Legal

Acceptable use policy

A rendering service is a machine that fetches whatever it is pointed at. This is what we will not be pointed at, and what happens when we are.

In effect since . Webshotter, France.

This policy is part of the terms of service. It applies to every request, from the API and from the web form alike.

You must have the right to fetch and capture the page. That means: your own sites, public pages you are permitted to access, and pages you have a customer's authorisation to render. It does not mean a page behind somebody else's login, or a page whose terms forbid automated access.

What we will not render

  • Attacks. Using renders to flood, stress, probe or degrade a third-party site. Every render is a real browser making real requests; a loop of them is a load test somebody did not consent to.
  • Circumvention. Defeating a paywall, a rate limit, a bot check or an access control. Also: attempting to reach private, loopback or cloud-metadata addresses through us, by any means, including DNS you control.
  • Surveillance. Monitoring an individual, or capturing pages to build a profile of a person without a lawful basis.
  • Illegal material. Child sexual abuse material, content that incites violence or terrorism, and anything else whose possession or distribution is a crime. Reports of CSAM go to the authorities, always, and the account is closed immediately and without notice.
  • Deception. Rendering a page in order to pass the image off as an authentic record — a fabricated receipt, a fabricated statement, a fabricated news article, a fabricated review. A webshot of a page you control is not evidence of anything, and using it as though it were is fraud.
  • Impersonation. Capturing a page designed to look like somebody else's brand, sign-in screen or communication, for use in phishing or in a scam.
  • Malware. Pointing us at, or distributing through us, anything designed to harm a system or exfiltrate data.
  • Infringement. Systematically capturing copyrighted material for republication.
  • Resale as a bare proxy. Reselling raw rendering capacity as an unbranded API to third parties you have not agreed these terms with. Building a product on top of us is fine and encouraged; being an anonymous front door for anybody with a URL is not.

Being a good neighbour to the fleet

  • Respect the rate limits. If you need more, ask — that is a plan conversation, not an arms race.
  • Do not open concurrent renders far beyond your plan's lane in order to jump the queue.
  • Do not retry a failing render in a tight loop. A 422 will keep being a 422; a 503 tells you when to come back.
  • Cache. If the page has not changed, you do not need another picture of it.

What happens when this is breached

It depends on what it is. Most breaches are somebody's script behaving badly, and a note fixes it. In escalating order, we may:

  1. Contact you and ask you to stop.
  2. Apply a temporary rate limit or block a target domain for your account.
  3. Suspend the account.
  4. Close the account and delete its data.
  5. Report it to the appropriate authority.

For anything involving CSAM, an active attack, or a credible threat to someone's safety, we skip straight to the end. Everywhere else we will tell you what the problem is first, because almost every case is a mistake rather than an intention.

Telling us about a breach

If one of our customers is pointing us at your site, or you have seen an image from us used to deceive, the report page says exactly what to send and where. We answer those.

Questions a policy cannot answer

If something here is unclear, or your legal team needs it in another shape, write to us — a person reads that address.