Acceptable use policy
Where the line is
The distinction we use is simple: are you collecting data, or are you doing something to a person? Gathering public information at a reasonable rate is legitimate and it is most of what our customers do. Using an IP address to reach a human being who did not want to be reached is not.
Fine by us
- Scraping publicly accessible data at a considerate rate
- Price monitoring, market research and competitor analysis
- Ad verification and brand protection
- SEO and SERP monitoring
- Checking how your own site or app behaves from another country
- Sneaker, ticket and release bots
- Academic and journalistic research
- Testing your own infrastructure
Not fine, and we will close your account
- Credential stuffing and account takeover. Testing stolen credentials against any service.
- Child sexual abuse material. Accessing, distributing or hosting it, in any form.
- Harassment and stalking. Including evading a block a person has placed on you.
- Fraud. Carding, payment fraud, fake account farms for scams, phishing infrastructure.
- Attacks on infrastructure. DDoS, port scanning third parties, exploiting vulnerabilities you are not authorised to test, spreading malware.
- Spam. Bulk unsolicited messaging on any platform.
- Deliberately overloading a target. Volume high enough to degrade a service for its real users.
- Reselling access without a written agreement with us.
Grey areas, handled case by case
Some things are legal in one country and not another, or depend entirely on scale and intent. Automated account creation, scraping behind a login you legitimately hold, and high-volume crawling of a small site are all examples. If you are unsure, ask us before you start rather than after we notice.
How we enforce this
We act on abuse reports sent to [email protected], and we investigate anomalies our own monitoring surfaces. Where we find a breach, we suspend the account.
When we close an account for abuse, we refund the unused balance. Keeping the money would give us a financial interest in abuse happening, and we would rather not have one.
If you have been harmed by traffic from our network
Email [email protected] with the timestamps, the destination, and the source IP if you have it. A human reads that address. We keep connection metadata for 30 days, so reports arriving inside that window are the ones we can act on most effectively.
Why this matters commercially
Beyond the obvious: pools that tolerate abuse end up on blocklists, and then nobody’s scraper works. Enforcing this is how the product stays usable. More on the reasoning behind it on the honesty page.