OmnaSenseSign in

BETA LEGAL POLICY

OmnaSense Acceptable Use Policy

The authorization, safety, privacy, and proportional-use rules for every monitored target and journey.

Beta policy noticeThis operating policy is based on the owner-supplied August 26, 2026 legal draft. It has not yet completed attorney review and may be replaced with a reviewed version. Version: 2026-08-26-beta.
OmnaSense Acceptable Use Policy Effective Date: August 26, 2026 Last Updated: August 26, 2026 This Acceptable Use Policy ("AUP") governs use of the OmnaSense Services and is incorporated into the OmnaSense Terms of Service. Capitalized terms not defined here have the meanings in the Terms. The core rule is simple: use OmnaSense only on systems you are authorized to test, within the authorized scope, using safe test data and reasonable traffic. 1. Authorized Targets Only You may monitor or connect only a website, domain, application, account, endpoint, tag manager, server-side container, marketing destination, or customer journey that you own, control, or have express authorization to test. Authorization must cover the actual activity configured in OmnaSense, including: • pages, subdomains, environments, accounts, and endpoints; • crawl depth, page limits, frequency, concurrency, and schedule; • journey actions such as navigation, clicking, typing, form submission, and account changes; • evidence collection, screenshots, and server-side polling; • third-party integrations and credentials; and • the duration of monitoring. Agencies and consultants must maintain documented permission from each client. You must stop monitoring immediately if permission expires, is withdrawn, or is disputed. A public page, accessible endpoint, or working credential does not by itself authorize testing. 2. Prohibited Security and Access Activity You may not use the Services to: • access or attempt to access a system, account, data, or function without authorization; • exceed granted permission or evade a target's access controls; • bypass authentication, paywalls, consent controls, CAPTCHA, rate limits, bot controls, or technical restrictions; • guess passwords, conduct credential stuffing or brute-force activity, enumerate accounts, or test stolen credentials; • scan for or exploit vulnerabilities, deliver malware, execute malicious code, establish persistence, or exfiltrate data;
• interfere with, disable, degrade, overload, or disrupt a system, including through denial-of-service activity; • probe internal networks, private addresses, cloud metadata services, or infrastructure not expressly included in an approved scope; • impersonate another person or falsify source, authorization, or ownership information; or • use a finding to harm, extort, deceive, or improperly pressure another person. Good-faith security testing of OmnaSense itself requires prior written authorization. Report suspected vulnerabilities privately to the in-product Help & support channel. 3. Prohibited Data Collection and Content You may not intentionally use the Services to collect, store, expose, or transmit: • real payment-card numbers, card authentication data, bank credentials, or financial-account passwords; • protected health information or patient records; • Social Security numbers, passport numbers, driver's-license numbers, or comparable government identifiers; • biometric identifiers or templates; • production passwords, private keys, secret answers, session tokens, or unrestricted API credentials in recorded inputs or visible artifacts; • precise geolocation tied to an identifiable person; • information from a child-directed service or personal information of a child under 13; • unlawfully obtained personal, confidential, proprietary, or trade-secret information; • content that is illegal, defamatory, infringing, fraudulent, deceptive, or that promotes violence or abuse; or • other sensitive or regulated data that OmnaSense has not expressly approved in a signed writing. Incidental personal information may appear in pages, events, URLs, data layers, requests, or screenshots. You must minimize collection, use synthetic or masked data, restrict test routes and accounts, review artifacts, and promptly delete or report prohibited data. 4. Safe Journey Monitoring Recorded and replayed journeys may take actions on a target. Unless a target is expressly configured for safe automated testing, you may not use journey monitoring to: • complete real purchases, transfers, donations, wagers, bookings, applications, or subscriptions;
• send messages or publish content to real users; • create, delete, or materially change a real person's account or rights; • accept legal terms, consent, or disclosures on behalf of another person; • change production pricing, inventory, permissions, security settings, or business records; or • trigger emergency, safety-critical, medical, financial, employment, housing, insurance, or government decisions. Use dedicated test accounts, test payment methods, sandbox endpoints, idempotent actions, and cleanup procedures. You are responsible for downstream effects, including analytics events, audience membership, advertising attribution, automated campaigns, logs, and provider fees. 5. Responsible Crawling and Traffic You must configure monitors to produce reasonable, proportionate traffic. Do not intentionally create excessive load, evade target rate limits, or coordinate monitors to overwhelm a target. Use the minimum crawl scope, frequency, concurrency, and page count needed for the monitoring purpose. You are responsible for reviewing applicable client instructions, target terms, robots directives where legally or contractually applicable, and provider policies. If a target asks you to reduce or stop traffic and you cannot establish clear authority, pause the monitor and resolve the issue before continuing. OmnaSense may throttle, limit, pause, or block traffic to protect a target, the Services, or third parties. 