Effective date: September 27, 2026 Last updated: September 27, 2026
This Acceptable Use Policy ("Policy") explains what you may not do with Tally Sign. It is part of the Tally Sign Terms of Service. Capitalized words not defined here have the meaning in the Terms of Service.
Tally Sign is built for businesses to send documents to people they deal with and collect genuine signatures. Almost everything in this Policy comes down to three ideas: every signature must belong to the person it says it belongs to, every document and email must have a legitimate reason to be sent, and nobody may use Tally Sign to harm other people, other customers or the Service itself.
1. Who this Policy applies to
1.1 "Tally", "we", "us" and "our" mean Tally Integrations LLC, a Nevada company that operates Tally Sign.
1.2 "You" means the Customer and every person who uses the Service under its Account. That includes Users (owners, admins, members, and Salesforce users who hold a Tally Sign seat) and Salesforce users in your org who use the Tally Sign package without a seat.
1.3 This Policy covers every way of using Tally Sign, including:
- the web app at https://app.tallysign.com (also reachable at sign.gettally.io) and its signing pages;
- signing in to your Account, including with Google, Microsoft or Salesforce, or through your company's own identity provider (single sign-on);
- email the Service sends on your behalf, including signing requests, reminders, negotiation messages and automation emails;
- the in-app AI assistant;
- Connected AI Apps (such as ChatGPT or Claude) and AI Agents (such as a Salesforce Agentforce agent using Tally Sign actions);
- API keys and any other programmatic access;
- the Tally Sign managed package for Salesforce and its write-back to your Salesforce org;
- automations, including emails, Slack, Microsoft Teams and Discord messages, and webhooks; and
- our website at https://www.tallysign.com and the Tally Sign University guides.
1.4 You are responsible for your Users and your tools. Anything done through your Account counts as done by you. That includes actions taken by a User, by an API key you created, by a Connected AI App a User approved, by an AI Agent or automation you set up, and by the Salesforce package in your org. You must make sure your Users know about and follow this Policy.
1.5 Recipients aren't bound by this Policy. People you send documents to, whether to sign or to receive a copy ("Recipients", as defined in the Terms of Service), don't need an account and don't agree to our Terms of Service. You, as the sender, are responsible for how you use the Service to deal with them. If a Recipient misuses a signing page (for example, by trying to attack the Service), we may act under Section 13.
2. Signatures, identity and signing records
The value of an electronic signature depends on it being the real act of the real person. Don't do any of the following.
2.1 Forge a signature. Don't sign, or adopt a signature, for anyone other than yourself, unless you have that person's actual legal authority to sign for them and the document makes that authority clear (for example, "signed by [name] as attorney-in-fact for [name]").
2.2 Impersonate a Signer. Don't send a signing request to an address you control, or to anyone other than the intended Signer, so that someone can sign in that person's name. Don't give a Recipient a name that doesn't match the person who will get the email.
2.3 Misuse a signing link. Don't open, forward or use another person's signing link to sign as them, and don't ask a Recipient to forward their link to someone else to sign for them. Don't let a Connected AI App or AI Agent open, fill in or sign a document through a Recipient's signing link. Each signing link belongs to one Recipient.
2.4 Misuse in-person signing. When you host an in-person signing on your device, the Signer must personally review the document and personally adopt and apply their own signature. Don't complete fields or sign for them, and don't pressure them to sign without a chance to read the document.
2.5 Tamper with signing records. Don't alter a completed document, its Certificate of Completion or its audit trail and then present the altered version as the original. Don't create or distribute documents, certificates or audit trails that falsely appear to have been produced by Tally Sign.
2.6 Misstate what a Tally Sign signature is. Tally Sign signatures are electronic signatures in the sense of Article 3(10) of the EU eIDAS Regulation and the equivalent UK rules (sometimes called simple electronic signatures), captured with an audit trail. They aren't advanced or qualified electronic signatures, and they aren't notarized, witnessed, certificate-based, sealed, qualified-time-stamped or identity-verified beyond control of the email address used. Don't tell anyone, in a document, email or elsewhere, that they are.
2.7 Obtain signatures by deception. Don't trick someone into signing, including by hiding material terms, sending a document that differs from what the Signer was told they would receive, or misrepresenting who they are contracting with.
