This Acceptable Use Policy applies to everyone who uses Merdial and forms part of the Terms of Service. It exists because a platform that records other people’s conversations can do real harm in the wrong hands, and because one customer’s misuse damages every other customer on the same infrastructure.
You are responsible for the people you let in
Everything below applies to your Authorised Users, your end clients using a portal, and anyone you give an API credential to, exactly as it applies to you.1. Nothing unlawful
Do not use the Service to:
- Break any law that applies to you or to the person you are calling.
- Record, intercept or transcribe a conversation without every consent and notice that jurisdiction requires. See Terms §7.1.
- Call in breach of the TCPA, the Telemarketing Sales Rule, national or internal do-not-call lists, calling-hour restrictions, or their equivalents outside the US.
- Falsify caller ID, spoof a number you are not authorised to use, or otherwise disguise the origin of a call.
- Facilitate fraud, phishing, vishing, extortion, money laundering, or the sale of prohibited goods.
- Infringe intellectual property or misappropriate trade secrets.
2. On the call: three hard lines
These are grounds for immediate suspension, without notice
Not a warning, not a cure period. The harm lands on a member of the public in the seconds it is happening.- No recording without the consent that jurisdiction requires. Fourteen US states require every party to a call to agree, and the fix is one sentence at the top of the script. See Terms §7.1.
- No impersonating a person or an organisation you do not represent. Including a government body, a bank, a utility, a healthcare provider or a law-enforcement agency — and including presenting your agents as employees of a company they do not work for.
- No deceiving the person on the line about a material fact. A fabricated offer, an invented affiliation, a false urgency about a debt or a legal action, or a spoofed caller ID intended to get a pick-up.
3. No consequential decisions without a human
Merdial generates scores, verdicts and qualifications. Do not use them as the sole basis for a decision that produces a legal or similarly significant effect on a person:
- Employment. Hiring, discipline, performance rating, pay, promotion or termination of your staff. A QA score is evidence for a manager, not a verdict.
- Access to essential services. Credit, insurance, housing, healthcare, education or a government benefit.
- Legal exposure. Anything that creates or forfeits a legal right for the person on the call.
The review queue, the dispute flow and the calibration report exist so that a human decides. Do not configure the platform to route around them and then treat the result as a decision.
4. Data you must not put in
- Payment card data in any field. The redaction layer strips card patterns from transcripts before generative processing, but it is a safety net, not a licence: Merdial is not a PCI-DSS cardholder data environment.
- Protected health information under HIPAA, unless a Business Associate Agreement is in place. We do not offer one by default.
- Government identifiers — social security, national insurance, passport or driving-licence numbers — as structured data.
- Special-category personal data (racial or ethnic origin, political opinions, religious belief, trade-union membership, genetic or biometric data, health, sex life or sexual orientation) submitted deliberately.
- Children’s data, or data about anyone under 16.
- Contact lists you have no lawful basis to hold — scraped, purchased from an unverified source, or obtained in breach of another platform’s terms.
5. Protecting the platform and other tenants
- No probing, scanning or testing the security of the Service without written authorisation. Responsible disclosure is welcome at team@merdial.com; see Security.
- No attempting to access another organisation’s data, to escalate privileges, or to bypass tenant isolation, authentication or rate limits.
- No reverse-engineering, decompiling, or attempting to extract model weights, prompts, system instructions or training data.
- No using the Service to build a competing product, to benchmark it for publication without consent, or to resell raw model access.
- No automated load beyond documented rate limits, no denial of service, no distributing malware.
- No sharing named-seat credentials between people, and no circumventing seat or usage metering.
6. Content
Do not use the Service to generate or transmit content that is:
- Harassing, threatening, defamatory, or that incites violence or self-harm.
- Sexual content involving minors, or non-consensual sexual content of any kind.
- Designed to deceive about a material fact — a fabricated offer, an invented affiliation, a false urgency about a debt or a legal action.
- Designed to manipulate a vulnerable person into a transaction they do not understand.
7. Enforcement
Where we believe this policy has been breached we may, depending on severity: ask you to fix it; disable a specific feature; suspend the account; or terminate the agreement. For the hard lines in §2 and for anything presenting immediate risk to a member of the public or to the platform, we act first and explain after. Suspension for cause does not entitle you to a refund of fees for the suspended period — see the Refund & Cancellation Policy.
We will cooperate with law enforcement acting under valid legal process, and we may report conduct that appears to present a risk of serious harm.
8. Changes
We will update this policy as new misuse patterns appear. Material changes are announced to account administrators at least 30 days before they take effect. This policy is effective 6 September 2026.

