Our AI agent can ring you back now.Get a call back
Acceptable use

The rules for every call and message

Mirakash agents place real phone calls and send real messages to real people. This policy is the rulebook for you, for everyone you let use your account, and for every agent you build. It is part of our Terms of Service, and it applies every time the Service is used.

Last updated 19 September 2026

In short
  • You are responsible for every agent you build and every call and message it makes, including what your team, your clients and your own users do with it.

  • Get the consent the law requires before you call or text anyone. For marketing by an AI voice that usually means prior express written consent, and a bought list is never consent.

  • Your agents say which business they are calling for, say that they are an AI, never claim to be a person, and stop when someone asks them to stop.

  • Show only phone numbers and sender names you are entitled to use. No spoofing, and no swapping numbers to get past blocks and spam labels.

  • No fraud, impersonation, harassment, scams or voice cloning without consent. Do not send us health records, card numbers or children's data.

  • If you break these rules we can suspend you, reclaim numbers and work with carriers and the authorities. Anyone can report misuse to us at /contact.

01

Who and what this covers

This Acceptable Use Policy is part of the agreement between you and Naridon, Inc., a corporation incorporated in Delaware, USA, which provides Mirakash ("Mirakash", "we", "us"). It is incorporated into our Terms of Service. Where something in this policy is stricter than something else you have agreed with us, this policy applies, unless a written agreement signed by both of us expressly says otherwise.

"You" means the business that holds the Mirakash account. This policy covers:

  • everyone you let into your workspace, and everything done with your logins and API keys;
  • your clients and end users, if you run workspaces or agents for others (for example as an agency) or let other people use an agent you built;
  • every agent you build, configure or deploy, and everything it says or does;
  • every call, message, chat, email, tool action and webhook made through the Service, on any channel;
  • traffic that runs over your own vendor accounts: your own carrier, SIP trunk or SIM gateway, your own WhatsApp Business Account, your own model, speech or messaging vendor. Bringing your own account changes who bills you for that part of the call. It does not take the traffic outside this policy.

If anyone uses the Service through you, you must bind them to rules at least as strict as these, and you are responsible for what they do as if you had done it yourself.

Follow the law and this policy, both. Where the law is stricter, follow the law. Where this policy is stricter, follow this policy. The laws that count are the laws where the person you contact is, as well as the laws where you are.

Examples are not limits. The lists in this policy show what a rule means; they are not a complete catalogue. Something plainly against the purpose of a rule is not allowed just because it is not listed. You may not do indirectly (through another company, a tool, a webhook, a chain of agents or a second account) anything you may not do directly.

Where this policy summarises a law, it does so to help you. It is not legal advice, it is not a complete statement of the law, and laws change. Take your own advice for the places you operate in.

02

You are responsible

You decide who your agents contact, what they say, and why. For the personal data in those conversations you are the controller, and we process it on your behalf under our Data Processing Addendum. Making sure that every call and message is lawful is your job.

Some of our controls refuse a call or message that looks wrong. They are described in this policy where they exist. They are there to catch mistakes. They do not do your compliance for you, they do not cover every law, and a call that gets through them was not thereby lawful.

You must:

  • keep records of each consent (who gave it, when, how, the exact wording they agreed to and the number or address it covers), of each opt-out, and of the do-not-call registers you checked and when, for at least as long as the law that applies requires (for example, five years for consent to phone advertising in Germany and for telemarketing records under the US Telemarketing Sales Rule);
  • give us those records within five business days when we ask, for example after a complaint, a carrier traceback or a question from a regulator;
  • make sure everyone in your workspace, and every client you serve, knows these rules and follows them;
  • tell us the truth when we verify your business, and keep it up to date. Before some features switch on (your own carrier, WhatsApp, your own email domain, US 10DLC messaging) we may verify your business, have a person review it, and ask you to sign an undertaking to follow calling and messaging rules. That undertaking is part of this policy.

04

Do-not-call lists and opt-outs

Before any marketing call or message, check every do-not-call register that applies to the person you are contacting (see the table in section 03), as often as the law requires (for the US National Do Not Call Registry, at least every 31 days). Keep your own do-not-contact list as well, and check it across every campaign, agent, channel and number you use.

