Skip to main content
This page is short on purpose. It says what is not allowed, where those rules come from, and what happens when they are broken. It is the minimum policy PhoneBase ships with, and it is not a contract. A full terms of service is being prepared for launch; until it is published, this page is the acceptable-use rule that applies. Where the two ever disagree, the published terms win.

Your model supplier’s rules reach you through us

PhoneBase’s copilot sends your instructions to a third-party model provider, OpenRouter, and runs the model’s replies against your phone. That means their rules apply to what you ask for here, not only to what we do. Your use of the copilot must comply with your model supplier’s usage policies. Those policies are theirs to write and to change, and we pass them on rather than restating them: read OpenRouter’s Terms of Service for the current text. This is the part people are most often surprised by. A request our own rules do not mention can still be refused upstream, and a refusal that arrives from the model provider is not a PhoneBase fault.

Three things you may not use a phone for

These are ours, and they are about the device rather than the model.
  1. Fraud. Do not use a phone to deceive a person or a service for gain. That includes payment fraud, fake engagement, fabricated identities and anything whose purpose is to make a counterparty act on a false belief.
  2. Taking accounts that are not yours. Do not use a phone to sign in to, recover, or hold an account you are not authorised to hold. Credential stuffing, SMS interception for somebody else’s login, and working through a list of accounts all fall here.
  3. Getting around a platform’s own protections. Do not use a phone to defeat another service’s security or integrity controls. Rate limits, device attestation, bot detection, region locks and account-linking protections are that service’s decisions about its own product.
The second and third are worth reading together. PhoneBase gives an agent a real handset with a real number, which is exactly the shape of thing those protections exist to see. Having a real device does not make you authorised to use it against somebody else’s account.

What we do when this is broken

We may throttle, suspend, or terminate. That is the right this policy reserves. What that means in practice today is withdrawal of access. An API key can be revoked, and from its next request it is refused with the reason it was refused for, which is a sentence your client can print. A device can have its entitlement revoked, and operator is one of the recorded reasons for that. Withdrawing access is not a deletion. The receipt ledger is a separate record and revoking a credential does not touch it, so what already happened stays readable.

If you are unsure

Ask before you build it. Describe the workflow to us at the address on phonebase.co and we will tell you whether it is something this product is for. That is a cheaper conversation than discovering the answer after your access is withdrawn.