NewThe ManyPI MCP Server is now live

Acceptable Use Policy

What you may and may not do with ManyPI — and why the line falls where it does.

Version 2.0 · Effective 5 September 2026

This policy is short by design and written to be read rather than scrolled past. It forms part of the Terms of Service, and breaching it is grounds for suspension.

The two rules that matter most: outreach sent through ManyPI leaves your own mailbox, so you are the sender; and you decide who to research and contact, so you are the data controller. Everything below follows from those two facts.

Contents

This Acceptable Use Policy ("AUP") governs your use of ManyPI. It forms part of the Terms of Service, and a breach of it is a material breach of those Terms.

It applies to everyone who uses the Service: the account holder, every member of the account holder's organisation, and anyone acting through the API, the MCP server or an integration.

Why this policy exists. ManyPI can research people, store information about them and send them email. Used well, that is ordinary business development. Used badly, it is spam, harassment or an unlawful data operation — and the harm falls on people who never chose to interact with either of us. This policy draws the line, and we enforce it.

If you are unsure whether something is permitted, ask at legal@manypi.com before doing it. We would rather answer a question than suspend an account.

Two things follow from how ManyPI works, and everything else in this policy follows from them.

You are the sender. Outreach sent through ManyPI leaves your own mailbox, under your own domain and your own name. We do not relay it. To the recipient, to their mail provider and to a regulator, you are the sender. Your domain reputation, your deliverability and your legal exposure are yours.

You are the controller. You decide which people to research, which contacts to import, what to say and why. Under data protection law you are the controller for all of it, and we are your processor. Our respective obligations are set out in the Data Processing Agreement.

We provide tools. We do not provide a legal basis, and we cannot supply consent you do not have.

You must, in every message you send through the Service:

  • have a valid legal basis for contacting that person, and where the law of their jurisdiction requires prior consent, actually hold that consent;
  • use accurate header information — a truthful "From" name, a real and monitored reply address, and a subject line that does not mislead about the content;
  • include a functioning unsubscribe mechanism, and honour every opt-out promptly and permanently;
  • include a valid postal address where the law of the recipient's jurisdiction requires one;
  • identify commercial messages as such where required;
  • send from a domain and mailbox you are authorised to use.

You must not:

  • send unsolicited commercial email where the recipient's jurisdiction requires prior consent;
  • send to addresses obtained from purchased, rented, traded or scraped lists that you have no lawful basis to contact;
  • send to addresses you have constructed or guessed without a lawful basis for contacting that person;
  • continue contacting a person who has unsubscribed, objected, marked your mail as spam, or asked you to stop, through any channel or any account;
  • disable, remove, obscure or fail to honour the unsubscribe mechanism;
  • use false or misleading headers, forged routing information, or a "From" identity that is not yours;
  • send messages that are deceptive, fraudulent, defamatory, harassing, threatening, or that impersonate another person or organisation;
  • operate accounts, domains or mailboxes to evade a suppression list, a block, a spam filter or a suspension;
  • attempt to manipulate deliverability through artificial engagement, seed-list gaming or reputation laundering;
  • send at a volume or velocity that ManyPI has not provisioned for your plan, or circumvent the sending limits, warm-up ramp or bounce protections built into the Service.

A specific warning about Germany, Austria and much of the EU. German law (§ 7 UWG) requires prior express consent for commercial email — and, unlike the position in some other countries, that requirement applies in a business-to-business context too. A legitimate-interest analysis under the GDPR does not substitute for it. Similar rules apply in Austria and in several other Member States. Fines and injunctions are real, and the sender is the party who bears them. If you intend to contact recipients in these jurisdictions, obtain proper advice and build consent-based lists.

We are telling you this because the Service will let you send those messages, and we do not want you to assume that means they are lawful.