Honour every opt-out, at once. When someone asks not to be contacted, stop contacting them for that purpose. They may say it on a call ("don't call me again", "take me off your list"), reply STOP or a similar word, press a key, send an email, or use any other reasonable means. This policy requires you to act on it immediately, and never later than the law allows (in the US, ten business days at most). An opt-out given to one of your agents applies to all of them, on every channel you use for the same purpose. Keep opt-outs for as long as the law requires, and never delete one so that you can contact the person again.

Your agents must not argue with an opt-out, stall it or pitch again after it. An agent may confirm the request once. If you send a confirmation text, send it within five minutes, and make it only a confirmation, with no marketing. Do not configure or prompt an agent to "overcome" a request to stop.

What the platform does, and what it does not. Each workspace has an opt-out list on our platform, and there is a platform-wide one as well. Before our gateway places an outbound call for an agent, it checks the number against both lists and refuses the call if the number is on either. If the lists cannot be read at that moment, the call is refused rather than placed. Where WhatsApp is enabled, template messages an agent sends are checked against the same lists.

Numbers are also added to your list automatically in two cases. Every agent has a built-in step, which you cannot switch off, that records a request to stop when the conversation has a phone number: a call where the caller's number is known, or a text or WhatsApp conversation. And a text, WhatsApp or RCS message that says only STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, OPTOUT or OPT-OUT is recorded before your agent sees it. Neither is complete. An agent can fail to recognise a request, a website chat has no number to record, opt-out emails are not captured, and replies your agents send in a conversation the person started, and any email, are not checked against the lists. Text and WhatsApp messages an agent starts with its send-message tool are checked. So capturing and honouring every opt-out remains your responsibility: build your agents, integrations and processes so that it happens, and keep your own list. When we register a US 10DLC campaign for you, the carrier's own STOP-keyword handling is switched on for it, which is a carrier-level backstop and not a replacement for yours.

If a person contacted through Mirakash asks us to stop the calls, we can add their number to the opt-out list of the customer concerned, or to the platform-wide list, and we tell that customer. See section 20.

05

When, how often and how you call

Hours

Call and text only in the hours the law allows where the person is: for example 08:00 to 21:00 in the US (08:00 to 20:00 in Florida), and the other hours in the table in section 03. If you do not know where someone is, use the strictest hours that could apply.

By default, campaigns on the platform hold a contact until a local calling window opens. The window is 09:00 to 21:00 unless a stricter rule is encoded for the destination: 09:00 to 18:00 in the UAE, for example. For US and Canadian numbers the area code decides the time zone and the state or province. Florida, Oklahoma, Maryland and Washington end at 20:00; Texas starts at noon on a Sunday; Canadian numbers keep to 10:00 to 18:00 at weekends. Where an area code covers two time zones, the window has to hold in both. A toll-free or unrecognised number could be anywhere, so it gets the strictest window of all: 09:00 to 20:00 in every zone from Hawaii to Newfoundland at once, which rules out Sundays.

This is still an estimate. A mobile number keeps its area code when its owner moves, a country outside North America with several time zones is treated as one, public holidays are not closed, and only the state rules named above are encoded. It is a safeguard, not a statement of the law. Plan your campaigns so that the law is met where the person actually is.

How often

Do not contact the same person more often than the law allows, or more often than is reasonable. For example: in Florida, no more than three commercial telephone solicitation calls to the same person on the same subject in 24 hours; for US debt collectors, more than seven calls in seven days is presumed to be harassment (Regulation F); in France, no more than four telemarketing calls to a consumer in 30 days.

Each campaign stops trying a contact after a maximum number of attempts (three by default, never more than ten), with the gap between attempts that you set. Across all your workspace's campaigns, including finished ones, a number is dialled at most three times in any 24 hours; a contact at that limit waits rather than being dropped. That limit counts campaign calls only. Callbacks a person asked for, calls your agents place themselves and calls started by hand are not counted, so keeping the total lawful across those is up to you.

No silent or abandoned calls

Do not leave people with silent or abandoned calls. In the US, no more than 3% of calls answered by a person, measured per campaign over each 30-day period, may be abandoned, and each abandoned call must get a recorded message within two seconds of the greeting that identifies you and offers an opt-out. The UK has similar limits under Ofcom's policy on persistent misuse, and other countries have their own.

