Effective Date: September 8, 2026 Last Updated: September 8, 2026
1. Our Approach to Responsible Use
Phillforce is designed to help businesses understand customer acquisition, interpret evidence, identify priorities, and make better-informed commercial decisions. We want customers to use that intelligence creatively, commercially, and productively. At the same time, a platform that analyzes websites, processes business evidence, uses artificial intelligence, and provides access to potentially confidential business information must have clear boundaries. This Acceptable Use Policy explains what you may and may not do when using Phillforce. Our goal is straightforward: Use Phillforce to understand and improve legitimate business activity. Do not use Phillforce to harm people, compromise systems, violate rights, deceive others, or interfere with the platform. This Policy forms part of the Phillforce Terms of Service.
2. Who We Are
Phillforce is operated by: Phillforce, Inc. 8 Wading Bird Loop Blythewood, SC 29016 United States Website: phillforce.com Legal enquiries: legal@phillforce.com Security reports: security@phillforce.com Privacy enquiries: privacy@phillforce.com General enquiries: philip@phillforce.com
3. Scope of This Policy
This Policy applies to your use of Phillforce products and services, including where applicable:
- phillforce.com;
- Phillforce Intelligence;
- Ask Phill;
- website analysis;
- customer acquisition diagnosis;
- reports;
- interventions;
- Company Evidence;
- customer workspaces;
- authentication systems;
- application programming interfaces;
- exports;
- integrations;
- Connected Intelligence;
- Prospect Intelligence where introduced;
- professional services;
- and other Phillforce services that reference this Policy.
It also applies to actions performed through automated systems, scripts, integrations, agents, employees, contractors, or other people using your account or organization.
4. Your Responsibility
You are responsible for using Phillforce lawfully and responsibly. If you use Phillforce on behalf of an organization, you are responsible for ensuring that people you authorize to use the organization's account understand and comply with this Policy. You should not assume that because Phillforce technically allows an action, that action is necessarily lawful or permitted. You remain responsible for understanding any laws, contracts, platform rules, confidentiality obligations, privacy requirements, or other restrictions that apply to your use.
5. Lawful Business Use
Phillforce may be used for legitimate activities such as:
- analyzing your customer acquisition system;
- evaluating a business website;
- understanding conversion paths;
- interpreting funnel data;
- identifying potential acquisition constraints;
- analyzing positioning or messaging;
- evaluating public business information;
- understanding commercial performance;
- improving sales or marketing processes;
- generating customer acquisition recommendations;
- asking Ask Phill questions about available business evidence;
- producing internal reports;
- planning interventions;
- measuring commercial outcomes;
- conducting legitimate business research;
- using Phillforce professional services.
This list is illustrative and does not limit other lawful uses consistent with our Terms and policies.
6. Illegal Activity Is Prohibited
You may not use Phillforce to violate applicable law. This includes using Phillforce to facilitate, encourage, organize, conceal, or materially assist unlawful activity. Examples may include:
- fraud;
- theft;
- extortion;
- unlawful hacking;
- identity theft;
- money laundering;
- unlawful surveillance;
- unauthorized access to systems;
- illegal data collection;
- intellectual property infringement;
- deceptive commercial practices;
- violations of applicable privacy law;
- unlawful discrimination;
- other prohibited activity.
If an activity is illegal where it occurs or under law applicable to you, using Phillforce does not make that activity lawful.
7. Unauthorized Access Is Prohibited
You may not use Phillforce to gain or attempt to gain unauthorized access to:
- another person's account;
- another customer's workspace;
- another customer's diagnosis;
- another customer's reports;
- another customer's business evidence;
- Phillforce infrastructure;
- internal systems;
- servers;
- databases;
- cloud infrastructure;
- administrative interfaces;
- private networks;
- third-party systems.
You may not exploit technical weaknesses to access information or functionality that has not been authorized for you.
8. Do Not Attempt to Access Other Customers' Information
Phillforce is designed to isolate customer information. You must not attempt to defeat or circumvent those protections. For example, you may not:
- change identifiers in URLs or API requests to access another customer's information;
- manipulate report IDs;
- manipulate diagnosis IDs;
- alter workspace IDs;
- manipulate company IDs;
- exploit authorization errors;
- use account credentials that do not belong to you;
- intentionally access information accidentally exposed through a technical defect.
