The short version: everyone you email must have asked you to email them, and you must be able to show when and how they asked. Everything below follows from that one rule.
1. Why this policy exists
Email deliverability is shared. When one sender emails people who did not ask for it, the complaints that follow damage the reputation of the infrastructure everyone else is sending from. A single bad campaign can put every other ReplyAid customer into spam folders.
So this policy is not a formality, and we enforce it. Accounts that breach it are suspended, usually without warning where the breach is serious.
This policy sits alongside our Terms of Service and forms part of your agreement with us. It also incorporates the AWS Acceptable Use Policy, because ReplyAid sends through Amazon SES — conduct prohibited by AWS is prohibited here.
2. The consent we require
Every address on your list must belong to someone who gave you permission to email them about the things you are emailing them about. Specifically:
- They took a positive action. They filled in a form, ticked an unticked box, or otherwise opted in deliberately. Pre-ticked boxes and "by continuing you agree" do not count.
- They knew what they were signing up for. The wording at the point of signup described the emails they would receive. Consent given for a newsletter does not extend to third-party promotions.
- You can evidence it. You must be able to produce, on request, the date, the source, and where possible the IP address of every subscriber's opt-in. Lists imported into ReplyAid must have this evidence behind them.
- It is recent enough to be meaningful. Addresses that have not been emailed in over 24 months, or that have not engaged in that time, should not be reactivated without re-permission.
The UK Privacy and Electronic Communications Regulations 2003 permit a narrow "soft opt-in" for existing customers of a similar product, where an opt-out was offered at the point of sale and in every message. If you rely on this, you must be able to demonstrate that each condition is met. It does not apply to prospects, and it does not apply to individual subscribers acquired any other way.
3. Lists you may not use
You may not send to addresses obtained from any of the following, on any plan, under any circumstances:
- Purchased, rented, leased, licensed or otherwise acquired lists — including "GDPR-compliant" and "opted-in" lists sold by data brokers.
- Addresses scraped or harvested from websites, directories, LinkedIn, Companies House, social media, or public records.
- Addresses generated by guessing patterns such as
firstname@company.com, or produced by any email-finding or enrichment tool. - Lists inherited from an acquisition, a partner, an affiliate or a previous business, unless the original consent explicitly covered you.
- Addresses collected for an unrelated purpose — a competition entry, a delivery address, a support ticket, a CV.
- Co-registration and lead-generation lists where the subscriber ticked one box covering multiple unnamed companies.
- Any list you cannot explain the origin of.
Uploading such a list is a breach of this policy whether or not you send to it.
4. Content and conduct you may not send
You may not use ReplyAid to send, host or link to:
- Phishing, credential harvesting, or anything designed to impersonate another person, business or brand.
- Malware, viruses, ransomware, or links to sites distributing them.
- Content that is unlawful, defamatory, obscene, harassing, or that incites violence or hatred against any group.
- Sexually explicit material, or material sexualising minors in any form.
- Content that infringes copyright, trade marks or other intellectual property.
- Chain letters, pyramid schemes, matrix schemes, multi-level marketing recruitment, "get rich quick" offers, or work-from-home income claims.
- Misleading claims about health outcomes, financial returns, or the identity of the sender.
- Deceptive subject lines, forged headers, or false sender names and addresses.
- Anything that breaches UK law, the law where your recipients are, or the AWS Acceptable Use Policy.
5. Restricted sectors
The following generate complaint rates well above average. We do not ban them outright, but accounts sending on their behalf require prior written approval and are monitored more closely. Sending without approval is a breach.
- Cryptocurrency, tokens, NFTs and related trading services.
- Forex, CFDs, binary options, and unregulated investment offers.
- Payday lending, debt consolidation, credit repair and claims management.
- Gambling, betting and casino promotions.
- Nutraceuticals, supplements and weight-loss products.
- Pharmaceuticals, vaping and tobacco products.
- Adult services, dating and escort services.
- Immigration, visa and "guaranteed job placement" services.
- List brokerage, lead generation, and email marketing services sold to others.
6. Technical requirements
Every campaign sent through ReplyAid must:
- Include a working, one-click unsubscribe link that is visible without scrolling to microscopic text, and a
List-Unsubscribeheader. We add these automatically and you may not remove, hide or disable them. - Identify the sender clearly — the legal name of the business responsible, and a valid physical postal address.
- Use a
Fromaddress on a domain you control, authenticated with SPF and DKIM. We will not send from free mailbox domains such as gmail.com or outlook.com. - Have a monitored reply-to address. Replies must reach a human.
- Use a subject line that accurately reflects the contents.
Unsubscribe requests must be honoured immediately. Our platform does this automatically; you may not re-import an address that has unsubscribed, and doing so deliberately is treated as a serious breach.
7. Quality thresholds
We monitor these figures per account and per campaign. They are not targets to aim near — they are the point at which sending stops.
| Metric | Warning | Sending paused |
|---|---|---|
| Spam complaint rate | 0.08% | 0.1% |
| Hard bounce rate | 3% | 5% |
| Spam trap hits | Any | Any confirmed hit |
| Unsubscribe rate | 1% | Reviewed case by case |
If a campaign crosses a pause threshold mid-send, we stop it. You will be told why, and we will help you work out what went wrong before sending resumes.
8. Using the platform itself
You may not:
- Open multiple accounts to get around a suspension or a sending limit.
- Resell, sublicense or provide access to ReplyAid as a service to third parties without our written agreement.
- Attempt to access another account, probe our systems for vulnerabilities, or interfere with the service for anyone else.
- Use the API in a way that degrades performance, or exceed published rate limits.
- Scrape, reverse engineer or reproduce the service.
- Give us false information when opening or verifying an account.
Responsible security disclosure is welcome and will never be treated as a breach. Email security@replyaid.com before testing anything.
9. How we monitor compliance
We review the first import and first campaign on every new account before it can send. We may ask you where a list came from, and to show us the signup form and the wording used. We monitor bounce, complaint and engagement metrics continuously, and we investigate every abuse report we receive.
We do not read your campaign content for any purpose other than abuse prevention, support you have asked for, and complying with a legal obligation.
10. What happens if you breach this policy
Our response is proportionate to what happened, but we act quickly. Depending on the breach we may:
- Ask you about it. Most issues are honest mistakes and are resolved with a conversation and a list clean-up.
- Pause sending. Your account stays open and your data is intact, but nothing goes out until the issue is fixed.
- Suspend the account. For repeated breaches, or where you cannot evidence consent for a list you have sent to.
- Terminate immediately, without refund. For phishing, malware, illegal content, deliberate evasion of a suspension, or knowingly sending to a purchased list.
Where a breach causes us financial loss — including loss of sending reputation, remediation costs, or action taken against us by a supplier or regulator — we may seek to recover it from you. We report unlawful conduct to the appropriate authorities.
You can appeal any suspension by emailing appeals@replyaid.com. We will look at it properly and respond within five working days.
11. Reporting abuse
If you received an email sent through ReplyAid that you did not ask for, tell us. Forward the message with full headers to abuse@replyaid.com.
We acknowledge every report within one working day and investigate every one of them. You do not need to be a customer, and we will not pass your details to the sender without asking you first.
12. Changes to this policy
Email abuse evolves, and so will this document. We will post updates here with a new version number. Where a change adds a new restriction, we will give account holders 30 days' notice by email unless the change is needed immediately to deal with an active threat.
Suspension appeals: appeals@replyaid.com
Security disclosure: security@replyaid.com
Everything else: hello@replyaid.com