Legal
Acceptable Use and Fair Use Policy
What you may and may not do with onlinesurvey.ai, what you may not collect through it, and what happens when this policy is broken.
Last updated September 1, 2026
1. Scope
This policy applies to everyone who uses onlinesurvey.ai (the "Service"): account holders, members of a customer workspace, anyone using the API or an integration, and anyone distributing a survey built here. It forms part of the Terms of Service at /legal/terms, and a breach of it is a breach of those terms.
This policy is not a complete list. Behavior that is plainly abusive, deceptive, dangerous or unlawful is prohibited whether or not it appears below, and we may act on it.
You are responsible for the conduct of everyone in your workspace and for anyone you allow to use your account or your API credentials.
2. Prohibited content
Do not create, upload, store, distribute or link to content that:
- is unlawful in any place where it is created, hosted or received, or that promotes, facilitates or instructs on unlawful activity;
- infringes a copyright, trademark, patent, trade secret, right of publicity, moral right or any other right of a third party, including using another brand identity or logo without permission;
- is hateful, or that harasses, threatens, bullies, degrades or incites violence or hatred against a person or a group, including on the basis of race, ethnicity, national origin, religion, caste, sex, gender identity, sexual orientation, disability, age or serious disease;
- is sexually explicit, pornographic, or presents sexual content in a context respondents did not agree to;
- promotes, glorifies or supports terrorism, violent extremism, or a violent extremist organization, or is intended to recruit for one;
- depicts, sexualizes, endangers or exploits a minor in any way. This carries zero tolerance and is dealt with in section 3;
- contains or distributes malware, spyware, ransomware, a virus, a worm, a keylogger or any other harmful code, or that links to a page that does;
- is deceptive or fraudulent, including a survey that impersonates another organization, that pretends to be a prize draw, a job offer, an official notice or a security alert in order to extract information, or that misrepresents who is collecting the data and why;
- defames a person or an organization, or that discloses another person private information without a lawful basis;
- promotes self-harm, suicide, disordered eating, or dangerous activity likely to cause serious injury.
3. Content involving minors: zero tolerance
Content that sexualizes, exploits, endangers or abuses a minor is prohibited absolutely. There is no research exemption, no artistic exemption and no warning step.
An account found to hold or distribute such content is terminated immediately and permanently, the content is preserved where the law requires it, and the matter is reported to the appropriate authorities. We will cooperate fully with any resulting investigation.
If your legitimate research involves minors as respondents, you are responsible for verifiable parental or guardian consent, for any institutional or ethics approval required, and for compliance with every law that protects children in the places where you collect data. See section 5.
4. Prohibited data collection
Some categories of data must never be collected through a survey on this platform, regardless of consent, because the Service is not designed or certified to hold them and doing so creates unacceptable risk for the respondent and for us. Do not build a survey, an upload field, an open text question or a hidden field that collects:
- payment card numbers, card verification values, expiry dates, bank account numbers, routing numbers or any other full payment credential;
- government issued identifiers, including national identity numbers, social security numbers, tax identification numbers, passport numbers, driving licence numbers and immigration numbers, or images of the documents that carry them;
- passwords, passphrases, PINs, security question answers, API keys, access tokens, private keys or any other credential for any system, including ours;
- full biometric identifiers, including fingerprints, facial recognition templates, voiceprints and genetic data;
- data obtained by intercepting, scraping or otherwise taking it from a person or a system without authorization.
If a respondent volunteers prohibited data into a free-text field despite your instructions, remove it promptly. Leaving it in place once you know about it is a breach of this policy.
5. Sensitive and regulated data
Sensitive categories of personal data, including health and medical information, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life and sexual orientation, criminal offences and convictions, and precise geolocation, may only be collected where you have a lawful basis and where you have obtained the explicit, informed, freely given and specific consent that the law requires, before the question is asked.
Obtaining, documenting and honoring that consent is entirely your responsibility. We do not obtain it for you, we do not verify it, and we do not check whether a question is lawful in the place it is being asked.
The Service is not designed for regulated workflows that impose their own technical and contractual requirements on a vendor, including protected health information under HIPAA, cardholder data under PCI DSS, and classified or export-controlled government data. Do not use the Service for those workflows unless we have agreed otherwise with you in writing.
