Acceptable Use Policy

Use CrystalSlate only for authorized, careful Smartsheet work.

Effective July 26, 2026 · Last updated July 26, 2026

1. Authorized use

You may use CrystalSlate only with accounts, subscriptions, Smartsheet environments, assets, users, groups, and data that you are authorized to access or manage. You must follow your organization’s policies, Smartsheet’s terms, applicable law, and the CrystalSlate Terms of Service.

2. Safe workflow expectations

  • Start with read-only discovery and low-risk or sandbox assets.
  • Review scope, preview results, and obtain required business approval before writes.
  • Use typed confirmations honestly and do not automate around safety interstitials.
  • Verify results and preserve appropriate Activity records or exports.
  • Stop a workflow when the selected scope or result is unexpected.

3. Prohibited access and security activity

You may not:

  • Access, test, enumerate, or change accounts or data without authorization.
  • Share accounts, authorized-user seats, passwords, session cookies, verification links, or Smartsheet tokens.
  • Bypass or interfere with authentication, role gates, subscription entitlements, rate limits, confirmations, logging, or other security controls.
  • Probe or exploit vulnerabilities outside a good-faith, minimally disruptive security report.
  • Upload malware, attempt credential theft, or use CrystalSlate to compromise another service or person.

4. Prohibited data and operational activity

You may not use CrystalSlate to:

  • Perform unlawful, fraudulent, abusive, deceptive, harassing, discriminatory, or privacy-invasive activity.
  • Run destructive or broad write operations without understanding and approving their scope.
  • Circumvent Smartsheet permissions or impersonate a person without authorization.
  • Collect or expose sensitive personal data beyond what is reasonably required for an authorized workflow.
  • Overload, disrupt, scrape, reverse engineer, or resell the service except where applicable law expressly permits.
  • Use exports, screenshots, or support messages to disclose customer information improperly.

5. Support and disclosure safety

Never send tokens, passwords, session cookies, one-time links, payment information, unredacted customer data, or exploit data through ordinary support email. Redact screenshots and provide the minimum information needed to understand an issue.

Good-faith security reports should identify the affected page or workflow, reproduction steps, impact, browser, and approximate time without accessing other customers or causing avoidable disruption.

6. Enforcement

CrystalSlate may investigate suspected violations and may limit, suspend, or terminate access; preserve relevant records; remove harmful material; or contact affected providers or authorities when reasonably necessary. Where practical and safe, CrystalSlate will provide notice and an opportunity to correct an issue.

7. Reporting concerns

CrystalSlate is using email-only contact during its controlled initial launch. Report abuse, account concerns, or security issues to hello@crystalslate.com with “Abuse” or “Security report” in the subject. Do not include secrets.