Campaigns dial at the fixed pace you set unless you switch on predictive pacing, which is off by default. When it is on, it aims to keep abandoned calls at or below 3% of connected calls, and it counts any connected call that ends within three seconds as abandoned. That is a proxy, and it deliberately over-counts. It helps you stay inside the rules; it does not guarantee that a campaign meets any law's definition, and measuring and meeting that is your job.

Say who you are

At the start of every call, your agent must say which business it is calling for, by the business's legal or registered trading name (a persona's first name is not enough), and why it is calling. During the call, or before it ends, it must give a telephone number the person can use to reach you or to ask not to be called again, and for telemarketing it must offer a way to opt out on the spot. Messages must identify your business too.

A message an agent leaves on voicemail or an answering machine is still a call made with an artificial voice. It needs the same consent, and it must identify you and give a callback number. "Ringless" voicemail counts as a call as well.

06

Saying it is an AI

People have a right to know when they are talking to a machine, and more and more laws say so.

  • EU AI Act, Article 50, applies from 2 August 2026. AI systems that interact directly with people must be designed so that people are told they are dealing with an AI, unless that is obvious. Article 50(1) puts that design duty on the provider of the system, and for our platform that is us: we build our agents to disclose, as described below, and this policy forbids configuring around it. Article 50 also requires AI-generated or manipulated audio and video that could pass as real to be disclosed when it is published.
  • California's B.O.T. Act makes it unlawful to use a bot to mislead a person in California about its artificial identity in order to sell them something or influence a vote. Utah and other states have AI-disclosure rules of their own.
  • The FCC treats AI voices as artificial voices under the TCPA (see section 03), so the rules for artificial-voice calls apply to your agents' calls.

Whether or not a law requires it where you operate, this policy requires that:

  • an agent never denies being an AI. If anyone asks, in any words, whether they are talking to a person, a bot, a recording or a machine, the agent says plainly and at once that it is an AI;
  • an agent never claims to be a human, and is never given a real person's identity. A persona name such as "Asha, the booking assistant" is fine. Presenting the agent as a named real employee is not, and neither is a made-up human backstory meant to make someone believe a person is speaking;
  • disclosure is not switched off, shortened, buried or talked over, and no prompt tells an agent to deny, dodge or delay it. Do not turn off the AI-disclosure skill on an agent;
  • text channels disclose too. On SMS, WhatsApp and other messaging channels the platform adds no notice of its own, so the first message your agent sends in a conversation (or the profile, where the channel shows one) must make clear that it is an automated AI assistant.

What the platform does today. At the start of a phone call handled by our gateway, before the agent speaks, a short spoken notice says the call is with an automated AI assistant. For numbers outside India it plays even if the notice is switched off in the agent's settings; your own wording replaces ours if you write it. For Indian numbers our default is to disclose when asked, and whether the notice plays is your setting. Our default wording does not name your business, which is one more reason your greeting must (section 05).

Our agents are instructed never to claim to be human, including when disclosure is set to happen only if asked. That is an instruction to the model, not a technical guarantee, and it stops applying if the disclosure skill is turned off, which this policy forbids. The chat widget labels the assistant as an AI in its header, shows a notice under its first reply that it is an AI and can get things wrong, and says in its profile panel that it is an AI agent, not a person.

The voices on the platform are synthetic. We do not currently add a watermark or other machine-readable mark to generated audio, so if you publish audio or video made with the Service (for example a call recording in an advert), label it as AI-generated yourself.

07

Recording and transcripts

Many places require people to be told before a conversation is recorded, and some require everyone's consent. In the US, "all-party consent" states include California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania and Washington. In Germany, recording a private conversation without consent is a criminal offence (§201 StGB). In the UK, the EU and India, a recording is personal data, and you need a lawful basis and a clear notice to make one.

What the platform does. Every conversation is transcribed, and the transcript is kept for your workspace's retention period whether or not audio is recorded. Call audio is kept only when a recording notice is configured for the agent (or a platform-wide notice applies), and the agent is told to give that notice; on phone calls it comes straight after the greeting. The platform does not stop recording by itself if someone objects. The agent is told to hand the conversation to a person instead.

