Acceptable Use Policy
Last updated: July 30, 2026
1. Scope
This policy states what you may not do with Flowboard. It forms part of the terms of service and is referenced in section 3.1 of those terms. In this policy, “Flowboard”, “we”, and “us” mean Harbor Software LLC, and “you” means the business that accepted the terms.
You are responsible for use of the Service by your team members and by the client users you invite. A prohibited use by any of them is your breach.
2. Regulated data you may not store
Flowboard is built for agency project, time, client, and billing records. It is not built for regulated data, and we hold no certification for it. You may not put any of the following into the Service:
- Protected health information, or any patient or medical record subject to HIPAA or an equivalent health-privacy law. We do not sign business associate agreements.
- Payment card numbers, cardholder data, or anything else within the scope of PCI DSS. Take card payments through your payment processor, not through a Flowboard field, a document, a proof, or a message.
- Government classified or export-controlled technical data.
- Full government identity numbers, such as a Social Security number or a national identity number, and biometric identifiers.
- Financial account credentials, or any password or access credential for another system.
If you need to handle any of the above, use a system built and certified for it. Placing this data into the Service is a breach whether or not it causes harm, and section 8.1 of the terms applies to a claim arising from it.
3. Prohibited uses
You may not use the Service to:
- Break the law, or help anyone else break it.
- Infringe a copyright, trademark, patent, trade secret, or other intellectual property right. Copyright notices are handled under section 4.5 of the terms, and repeat infringers are terminated.
- Store or transmit unlawful content. Where the law requires us to report content to an authority, we will do so.
- Harass, threaten, defame, or abuse any person, including through the client portal, channels, or any message the Service sends.
- Send unsolicited bulk or commercial messages. Invoices, notifications, and portal invitations are for people who expect to hear from you about work you are doing for them.
- Transmit malware, ransomware, or any other harmful code.
- Attempt to gain unauthorized access to the Service, to another workspace, or to any account. Do not probe, scan, or test the security of the Service without our prior written permission.
- Interfere with the Service or place an unreasonable load on it, including by scraping, by automated access outside a documented interface, or by generating traffic designed to degrade it for others.
- Share a team member login, or use one paid team member account for more than one person. Each person who works in the workspace needs their own team member account. Client users are free and unlimited and are the correct way to give an external person access.
- Circumvent or attempt to circumvent any usage limit, billing mechanism, or access control.
- Reverse engineer, decompile, or attempt to derive the source code of the Service, except to the extent the law permits despite this restriction.
- Resell the Service, or provide it to a third party as a service of your own, without our written agreement.
- Copy the Service, or use it to build or benchmark a competing product.
- Misrepresent your identity or your affiliation, or impersonate another person or business.
4. How we enforce this policy
Where a breach is capable of being cured and the circumstances allow it, we will describe the breach and give you a reasonable opportunity to cure it, as section 6.3 of the terms provides. We may suspend access immediately, without prior notice, where continued access presents a security risk, where the law requires it, or where the breach is causing harm to another person or to the Service.
We may remove or disable access to specific content that breaches this policy. Repeated breaches, and repeated valid notices of claimed copyright infringement, lead to termination of the account.
Suspension or termination for breach of this policy does not entitle you to a refund. Section 5.4 of the terms applies.
5. Reporting a problem
To report abuse, a security issue, or content that breaches this policy, email legal@flowboardhq.com. Describe what you found and where, and include enough detail for us to locate it. For account and billing questions, email support@flowboardhq.com.
To report claimed copyright infringement, follow the notice procedure in section 4.5 of the terms of service, which names our designated agent and lists what a notice must contain.
6. Changes to this policy
We may update this policy. The current version is always posted on this page, and the last updated date appears at the top. We will notify you of material changes by email or by a notice inside the Service, on the same basis as section 10.8 of the terms. Continued use of the Service after a change constitutes acceptance of the updated policy.