2.8 Rewrite what someone already signed without telling them. If you void, unlock or replace a document after someone has signed it, their signature is cleared. Don't use this to change terms behind a Signer's back. Tell Signers who have already signed when you void, replace or delete a document, including if you have turned off void notices.
3. A lawful basis for every document and every Recipient
3.1 You need a legitimate reason to send. Send documents only to people you have a real business relationship with, or a genuine and lawful reason to contact about the document. Don't send documents to people who haven't dealt with you, to purchased or scraped lists, or to addresses you guessed.
3.2 You are responsible for the personal data you put into Tally Sign. Depending on the laws that apply to you, you may be the "controller" or "business" for the personal data in your documents, including Recipient names, email addresses, the values Recipients type into fields, and signatures. You must:
- have a lawful basis (for example, under the EU or UK GDPR) and any required notices or consents for collecting and using that data, including telling Recipients what you collect and why;
- only ask Recipients for information you actually need for the document; and
- have the right to share any third party's personal data you include in a document, template, attachment or upload.
Our processing of that data on your behalf is described in the Data Processing Addendum and the Privacy Policy.
3.3 Consumer disclosures are yours to give. If a law requires you to give a consumer information in writing, you are responsible for obtaining their consent to receive it electronically and for giving any disclosures that law requires (for example, under 15 U.S.C. § 7001(c) of the U.S. ESIGN Act). Tally Sign shows Recipients a default Electronic Records and Signature Disclosure in your name, and you must honor it as Section 13.10 of the Terms of Service describes. It is your responsibility to decide whether it is sufficient for your documents and your Recipients.
3.4 Capacity and authority. You are responsible for making sure each Signer has the legal capacity and authority to sign. Don't use Tally Sign to obtain signatures from minors on documents they can't lawfully sign, or from people who you know lack authority to bind the party named in the document.
3.5 Sensitive data needs extra care. Unless we have agreed otherwise in a Signed Agreement, don't use Tally Sign to collect or store:
- full payment card numbers, card security codes, or bank account login credentials;
- passwords, one-time passcodes or other authentication secrets for any system;
- protected health information regulated by the U.S. HIPAA rules; or
- any other data where a law you are subject to requires safeguards or certifications you haven't confirmed Tally Sign provides.
Document fields, comments and attachments are not a secure vault for these kinds of data.
4. Documents that need more than an electronic signature
4.1 You decide whether e-signature is right for each document. Electronic signatures are widely recognized, but not for everything. It is your responsibility to decide, for each document and each place your Signers are, whether an electronic signature is legally sufficient. We don't guarantee that any document signed through Tally Sign will be valid or enforceable.
4.2 Examples of documents that may be excluded or need more. This is the list the Terms of Service refer to. The following commonly fall outside U.S. e-signature laws (ESIGN and UETA) or require a handwritten ("wet ink") signature, witnesses, notarization, a qualified electronic signature, or a specific form or delivery method. This list isn't complete, and the rules differ by country and by U.S. state:
- wills, codicils and testamentary trusts;
- adoption, divorce and other family-law documents;
- court orders, notices, pleadings and other official court documents;
- certain notices, including notices of utility shut-off; default, acceleration, repossession, foreclosure or eviction, or the right to cure, relating to a primary residence; cancellation of health or life insurance; and product recalls or safety failures;
- documents required to accompany the transport or handling of hazardous materials;
- many Uniform Commercial Code documents, including negotiable instruments such as negotiable promissory notes;
- transferable records and electronic promissory notes intended to be negotiable (the Service can't give any person "control" of a transferable record under 15 U.S.C. § 7021 or UETA § 16);
- deeds and other documents that must be recorded, witnessed or notarized;
- documents for which a government agency or regulator sets its own electronic-record requirements, and certain government, immigration, tax and regulatory filings; and
- documents that local law requires to be in "written form" or signed with a qualified electronic signature (for example, certain employment and consumer-credit documents in some EU countries, and documents that must meet the written-form rules of Swiss law).
4.3 Tally Sign doesn't notarize or witness. Tally Sign doesn't offer notarization, remote online notarization, witnessing, or Signer identity checks such as ID document, SMS or knowledge-based verification. Don't use Tally Sign in a way that suggests a document has been notarized, witnessed or identity-verified when it hasn't.