6. Distribution, messaging and spam
Do not:
- send unsolicited survey invitations, reminders or any other message to people who have not agreed to hear from you or with whom you have no lawful basis to communicate;
- upload or use a contact list you did not collect yourself with permission, or that you purchased, scraped, harvested or otherwise acquired without the consent of the people on it;
- send messages that hide or falsify the sender, the reply-to address, the routing information or the purpose of the message;
- omit a working way to opt out of further messages, or continue messaging someone after they have opted out;
- use the Service for phishing, credential harvesting, or any scheme that induces a respondent to reveal information under a false pretext;
- impersonate any person, organization, brand or public authority, or state or imply an affiliation, sponsorship or endorsement that does not exist;
- misrepresent the purpose of a survey, for example by presenting a sales campaign, a lead generation exercise or a political operation as independent research.
You are responsible for complying with every anti-spam and electronic marketing law that applies to your sending, including in the countries where your recipients are.
7. Platform integrity and technical restrictions
Do not:
- probe, scan, penetration test, stress test or attempt to breach the Service or its infrastructure without our prior written permission;
- attempt to gain unauthorized access to any account, workspace, survey, response, report, system or network, or to data belonging to another customer;
- scrape, crawl, harvest or index the Service, or extract data from it by any automated means other than a documented API used within its limits;
- reverse engineer, decompile or disassemble any part of the Service, except to the extent that restriction is unenforceable by law;
- interfere with, disrupt or place an unreasonable load on the Service or on any other customer use of it, including by denial of service, by flooding, or by generating artificial traffic or artificial responses;
- circumvent or attempt to circumvent any limit, quota, rate limit, entitlement, metering or access control, including AI credit metering, or share credentials in order to exceed the seats or usage your plan provides;
- resell, sublicense, rent, lease or provide the Service to a third party as a standalone service without our written authorization;
- remove, obscure or alter any proprietary notice on the Service;
- use the Service to build or train a competing product, or to benchmark it for publication, without our written permission.
8. Fair use of unmetered features
Where a feature is offered without a published numeric limit, that reflects normal use, not an entitlement to unlimited resources. Storage, bandwidth, request volume, media size and concurrency are all finite, and a single account can consume enough of them to degrade the platform for everyone else.
We may apply reasonable technical limits to protect the platform, including rate limits, request size caps, storage caps, concurrency limits and queueing, and we may apply them to a single account whose consumption is far out of proportion to normal use.
Where practical we will contact you first and discuss a plan that fits your usage. Where the load is actively threatening the platform, we may act immediately.
9. Monitoring
We do not routinely review the content of surveys or responses, and nothing in this policy obliges us to. We do operate automated abuse, security and integrity systems, and we do act on reports and on evidence that comes to our attention.
We may, but are not obliged to, review any content or account activity where we believe it is necessary to enforce this policy, to protect the platform or a person, or to comply with the law. Not acting on a particular matter is not a waiver of the right to act on it or on any other matter.
10. Reporting abuse
To report a survey, an account or any content that breaks this policy, write to [email protected]. Include the survey link or the account identifier, a description of the problem, and any evidence you can share. Reports about content involving minors are treated as the highest priority.
If you are a respondent and you want your answers deleted, contact the survey author first, since they control that data. Where you cannot reach them, write to us and we will route the request.
We will investigate reports we consider credible. We do not promise an outcome, a timeline, or a report back to the person who raised the issue.
11. Enforcement
We enforce this policy at our sole discretion. Depending on the severity, the history and the risk, we may take any of the following steps, in any order, with or without prior notice:
- contact you and ask you to fix the problem;
- issue a formal warning;
- remove, unpublish, disable or restrict access to specific content, a survey, a media asset or a shared report;
- stop a distribution campaign or block further sending;
- throttle, rate limit or reduce the resources available to an account;
- suspend the account, in whole or in part, temporarily or pending an investigation;
- terminate the account permanently and delete its content;
- refuse to provide the Service to you or to any organization connected with you in the future.
For severe violations, including content involving minors, credible threats of violence, active fraud, and attacks on the platform, we terminate immediately and without notice.
No refund is owed for a suspension or a termination arising from a breach of this policy. See /legal/refunds.
12. Preservation and disclosure
We may preserve content and account records, and we may disclose them to law enforcement, to a regulator, to a court or to another third party, where we believe in good faith that doing so is required by law or legal process, or is reasonably necessary to investigate a violation of this policy, to protect the rights, property or safety of any person, or to defend a legal claim.
Where we are permitted to tell you about such a disclosure, and where doing so would not compromise an investigation, we will.
13. No waiver, and changes
Choosing not to enforce this policy in one instance does not waive our right to enforce it later, in that instance or in any other. Every remedy here is in addition to, not in place of, any other remedy available to us at law or under the Terms of Service.
We may update this policy as the Service and the threats against it change. The current version is always the one posted on this page, with the date at the top. Continued use after an update means you accept it.
14. Contact
Questions about this policy, requests for permission where this policy requires it, and abuse reports all go to [email protected].