Acceptable Use Policy
These rules supplement the Kshana API Terms and apply to every user, workspace, campaign, automation, API client, and connected WhatsApp account.
Last updated: August 7, 2026
Customers remain responsible for their recipients, content, consent records, message purpose, regulated-industry requirements, and compliance with Meta and WhatsApp policies.
Lawful and authorized use
You may use Kshana API only for legitimate business communications and only with data, accounts, phone numbers, content, and integrations you are authorized to use. You are responsible for applicable notices, consents, licenses, and regulatory requirements.
Consent and messaging quality
Do not send unsolicited or unexpected messages. Maintain evidence of appropriate WhatsApp opt-in, identify the sending business accurately, use approved templates for their intended category, and immediately honor STOP, blocking, unsubscribe, and other opt-out requests.
Automation must not mislead recipients into believing they are communicating with a human, and customer-facing flows must provide a clear path to support or human assistance when appropriate.
Prohibited activity
You must not use Kshana API to facilitate, promote, or distribute the following.
- Illegal, fraudulent, deceptive, abusive, harassing, discriminatory, exploitative, or infringing activity
- Malware, credential theft, unauthorized surveillance, phishing, evasion of platform controls, or attempts to gain unauthorized access
- Spam, purchased contact lists without valid permission, deceptive opt-in, or communication after an opt-out
- Sensitive financial credentials, passwords, one-time passwords, full identity numbers, or other data that should not be collected through ordinary chat
- Products, services, organizations, or regulated activities prohibited or restricted by applicable law or Meta and WhatsApp policies
Platform and infrastructure protection
Do not probe, overload, scrape, reverse engineer, bypass quotas, defeat access controls, interfere with queues or webhooks, share API credentials, or use Kshana API in a way that degrades service for another customer.
API callers must follow published scopes, rate limits, idempotency requirements, and security instructions.
Enforcement and reporting
We may investigate suspected abuse and restrict campaigns, automations, credentials, integrations, phone numbers, users, or workspaces where reasonably necessary to protect people, customers, providers, or the platform. Serious or repeated violations may result in suspension or termination.
Report suspected misuse to security@kshanaapi.com with the workspace, sender number ending, message time, and enough context to investigate without including unnecessary personal information.