Under this policy:

  • a transcript counts as a recording. Because the platform always keeps one, every conversation needs a notice that it is recorded or transcribed, and why, even if you switch audio recording off;
  • give the notice at the start, before anything substantive is discussed, and get consent wherever the law requires it;
  • if someone objects, or does not consent where consent is needed, stop: end the AI conversation, offer another way to reach you, and delete what you have no basis to keep. Per-person erasure is in the console under Settings, then Data;
  • do not record, or have an agent listen to, a conversation you are not a party to;
  • set retention windows no longer than you need. How long we keep data is set out in /privacy and /dpa.

08

Caller ID and sender identity

The US Truth in Caller ID Act makes it unlawful to send misleading or inaccurate caller ID with intent to defraud, cause harm or wrongfully obtain anything of value, and telemarketers must send a caller ID they can be reached on. In the UK, Ofcom's rules require a valid, diallable number that identifies the caller and that the caller has the right to use. In India, promotional voice calls must come from the 140 series, the 160 series applies to service and transactional calls where it is required, and ordinary ten-digit mobile numbers must not be used for telemarketing.

Under this policy:

  • show only a number that your business owns, leases or is otherwise authorised to use, that can be called back, and that reaches you or a way to opt out;
  • never spoof, and never show a number that belongs to someone else: a bank, a government body, a hospital, a well-known company or any individual;
  • no number rotation and no "snowshoeing". Do not spread calls or messages across many numbers to get past spam labels, carrier filters or blocks. Bringing in fresh numbers after one has been flagged is a breach, not a fix;
  • a local number (local presence) is allowed only if it is genuinely yours and calls to it reach you;
  • sender names (text message headers, WhatsApp display names, email "From" names and domains) must identify your business truthfully.

What the platform does. A campaign's caller ID can be set to a number your workspace holds. Members who manage your numbers can also enter other numbers, and API keys can use only numbers your workspace holds. Whoever enters a number is confirming that you are entitled to use it. Our local-presence feature picks only from your workspace's own numbers, and for calls to India it applies the Indian number-series rules first.

Call authentication (STIR/SHAKEN in the US and Canada) is applied by the carrier that places the call, not by Mirakash, and we cannot promise any particular attestation level or how a call will be labelled on the other person's phone.

09

SMS, WhatsApp and other channels

Everything in sections 03 to 08 applies to messages as much as to calls: consent, opt-outs, hours, identifying yourself and disclosing that it is an AI. No bought lists and no snowshoeing on any channel.

Text messages

  • US and Canada. Follow the CTIA Messaging Principles and Best Practices and the carriers' codes of conduct. Register US 10DLC brands and campaigns with The Campaign Registry, and verify toll-free numbers, before you send. Send only the use case you registered, with content that matches its sample messages. Content about sex, hate, alcohol, firearms, tobacco or cannabis is allowed only where the carriers allow it, with the age checks they require. Do not use public link shorteners; use links on your own domain. Honour STOP and the other standard opt-out keywords, and answer HELP.
  • India. Every text to an Indian number must use a header and a content template registered and approved on DLT under TCCCPR, in the right category (promotional, service or transactional), with only whitelisted links and callback numbers in it. Our platform will not send a text to an Indian number unless your workspace has an active DLT registration and the message matches one of your approved templates, and it sends promotional templates only between 09:00 and 21:00 India time. There is no setting to turn this off.
  • Everywhere. Follow the sender-registration rules of the country you send to. Where our verification rules apply, a US ten-digit long code cannot send until its registration is approved.

WhatsApp

WhatsApp features are available only where we have enabled them for your workspace. Where they are, follow the WhatsApp Business Messaging Policy, the WhatsApp Commerce Policy and Meta's business and platform terms. In particular:

  • message only people who have opted in to WhatsApp messages from your business, and honour every request to stop;
  • start conversations with approved message templates. Outside the customer-service window (24 hours after the person's last message) only a template may be sent;
  • never ask for full payment card numbers, bank account numbers, national identity numbers, passwords or other sensitive identifiers in a WhatsApp chat;
  • do not sell or promote anything the Commerce Policy prohibits;
  • use WhatsApp for your own business's conversations with your own customers. WhatsApp's terms do not allow a general-purpose AI assistant to be offered through the WhatsApp Business Platform;
  • if Meta limits, flags or bans a number or an account, do not work around it with new numbers or accounts.