If you unintentionally encounter information that appears to belong to another customer, stop accessing it and notify: security@phillforce.com
9. Security Testing
You may not probe, scan, exploit, attack, or test Phillforce systems for vulnerabilities without authorization. This includes:
- vulnerability scanning;
- penetration testing;
- port scanning;
- password attacks;
- credential stuffing;
- brute-force testing;
- authentication bypass attempts;
- authorization bypass attempts;
- denial-of-service testing;
- exploit development against production systems.
The only exception is activity expressly permitted under the Phillforce Responsible Vulnerability Disclosure Policy or another written authorization from Phillforce. Responsible security research should follow that process.
10. Malware and Harmful Code
You may not use Phillforce to create, introduce, distribute, transmit, host, or facilitate malicious software. This includes:
- viruses;
- ransomware;
- spyware;
- worms;
- trojans;
- credential stealers;
- destructive scripts;
- malicious payloads;
- unauthorized crypto-mining software;
- botnets;
- other malware.
You may not deliberately submit malicious files, URLs, scripts, or content in an attempt to compromise Phillforce or another system.
11. Denial of Service and Platform Disruption
You may not intentionally interfere with the availability, stability, or performance of Phillforce. Prohibited conduct includes:
- denial-of-service attacks;
- distributed denial-of-service attacks;
- deliberately overwhelming APIs;
- generating excessive automated traffic;
- repeatedly launching resource-intensive analyses for the purpose of disruption;
- intentionally triggering expensive processes to exhaust platform resources;
- creating automated loops intended to degrade performance.
Legitimate high-volume usage may require an appropriate plan or prior agreement with Phillforce.
12. Circumventing Usage Limits
Phillforce may impose reasonable technical or commercial limits on certain features. These may include limits relating to:
- free diagnoses;
- Ask Phill usage;
- API requests;
- website scans;
- reports;
- exports;
- storage;
- users;
- workspaces;
- connected accounts;
- background jobs.
You may not circumvent these limits by:
- creating multiple accounts;
- rotating IP addresses;
- manipulating browser identifiers;
- using bots;
- altering requests;
- exploiting technical defects;
- sharing accounts improperly;
- using another mechanism intended primarily to avoid restrictions.
13. Account Abuse
You may not:
- create accounts using false identities for fraudulent purposes;
- impersonate another person or organization;
- sell access to accounts without authorization;
- intentionally share credentials to bypass seat limits;
- transfer an account in violation of the Terms;
- maintain unauthorized duplicate accounts to evade suspension;
- use compromised credentials.
You are responsible for protecting your account credentials.
14. Website Analysis and Crawling
Phillforce may analyze publicly accessible websites and business information as part of customer acquisition intelligence. You may use this functionality for legitimate purposes such as:
- analyzing your own website;
- analyzing a customer's website with appropriate authority;
- evaluating publicly accessible business information;
- conducting legitimate competitive or commercial research.
However, Phillforce website analysis does not authorize you to access private systems.
15. Prohibited Website Analysis
You may not intentionally use Phillforce website analysis to:
- access localhost or internal infrastructure;
- access private networks;
- access cloud metadata services;
- access authenticated areas without authorization;
- bypass paywalls or authentication controls unlawfully;
- scan internal company systems;
- probe ports or network services;
- test third-party infrastructure for vulnerabilities;
- evade technical access controls;
- obtain sensitive information that is not intended to be public;
- conduct malicious reconnaissance.
Submitting a URL does not create permission to access systems that are not publicly accessible.
16. Public Information Does Not Mean Unlimited Use
Information appearing publicly online may still be protected by:
- copyright;
- privacy rights;
- database rights;
- contractual terms;
- platform rules;
- confidentiality obligations;
- applicable laws.
You are responsible for ensuring that your use of information obtained through Phillforce is lawful. Phillforce's ability to technically process information does not represent a legal opinion that every possible downstream use is permitted.
17. Personal Data Harvesting
You may not use Phillforce primarily as a tool to unlawfully collect, aggregate, identify, profile, or exploit personal information about individuals. You may not use Phillforce to:
- harvest personal email addresses unlawfully;
- collect passwords;
- collect private account information;
- obtain highly sensitive personal data without authorization;
- construct unlawful surveillance databases;
- infer sensitive personal traits for unlawful purposes;
- bypass privacy restrictions.
Phillforce is designed primarily for business and customer acquisition intelligence, not indiscriminate personal surveillance.
18. Highly Sensitive Information
Unless a Phillforce feature expressly requires and supports it, you should not submit highly sensitive personal information. This may include:
- Social Security numbers;
- government identification numbers;
- payment credentials;
- private passwords;
- detailed medical records;
- biometric information;
- precise personal location histories;
- confidential authentication credentials;
- similarly sensitive personal records.
