Compliance & AI Safety Standards

Acceptable Use & AI Messaging Policy

Effective Date: September 7, 2026 • Last Revised: September 7, 2026

Safe AI Execution

No jailbreaks, prompt injections, deceptive impersonation, or unverified high-risk financial/medical advice.

Zero Tolerance for Spam

Verifiable recipient opt-in is required before any broadcast or sequence. Automated STOP/opt-out is mandatory.

Data Privacy & PII

Sensitive personal data and credentials must never be passed to automated generative AI prompts or public models.

1. Overview & Scope of Infrastructure

This Acceptable Use Policy ("AUP") outlines mandatory standards and behavioral guidelines for all users, subscribers, and developers accessing or interacting with the Flowista platform ("Service", "we", "our").

Flowista provides enterprise-grade customer communications infrastructure, featuring a Visual Flow Builder, Omnichannel Unified Inbox, automated sequence triggers, and AI-assisted conversational tools powered by Large Language Models (LLMs). This infrastructure bridges directly into third-party communication networks, including:

WhatsApp Business Cloud API
Instagram Direct Messaging
Facebook Messenger
Telegram Messenger
X / Twitter Direct Messages
Webchat & Custom Widgets
Audio / Voice Transcription
CRM & Webhook Connectors

By signing up for an account, linking communication channels, creating automated visual flows, or deploying AI nodes, you agree to comply fully with this Policy. Any violation may result in immediate rate-limiting, temporary integration suspension, or account termination.

2. Prohibited Uses of AI-Assisted Conversational Features

Flowista incorporates generative AI copilot features, autonomous AI agent nodes, smart reply suggestions, audio-to-text transcription, and intent classification. You may never configure, prompt, or deploy our AI tools for the following purposes:

Deceptive Impersonation & Falsification

Misleading end-users by claiming the AI bot is an authorized government official, legal representative, emergency personnel, or real individual without authorization. Where required by regional consumer law (e.g., EU AI Act, California BOT Disclosure Law), you must clearly disclose to end-users that they are interacting with an automated AI system.

Safety Filter Bypass & Adversarial Prompting

Executing prompt injection attacks, jailbreaks, system prompt extractions, or adversarial test suites intended to bypass safety layers, content moderation thresholds, or platform system constraints.

Unregulated & High-Risk Advisory

Deploying unmonitored AI agents to dispense professional medical diagnosis, emergency medical advice, individualized legal defense strategies, or definitive investment recommendations without certified human licensure and explicit disclaimers.

Harmful, Hateful & Illegal Content Generation

Generating, circulating, or facilitating material depicting sexual exploitation, non-consensual imagery, harassment, defamatory statements, terrorist propaganda, self-harm encouragement, or cyberattack payloads/phishing kits.

3. Omnichannel Customer Messaging & Anti-Spam Rules

Flowista's automation engine enables scheduled broadcasts, automated drip campaigns, and trigger-based conversational sequences across WhatsApp, Instagram, Telegram, Messenger, and X. All outbound communications must comply with strict deliverability and consumer protection standards:

  • Verifiable Express Consent (Opt-in): You must have clear, affirmative consent from every recipient before sending marketing, promotional, or automated broadcast communications. Purchasing, renting, or scraping contact databases is strictly prohibited.
  • Immediate Frictionless Opt-Out: Every automated marketing campaign or broadcast sequence must support standard opt-out keywords (including STOP, UNSUBSCRIBE, CANCEL, or local language equivalents). Upon receipt of an opt-out request, your flows must immediately cease sending non-transactional messages to that recipient.
  • Carrier & Upstream Ecosystem Compliance: You must strictly adhere to the policies of each respective communication network:
    • WhatsApp / Meta: WhatsApp Business Messaging Policy, Commerce Policy, and WhatsApp Tiered Quality Rating guidelines.
    • Telegram: Telegram Bot API Terms and community spam guidelines.
    • X / Twitter: X Developer Agreement, Direct Message Automation Rules, and Automation Policy.
    • Instagram / Facebook: Meta Platform Terms and Messenger Platform Policy (including the 24-hour standard messaging window).
  • No Phishing or Credential Harvesting: Flows must never prompt users to submit plaintext passwords, credit card CVV numbers, bank PINs, or government-issued national identity numbers through chat.

4. Data Privacy & Confidentiality in AI Workflows

When utilizing Flowista's AI nodes (such as dynamic knowledge-base queries, conversation summarization, and copilot draft generation):

  • No Proprietary Training on Customer Conversations: Flowista does not sell, lease, or use your end-customer private conversational dialogues to train public, open foundational AI models.
  • Sensitive PII Masking: Customers are responsible for configuring data sanitation filters to ensure highly sensitive data (e.g., health records, biometric identifiers, payment credentials) is not injected into unstructured prompt contexts.
  • Audio & Voice Message Processing: Inbound voice notes and audio clips processed by Flowista's transcription nodes are transcribed solely for the purpose of indexing, workflow automation, and agent inbox display.

5. Human-in-the-Loop & Fail-Safe Architecture

To maintain high customer experience standards and reduce hallucination risks:

  • Human Escalation Fallback: We strongly recommend and require automated workflows handling customer support or commerce transactions to implement a fallback handoff node ("Assign to Human Agent") when confidence scores are low or when explicitly requested by an end-user.
  • Monitoring & Accuracy: You remain solely responsible for validating the accuracy, factual reliability, and tone of automated AI-generated responses published to your customers.

6. Infrastructure Protection & Fair Use

You agree not to exploit or abuse the infrastructure supporting Flowista:

  • Do not circumvent workspace tier rate limits, monthly message allowances, or concurrent execution limits.
  • Do not launch automated denial-of-service (DoS) attempts or reverse-engineer webhook delivery endpoints.
  • Do not share enterprise API credentials or account access tokens with unauthorized external organizations.

7. Enforcement, Audits & Account Suspension

Flowista employs automated abuse-detection heuristics, message bounce-rate monitors, and upstream carrier feedback loops. If an account or automated flow is found to be in violation of this Policy:

  1. Notice & Remediation: For minor or unintentional infractions, we will notify the account owner and provide instructions to adjust the offending flow within 24 hours.
  2. Selective Feature Restriction: We may selectively disable specific AI agent nodes, suspend outbound broadcast queues, or throttle incoming webhooks while investigating reported abuse.
  3. Immediate Termination: In cases of egregious misconduct (including mass phishing, deliberate spamming, hate speech, or carrier regulatory enforcement), we reserve the right to immediately terminate the account, forfeit remaining subscription balances, and report the abuse to relevant upstream telecommunications authorities.

8. Reporting Violations & Support Contact

If you discover an account or flow built on Flowista that is generating unauthorized messages, abusing AI features, or violating this policy, please notify our compliance team immediately.

Flowista Trust, Safety & Compliance

Reports are reviewed promptly by our dedicated compliance officers.

info@flowista.net