When WhatsApp is enabled, an agent sends a template only to the person it is talking with or to a number with a recorded WhatsApp opt-in, never to a number on the opt-out lists, and template sends are rate-limited per person and per workspace. Mirakash's WhatsApp features run on a Meta developer app and a WhatsApp Business Account registered to Aikolumi Software Pvt Ltd (India), which operates them for Mirakash. If you connect your own WhatsApp Business Account, you are also Meta's customer for that account. Meta can enforce its own policies against you, independently of us.

Email and other channels

Email must follow the anti-spam law of the recipient's country (for example CAN-SPAM in the US, and PECR and the ePrivacy rules in the UK and EU): accurate headers and sender, a working unsubscribe link, honoured promptly, and consent where the law requires it. On any other channel (web chat, social media inboxes, Telegram, Slack and the like) the channel's own terms apply as well as this policy, and they may be stricter.

Do not use unofficial, modified or reverse-engineered clients for WhatsApp or any other messaging service, and do not automate personal accounts, through the Service or alongside it.

10

What you may never do

You must not use the Service, or let an agent be used, for any of the following, anywhere:

  • Anything illegal where you are or where the person you contact is, or helping anyone else break the law.
  • Fraud and scams: phishing by voice, text or email; tech-support, refund, prize, lottery, loan-fee, investment, crypto, romance and "family emergency" scams; fake invoices and fake debts; collecting passwords, PINs or login details by deception; any social engineering to get into someone's accounts or systems. An agent must never ask a person to read out, forward or type in a one-time code, password or PIN that another company sent them.
  • Impersonation: pretending to be, or implying you are connected with, a government body, the police, a court, a tax authority, a bank, a carrier, a utility, a hospital, a well-known company or any real person, unless you have their written authority. That includes misleading caller names, display names, logos and voices.
  • Harassment and abuse: threats, intimidation, stalking, bullying, abusive language, publishing someone's private information, repeated unwanted contact, and contacting anyone to punish them for complaining or opting out.
  • Hate and violent extremism: promoting violence against people, or hatred or discrimination because of a protected characteristic; supporting terrorist or violent extremist groups; incitement.
  • Child sexual abuse and exploitation: any content that sexualises a minor, and any grooming. There is no tolerance for this at all. We remove it, close the account and report it as the law requires.
  • Sexual content: sexually explicit content, adult chat lines, sexual services, erotic or "companion" agents, and any intimate content shared without consent.
  • Self-harm: encouraging or instructing suicide, self-harm or eating disorders.
  • Weapons, drugs and dangerous goods: selling or promoting firearms, ammunition, explosives, illegal drugs, or prescription medicines without a prescription; instructions for making weapons, including chemical, biological, radiological and nuclear weapons.
  • Gambling without a licence where the person is, or aimed at anyone under the legal age.
  • Deceptive practices: false or misleading claims about a product, a price, who you are or why you are calling; fake urgency ("your account will be closed today"), fake scarcity and other dark patterns; hidden conditions on "free" offers; fake reviews and testimonials; selling under the pretence of a survey or research.
  • Preying on vulnerable people: targeting people because of their age, illness, disability, grief or financial distress in order to take advantage of it.
  • Malware and harmful links: sending malware, or links to phishing or malicious sites.
  • Fake alerts: anything that imitates an emergency alert, a public warning or an official notice.
  • Other people's rights: content you have no right to use, and covert surveillance of anyone.

We decide whether a use breaks this section. In a close case we will decide in good faith, and we will look at what the use does, not what it is called.

11

Regulated and higher-risk uses

Some uses are allowed only if you meet the extra rules of that field. Some need our written agreement before you start.

  • Political and election communication needs our written agreement first. It must follow the election and campaign laws where it is received: sponsor ("paid for by") disclosures, the AI-content disclosure laws many US states now have, and the TCPA, which applies to political calls to mobile phones too. Never impersonate a candidate or an official, never give false information about when, where or how to vote, and never try to discourage anyone from voting.
  • Debt collection must follow the rules for collectors: in the US the Fair Debt Collection Practices Act and Regulation F (say that you are a debt collector, limit how often you call, respect time and place, never tell third parties about the debt) and state licensing; in the UK the FCA's rules; in India the Reserve Bank of India's rules for recovery agents, including calling only between 08:00 and 19:00.
  • Financial services (lending, insurance, investments, crypto assets) need the licences and the disclosures the law requires. An agent must not promise approval, guarantee a return, or give personal investment, tax or legal advice unless you are authorised to give it and a qualified person is accountable for it.
  • Healthcare: no protected health information at all (section 15), and an agent must not diagnose, triage or recommend treatment.
  • Alcohol, tobacco, vaping and cannabis: only where lawful, and only to adults whose age you have checked.
  • Charity fundraising: only if you are registered where the law requires, with the disclosures fundraisers must make.