Submitting unnecessary sensitive information may create risks for you and others.
19. Privacy and Data Protection
You must respect applicable privacy and data-protection laws when using Phillforce. If you submit personal information relating to another individual, you are responsible for having an appropriate legal basis, permission, authority, or other lawful justification where required. If you use Phillforce on behalf of an organization, your organization remains responsible for its own privacy obligations. Additional information is available in the Phillforce Privacy Policy and Data Rights Request Policy.
20. Ask Phill
Ask Phill is intended to support legitimate customer acquisition analysis and business decision-making. You may use Ask Phill to:
- understand a diagnosis;
- interpret evidence;
- evaluate commercial priorities;
- explore interventions;
- ask questions about your acquisition system;
- understand platform outputs.
You may not use Ask Phill to intentionally attack or compromise Phillforce.
21. Prompt Injection and AI Abuse
You may not deliberately attempt to manipulate Ask Phill or other Phillforce AI systems to:
- reveal confidential system instructions;
- reveal system prompts;
- reveal API keys;
- expose internal security controls;
- access another customer's private information;
- bypass authorization;
- disable security rules;
- obtain internal secrets;
- obtain restricted infrastructure information;
- override platform policies;
- misuse connected tools.
Security researchers acting under an authorized vulnerability disclosure process should follow the separate rules applicable to that program.
22. AI Output Manipulation
You may not deliberately manipulate inputs for the purpose of making Phillforce generate fraudulent or deceptive commercial evidence. For example, you should not knowingly submit fabricated funnel information and then represent the resulting Phillforce diagnosis as independently verified. Where Phillforce labels information as client-supplied, connected, public, modeled, or otherwise describes its evidentiary basis, you may not intentionally remove those qualifications in order to mislead another person about the nature of the output.
23. Misrepresentation of Phillforce Intelligence
You may use legitimate Phillforce reports and outputs in your business. However, you may not knowingly misrepresent:
- modeled scenarios as guaranteed forecasts;
- client-supplied evidence as independently audited data;
- AI-generated recommendations as regulatory approval;
- preliminary findings as verified facts;
- screenshots that have been materially altered to create a false result;
- Phillforce output as an official statement made by Phillforce about a third party where it is not.
Use outputs responsibly and in context.
24. Fraud and Deception
You may not use Phillforce to facilitate fraud or material deception. This includes:
- impersonating a business;
- fabricating testimonials;
- creating fraudulent case studies;
- falsifying customer results;
- deceiving investors;
- misrepresenting revenue;
- producing intentionally false evidence;
- misleading customers about the nature of an offer;
- using Phillforce outputs to support fraudulent claims.
25. Intellectual Property Rights
You may not use Phillforce to infringe another person's intellectual property rights. This includes misuse involving:
- copyrights;
- trademarks;
- trade secrets;
- patents;
- confidential materials;
- protected database rights;
- other intellectual property.
You are responsible for ensuring you have the rights necessary to upload or use content you provide to Phillforce.
26. Phillforce Intellectual Property
You may not misuse Phillforce's own intellectual property. Except where permitted by the Terms or applicable law, you may not:
- copy substantial portions of Phillforce software;
- reproduce proprietary interfaces for unauthorized commercial resale;
- steal proprietary scoring systems;
- extract protected model instructions;
- redistribute Phillforce source code;
- impersonate Phillforce;
- use Phillforce trademarks in a misleading way;
- represent an unauthorized product as officially affiliated with Phillforce.
Nothing in this Policy removes rights that cannot lawfully be restricted.
27. Reverse Engineering
Except to the extent permitted by applicable non-waivable law or authorized security research, you may not reverse engineer, decompile, disassemble, or otherwise attempt to extract the underlying implementation of Phillforce for an unauthorized purpose. Legitimate interoperability rights provided by applicable law remain unaffected where they cannot legally be waived.
28. Spam and Unsolicited Communications
Phillforce may provide information that assists legitimate customer acquisition. That does not authorize spam. If Phillforce later introduces Prospect Intelligence, outreach assistance, contact research, or similar functionality, you remain responsible for complying with applicable laws and rules governing:
- commercial email;
- marketing messages;
- telephone communications;
- SMS;
- direct marketing;
- consent;
- opt-outs;
- suppression lists.
You may not use Phillforce to conduct mass unsolicited communications in violation of applicable law.