6. Third-Party Integrations and Server-Side Evidence You may connect only accounts and integrations you are authorized to access. Use the narrowest permissions that support the monitor, store credentials only through approved secret functions, and revoke credentials when no longer needed. You may not use integration or evidence-polling features to: • read another customer's or account holder's data; • enumerate unrelated events, users, containers, or destinations; • bypass provider access restrictions; • retrieve raw payloads unrelated to the configured test; or • violate a provider's terms or developer policies. Where OmnaSense supports hashed or minimized identifiers, use those methods. Do not place secrets in monitor names, URLs, assertions, screenshots, support messages, or other fields not intended for secret storage.
7. Privacy and Consent You must comply with privacy, interception, communications, employment, and data-protection laws applicable to your monitoring. You are responsible for required notices, permissions, consents, contracts, data-subject requests, and retention decisions. You may not use OmnaSense for covert surveillance of real users, employees, contractors, or competitors; to build profiles about identifiable people; or to infer sensitive characteristics. OmnaSense is designed for synthetic observability, not session replay of real visitors or behavioral advertising. You must not disable or circumvent a target's consent-management behavior merely to create evidence, unless the test scope expressly authorizes that condition and the activity is lawful. Clearly distinguish tests of consent states from real user consent. 8. Alerts and Communications Provide alert recipients only when you are authorized to do so. Do not use OmnaSense to send spam, phishing, misleading messages, harassment, or unlawful marketing. Maintain current recipient lists and remove people who should no longer receive alerts. You may not manipulate monitoring results or alerts to deceive a client, vendor, regulator, or other person. 9. Misuse of OmnaSense or Other Customers You may not: • attempt to access another customer's workspace, monitor, evidence, artifact, or secret; • test tenant isolation or OmnaSense infrastructure without written authorization; • scrape or systematically extract the Services, documentation, or non-public product data; • reverse engineer the Services except where a restriction is prohibited by law; • interfere with authentication, billing, logging, alerts, or abuse controls; • submit malicious files, instructions, URLs, redirects, or payloads; • conceal the source or purpose of abusive traffic; or • help another person violate this AUP. 10. Regulated and High-Risk Uses Without a signed written agreement expressly approving the use, you may not use OmnaSense in a manner that makes it a required component of: • emergency or life-safety systems; • medical diagnosis, treatment, or clinical decisions;
• credit, lending, insurance, housing, employment, education, or government-benefit eligibility decisions; • securities trading or movement of funds; or • legal compliance certification. You may use OmnaSense to gather technical evidence related to an authorized site, but the Services do not replace qualified professional review or independent controls. 11. Reporting Concerns Report suspected abuse to the in-product Help & support channel and security vulnerabilities to [SECURITY EMAIL]. Include the relevant domain, monitor or workspace identifier if available, dates, a concise description, and non-sensitive evidence. Do not send passwords, private keys, payment-card data, or another customer's artifacts by email. OmnaSense may investigate suspected violations and may request evidence of authorization. You agree to cooperate reasonably with an investigation. 12. Enforcement OmnaSense may warn, throttle, limit, pause, remove data, suspend, or terminate access based on the nature, urgency, frequency, and impact of a violation. We may act immediately when necessary to protect a target, customer, third party, or the Services; comply with law; or address unauthorized activity. Where practical and lawful, OmnaSense will provide notice and an opportunity to cure. We may preserve relevant records, notify an affected customer or provider, or report conduct to authorities when legally required or reasonably necessary to prevent harm. 13. Changes to This AUP We may update this AUP as the Services and risks evolve. We will post the revised version and update the date above. Material changes will be communicated as required by the Terms or applicable law. 14. Contact OmnaSense Mailing address available through the in-product Help & support channel. Abuse: the in-product Help & support channel Security: the in-product Help & support channel Legal: the in-product Help & support channel
© 2026 OmnaSense
Privacy PolicyTerms of ServiceBeta TermsAcceptable Use