Uses that decide things about people (jobs, credit, insurance, housing, education) are covered in section 12.

12

Banned AI practices and decisions about people

Article 5 of the EU AI Act has banned certain AI practices since 2 February 2025. You must not use the Service for any of them, anywhere, not only in the EU:

  • subliminal, manipulative or deceptive techniques that materially distort someone's behaviour and cause, or are likely to cause, significant harm;
  • exploiting a person's vulnerabilities because of their age, disability or social or economic situation;
  • social scoring that leads to people being treated unfairly;
  • predicting that a person will commit a crime based only on profiling or their personality traits;
  • building facial-recognition databases by untargeted scraping;
  • inferring people's emotions in the workplace or in education, except for medical or safety reasons;
  • biometric categorisation to work out someone's race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation;
  • real-time remote biometric identification in public places for law enforcement.

Emotion. Our agents can adapt their tone to how a caller sounds. If an agent talks to employees or students (for example an HR line or a school's helpline), switch off emotion inference for that agent in its guardrails settings.

Biometrics. The platform does not offer voice biometrics. Do not use it to identify or verify people by their voice, or to categorise them biometrically, without our written agreement and the consent the law requires.

Decisions about people. Do not let an agent make, on its own, a decision that has legal or similarly significant effects on a person: hiring or dismissal, credit, insurance, housing, admission to education, access to essential services or benefits. A person must meaningfully review it, and the person affected must be able to contest it (GDPR Article 22, UK GDPR, and a growing number of US state laws).

High-risk uses. Uses the EU AI Act lists as high-risk in Annex III (for example recruitment and candidate screening, credit scoring, access to education, essential public services and benefits, pricing of life and health insurance, and evaluating or dispatching emergency calls) need our written agreement before you start, and you take on the duties the Act places on deployers.

13

Emergencies and safety-critical uses

Mirakash is not an emergency service and must not be used as one. Our outbound destination policy dials only full international phone numbers, so it refuses short emergency codes such as 911, 112 and 999. The platform does not provide the caller-location information that emergency services rely on.

  • Do not use an agent to triage, dispatch, evaluate or classify emergency calls, to run a crisis or suicide line, or to give medical advice in an emergency.
  • Do not use the Service to control anything where a failure could cause death, injury or serious damage: medical devices, industrial control, vehicles, aviation.
  • If a person tells your agent they are in danger, or that there is an emergency, the agent must tell them to hang up and call the local emergency number, or hand them to a trained person at once, and must not try to handle it.
  • An AI agent must not be the only way to reach urgent help (for example a care provider's out-of-hours line) unless a person is available to take over.

14

Voices and likeness

Clone or imitate a voice only with the documented, written, informed consent of the person whose voice it is, for the purpose you will use it for. Keep that consent. If they withdraw it, stop using the voice and delete it.

When you create a cloned voice, the console asks for the name of the person who gave consent. That typed name is all the platform records: it does not check the consent or keep it, so keeping it is your job. We do not keep the sample recording you upload; it is sent to the voice vendor to create the voice.

  • Never clone or imitate the voice of a public figure, politician, celebrity, child or dead person, or anyone else, without the authority of that person or of whoever holds their rights.
  • Never use a voice to impersonate someone, including to get past a bank's or an employer's voice checks.
  • The same applies to faces and likeness: do not use a real person's face or likeness for an avatar without their written consent.
  • If you publish audio or video made with the Service that sounds or looks like a real person, or could be mistaken for real, label it as AI-generated.

15

Data you must not send us

The Service is not built for certain kinds of data. Do not put them in, and do not build agents that ask for them.

  • Protected health information (PHI). We do not sign business associate agreements, and the Service is not set up to handle PHI under HIPAA. If you are a HIPAA covered entity or business associate, do not use the Service for anything that involves PHI.
  • Payment card data. No full card numbers, security codes (CVV/CVC) or PINs, by voice, chat, message, upload or knowledge base. Take payments through a payment provider's own secure page or line, never through the agent. Our agents are built not to read card numbers or codes aloud, and card numbers are redacted from transcripts by default, but those are backstops: the spoken-number guard does not cover every agent type (it does not cover native-audio agents), a workspace can turn redaction off for an agent, and a caller can still say the numbers.
  • Special categories of personal data (health, genetic and biometric data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, sex life or sexual orientation), data about criminal convictions, and "sensitive personal information" under US state laws: only where you have a lawful basis and a real need, never to profile people, and never for anything section 12 forbids.
  • Children's data. The Service is for businesses, and for users aged 18 and over. Do not use it to contact, profile or collect data from anyone under 18, or build agents aimed at them, unless we have agreed in writing and you have the verifiable parental consent the law requires (India's DPDP Act, for example, treats everyone under 18 as a child; in the US, COPPA protects children under 13).
  • Data you have no right to. Personal data you have no lawful basis to use, including scraped, bought or leaked lists, and data collected for another purpose.
  • Knowledge bases may hold only content you have the right to use. Do not load other people's personal data or confidential information into them, and respect the terms of any website you crawl.

16

Security and fair use

  • No testing without permission. Do not scan, probe, load-test or penetration-test the Service, or look for vulnerabilities in it, without our written permission first. Ask through /contact, under "Report a security vulnerability". If you come across a vulnerability by accident, report it there straight away, do not use it or share it, and do not access data that is not yours. We will not take action against a good-faith report that follows these rules.
  • No breaking in. Do not access, or try to access, another customer's workspace, data, numbers or agents, get around sign-in, roles or multi-factor authentication, or use the Service to attack anyone else's systems.
  • No scraping. Do not scrape, crawl or copy the Service, its interfaces or its content by automated means, except through the interfaces we provide for that purpose, and do not reverse-engineer it except where the law allows.
  • No getting around limits. Do not evade any limit, quota, spend ceiling, rate limit, destination rule, verification step or suspension, for example by opening extra accounts or workspaces, splitting traffic, rotating numbers or routing around our gateway.
  • No shared logins. Every person gets their own login. Do not share logins, sessions or authenticator devices. Keep API keys and other credentials secret, give them only the access they need, and replace them if they may have leaked. You are responsible for everything done with your credentials.
  • No reselling without an agreement. Do not resell, sublicense or white-label the Service, or run it for others (for example as an agency), unless a written agreement with us allows it. Where one does, sections 01 and 02 apply to your clients.
  • Trial credits are for testing. Do not use trial credits or a trial workspace for live websites, production traffic or real campaigns, and do not open more than one trial. A trial workspace must verify a phone it can answer before it can dial a campaign.
  • No abuse of our vendors. Do not attack, overload or misuse the carriers, model and speech vendors or messaging platforms behind the Service, or break their terms through it, including with prompts or content designed to get round their safety systems or extract their data.
  • No telecom fraud. No International Revenue Share Fraud (IRSF), traffic pumping, artificially inflated traffic or SMS pumping; no calls or messages made to earn termination revenue, inflate usage or test number ranges; no one-ring ("wangiri") calls.
  • No gaming the meter. Do not manipulate how minutes, usage or resolutions are measured, for example by holding calls open, generating fake conversations, or triggering or disputing outcome counts in bad faith.
  • Our own demos are for you. The demo call and the assistant on our website are for trying Mirakash yourself. Do not use them to call anyone else, to load-test, or to extract their instructions.

17

Where you can call

The Service is available only for some countries, and which ones may change at any time. It is not enabled for the United Arab Emirates, and you must not use it to contact people there until we tell you in writing that it is. Do not use the Service in, from or to a country or region under comprehensive sanctions, or for anyone on a sanctions list that applies to you or to us.

What the platform does. Before our gateway places an outbound call, the number is checked against a destination policy. A call to a country that is not enabled, to premium-rate, personal-numbering or satellite numbers, or to certain other high-risk ranges is refused, and so is anything that is not a full international phone number. Anything the policy does not positively allow is refused, before the call is made. The same check applies to transfers, callbacks and click-to-call. Messages are covered by the channel rules in section 09; this destination policy is about calls.

