Acceptable Use Policy
Effective Date: September 9, 2026
Introduction
This Acceptable Use Policy ("Policy") sets forth the rules and guidelines applicable to the use of Recura AI, Inc.'s ("Recura AI," "we," "us," or "our") SMS messaging services (the "Services"). This Policy applies to all clinics and users who utilize our Services to send SMS messages to patients or clients.
This Policy is incorporated by reference into the Recura AI, Inc. Terms of Service. We may suspend, terminate, or take other interim action regarding access to or use of the Services if, in our sole judgment, we believe you have violated this Policy or authorized or helped others to do so.
We may modify this Policy from time to time by posting a revised version on our website. By using the Services, you agree to the latest version of this Policy. Any capitalized terms not defined in this Policy have the meaning set forth in the Terms of Service.
General Requirements
All communications sent through the Services must comply with applicable laws and telecommunications industry guidelines and standards. To ensure messages reach intended recipients unhindered by filtering or blockers, all SMS messages must comply with this Policy, which sets out rules regarding:
- Consent ("opt-in") requirements
- Revocation of consent ("opt-out") procedures
- Sender identification
- Messaging usage guidelines
- Prohibited content
- Filter evasion prohibitions
- Enforcement mechanisms
Consent Requirements
Standard Consent Requirements
Prior to sending the first message to an individual, you must obtain explicit agreement from the message recipient to communicate with them via SMS. You must clearly disclose the types of messages the recipient will receive (e.g., appointment reminders, confirmations, promotional offers).
You must maintain a record of consent, such as a copy of a signed form, timestamp of a completed sign-up flow, or other documented proof of consent. This record must be retained as required by applicable regulations or best practices, even after an end user opts out of receiving messages.
If you do not send an initial message to an individual within a reasonable period after receiving consent (or as required by local regulations), you must reconfirm consent in the first message you send to that recipient.
Consent applies only to you (the clinic) and to the specific use for which the recipient has consented. Consent cannot be bought, sold, or exchanged. You cannot obtain consent by purchasing a phone list from another party, nor can you treat consent as blanket authorization to send messages from other brands, companies, or for uses beyond what was originally consented to.
Alternative Consent Scenarios
Contact Initiated by an Individual: If an individual sends a message to you, you may respond directly to that individual in an exchange. For example, if an individual texts your phone number asking about hours of operation, you can respond directly. In such cases, the individual's inbound message constitutes both consent and proof of consent. However, this consent is limited only to that particular conversation. Unless you obtain additional consent, do not send messages outside that conversation.
Informational Content Based on Prior Relationship: You may send a message to an individual where you have a prior relationship, provided that: (1) the individual provided their phone number to you, (2) the individual has taken some action to trigger the potential communication (such as scheduling an appointment, placing an order, or setting up an alert), and (3) the individual has not opted out or otherwise expressed a preference to not receive messages from you.
Examples of acceptable messages in these scenarios include appointment reminders, receipts, order confirmations, shipping notifications, and service call confirmations. These messages must be transactional or informational in nature and cannot attempt to promote a product, convince someone to buy something, or advocate for a social cause.
Periodic Messages and Ongoing Consent
If you intend to send messages to a recipient on an ongoing basis, you should periodically confirm the recipient's consent by offering a clear reminder of how to unsubscribe using standard opt-out language. You must also respect the message recipient's preferences regarding frequency of contact and proactively ask individuals to reconfirm their consent as required by local regulations and best practices.
Sender Identification
Every message you send must clearly identify you (the clinic that obtained consent from the recipient) as the sender, except in follow-up messages of an ongoing conversation where the context makes the sender clear. Messages must not mislead recipients about who is sending the message.
Opt-Out Requirements
The initial message that you send to an individual must include opt-out language such as "Reply STOP to unsubscribe" or the equivalent using another standard opt-out keyword, including END, STOPALL, UNSUBSCRIBE, and QUIT.
Individuals must have the ability to revoke consent at any time by replying with a standard opt-out keyword. When an individual opts out, you may deliver one final message to confirm that the opt-out has been processed, but any subsequent messages are not allowed. An individual must once again provide consent before you can send any additional messages.
Opt-out requests must be processed promptly and in accordance with applicable laws and regulations, including the Telephone Consumer Protection Act (TCPA).
Prohibited Content
You agree that you will not use the Services, or encourage, promote, facilitate, or instruct others to use the Services, to send messages that contain, offer, promote, reference, or link to any information or content related to any of the following:
Spam and Unsolicited Messages
Any messages, communications, promotions, advertising, or solicitations that are unsolicited or for which you do not have proper consent from the intended recipient. This includes commercial advertising and informational announcements sent without consent.
