Acceptable Use Policy
Last updated: June 17, 2026
This Acceptable Use Policy ("AUP") is incorporated into the ByteKit Terms of Service. It applies to all use of the ByteKit Service, including the API, dashboard, CLI, SDKs, MCP server, screenshots, recordings, extraction, sitemap discovery, change monitoring, and bulk or automated requests.
Violation of this AUP is a material breach of the Terms.
1. Customer Responsibility
You are responsible for every request submitted through your account, API keys, users, integrations, and applications.
You must ensure that your use of the Service complies with all applicable laws, third-party rights, third-party website terms, robots or access-control requirements that bind you, and any consents or authorizations required for your use case.
ByteKit's technical ability to access a target does not mean you are authorized to access, capture, store, use, or redistribute that target or its content.
2. Prohibited Uses
You must not use the Service, or help anyone else use the Service, for any of the following.
2.1 Unauthorized Access
- Access password-protected, gated, non-public, or restricted content without authorization.
- Collect, replay, test, or use credentials, session tokens, API keys, authentication cookies, or similar secrets.
- Engage in credential stuffing, password spraying, account enumeration, session hijacking, or similar activity.
- Access any system after receiving a request, notice, or instruction to stop automated access.
2.2 Circumvention and Platform Abuse
- Circumvent or attempt to bypass CAPTCHAs, rate limits, paywalls, access controls, anti-bot systems, geofencing, technical protection measures, or other restrictions where you are not authorized to do so.
- Use the Service to breach a third-party website's terms or contractual restrictions that apply to you.
- Misrepresent your identity, authorization, source, affiliation, or purpose to a target site or third party.
2.3 Ticketing, Queues, and Inventory Abuse
- Operate or support ticket-purchase bots, queue-jumping systems, reservation bots, inventory hoarding, or similar activity.
- Violate the U.S. Better Online Ticket Sales Act or comparable ticketing, queueing, or resale laws.
2.4 Fraud, Deception, and Harmful Content
- Generate fake ad impressions, clicks, installs, conversions, reviews, rankings, or engagement.
- Support phishing, impersonation, spam, scams, social engineering, fake reviews, or deceptive monetization.
- Collect content for malware, exploit delivery, command-and-control, or other harmful activity.
2.5 Sensitive Data and Children
- Capture, store, or process sensitive personal data unless you have a lawful basis, have provided all required notices and consents, and ByteKit has expressly approved the use case where required.
- Capture, store, or process children's personal data unless you have all required rights, notices, consents, and legal bases.
- Use recordings or screenshots to capture private account pages, health information, financial information, biometric data, intimate content, or communications without all required authorization and consent.
2.6 Surveillance, Doxxing, and Harassment
- Identify, locate, monitor, profile, stalk, harass, intimidate, or track a specific person without a lawful basis and all required consent.
- Compile, sell, publish, or distribute doxxing materials or similar personal-information dossiers.
- Support intimate-partner surveillance, workplace surveillance, political targeting, or similar high-risk monitoring without express written approval from ByteKit.
2.7 Security Testing and Interference
- Perform vulnerability scanning, fuzzing, exploit delivery, denial-of-service testing, load testing, or other security testing against a third-party system without written authorization from the system operator.
- Disrupt, degrade, overload, or interfere with ByteKit, a target site, another customer, or an upstream provider.
- Probe, test, or attack ByteKit systems except through an authorized security-disclosure process.
2.8 Government, Critical Infrastructure, and Restricted Systems
- Target government, military, election, law-enforcement, judicial, healthcare, financial, energy, water, transportation, communications, emergency-services, or other critical-infrastructure systems without express written authorization from the operator.
- Use the Service for intelligence gathering, public-sector surveillance, or law-enforcement purposes unless expressly approved in a written agreement with ByteKit.
2.9 Regulated Uses
Unless ByteKit approves the use case in a separate written agreement, you must not use the Service for:
- credit, employment, housing, insurance, tenant-screening, or other eligibility decisions;
- healthcare or HIPAA-regulated processing;
- GLBA, FERPA, or education-record processing;
- biometric identification, face recognition, or voiceprint identification;
- people-search, background-check, lead-enrichment, data-broker, or regulated profiling products; or
- other regulated decisions or regulated-data use cases requiring terms ByteKit has not accepted in writing.
2.10 Sanctions and Export Controls
- Use the Service in violation of sanctions, export-control, anti-boycott, or restricted-party laws.
- Use the Service while located in, ordinarily resident in, or acting for a person or entity subject to comprehensive sanctions.
- Use the Service for the benefit of a person or entity on an applicable restricted-party list.
2.11 Misuse of ByteKit
- Resell, sublicense, or provide the Service as a primary feature of another product without a written agreement.
- Evade billing, quotas, rate limits, concurrency limits, enforcement systems, or abuse controls.
- Create multiple accounts or identities to avoid restrictions.
- Reverse engineer, extract, or misuse ByteKit systems, models, infrastructure, source code, or non-public interfaces.
3. Request Representations
Each time you submit a request, you represent that:
- you have the legal right and authority to submit the target;
- the request and resulting use of Captured Content comply with applicable law;
- you have obtained required consents, notices, and permissions;
- the request does not access restricted content without authorization;
- the request does not violate third-party terms that bind you; and
- the request is not for a prohibited use listed in this AUP.
4. Product Enforcement
ByteKit may block, reject, throttle, rate-limit, or review requests based on target, hostname, path, port, geography, account history, abuse signals, legal risk, or security risk.
Product-side controls are not a complete list of prohibited uses. A request that is technically accepted by the Service may still violate this AUP.
Rejected requests may be logged as abuse, security, or enforcement signals.
5. Reporting Abuse
If you believe someone is using ByteKit to violate this AUP, contact [email protected] and include:
- the target URL or hostname;
- the approximate date and time of the activity;
- relevant request logs, headers, or identifiers if available;
- a description of why you believe the activity is unauthorized or harmful; and
- your contact information.
ByteKit may investigate, suspend accounts, block targets, preserve records, request more information, or take other action at our discretion.
6. Enforcement
ByteKit may suspend or terminate accounts, revoke API keys, block targets, throttle traffic, remove content, refuse refunds where permitted, preserve evidence, notify affected parties, or cooperate with lawful requests when we believe this AUP has been violated.
These remedies are in addition to any rights or remedies available under the Terms, law, or equity.
7. Updates
ByteKit may update this AUP from time to time. Material adverse changes will be announced through the Service, by email, or by another reasonable method. Emergency changes for legal, security, abuse-prevention, or operational reasons may take effect immediately.