29. Prospect Intelligence
Where Phillforce introduces Prospect Intelligence or related prospect-research functionality, it is intended to help businesses identify and prioritize legitimate business opportunities. You may not use Prospect Intelligence to:
- unlawfully obtain private personal information;
- stalk individuals;
- construct unlawful surveillance profiles;
- evade platform restrictions;
- obtain credentials;
- conduct discriminatory targeting prohibited by law;
- automate abusive outreach;
- violate applicable privacy or marketing laws.
The value of Prospect Intelligence is intended to come from business intelligence and prioritization, not unauthorized personal-data collection.
30. Connected Intelligence
Phillforce may allow customers to connect third-party systems. You may only connect an account, service, database, advertising account, analytics account, CRM, payment system, or other service where you have proper authorization to do so. You may not:
- connect stolen credentials;
- connect an account belonging to another organization without permission;
- circumvent provider access controls;
- exploit a connected service;
- manipulate integration permissions dishonestly.
31. Third-Party Platform Rules
Third-party services connected to Phillforce may have their own terms, policies, API requirements, and usage rules. You are responsible for complying with those requirements where they apply to your use. Phillforce's integration with a service does not give you permission to violate that service's rules.
32. Payment Abuse
You may not engage in payment-related abuse involving Phillforce. This includes:
- fraudulent payment instruments;
- stolen cards;
- chargeback fraud;
- knowingly false billing information;
- attempting to circumvent payment requirements;
- exploiting checkout defects;
- attempting unauthorized refunds.
Legitimate billing disputes should be addressed through appropriate support or legal channels.
33. Resale and Commercial Exploitation
You may use Phillforce for legitimate commercial activity consistent with your plan or agreement. However, unless Phillforce gives permission, you may not:
- resell access to the platform as though you own it;
- sublicense accounts;
- provide unauthorized white-label access;
- offer shared credentials to unrelated third parties;
- create an unauthorized competing service using copied Phillforce technology.
Agency, partner, reseller, or enterprise arrangements may be governed by separate agreements.
34. Automated Access
You may not use bots, scripts, crawlers, agents, or automated systems to access Phillforce in a manner that:
- bypasses access controls;
- circumvents plan limitations;
- overwhelms infrastructure;
- extracts customer information;
- scrapes protected application data;
- violates technical instructions;
- materially degrades the experience for others.
Authorized APIs, integrations, or approved automation may be used according to the applicable documentation and agreement.
35. Excessive Resource Consumption
Some Phillforce functions may require significant computing, AI, crawling, storage, or processing resources. You may not intentionally consume resources in a manner designed to create unreasonable cost or instability. Phillforce may apply:
- rate limits;
- fair-use limits;
- concurrency limits;
- scan limits;
- token limits;
- storage limits;
- other reasonable protections.
This helps maintain a reliable service for all customers.
36. Manipulation of Technical Controls
You may not intentionally disable, remove, alter, or evade Phillforce technical controls. This includes controls relating to:
- authentication;
- authorization;
- rate limiting;
- subscription limits;
- security;
- logging;
- content restrictions;
- tenant isolation;
- account verification;
- abuse prevention.
37. Security and Abuse Monitoring
Phillforce may use automated and manual systems to detect abuse, fraud, unusual usage, security events, or violations of this Policy. Depending on the circumstances, we may review information reasonably necessary to investigate suspected misuse. Such activities will be conducted consistent with applicable law, our Privacy Policy, and legitimate security interests.
38. Investigation of Suspected Violations
If Phillforce reasonably suspects that an account is being used in violation of this Policy, we may investigate. An investigation may involve reviewing relevant information such as:
- login activity;
- account activity;
- requests;
- diagnostic activity;
- API activity;
- security events;
- usage patterns;
- reports;
- other information reasonably related to the suspected violation.
We will seek to avoid unnecessarily accessing information unrelated to the investigation.
39. Temporary Restrictions
Phillforce may temporarily restrict certain functionality while investigating significant security, fraud, abuse, or legal concerns. This may include temporarily restricting:
- login;
- diagnoses;
- website scans;
- Ask Phill;
- exports;
- connected integrations;
- APIs;
- account modifications.
Temporary restrictions are not necessarily a final determination that a violation occurred.
40. Suspension
Phillforce may suspend an account where we reasonably believe suspension is necessary to:
- prevent immediate harm;
- protect another customer;
- protect infrastructure;
- stop ongoing abuse;
- prevent fraud;
- comply with law;
- investigate a serious violation;
- enforce our Terms.
Where circumstances allow, we may provide notice or an opportunity to address the issue. Immediate suspension may be necessary for serious security or abuse situations.