Illegal, Harmful, or Fraudulent Activities
Any activities that are illegal, violate the rights of others, or may be harmful to others, our operations, or reputation, including but not limited to:
- Child pornography, child sexual abuse material, or other sexually exploitative content
- Fraudulent goods, services, schemes, or promotions
- Make-money-fast or "get-rich-quick" schemes (including work-from-home programs, risk investment opportunities, ponzi and pyramid schemes)
- High-risk financial services (including payday loans, short-term high-interest loans, third-party auto or mortgage loans, student loans, or cryptocurrency)
- Third-party lead generation services (companies that buy, sell, or share consumer information)
- Debt collection or forgiveness services (including third-party debt collection, debt consolidation, debt reduction, or credit repair programs)
- Illegal or regulated substances (including, but not limited to, Cannabis, CBD, or offers for Prescription Drugs that cannot be sold over-the-counter)
- Gambling
- "SHAFT" use cases (Sex, Hate, Alcohol, Firearms, Tobacco, including vaping-related activities)
- Phishing or pharming
Infringing Content
Content that infringes or misappropriates the intellectual property or proprietary rights of others, including copyright, trademark, or patent infringement.
Offensive Content
Content that is harassing, defamatory, obscene, abusive, invasive of privacy, or otherwise objectionable.
Harmful Content
Content or other computer technology that may damage, interfere with, surreptitiously intercept, or expropriate any system, program, or data, or otherwise effect a security breach, including viruses, Trojan horses, worms, time bombs, or cancelbots.
Healthcare-Specific Restrictions
Messages must comply with all applicable healthcare regulations, including HIPAA. Protected Health Information (PHI) must be handled in accordance with HIPAA requirements and any applicable Business Associate Agreements. Messages must not provide medical advice unless you are a licensed healthcare provider authorized to do so, and must not mislead recipients about the nature of healthcare services or treatments.
Message Abuse and Falsification
You will not send messages using spam bots or other similar automated systems designed to send unsolicited messages. You will not alter or obscure message headers, provide false identification, or assume a sender's identity without the sender's explicit permission. You will not create a false identity or attempt to mislead others as to the identity of the sender or the origin of any communications.
Filter Evasion Prohibitions
You may not use the Services to evade unwanted messaging detection and prevention mechanisms employed by Recura AI, telecommunications providers, or carriers. Prohibited practices include:
- Content designed to evade detection: We do not allow content that has been specifically designed to evade detection by unwanted messaging detection and prevention mechanisms. This includes intentionally misspelled words or non-standard opt-out phrases created with the intent to evade these mechanisms.
- Snowshoeing: We do not permit snowshoeing, which is defined as spreading similar or identical messages across many phone numbers with the intent or effect of evading unwanted messaging detection and prevention mechanisms.
- Use of shared public URL shorteners: Where a web address (URL) shortener is used, you should not use links that have been shortened using shared public URL shorteners like Bitly or TinyURL. If you want to include shortened URLs in your messages, we recommend using a dedicated short domain.
Message Frequency and Volume
All Services are subject to reasonable use limits and are intended for normal business use in compliance with this Policy and the Terms of Service. Any unusually high or excessive usage of the Services may impair Recura AI's ability to provide the Services to you and other users, in which case Recura AI may suspend or terminate your use of and/or access to the Services.
You must respect message recipients' preferences regarding frequency of contact and comply with carrier guidelines and rate limiting requirements.
Compliance with Regulations
You must comply with all applicable laws and regulations governing SMS messaging, including but not limited to:
- The Telephone Consumer Protection Act (TCPA) and its implementing regulations
- The CAN-SPAM Act
- A2P 10DLC (Application-to-Person 10-Digit Long Code) requirements
- State-specific regulations governing SMS messaging
- Carrier requirements (AT&T, T-Mobile, Verizon, Sprint, and other major U.S. carriers)
- HIPAA and other healthcare privacy regulations (if applicable)
- Industry best practices and guidelines
Monitoring and Enforcement
We reserve the right, but do not assume the obligation, to monitor content sent through the Services and to investigate any violation of the Terms of Service, including this Policy, or misuse of the Services. We may remove or disable access to any user, content, or resource that violates the Terms of Service or this Policy or any other agreement we have with you for use of the Services.
We may report any activity that we suspect violates any law or regulation to appropriate law enforcement officials, regulators, or other appropriate third parties. Our reporting may include disclosing appropriate customer information. We may also cooperate with appropriate law enforcement agencies, regulators, or other appropriate third parties to help with the investigation and prosecution of illegal conduct by providing network and systems information related to alleged violations of this Policy.
Reporting Violations
If you become aware of any violation of this Policy, you will immediately notify us and provide us with assistance, as requested, to stop or remedy the violation. To report a violation, please contact us using the contact information provided below.
Contact Information
If you have questions about this Acceptable Use Policy, please contact Recura AI, Inc.: