Skip to main content

Legal

Acceptable Use Policy

What you may and may not do with our apps, the Ṣọ Shield API, and our enterprise and partner offerings.

Effective: July 25, 2026Last Updated: July 25, 2026

This Acceptable Use Policy (the “Policy”) sets out the rules for using the products and services provided by SO Labs Inc. (“Ṣọ,” “we,” “our,” or “us”), a company based in Calgary, Alberta, Canada. It is incorporated into our Terms of Service and our API Terms, and it forms part of both. Breaking this Policy is a breach of those agreements. The Terms of Service set the governing law and the process for resolving disputes, and they apply to this Policy as well.

01Who This Policy Applies To

This Policy applies to everyone who uses any of our products:

  • Consumer and small business apps. The Chrome extension for Gmail and Outlook web, the iOS app, the Android app, the desktop app, and the web dashboard.
  • The Ṣọ Shield API. All endpoints, API keys, the developer dashboard, and any sandbox environment.
  • Enterprise deployments. Organisation-wide use under a signed agreement.
  • The MSP and MSSP partner offering. This is an early access programme for design partners. The partner platform has not shipped and is not generally available. Where we work with a design partner, this Policy applies to that work.

It applies to the account holder, to every user under that account, and to anyone acting on the account holder's behalf, including automated systems and AI agents.

This Policy is incorporated into the Terms of Service and the API Terms. Where an enterprise or partner customer has a separate signed agreement with us, that agreement also applies.

02Prohibited Uses

2.1 Permitted use

  • Use Ṣọ Email Security only for lawful purposes and in line with our Terms of Service.
  • Use the service to improve your email security and productivity.
  • Comply with all laws and regulations that apply to you.

2.2 Prohibited activities

You must not:

  • Engage in any illegal activity, or use the service to help anyone else act illegally.
  • Send spam, phishing email, or other unsolicited communications through the service.
  • Transmit harmful code, malware, or malicious content through the service.
  • Try to breach, disable, or get around our security or authentication measures.
  • Reverse engineer, decompile, or try to extract our source code, models, rules, or weights.
  • Interfere with or disrupt the service, our servers, or other customers' use of it.
  • Access another person's mailbox or inbox without proper authorisation.
  • Violate the privacy or the security of other users.
  • Scrape the service, harvest data from it automatically, or try to bypass rate limits.
  • Share account credentials or API keys, or allow unauthorised access to your account.
  • Use the service in a way that could damage our reputation or our business.

03Rules for the Ṣọ Shield API

These rules apply in addition to Section 02 if you use the API. They sit alongside the API Terms.

  • Keep your keys secret. An API key is a credential. Treat it like a password. All activity on a key is treated as your activity.
  • Never expose a live key. Do not put a production key in client-side code, a mobile app binary, a browser extension, a public repository, a screenshot, or a support ticket.
  • Do not resell or share raw API access. You may not sell, sublicense, or pass through direct API access to another party without a written agreement with us.
  • Respect the published rate limits. Handle HTTP 429 responses with retry and backoff. Do not create multiple accounts, share keys, or spread traffic across keys to get around a limit or the credit count.
  • Do not build a competing dataset. You may not use the API to build, train, or enrich a competing threat-detection dataset, model, or service.
  • Only submit content you have the right to submit. See Section 05.
  • Use sandbox keys for testing only. Sandbox responses must not be relied on for real security decisions.

If you think a key has been exposed, rotate it in the developer dashboard and tell us at privacy@soemailsecurity.com.

04AI Agent Use

You may call the Ṣọ Shield API from an autonomous agent. If you do, the following applies.

  • You remain responsible. Anything your agent submits is treated as submitted by you. “The agent did it” is not a defence to a breach of this Policy.
  • You must have the right to submit what it sends. Before you point an agent at a mailbox or a document store, make sure you have the lawful basis and any consents needed for that content to reach us.
  • Scope the agent's access. Give it only the mailboxes, data, and permissions it needs, and use a key you can revoke on its own.
  • Control the request volume. An agent in a loop can burn through credits and hit rate limits quickly. Put a ceiling on request rate and spend on your side.
  • Do not let an agent make the final call alone on a high-risk action. Our results are probabilistic. Keep human review or an independent control for payments, account changes, and anything else where a wrong answer causes real harm. Section 08 of the API Terms explains the limits of detection.

05Content Responsibility

  • You need a lawful basis. You are responsible for having the legal right, and any consents or notices required, to send us the email content, documents, URLs, and images you submit.
  • This matters most for other people's data. If the content belongs to your own end users, your employees, or your clients, the duty to have that basis and to tell them sits with you, not with us.
  • You are responsible for your own communications. You are solely responsible for the content of the email you send. We do not endorse or take responsibility for content created by users.
  • What we do with submitted content. Email content is analysed in memory and is not written to persistent storage. The one exception is content you choose to send us when you report a false positive, which is encrypted at rest and deleted after 90 days. Our Privacy Policy and Data Processing Agreement cover this in full.
  • You grant us the permissions we need. By using the service you give us the limited rights needed to provide it, as described in our Privacy Policy.

06Enforcement

If we believe this Policy has been broken, we may take any of these steps, depending on how serious the problem is:

  • Warning. We contact you, explain the problem, and ask you to fix it.
  • Rate limiting. We apply a temporary limit to your traffic to protect the service.
  • Suspension. We suspend a key, a user, or the account until the problem is resolved.
  • Termination. We end the account for a serious breach or a breach that keeps happening.

Where it is practical we will give you notice first and a chance to put things right. We may act immediately, and explain afterwards, where there is a risk of harm to people, to other customers, or to the service, where there is a live security incident, or where the activity creates legal exposure for us or for you.

We may also report unlawful activity to the relevant authorities where the law requires it or where we reasonably believe it is necessary. Fees already paid are handled as set out in the Terms of Service and the API Terms.

If you think we got an enforcement decision wrong, reply to the notice we sent or write to support@soemailsecurity.com. A person will look at it.

07Reporting Abuse

Tell us if you see something wrong. We would rather hear about it early.

  • Security issues: privacy@soemailsecurity.com. Use this for a vulnerability, an exposed API key, a suspected compromise, or abuse of the service to attack someone.
  • Everything else: support@soemailsecurity.com. Use this for policy breaches, account questions, and anything that is not a security issue.
  • Privacy questions: privacy@soemailsecurity.com.
  • Mailing address: SO Labs Inc., 7909 Flint Rd SE #202 Calgary AB T2H 1G3 Canada

When you report something, include what you saw, when you saw it, and enough detail for us to reproduce it. Please do not send us more personal data than we need to look into it.

By using Ṣọ Email Security, the Ṣọ Shield API, or any of our enterprise or partner offerings, you agree to follow this Acceptable Use Policy.