, terminate it, report you to law enforcement, or all of the above. We will try to be fair, but we will not host abuse.

1. Spam and unsolicited email

Truepost is a personal and small-team email client, not a bulk-mail platform. Don’t use it to push messages people didn’t ask for.

  • No sending bulk unsolicited commercial email, newsletters, or political mail through Truepost-connected accounts.
  • You must comply with the U.S. CAN-SPAM Act and any equivalent law that applies to you (CASL, GDPR/ePrivacy, etc.).
  • No harvesting, scraping, buying, or trading email addresses for the purpose of sending mail.
  • No mailing-list operation that lacks clear opt-in and a working unsubscribe.
  • No "cold outreach" tools, sequences, or automation that send identical or near-identical messages at volume.

2. Phishing, spoofing, and impersonation

  • No phishing of any kind — credential theft, fake invoices, fake shipping notices, fake support, fake anything.
  • No spoofing sender names, domains, or display fields to make a message appear to come from someone else.
  • No impersonating real people, companies, government agencies, or Truepost itself.
  • No homoglyph or look-alike domain tricks designed to fool a recipient.

3. Malware, exploits, and attacks on Truepost

  • No sending malware, ransomware, spyware, stalkerware, miners, droppers, or links to any of the above.
  • No weaponized attachments — macro bombs, exploit documents, malicious archives, etc.
  • No probing, fuzzing, DoS, or other attacks against Truepost infrastructure or other users.
  • No attempts to bypass authentication, escalate privileges, or read data that isn’t yours.
  • Good-faith security research is welcome — see Safe Harbor below.

4. Illegal content and conduct

The following are absolutely prohibited and will result in immediate termination:

  • Child sexual abuse material (CSAM): zero tolerance. We report all such material to the National Center for Missing & Exploited Children (NCMEC) and cooperate fully with law enforcement.
  • Credible threats of violence, terrorism, or self-harm directed at others.
  • Targeted harassment, stalking, or doxxing — publishing private information to enable harm.
  • Incitement to violence, genocide, or unlawful action against any individual or group.
  • Human trafficking, exploitation of minors, or non-consensual intimate imagery.
  • Anything else that is illegal under U.S. federal law or the law of your jurisdiction.

5. Intellectual property

  • Don’t use Truepost to send or distribute material that infringes someone else’s copyright, trademark, patent, or trade secret rights.
  • Don’t remove or alter copyright notices on material you forward.
  • If you believe content sent through Truepost infringes your rights, send a DMCA notice to legal@truepost.com. We follow the standard DMCA process: notice, takedown, counter-notice, restoration.

6. Export controls and sanctions

  • Truepost is a U.S. company and complies with U.S. export control and sanctions law.
  • You may not use Truepost if you are on the OFAC Specially Designated Nationals (SDN) list, or if you are located in or ordinarily resident in a comprehensively sanctioned region.
  • You may not use Truepost to facilitate any transaction that would violate U.S. sanctions or export controls.

7. Service abuse

  • No scraping, crawling, or bulk extraction of Truepost’s service, UI, or APIs.
  • No evading rate limits, quotas, or throttles — including by rotating accounts or IPs.
  • No reverse engineering, decompiling, or disassembling Truepost software, except to the extent that applicable law expressly permits and contract cannot waive.
  • No reselling, white-labeling, or sublicensing Truepost without a written agreement with Truepost, LLC.
  • No using Truepost to build, train, or benchmark a competing email product.

8. Account sharing and multi-accounting

  • Free-tier accounts are for one person. Don’t share credentials or hand your account around a team.
  • Don’t create multiple free accounts to dodge limits, evade a ban, or game promotions.
  • Enterprise and team plans (when available) will have their own seat-sharing rules — this section will be revised when those launch.

9. HIPAA and protected health information

Truepost is not, by default, a HIPAA-compliant service. Do not transmit Protected Health Information (PHI) through Truepost unless you have a signed Business Associate Agreement (BAA) with Truepost, LLC. If you need a BAA, write to legal@truepost.com. Without one, sending PHI through Truepost violates this policy and may violate HIPAA.

10. Reporting abuse

If you receive abusive mail through a Truepost-connected account, or if you see Truepost being used to break this policy, tell us:

  • Email abuse@truepost.com with the offending message (full headers if you can), the sender, and a brief description of what’s wrong.
  • For CSAM specifically, you may also report directly to NCMEC at report.cybertip.org.
  • We aim to acknowledge abuse reports within two business days. We investigate every report we receive. We won’t always tell you what action we took — privacy works in both directions — but we will act.

11. Enforcement

When we find a violation, we generally escalate as follows:

  • Warning: a notice describing the problem and asking you to stop. Most issues end here.
  • Suspension: temporary loss of access while we investigate or while you fix the issue.
  • Termination: permanent loss of your Truepost account and a ban on creating new ones.
  • Immediate termination for severe violations (CSAM, credible threats, active attacks on Truepost, sanctions violations) with no warning step.

Appeals. If you think we got it wrong, reply to the enforcement notice or write to appeals@truepost.com within 30 days. A human who was not involved in the original decision will review it. We’ll respond within a reasonable time and tell you the outcome.

12. Safe harbor for security researchers

We welcome good-faith security research. If you find a vulnerability in Truepost, report it to security@truepost.com and give us a reasonable chance to fix it before publishing. In return, if you act in good faith, follow this policy, avoid harming users or their data, don’t exfiltrate more than the minimum needed to demonstrate the issue, and don’t disrupt our services:

  • We will not pursue civil action or initiate a complaint to law enforcement against you for your research.
  • We consider your activity authorized under the Computer Fraud and Abuse Act and equivalent laws.
  • We’ll work with you on coordinated disclosure and credit you if you’d like.

This safe harbor does not extend to social engineering of Truepost staff or users, physical attacks, or testing on accounts that aren’t yours without permission.

Contact

Truepost, LLC (in formation), United States. We may update this AUP from time to time; the "Last updated" date at the top will change when we do.