Policy

API Usage Policy

Your responsibilities when you connect to the Check Cherry API, and what we can and can't help with.

API Usage Policy

Effective date: September 24, 2026
The short version: Your API key acts as you. You're responsible for keeping it safe, for everything done with it, and for building and maintaining your own integration.

This policy applies to every API key and connected app on your account. It adds to our Terms of Service, and the Email Sending Policy applies to every email your integration triggers.

Your key acts as you

  • Every request made with your key is treated as your account's activity and attributed to you, whoever or whatever made it.
  • A new key starts with no permissions. Grant only what your integration needs, up to your own access level.
  • Leads, bookings, and contacts created through the API are real records in your account. They trigger your automated messages like any other.

Keep your key secure

  • Treat your key like a password.
  • Keep keys on your server. Never put a key in website code, a browser extension, or a mobile app where someone could read it.
  • Never share a key in a public repository, a support forum, or an unsecured message.
  • Use one key per integration so you can shut one off without breaking the others.
  • If a key is exposed, revoke it right away from the API Keys page.

Protect your clients' data

Data you pull through the API, like client names, emails, and event details, is your responsibility once it leaves Check Cherry. Store it securely, share it only with tools you trust, and follow the privacy laws that apply to you and your clients.

Protect public forms

If a form on your website sends submissions to the API, it's a public door into your account. Bots find these forms and fill them with fake names and real people's email addresses, and your account then emails those people.

Any public form that posts to the API must have bot protection, such as a captcha, a honeypot field, or a spam filter from your form provider. Check your leads after you connect a form, and again whenever you change it.

Support

Check Cherry support can help with your account and with bugs in the API itself. We can't build, review, or debug custom integrations, including code written by you, a developer you hired, or an AI tool. You're responsible for developing and maintaining your own integration, including keeping it working as the API changes.

Usage limits

Every key has rate limits to keep the platform fast for everyone. Requests over the limit are refused until the window resets. Limits may change as the API evolves.

What's not allowed

  • Creating leads, bookings, or contacts for people who did not ask to hear from you.
  • Importing purchased, rented, or scraped contact lists.
  • Using the API to get around email limits, quarantine, or any other safeguard on your account.
  • Accessing data from an account you are not authorized to use.
  • Reselling API access or sharing your key with another business.
  • Sending traffic meant to overload or disrupt the service.

What happens if there's a problem

When we see a compromised key, junk traffic, or abuse, we act first to protect your account and the people you email. We may do this immediately and without prior notice. Possible actions include:

  • Revoking the key.
  • Pausing API access for your account.
  • Holding email your account sends, including automated messages.
  • Removing leads or contacts created by junk traffic.
  • Suspending your account for serious or repeated problems.

A revoked key stays revoked. Once the problem is fixed, create a new key and update your integration. If you believe we acted in error, email support@checkcherry.com.

Changes to the API and this policy

The API and this policy may change as our platform evolves. The effective date at the top of this page reflects the most recent policy change. Significant updates will be communicated to active customers by email or in-app notice.