4.4 If a document needs any of these, use a method that meets the requirement. You may still use Tally Sign for parts of the process where the law allows it.
5. Email, spam and harassment
Tally Sign sends email on your behalf, under your company name, to people you choose. Those emails affect everyone who relies on Tally Sign's email reputation, so these rules are strict.
5.1 No spam. Don't use Tally Sign to send unsolicited bulk email. That includes signing requests, reminders, copies to Recipients, negotiation messages, void notices and automation emails. Don't send documents, or set up automations, to reach people who have no reason to expect them. (Bulk and marketing email also breaks the fair-use rules in Section 11 of the Terms of Service.)
5.2 No marketing through signing emails. Tally Sign is for sending documents and messages about documents. Don't use templates, documents, reminders or automation emails as newsletters, advertising, cold outreach or promotional campaigns. If a message you send through Tally Sign is a commercial message under laws such as the U.S. CAN-SPAM Act, Canada's Anti-Spam Legislation, or EU and UK e-privacy rules, you are responsible for meeting those laws, including consent and opt-out requirements.
5.3 Respect "stop" and withdrawn consent. If a Recipient asks you to stop sending them documents or reminders, stop, unless you have a legal right to continue. If a Recipient withdraws consent to receive records electronically, don't use Tally Sign to deliver any record the law requires you to give that person in writing. Use another method the law allows. Never use Tally Sign to deliver a notice that the law excludes from electronic delivery (see Section 4.2).
5.4 No harassment. Don't use documents, emails, reminders, comments, suggested edits, decline reasons or automation messages to threaten, harass, bully, stalk, intimidate or abuse anyone. Don't send reminders so often, or re-send a document so many times, that it becomes harassment.
5.5 Keep complaint and bounce rates normal. Use accurate, current email addresses. If your sending causes unusual numbers of bounces, spam complaints or blocklistings, we may limit or pause sending from your Account while we work with you to fix it (see Section 13).
6. Sender identity and email deliverability
6.1 How Tally Sign email works today. Emails sent for your documents come from Tally Sign's own sending address. They show your company name as the sender name (for example, "Your Company via Tally Sign") and set the reply-to address to the sending User or your company email.
6.2 Use only names and addresses you're entitled to use. Don't:
- create a company, sender profile, display name, logo or reply-to address that uses the name, brand or email address of a business, person or government body you aren't authorized to represent;
- set a reply-to address, sender profile email, or automation "to" address that you don't own or aren't authorized to use;
- make an email look as if it comes from Tally, from another e-signature provider, or from a bank, government agency or other trusted body, when it doesn't;
- disguise or falsify the origin, subject or content of an email, or write content designed to get past spam or security filters; or
- include links to phishing pages, malware, or pages designed to collect passwords or payment details.
6.3 Your own sending domain. If we offer the option to send from your own email domain, you may use only domains you own or are authorized to use, and you must keep that domain's email authentication settings accurate. Don't use Tally Sign to send "from" any domain you don't control.
7. Illegal, harmful and infringing content
Don't use Tally Sign to create, upload, store, send or share anything that:
7.1 is illegal, or promotes or facilitates illegal activity, in any place where you, your Users or your Recipients are;
7.2 is part of a fraud or scam, such as fake invoices, advance-fee schemes, fraudulent loan or investment offers, fake job offers, or documents intended to trick someone into paying money or handing over property or personal information;
7.3 infringes anyone's intellectual property, privacy or publicity rights, including uploading documents or images you don't have the right to use;
7.4 is defamatory, threatening, or incites violence or hatred against people based on a protected characteristic;
7.5 sexually exploits or endangers children, or is sexually explicit content involving anyone who has not consented;
7.6 contains viruses, malware, malicious scripts or other harmful code, including inside uploaded PDFs, Word documents, images or attachments;
7.7 facilitates trade or dealings with any person, organization or country in violation of U.S. or other applicable sanctions or export control laws (see Section 28.6 of the Terms of Service); or
7.8 falsely suggests that Tally endorses, sponsors or is affiliated with you, your documents or your business.