You must:

  • limit collection to what you actually need for a defined, lawful purpose;
  • respect the terms of service, robots exclusion rules and technical access controls of the sites you collect from;
  • give the people whose data you collect the information required by Article 14 GDPR — normally within one month of collecting it or at the time of your first message to them, whichever comes first — including telling them where you obtained it;
  • keep a record of the source of each record, so you can answer that question when asked;
  • delete data you no longer have a purpose for.

You must not:

  • collect from sources behind a login, a paywall, a CAPTCHA or any other access control that you are not authorised to pass;
  • collect in breach of a website's terms of service, or from a site that has told you not to;
  • bypass, disable or interfere with rate limits, bot detection or other technical protections;
  • collect at a volume or rate that degrades the performance or availability of a third-party website;
  • collect special categories of personal data under Article 9 GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation — or data relating to criminal convictions and offences;
  • collect data about children, or about people in their private rather than professional capacity where you have no basis for doing so;
  • build or sell a general-purpose profile database, a people-search product or a data-broker service from data collected through the Service;
  • use the Service to compile dossiers on individuals for the purpose of surveillance, harassment, discrimination, or to assess them for employment, credit, insurance, housing or any other decision with a legal or similarly significant effect.

Controls we operate. ManyPI parses and respects robots exclusion files, maintains a block list of sources from which collection is not permitted, and reviews collection targets that our risk assessment flags. Attempting to work around these controls is itself a breach of this policy.

These controls are not permission. That a site is technically reachable through the Service, and not on our block list, tells you nothing about whether you are entitled to collect from it. That assessment is yours.

§7 of the Terms of Service sets out the full warranties you give in respect of scraping — including database rights under Directive 96/9/EC, text-and-data-mining reservations under the DSM Directive, and computer-misuse law — together with the indemnity that goes with them. This section and §7 are to be read together.

Connecting a mailbox grants ManyPI access to read and send mail on your behalf. That is a significant permission and it carries corresponding obligations.

You must:

  • connect only a mailbox you own or are expressly authorised by its owner to connect;
  • where the mailbox belongs to an organisation, be authorised by that organisation to grant a third party access to its contents;
  • inform the people within your organisation whose correspondence may be synchronised;
  • bear in mind that synchronised correspondence becomes visible to every member of your ManyPI organisation, and manage your membership accordingly;
  • disconnect a mailbox promptly when you no longer need it, or when your authority to use it ends.

You must not:

  • connect a mailbox belonging to another person without their authority;
  • use mailbox access to read correspondence for a purpose unrelated to your use of the Service — for example to monitor an employee's private communications;
  • synchronise a mailbox that routinely receives special-category data, legally privileged material or the confidential information of third parties you are not entitled to place in a third-party system.

The Service can record when a message you send is opened.

You must:

  • disclose tracking to recipients where the law of their jurisdiction requires it, and obtain consent where it is required;
  • turn tracking off where you cannot meet that requirement.

You must not:

  • use tracking to infer sensitive characteristics about a person;
  • use tracking data to harass a recipient or to time contact in a way a reasonable person would find intrusive;
  • represent to a recipient that a message is not tracked when it is.

ManyPI records an open as a counter only. We do not log the recipient's IP address or user agent for this purpose.

You must not:

  • probe, scan or test the vulnerability of the Service or its infrastructure without our prior written permission;
  • breach or attempt to breach authentication or access controls, or access data belonging to another customer;
  • interfere with service to any user, host or network, including by denial-of-service or by flooding;
  • introduce malware, or use the Service to host, distribute or command malicious code;
  • reverse engineer, decompile or disassemble the Service except to the extent that restriction is prohibited by law;
  • resell, sublicense or provide the Service to a third party except as expressly permitted in the Terms of Service;
  • use automated means to create accounts, or create accounts to evade limits, trials or suspensions;
  • misrepresent your identity or affiliation when registering or when contacting support;
  • use the Service to build a product that competes with it.