A country being enabled does not make a call to it lawful. Its own rules still apply.

18

What we do about a breach

We may investigate any suspected breach of this policy. That can include reviewing your agents' configuration and prompts, logs, transcripts and recordings, as far as needed and as set out in /dpa and /privacy. You must answer our questions about it promptly and fully.

Depending on how serious it is, we may do any of the following:

  • warn you, and require a fix by a deadline;
  • pause a particular agent, campaign, number, channel, integration or API key;
  • suspend your workspace, which stops its calls, messages and agents. We will try to tell you first. We may act immediately and without notice where there is a risk of harm to people, a legal or regulatory risk, a demand from a carrier or from Meta, or fraud;
  • terminate your account;
  • remove or disable content, agents, prompts, knowledge bases or voices;
  • reclaim or release phone numbers and sender IDs we provided, including during a campaign;
  • cancel or withhold credits that were obtained or used abusively (including trial and promotional credits), and charge you for costs your breach causes us, such as carrier fines and fraudulent-traffic charges;
  • report the breach to, and work with, carriers, Meta, registries, regulators and the police (section 19);
  • refuse future service to you and to anyone acting for you.

We do not have to warn you before acting, and not acting on one breach does not mean we accept it or give up the right to act later. Carriers, Meta and registries can also act on their own (blocking numbers, lowering a quality rating, suspending a WhatsApp account, fining you), and we cannot reverse their decisions.

You are responsible for claims, fines and costs caused by your breach of this policy, and you indemnify us for them as set out in our Terms of Service.

If you think we have got it wrong, tell us through /contact and a person will review it.

19

Carriers, regulators and law enforcement

Carriers, industry traceback groups (such as the US Industry Traceback Group), Meta, registries such as The Campaign Registry and India's DLT operators, and regulators may ask us who sent a call or message. We answer them. We may share your business identity, the verification details you gave us, and records of the calls and messages they ask about, as the law allows. Your verification undertaking already lets us do this.

We disclose customer data to law enforcement only in response to legally valid requests, and we tell you about a request for your data unless the law, or an emergency involving risk to someone's life or safety, stops us.

When we are investigating, or a carrier, regulator or authority asks us to, we may take steps to preserve records relevant to the matter. When we ask you to preserve your own records (consent, opt-outs, lists, prompts), you must.

20

Reporting abuse

If an agent on Mirakash contacted you in a way you think breaks this policy, or you have seen any other misuse, tell us through /contact, under "Report abuse". Security vulnerabilities have their own topic on the same form (section 16). If it is urgent, or a crime is happening, contact the police or your local emergency number first.

Please tell us, as far as you can:

  • the number or sender that contacted you, and the number or address it reached;
  • the date, the time and your time zone;
  • what was said or written, with a screenshot or recording if you have one;
  • the business it said it was calling for;
  • whether you had ever given that business consent, and whether you had asked it to stop;
  • what you would like us to do, for example make sure the number is not called again.

A person reads every report. We look at the traffic, act under section 18 where needed, and tell the customer concerned about the complaint. We share the number involved and what happened with that customer, so that they can stop contacting it, but not your name or contact details unless you ask us to or the law requires it. If you ask, we can add your number to the customer's opt-out list or to our platform-wide list, which our gateway checks before it places any agent's outbound call.

Requests about your own personal data (to see it, delete it or object to its use) have their own topics on the same form. See /privacy. You can also complain to a regulator: in the US the FTC or the FCC, in the UK the ICO, in India through TRAI's DND service (1909) or the Chakshu facility on the government's Sanchar Saathi portal.

No retaliation. Customers must not retaliate against anyone who reports abuse, complains or opts out: no punitive calls or messages, no charges, and no worse service.

21

Changes and effective date

This is the first version of this policy. It takes effect on 19 September 2026.

The law, carriers' and Meta's rules, and the ways people misuse platforms all change, so this policy will change too. We will tell you about a material change at least 30 days before it takes effect, in the console or by another reasonable means, and the date at the top of this page changes with it. A change needed to comply with the law or a carrier's or Meta's rules, or to stop abuse, can take effect immediately. If you keep using the Service after a change takes effect, the changed policy applies to you.

Questions and legal notices about this policy go to /contact. The rest of our terms are at /terms, and how we handle personal data is at /privacy and /dpa.