41. Termination
Serious or repeated violations of this Policy may result in termination of access to Phillforce. Examples that may justify termination include:
- intentional attempts to access customer data;
- malicious attacks;
- fraud;
- malware distribution;
- repeated evasion of security controls;
- unlawful activity;
- serious privacy violations;
- abuse that creates material risk to Phillforce or its customers.
Termination may be handled according to the Terms of Service and applicable law.
42. Reporting to Authorities
Where Phillforce reasonably believes activity may involve serious unlawful conduct, fraud, security threats, or other activity requiring legal action, we may preserve or disclose relevant information to competent authorities where required or permitted by law. We will evaluate such actions in light of applicable legal requirements.
43. Preservation of Evidence
Phillforce may preserve relevant records where reasonably necessary to:
- investigate security incidents;
- address fraud;
- comply with legal obligations;
- enforce agreements;
- establish or defend legal claims;
- respond to valid legal process.
Preservation does not necessarily mean that information will be permanently retained. Retention remains subject to applicable policies and law.
44. Responsible Vulnerability Disclosure
We value responsible security research. If you believe you have discovered a security vulnerability in Phillforce, please contact: security@phillforce.com and follow the Phillforce Responsible Vulnerability Disclosure Policy. Good-faith researchers who comply with that Policy should use the authorized reporting process rather than publicly exploiting or disclosing vulnerabilities in a way that unnecessarily creates risk.
45. Reporting Abuse
If you believe Phillforce is being used in violation of this Policy, you may report the issue to: legal@phillforce.com For security issues: security@phillforce.com For privacy issues: privacy@phillforce.com Please provide enough information for us to understand the concern without including unnecessary sensitive information.
46. Appeals and Questions
Where Phillforce takes an enforcement action and an appeal or review is appropriate, you may contact: legal@phillforce.com Please identify:
- the account involved;
- the relevant enforcement action;
- why you believe the action should be reconsidered;
- any relevant supporting information.
An appeal does not automatically restore suspended functionality while a serious security or abuse risk remains under investigation.
47. No Retaliation for Good-Faith Reports
Phillforce will not intentionally punish a user merely because that person responsibly reports:
- a security vulnerability;
- privacy concern;
- abuse;
- illegal activity;
- suspected policy violation.
Reports themselves must still be made responsibly and lawfully.
48. Global Users
Phillforce serves users internationally. You are responsible for complying with laws applicable to your location, organization, customers, and activities. Where local law imposes stricter requirements than this Policy, the applicable law must be followed. Availability of Phillforce in a jurisdiction does not represent a legal opinion that every possible use of the platform is lawful there.
49. Mandatory Legal Rights
Nothing in this Policy is intended to prevent you from exercising rights that cannot legally be restricted. For example, applicable law may provide certain rights relating to:
- legitimate security research;
- interoperability;
- competition;
- whistleblowing;
- government reporting;
- privacy rights.
Where this Policy conflicts with a non-waivable legal right, the applicable law controls to the extent required.
50. Relationship to Other Phillforce Policies
This Acceptable Use Policy forms part of the Phillforce Terms of Service. Your use of Phillforce may also be governed by:
- Privacy Policy;
- Terms of Service;
- Cookie Policy;
- Data Rights Request Policy;
- Accessibility Policy;
- AI & Customer Acquisition Intelligence Disclaimer;
- Subscription, Cancellation & Refund Policy;
- Account & Data Deletion Policy;
- Responsible Vulnerability Disclosure Policy;
- applicable order forms;
- statements of work;
- customer agreements.
If a separate signed agreement contains specific acceptable-use requirements, that agreement may also apply.
51. Changes to This Policy
Phillforce may update this Acceptable Use Policy as:
- the platform evolves;
- new functionality is introduced;
- new security risks emerge;
- new integrations are added;
- our business changes;
- applicable laws change.
The “Last Updated” date at the top of this Policy will indicate the current version. Where a material change significantly affects customer rights or permitted use, Phillforce may provide additional notice where appropriate or legally required.
52. Contact Phillforce
Questions about this Acceptable Use Policy may be directed to: Phillforce, Inc. 8 Wading Bird Loop Blythewood, SC 29016 United States Legal enquiries: legal@phillforce.com Security reports: security@phillforce.com Privacy enquiries: privacy@phillforce.com General enquiries: philip@phillforce.com Website: phillforce.com
Phillforce, Inc. Clarity before activity.
End of Acceptable Use Policy