Responsible disclosure. If you find a security vulnerability, report it to security@manypi.com. We will not pursue legal action against a researcher who acts in good faith, gives us reasonable time to remediate, does not access or retain data beyond what is needed to demonstrate the issue, and does not degrade the Service.

You must:

  • review AI-generated output before you act on it, and in particular before you send it — output is probabilistic and can be wrong, outdated or fabricated;
  • remain responsible for the accuracy and legality of everything you send, whoever or whatever drafted it;
  • disclose that you are using an automated system where the law requires it.

You must not:

  • present AI-generated content as the verified statement of a person or organisation who has not reviewed it;
  • use the Service to generate content that impersonates a real person or organisation;
  • use the Service to produce material that is defamatory, deceptive, or designed to manipulate a person into a decision against their interests;
  • use output as a substitute for professional advice, or hold it out to others as such;
  • use the Service to make or materially inform decisions with a legal or similarly significant effect on a person, including in employment, credit, insurance, housing, education or the provision of essential services.

You must not use the Service in connection with:

  • sexual content involving minors, or any content that sexualises a minor — we report this to the competent authorities without notice to you;
  • promotion or facilitation of terrorism, violent extremism, or violence against any person or group;
  • harassment, stalking, doxxing, threats, or content intended to intimidate or silence;
  • content that incites hatred or discrimination on the basis of a protected characteristic;
  • fraud, phishing, pretexting, advance-fee schemes, fake invoicing, or any attempt to obtain credentials, payment details or confidential information by deception;
  • the sale or promotion of goods or services whose sale is unlawful in the recipient's jurisdiction, including controlled substances, weapons, counterfeit goods and stolen data;
  • unlicensed financial, medical, legal or other regulated services, or investment solicitation in breach of applicable securities law;
  • infringement of intellectual property, or misappropriation of trade secrets;
  • political disinformation, coordinated inauthentic behaviour, or interference with an election or referendum;
  • any purpose prohibited by applicable export control or sanctions law, or on behalf of any person or entity subject to such sanctions.

What we do. We investigate reports and signals of abuse. We do not routinely monitor the content of your outreach or your data, and nothing in this policy creates an obligation for us to do so.

Graduated response. Where the circumstances allow, we will contact you first and give you a reasonable opportunity to explain or to remedy. Where they do not — because the conduct is serious, ongoing, or presents a risk to third parties, to our infrastructure or to our own legal position — we may act immediately.

Measures available to us, singly or together:

  • a warning, with a deadline to remedy;
  • throttling or suspension of a specific function, such as sending;
  • suspension of the account;
  • termination of the account and the subscription;
  • removal or blocking of specific content or data;
  • disclosure to a competent authority where we are legally obliged to make it, or where we reasonably believe there is a risk of serious harm to a person.

Consequences. Termination for breach of this policy does not entitle you to a refund of fees paid, and unused credits are forfeited. You remain liable for fees accrued up to termination, and the indemnity in the Terms of Service continues to apply.

Reinstatement. If your account is suspended and you believe the decision was wrong, write to abuse@manypi.com. We will review it and respond. If we got it wrong we will reinstate you and credit any period of lost service.

Reporting abuse. To report misuse of the Service by another user, write to abuse@manypi.com with the message headers or other evidence. We investigate every report and act on those we substantiate.

We may update this policy as the law changes, as the Service changes, or as new categories of abuse emerge.

We will give you at least thirty (30) days' notice of a material change, by email to your account address and by updating the effective date at the top of this page — except where a shorter period is required to address an urgent legal or security risk, in which case we will give as much notice as is reasonably possible.

If you do not accept a material change you may terminate your subscription before it takes effect and receive a pro-rata refund of prepaid fees for the unused remainder of your term. Continued use after the change takes effect constitutes acceptance.

Clarifications that do not expand the scope of what is prohibited may take effect immediately.

Contact

Report abuse: abuse@manypi.com
Security vulnerabilities: security@manypi.com
Questions about this policy: legal@manypi.com