Dual Login
← Trust Center

Acceptable Use Policy

Last updated: August 9, 2026

This Acceptable Use Policy ('AUP') sets out the rules for using Dual Login. It is part of our Terms of Service. Our goal is simple: Dual Login is a professional tool for legitimate work, and we do not tolerate its use for fraud or crime.

In plain English

A policy has to be precise, which makes it hard to read. Here is the same document answered as the questions people usually arrive with. It is a summary: where the two could be read differently, the numbered sections below govern.

What is this policy actually for?

It draws the line between the work the tool is built for and the things it will get you banned from using it for. The short version: separating accounts you are entitled to hold is what Dual Login is for; using separation to defraud somebody is not. Everything below is that one idea applied to specific cases.

What am I clearly allowed to do?

Section 1 lists it: browser and QA testing across environments, managing advertising and marketplace accounts you or your clients own, agency work on behalf of clients who have asked you to do it, research and price monitoring on public data, and keeping your own browsing compartmentalised. If your work is on that list, nothing in this policy is aimed at you.

What will get an account closed?

Section 2 is the list, and it is the ordinary one: fraud, stolen or resold credentials, payment-card abuse, phishing, malware distribution, harassment, and anything that is a crime where you are. Note the shape of it — every item involves a victim. It is not a list of sites you may not visit.

Somebody could break these rules with any browser. Why is this here?

Because a tool that makes accounts harder to link is genuinely more attractive to somebody committing fraud, and pretending otherwise would be dishonest. Saying plainly what the tool is not for, and enforcing it, is the price of building something that has legitimate uses at all.

What happens if someone reports me?

Sections 3 to 5 cover it. A report is the beginning of a look, not a verdict, and the enforcement is graduated rather than binary — a warning where a warning fits, a suspension where it does not. If your account is actioned you are told what the finding was, so you can answer it. See the Anti-Abuse Policy for how that process runs.

Is having multiple accounts on a platform against your rules?

No. It may be against that platform's rules, which is a different question and one only their terms can answer. Plenty of multi-account use is explicitly permitted -- agencies holding client advertising accounts, sellers with separate legal entities, testers who need a dozen states of the same app. Our rules are about harm, not about count.

I am an agency. Whose responsibility is the client's account?

Yours, in your relationship with us. We contract with the account holder, so if work is done through your workspace, it is your workspace that answers for it. In practice this means being able to show a client asked you to manage the account -- which is ordinary agency hygiene and worth having on file long before anyone asks.

Do you scan what I browse to enforce this?

No, and section 3 is deliberately narrow about what we do look at. Enforcement works from platform-level signals -- payment patterns, signup behaviour, and credible reports -- not from reading through profile data. The isolation the product sells would be a fiction if we were inspecting the sessions it isolates.

What counts as a credible report?

One we can check. Something with specifics -- what was done, where, and anything that lets us verify it independently -- gets acted on. An anonymous assertion with no detail is not thrown away, but it starts an investigation rather than concluding one, and it does not by itself close an account.

Can I resell access to my workspace?

No -- that is a reseller arrangement, and there is a partner programme for it. The distinction matters because a shared workspace has one account holder answerable for everything in it, which is a poor arrangement for you as well as for us the moment one of your customers does something you would not have.

Does automation count as abuse?

No. Automation is a documented feature and a large part of why people choose this product. What can cross the line is what the automation does -- scale that harms a service, or actions the prohibited list already names. The tool is not the question; the effect on somebody else is.

1. Allowed uses

Dual Login is designed and intended for lawful business and privacy purposes, including:

  • Web development and QA/browser testing across environments.
  • Digital marketing, affiliate marketing and advertising-account management.
  • Managing multiple business profiles and agency client workflows.
  • E-commerce and marketplace account management.
  • Social media management for brands and clients.
  • Privacy protection and reducing cross-site tracking.
  • Lawful security research and fingerprint management.

You are responsible for making sure your specific use is lawful where you operate and consistent with the terms of any platform you interact with.

2. Prohibited uses

You must not use Dual Login to do, attempt, or help anyone else do any of the following:

  • Fraud, phishing, scams, or deceptive or misleading practices.
  • Spam or unsolicited bulk messaging of any kind.
  • Identity theft, impersonation of others, or account takeover.
  • Unauthorised access to accounts, systems or data.
  • Bypassing security controls, bans or access restrictions unlawfully.
  • Illegal automation, credential stuffing, or scraping in violation of law.
  • Distributing malware or engaging in cybercrime.
  • Money laundering, sanctions evasion, or terrorist financing.
  • Child sexual abuse material or any content that exploits or harms minors.
  • Infringing intellectual property, privacy or publicity rights.
  • Any other activity that is illegal where you or the targeted service operate.

3. Abuse prevention

We use technical and operational measures to detect and prevent abuse, including rate limits, fraud screening on payments, and monitoring for patterns associated with prohibited activity. We do not routinely inspect the contents of your browser profiles, but we may act on credible reports or clear signals of abuse.

4. Reporting abuse

If you believe someone is misusing Dual Login, report it to abuse@duallogin.com with as much detail as you can. We review every report.

5. Enforcement

Breaking this AUP can lead to a warning, feature limits, suspension, or permanent termination without refund, depending on the severity. Where activity appears illegal, we may preserve records and cooperate with lawful requests from authorities. We aim to be fair and proportionate, and to give notice where it is safe and practical to do so.

This document is provided for transparency and does not constitute legal advice. If you have questions, contact us at legal@duallogin.com.