Acceptable Use Policy
This policy forms part of the Terms of Service. It exists because a screenshot API is a machine that fetches arbitrary URLs on a stranger’s instruction, which makes it useful to a lot of people and attractive to a few of the wrong ones. The rules below are the ones that keep it available to everybody else.
1. The one rule
Only point the renderer at pages you are entitled to capture, and only do with the result what you would be entitled to do if you had pressed the screenshot key yourself. The API is not a permission slip. It does not give you access you did not already have; it only saves you the browser.
2. Pages you are entitled to capture
You may capture:
- pages you own or operate;
- pages a customer or client has asked you to capture on their behalf;
- publicly accessible pages, where the capture and your use of it are lawful and consistent with that site’s own terms;
- pages your users submit in your product, provided you have told them what you do with the URL and you have a lawful basis for it.
You may not capture:
- pages behind someone else’s login, using someone else’s session, or otherwise not meant for you;
- internal, staging or intranet systems you have not been authorised to reach;
- anything a site’s terms, licence or access controls forbid you from taking.
3. Authentication, paywalls and bot protection
Do not use the service to get around a control the site owner put there on purpose. Specifically, no:
- defeating logins, session checks, tokens or access control of any kind;
- capturing content behind a paywall, metered wall or subscription you have not paid for;
- working around CAPTCHAs, bot detection, IP bans or rate limits;
- rotating through the service to disguise the origin of automated traffic another site has blocked;
- ignoring a site’s
robots.txt, terms of service, or a direct request from its owner to stop.
We do not offer, and will not add on request, features whose purpose is evading another operator’s controls — no proxy rotation, no CAPTCHA solving, no stealth fingerprinting.
4. Illegal and harmful content
Do not use the service in connection with:
- child sexual abuse material, in any form — this ends an account instantly and is reported to the authorities;
- terrorist or violent extremist content;
- non-consensual intimate imagery, or material produced to harass, stalk, dox or threaten a person;
- phishing, fraud, malware distribution, or building or maintaining any of those;
- content that is illegal where you are, where we are, or where the target site is.
5. Copyright and other people’s rights
A screenshot of a page is a copy of that page. Rendering one does not give you a licence to it. You are responsible for making sure your capture and your use of it are covered — by permission, by an exception such as quotation or reporting, or because there is nothing protectable in it. Do not use the service to reproduce a paid product, a database or a media library wholesale, and do not pass captured material off as your own.
6. Other people’s personal data
Captured pages often contain personal data. Where they do, you are the controller for it and we are your processor — see the Data Processing Addendum. You need a lawful basis, and you need to be able to answer to the people whose data it is.
Do not use the service to compile profiles of individuals, to harvest personal data at scale from social platforms or directories, or to monitor a specific person’s activity.
7. Networks and security
The renderer is not a network tool, and using it as one is the fastest way to lose an account. Do not:
- aim it at private, loopback, link-local, carrier-grade NAT or cloud metadata addresses, or at hostnames chosen to resolve to them;
- use it to scan, enumerate, fingerprint or probe any network, ours or anyone else’s;
- use it as a general-purpose proxy, anonymiser or file fetcher;
- try to escape the browser sandbox, reach the host, or read another customer’s data;
- attack the service itself, including by flooding it or by trying to exhaust its renderers.
Every submitted URL is validated against reserved and private address ranges before a browser touches it, and the renderer’s own network egress is filtered independently, because DNS can resolve differently the second time. Attempts to get past either are logged and treated as an attack on the service, not as a bug report. Genuine security research is welcome — tell us first, at the address below.
8. Load and fair use
- Do not create multiple accounts to multiply the free quota, and do not sign up on behalf of users to give each of them a free tier.
- Do not share one key across unrelated parties, or resell access to a single account.
- Do not script the public demo. It exists so people can try the product; it is rate-limited by IP, and working around that limit is a breach of this policy.
- Retry politely. Back off on
429and503, and honour theRetry-Afterheader. - Do not point the service at a single third-party site at a volume that would amount to attacking it.
9. Reselling
You may build a product on top of the API, including a commercial one, and you may render on behalf of your own users. You may not resell raw rendering capacity as a competing screenshot API, sublicense your quota, or present the service as your own infrastructure to buyers of a comparable API. If you are unsure which side of that line you are on, ask — the answer is usually yes.
10. How we enforce this
We do not monitor what you render. We see hostnames, volumes and error rates, and we act on those and on reports we receive. When something needs acting on, the ladder is:
- An email, if it looks like a mistake or a misconfiguration. Most cases end here.
- A throttle or a key revocation, if it continues.
- Suspension, then termination, for material or repeated breaches.
- Immediate termination, without warning, for illegal content, attacks on the service or on third parties, or attempts to reach internal networks. Where the law requires it, we report it.
Termination for a breach of this policy does not entitle you to a refund. If you think we got it wrong, reply to us — a human reads it, and reinstatement is possible.
11. Reporting abuse
If someone is using this service against you, write to me@caioricciuti.com with abuse in the subject. Include the date and time with a timezone, the URL or domain involved, and anything that identifies the traffic — log lines are ideal. We aim to acknowledge within two working days.
12. If you own a site we captured
Renders come from our server in Helsinki and reach your site as an ordinary headless Chrome browser. If you do not want your pages rendered through this service, you can block that traffic at your end, and you can also write to us: tell us the domain, show that you control it, and we will look into who was rendering it and can stop it from our side. We would rather hear from you than be found out by your logs.