8. AI features
This Section covers the in-app AI assistant that writes, edits and reviews templates and email designs. The assistant runs on third-party AI models (currently Anthropic's Claude models) reached through OpenRouter, as described in the Subprocessors list.
8.1 Review everything the AI writes. AI output can be wrong, incomplete, out of date or unsuitable, and it isn't legal advice. An AI review that finds no problems doesn't mean there are none. You must review and take responsibility for anything the assistant produces before you use it or send it to anyone.
8.2 Don't use the AI for prohibited purposes. Don't use the assistant to create content that breaks this Policy, including forged or deceptive documents, phishing emails, content that impersonates another business or person, or content that infringes someone else's rights.
8.3 Be careful what you give it. The content of the draft or template you're editing (including the signers' names, email addresses, titles and companies, the fill-in values and the signing email you've entered), your chat messages, and any pictures you attach are sent to our AI Subprocessors to produce a response. Don't give the assistant personal data or confidential information you aren't allowed to share with them, or the sensitive data described in Section 3.5. Pictures you attach in the email designer are stored as email images that anyone with the link can open.
8.4 Don't attack or extract from the AI. Don't:
- try to make the assistant or any AI tool ignore its instructions or safety rules, or reveal hidden instructions ("jailbreaking" or "prompt injection"). This includes planting instructions in documents, templates, uploads, images, emails, comments or decline reasons meant to manipulate Tally Sign's AI features or the AI tools of the people you send documents to;
- try to extract model weights, training data, or our prompts and configuration; or
- use the assistant through automated or systematic querying to generate data for building or training a competing AI model or product.
8.5 AI usage limits. The AI assistant has usage limits, described in Section 11.4 of the Terms of Service. Don't try to get around them, for example by creating extra accounts, spreading requests across companies, or automating the assistant.
8.6 Model provider policies and human review. You must also follow the usage policies of the model providers that power the assistant, as linked from the Subprocessors list, as they apply to your use of the assistant. We may limit or pause AI features for an Account whose use would breach them. You may use AI output in documents sent to consumers, or in documents with legal effect, only after a person at your company has reviewed and approved it.
9. Connected AI Apps, AI Agents, API keys and automation
You can connect ChatGPT, Claude or other apps to Tally Sign, set up AI Agents and automations, and use API keys, so that software can create, edit and send documents for you. That power comes with these rules.
9.1 Your connected tools act as you. A Connected AI App or API key acts as the User who approved or created it and has that User's access. An AI Agent acts with the permissions of the Salesforce user or integration it runs as. You are responsible for everything they do, including documents they create, edit, send, remind, void or delete.
9.2 Sending must be authorized by a person. Every document sent through the Service must be sent with the authority of a User. That authority can be given case by case, or in advance through a rule a User has deliberately set up and can review, such as a Salesforce send rule or flow, a Tally Sign action added to a Salesforce Agentforce agent, an automation, or an integration using an API key. When a Connected AI App asks to send a document, Tally Sign asks the app to get the User's explicit approval first. Don't instruct, prompt or configure a Connected AI App to give that approval when no person has reviewed the send. You are responsible for every document sent under a rule, agent or integration you set up, including documents it sends in error, and for reviewing those rules regularly.
9.3 Protect your credentials. Keep API keys, OAuth tokens and Salesforce package credentials secret. Don't share them outside your company, publish them (for example, in public code repositories), or use one company's credentials for another company. If you think a credential has been exposed, revoke it right away (you can revoke API keys, and owners and admins can disconnect all Connected AI Apps, in Settings) and tell us at security@tallysign.com. Removing a User stops their API keys and apps from working, but changing a password doesn't, so revoke and disconnect them as well when you only change credentials.
9.4 No abusive automation. Don't:
- send requests at a volume or speed that degrades the Service for others, or far beyond what your normal business use requires;
- use scripts, bots, crawlers or scrapers to collect data from the Service, the signing pages, our website or Tally Sign University, other than through the features and interfaces we provide and only for your own Account's data;
- try to guess, enumerate or collect signing links, document IDs, file or image IDs, API keys, tokens or other identifiers;
- use features that fetch content from a web address (for example, attaching a PDF from a link) or send data to a web address (for example, webhook automations) to reach systems you aren't authorized to access, or to attack, probe or overload any system; or
- use Tally Sign as a general file-hosting service, image host or content delivery network (for example, by linking to logos, images or pages from Tally Sign for purposes unrelated to your documents and emails).
