Vesopa Vesopa

Last updated 2026-09-08

Acceptable Use Policy

A sign-in service is a target. If someone breaks it, or abuses it, the damage lands on ordinary people who just wanted to order a coffee or open a till. That is the whole reason this page exists.

This policy applies to everyone who touches Vesopa OAuth: people with an account, developers who have registered an application, and anyone else sending us traffic. It forms part of the Terms of Service.

The short version

Do not attack the service. Do not use it to deceive people. Do not use our email or SMS routes to send things nobody asked for. Do not hoover up other people's data. If you break something and tell us honestly, we will work with you.

1. Do not attack the service

Do not:

2. Do not abuse the code and message routes

One-time codes cost real money to send and are a favourite tool of fraudsters.

Do not:

3. Do not impersonate or phish

Do not:

4. Do not misuse accounts

Do not:

5. Do not harvest data

Do not:

6. Do not use the service for unlawful or harmful purposes

Do not use Vesopa OAuth in connection with fraud, money laundering, harassment, stalking, threats, the sexual exploitation or abuse of children, the distribution of unlawful material, sanctions evasion, or anything else that is a criminal offence in the United Kingdom.

We report child sexual abuse material and credible threats to life to the authorities, immediately, without warning the account holder.

7. Security research

We would rather you found a problem than someone else did. If you follow these rules, we will not pursue legal action against you for your research, and we will work with you on a fix.

You may:

You must not:

We aim to acknowledge a report within two working days and to keep you informed while we fix it. We do not currently run a paid bug bounty, and we will not imply that we do — but we will credit you if you would like us to.

8. What happens if you break these rules

We match the response to the harm. In rough order:

  1. We rate limit or block the traffic causing the problem, often automatically and immediately.
  2. We warn you and ask you to fix it, where there is a plausible innocent explanation and no ongoing harm.
  3. We suspend the account or the application, so it stops while we work out what happened.
  4. We terminate the account or remove the application.
  5. We report it to the police, to the ICO, or to an identity provider whose rules were also broken, where the conduct warrants it.

Where the harm is immediate — an attack in progress, an application harvesting user data, a phishing clone — we act first and explain afterwards.

We may also preserve evidence, including logs that would otherwise have been deleted on schedule, where we need it for an investigation or a legal claim.

9. Appeals

If you think we have got it wrong, write to info@vesopasoftware.com with the account or application name and what you think happened. A person reads it. If we made a mistake we will say so and put it back.

10. Reporting abuse

Tell us what you saw, when, and where. Screenshots and URLs help more than adjectives.

11. Changes

We update this policy as new kinds of abuse appear, which they do. The date at the top is the current version.


Questions about any of this: privacy@vesopa.com. All our policies are listed at /policies.