Acceptable Use Policy

Last updated: 16 August 2026

In short. SessionPilot is a browser-isolation and session-management tool. Keeping work accounts separated, auditable and consistently configured is ordinary, lawful business practice. Using that isolation to commit fraud, gain unauthorised access, or evade enforcement of the law is not, and we will terminate accounts that do it.

This Acceptable Use Policy (“AUP”) forms part of the Terms of Service and applies to everyone who uses SessionPilot, including a customer’s team members and anyone acting on their behalf. Capitalised terms not defined here have the meaning given in the Terms.

1. Permitted use

SessionPilot exists because one browser profile per person does not fit how modern businesses operate. Typical, legitimate uses include:

2. Prohibited use

You must not use SessionPilot, or allow it to be used, to:

Fraud and financial crime

  • Commit payment fraud, including using stolen, tested or otherwise unauthorised payment instruments, or evading a payment provider’s fraud controls.
  • Open, operate or launder funds through accounts in someone else’s name, or with fabricated or stolen identity information.
  • Carry out money laundering, sanctions evasion, or transactions with sanctioned parties or jurisdictions.
  • Manipulate incentive, referral, cashback, bonus or airdrop programmes through accounts that misrepresent who is behind them.

Unauthorised access

  • Access any account, system or data you are not authorised to access.
  • Conduct credential stuffing, password spraying, brute forcing, session hijacking or account takeover of any kind.
  • Circumvent authentication, authorisation or security controls that are protecting someone else’s systems or data.

Harmful and illegal content or conduct

  • Distribute malware, ransomware, phishing pages or other malicious code.
  • Send spam or operate bulk unsolicited messaging campaigns.
  • Create, store or distribute child sexual abuse material, or any content that is unlawful where you or your users are located.
  • Harass, stalk, defame, impersonate or threaten any person, or run coordinated inauthentic behaviour intended to deceive the public.
  • Infringe intellectual property or misappropriate trade secrets.

Data misuse

  • Collect personal data unlawfully, including scraping personal data without a lawful basis, or building profiles of individuals in breach of applicable data-protection law.
  • Re-identify individuals from anonymised data, or use the Service to defeat privacy protections that exist to protect people.

Abuse of the Service itself

  • Resell, sublicense or white-label the Service without a written agreement permitting it.
  • Share a single seat among multiple people to avoid paying for seats, or exceed the limits of your plan by technical means.
  • Reverse engineer, tamper with or attempt to defeat licensing, enforcement or audit-logging functionality.
  • Probe, scan or stress-test our infrastructure without prior written authorisation.

3. Third-party services and their terms

Many websites set their own rules about multiple accounts and automated access. Those rules are a matter between you and that website. You are solely responsible for ensuring your use of any third-party service complies with that service’s terms and with the law. Nothing in SessionPilot’s documentation, marketing or support should be read as advice that it is acceptable to breach a third party’s terms, and we do not provide guidance on evading a specific platform’s enforcement.

Where a breach of a third party’s terms would also be unlawful — for example, unauthorised access to a computer system, or fraud — it is prohibited by this AUP outright.

4. Data you process through the Service

SessionPilot is designed so that we cannot read the contents of your profiles or sessions: they are encrypted on your device before they reach us and we never hold your passphrase (see Security). That design protects your confidentiality, and it also means we cannot inspect your content to check it is lawful. The responsibility for what you process is yours.

If you process personal data belonging to other people, you must have a lawful basis to do so and must comply with applicable data-protection law. Our Data Processing Addendum governs the limited personal data we do process on your behalf.

5. Proxy and network use

Where you connect SessionPilot to a proxy — your own, a third party’s, or one supplied by us — you must have the right to use that network path. You must not:

6. Automation and rate of use

SessionPilot exposes a local automation API. Automation is a legitimate and supported use, but it must be applied responsibly: do not generate request volumes that degrade a third party’s service, and respect published rate limits and access controls. Automation that is designed to overwhelm, deny service to, or exhaust the resources of another system is prohibited.

7. Enforcement

We would rather resolve an issue than lose a customer, so where the circumstances allow we will contact you first and give you an opportunity to correct the problem. Where the conduct is serious, ongoing, or exposes us or others to legal risk, we may act immediately and without notice.

Depending on severity, we may:

Because of the encryption described above, an enforcement decision is based on the limited account and operational information available to us (see the Privacy Policy), on your conduct toward us and our infrastructure, and on credible reports we receive — not on inspection of your encrypted content, which we cannot decrypt.

8. Reporting abuse

If you believe SessionPilot is being used in breach of this policy, tell us through the contact form with the subject “Abuse report”. Please include as much detail as you can — what happened, when, and any identifiers you have. We investigate every credible report.

We may update this policy as the product and the legal landscape change. Material changes will be announced in advance to account holders where practicable, and the date at the top of this page always reflects the current version.