Acceptable Use Policy
Document status: Approved v1.0 (2026-07-21) Effective date: 2026-07-21
This Acceptable Use Policy (“AUP”) governs your use of the SurveyRock platform and related services (the “Service”) provided by Oak Mountain Digital LLC (“SurveyRock”). The AUP is incorporated into our Terms of Service. Violation of the AUP is a material breach of the Terms.
We monitor for AUP violations through automated systems and respond to user reports. We act in good faith to enforce these rules consistently and proportionately.
1. Purpose
SurveyRock is built for legitimate research, customer feedback, employee feedback, market research, and similar feedback programs. Survey platforms can be misused for harm — phishing, scams, harassment, illegal data collection, and unsolicited marketing. This AUP defines what’s not permitted and what we do about violations.
2. Prohibited content
You may not use the Service to create, distribute, or collect responses for content that:
2.1 Phishing and credential theft
- Asks Respondents for passwords, OTP codes, account verification credentials, or any authentication information
- Impersonates a legitimate organization to extract sensitive information (banking, government, employer)
- Uses brand impersonation language (“Your [Company] account requires verification…”)
- Combines urgency + verification (“Verify within 24 hours to avoid suspension”)
2.2 Scams and fraud
- “Free [valuable item]” prize draws that extract data without delivering
- Advance-fee fraud schemes (Nigerian prince patterns, fake job offers requiring upfront payment)
- Crypto investment / token airdrop solicitations
- Romance scam patterns
- Fake survey rewards / undelivered incentive schemes
2.3 Hate, harassment, and illegal content
- Slurs, dehumanizing language, or content targeting individuals based on protected characteristics (race, religion, gender, sexual orientation, disability, national origin)
- Targeted harassment of named individuals
- Content sexualizing minors (immediate report to authorities per legal obligation)
- Content promoting violence, terrorism, or self-harm
- Content that is illegal in the jurisdiction where collected
2.4 Adult content distributed to non-adults
- Sexually explicit content distributed without age verification
- Content soliciting personal information from minors
2.5 Personal data harvesting beyond legitimate research
- Surveys whose primary purpose is to harvest personal data for resale, spam, or unsolicited marketing
- Data collection in violation of GDPR, CCPA, or other applicable privacy law
- Collecting Personal Information without a lawful basis or required consent
- Collecting sensitive personal information (health, financial, biometric, government IDs) without appropriate safeguards and consent
2.6 Intellectual property infringement
- Content that infringes copyright, trademark, patent, or other intellectual property rights
- Use of others’ brand assets without authorization
- Content that violates publicity or likeness rights
2.7 Other prohibited content
- Content that infringes others’ privacy rights
- Defamatory or libelous content
- Content promoting illegal activity
- Content that violates laws in jurisdictions where the Service operates
3. Prohibited conduct
You may not:
3.1 Distribution violations
- Send survey invitations as unsolicited bulk email (spam) in violation of CAN-SPAM (US), CASL (Canada), GDPR consent requirements (EU/UK), or other applicable anti-spam law
- Use purchased or scraped email lists without verifying lawful basis for contact
- Distribute surveys to people who have explicitly opted out of contact
- Misrepresent the sender’s identity or purpose
3.2 Technical abuse
- Attempt to gain unauthorized access to the Service, other Customers’ accounts, or our infrastructure
- Probe, scan, or test the security of the Service except through our coordinated disclosure program at security@surveyrock.com
- Interfere with or disrupt the Service or its servers
- Run automated processes against the Service except via our documented API and within published rate limits
- Bypass rate limits, quotas, or other technical restrictions
(License-scope restrictions — no reverse-engineering, no building a competing product — are in Section 8.1 of the Terms of Service.)