9.5 Third-party apps have their own terms. When you connect ChatGPT, Claude or another app, the information that app receives from Tally Sign is handled under your own agreement with that app's provider, not by us. You must comply with that provider's terms and policies.
10. Salesforce integration
10.1 Only connect orgs you're authorized to connect. Connect Tally Sign only to a Salesforce org that you own or are authorized to connect, using a Salesforce user you are authorized to use for that purpose. You must have your own valid Salesforce licenses, and you must follow Salesforce's own terms and policies.
10.2 Don't tamper with the package. Don't modify, decompile or work around the Tally Sign managed package, its authentication, or its seat and licensing checks. You may change the flows and settings the Service deploys into your org, which are your configuration (Terms of Service Section 15.8(a)).
10.3 Seats are for named people. Each Tally Sign seat, including a seat held by a Salesforce user, is for one named person. Don't share a seat or sign-in among several people, and don't repeatedly move seats between users so that more people can send documents than you pay for. Normal staffing changes are fine.
11. Security, integrity and getting around the Service
11.1 No security testing without permission. Don't probe, scan, or test the vulnerability of Tally Sign or any system connected to it (including penetration testing, vulnerability scanning, load or stress testing, and social engineering of our staff) unless we have given you written permission in advance, and stay within the scope we approve. Good-faith research that follows Section 11.5 is allowed.
11.2 No unauthorized access or interference. Don't:
- access, or try to access, any account, company, document, signing page or data you aren't authorized to access, including another customer's data;
- bypass or break any authentication, access control, tenant separation, usage limit, billing control or other security measure, including a company's requirement to sign in through its single sign-on;
- interfere with or disrupt the Service, including through denial-of-service attacks, flooding, or uploading files designed to crash or overload our systems; or
- use the Service to attack, probe or gain unauthorized access to any other system or network.
11.3 No reverse engineering. Except to the extent the law expressly allows it despite this restriction, don't decompile, disassemble or reverse engineer any part of Tally Sign, or copy its features, interface or design to build a competing product.
11.4 No getting around your plan. Don't:
- create multiple companies or accounts to get repeated free trials or to avoid paying for seats;
- use another company's account, or a new account, to keep sending documents or using the AI assistant while your own Account is Paused or suspended;
- resell or provide Tally Sign to others (see the fair-use rules in Section 11.2(b) of the Terms of Service); or
- remove, hide or alter any Tally Sign branding, notices, disclosures or legal statements that the Service shows to Recipients or places on signed documents, unless the Service gives you a setting to do so.
11.5 Reporting security vulnerabilities. Report suspected security vulnerabilities in Tally Sign to security@tallysign.com. Include enough detail for us to reproduce the issue. We will acknowledge your report within 5 business days and keep you informed while we fix it. If you act in good faith and follow these rules, we won't treat your research as a breach of our Terms of Service or this Policy, and we won't take legal action against you for it:
(a) test only against your own account and data, and stop as soon as you confirm the issue;
(b) don't access, change, download or keep other customers' or Recipients' data beyond the minimum needed to show the issue, and tell us if you accidentally did;
(c) don't degrade the Service (no denial-of-service, spam, social engineering or physical testing); and
(d) give us a reasonable time, normally 90 days, to fix the issue before you disclose it publicly.
We don't currently offer a bug bounty.
12. Fair use
Tally Sign plans include unlimited documents, envelopes, templates, signers and automations, subject to the fair-use rules in Section 11 of the Terms of Service. Breaking those rules also breaks this Policy. We don't publish numerical thresholds for fair use or for AI usage.
13. Enforcement
13.1 We may investigate. We don't routinely review the content of your documents. We may review your Account, activity, documents and emails when we reasonably suspect a violation of this Policy, receive a report, or need to protect the Service, our customers, Recipients or the public. When we do, our staff access your Account only as Section 20.3 of the Terms of Service allows. You agree to cooperate with reasonable requests for information during an investigation.