3.3 Account abuse
- Create multiple accounts to circumvent plan limits or restrictions
- Share account credentials with people outside your Authorized Users
- Use the Service after we have suspended or terminated your account
- Provide false information when creating or maintaining your account
3.4 Respondent rights
- Coerce Respondents (financial threats, employment retaliation) into responding
- Discriminate against Respondents based on their responses in ways that violate applicable law
- Misrepresent the purpose of a survey or how response data will be used
- Fail to honor opt-out requests from Respondents who have asked not to be contacted
3.5 Reputation and resource abuse
- Cause the Service to be used for activities that damage our sender reputation (high bounce rates, high spam complaint rates, dirty contact lists)
- Cause excessive resource consumption that degrades the Service for other Customers
- Use the Service in a manner that creates significant legal or regulatory risk for SurveyRock
4. Special use cases — additional requirements
4.1 Healthcare research
If you conduct surveys collecting health information (other than general wellness questions):
- You are responsible for HIPAA compliance and any other applicable healthcare privacy law
- Do not collect protected health information (PHI) through the Service unless you have a signed Business Associate Agreement (BAA) with us. To ask about a BAA, contact legal@surveyrock.com.
4.2 Financial information
If you conduct surveys collecting financial information (bank accounts, credit cards, tax IDs):
- You are responsible for applicable financial privacy law (Gramm-Leach-Bliley Act in US, PCI DSS where credit cards are involved)
- Never use SurveyRock to collect full credit card numbers; use Paddle or your own PCI-compliant processor for any payment transaction
4.3 Children’s data
If you conduct surveys involving children under 13 (US) or 16 (EU):
- You are responsible for COPPA (US) and equivalent compliance
- Verifiable parental consent is required
- Additional restrictions on data collection and retention apply
4.4 Research with protected populations
If you conduct research with prisoners, employees subject to coercion, medical patients, or other protected populations, you are responsible for IRB approval and any institutional research requirements.
5. AI-specific restrictions
The Service includes AI features. You may not:
- Use AI features to generate phishing content, scam content, or other prohibited content described above
- Attempt to extract our AI prompts, model weights, or proprietary AI logic
- Use AI-generated outputs to deceive Respondents about whether they’re interacting with a person or a machine where such disclosure is required
- Use the Service to train competing AI models on Customer Content (including others’ Customer Content)
6. Reporting violations
If you believe someone is violating this AUP:
- Email: support@surveyrock.com
- Subject line: “AUP violation report”
- Include: the URL or survey ID of the offending content, the nature of the violation, and any supporting evidence
We investigate all reports made in good faith. We do not retaliate against Customers or third parties who report violations in good faith.
7. Our response to violations
Our response depends on the severity, intent, and pattern:
7.1 Minor violations
- First incident, ambiguous intent: warning + education
- Repeated minor incidents: restriction of specific features (e.g., contact list size reduction)
7.2 Material violations
- Active phishing, scam, or harassment: immediate content removal + account suspension pending investigation
- Repeated material violations: account termination
7.3 Severe violations
- Content sexualizing minors: immediate removal, mandatory legal reporting, account termination
- Active fraud causing demonstrable harm: immediate suspension, cooperation with law enforcement, account termination
- Content threatening violence or terrorism: immediate report to authorities, account termination
7.4 Process
We:
- Investigate before acting where time permits
- Notify the Customer of the violation and our action (unless prohibited by law or the situation precludes notice)
- Provide an opportunity to respond and remediate where appropriate
- Maintain records of enforcement actions for consistency
- Apply enforcement proportionate to the violation
We reserve the right to take action without prior notice for severe violations or where notice would impede investigation.
8. Appeals
If you believe we acted in error:
- Email legal@surveyrock.com within 30 days of the action
- Include the action taken, why you believe it was in error, and any supporting information
- We will review and respond within 14 days
Appeals do not pause enforcement unless we determine the original action was incorrect.
9. Reporting illegal content to authorities
We comply with all applicable legal obligations to report certain content to authorities:
- Content sexualizing minors → reported to the National Center for Missing & Exploited Children (NCMEC) per US legal obligation
- Imminent threats of violence → reported to law enforcement
- Other content requiring reporting under specific jurisdictional law
We respond to valid legal process (subpoenas, court orders, warrants) regarding Customer data per our Privacy Policy.
10. Updates to this Policy
We may update this AUP from time to time. When we make material changes:
- We update the “Effective date” at the top
- We notify Customers via in-product notification and/or email
- Continued use of the Service after the effective date constitutes acceptance
11. Contact
Abuse reports: support@surveyrock.com Legal questions: legal@surveyrock.com Appeals: legal@surveyrock.com