13.2 What we may do. If we reasonably believe you or your Users have violated this Policy, we may take action that is appropriate to the violation, including one or more of the following:
- warn you and ask you to fix the problem within a reasonable time;
- remove, or require you to remove, offending content, templates or automations;
- limit or pause specific features, such as sending documents, emails, automations, the AI assistant, API access or Connected AI Apps;
- revoke API keys or connected-app access;
- disable individual Users;
- suspend your company's Account, which also blocks access through API keys, Connected AI Apps and the Salesforce package;
- take reasonable steps to prevent further signing of a document we reasonably believe is fraudulent or harmful, or warn the affected Recipients;
- terminate your Account under the Terms of Service; and
- report activity to law enforcement or other authorities, and cooperate with them, where we believe that is appropriate or required by law.
13.3 Notice. Suspensions follow Sections 23.1 and 23.2 of the Terms of Service. For other actions, where it's practical and lawful, we'll tell you before we act and give you a chance to respond or fix the problem. We may act first and tell you afterwards when we reasonably believe that waiting would risk harm to anyone, or would compromise security or an investigation. We won't tell you only where the law prohibits it.
13.4 Proportionate response. Where we can address a problem by limiting a single User or feature, we'll generally do that rather than suspend your whole Account.
13.5 Your documents during a suspension. You can ask for copies of your signed documents, Certificates of Completion and audit trails while your Account is suspended, as Section 23.3 of the Terms of Service describes. Recipients can generally still view and download documents they have already signed.
13.6 Fees and data. Refunds after a suspension or termination are governed by Section 6.6 of the Terms of Service. What happens to your data after suspension or termination is set out in Sections 10 and 23 of the Terms of Service.
13.7 No duty to monitor. Our right to enforce this Policy doesn't mean we monitor all use of Tally Sign or that we are responsible for your content or conduct. Our choosing not to act on one violation doesn't waive our right to act on that or any other violation later.
14. Reporting abuse
14.1 Anyone can report. If you believe someone is misusing Tally Sign, including if you received a signing request or email you think is fraudulent, forged, harassing or spam, please tell us at support@tallysign.com. Include, if you can:
- the email you received (forwarded with its headers, if possible), or the company name shown in it;
- the date you received it; and
- what you believe is wrong.
Please don't send us the signing link itself unless we ask for it. Anyone with the link can open the document.
14.2 If you received a document you didn't expect. Documents and emails sent through Tally Sign are written and sent by the company named in them, not by Tally, and Tally doesn't verify that a sender is who it says it is. If you don't recognize the sender or the document:
- don't sign it, and don't enter passwords, payment details or other sensitive information into it;
- you can use "Decline to sign" on the signing page;
- check with the sender using contact details you already trust, not the ones in the email; and
- report it to us as described above.
14.3 Security vulnerabilities. Report suspected vulnerabilities to security@tallysign.com as described in Section 11.5.
14.4 Intellectual property complaints. If you believe content on Tally Sign infringes your copyright or other rights, send a notice to support@tallysign.com (our postal address: available on request from support@tallysign.com). Include your contact details, a description of the work or right, where the content appears, and a statement that you believe in good faith the use isn't authorized.
14.5 Requests from authorities. Law enforcement and government requests should be sent to support@tallysign.com.
14.6 What happens next. We review reports and act under Section 13 where appropriate. We may not be able to tell you the outcome, particularly where it involves another customer's Account or personal data. We'll keep the identity of the person reporting confidential where we reasonably can, unless the law requires otherwise or you agree.
15. Changes to this Policy
We may update this Policy from time to time, for example to respond to new kinds of abuse, new features or changes in the law. We'll post the updated Policy at https://www.tallysign.com/legal/acceptable-use-policy and update the "Last updated" date. Material changes that restrict your existing use take effect after at least 30 days' notice, as Section 25.2 of the Terms of Service describes. Changes needed to comply with law or to stop a new kind of abuse may take effect when posted.
16. Contact
- Questions about this Policy and legal notices: support@tallysign.com
- Abuse reports: support@tallysign.com
- Security vulnerabilities: security@tallysign.com
- Postal address: available on request from support@tallysign.com
Related documents: Terms of Service · Privacy Policy · Data Processing Addendum · Electronic Records and Signature Disclosure · Subprocessors · Cookie Notice
