Skip to content
CaptchAPI
Legal

Acceptable use policy

Last updated August 5, 2026

This is the most important document on the site, and the shortest rule in it is the one that matters: use CaptchAPI only against systems you own, or that you have written authorisation to test. Everything below explains what that means in practice, and what happens when someone ignores it.

These documents are complete in substance but still reference company details that will only exist once the legal entity is incorporated: the registered name, address, company and VAT numbers, the data protection contact and the governing jurisdiction. Those placeholders are marked in the text. Nothing here has been invented to fill a gap.

1The rule

You may use CaptchAPI to solve a CAPTCHA on a system only if you own that system, or you hold current written authorisation from the person who does, covering the activity you are performing.

This is not boilerplate. A CAPTCHA is a technical measure a site operator has chosen to deploy. Removing it without authorisation may be unlawful in most of the jurisdictions we operate in, and it is against this agreement everywhere.

If you cannot name the person who authorised your testing, you are not authorised.

2What the service is for

These are the uses the service was built for, and the ones we support.

  • Automated testing of your own applications, including end-to-end suites that would otherwise be blocked by your own CAPTCHA.
  • Penetration testing and security research under a signed engagement, within the agreed scope and window.
  • Quality assurance and monitoring of systems you operate, such as checking that a sign-up flow still works from outside your network.
  • Accessibility work: automating a flow for users who cannot complete a visual or audio challenge, on a service you run.
  • Load and resilience testing of your own infrastructure, with our prior agreement where the volume is unusual.
  • Academic and industry research into CAPTCHA effectiveness, on targets you control or with the target operator's consent.

3What is prohibited

The following are prohibited outright. This list is illustrative, not exhaustive — an activity is not permitted merely because it is missing from it.

  • Credential stuffing, password spraying, brute forcing, or any attempt to access an account you do not own.
  • Mass or fraudulent creation of accounts, including for promotional abuse, referral fraud, review manipulation or evading a ban.
  • Automated purchasing that is unlawful where it takes place, including ticket resale in jurisdictions that prohibit automated buying.
  • Sending spam, or any bulk unsolicited messaging, including via forms protected by a CAPTCHA.
  • Scraping in breach of applicable law, a court order, or a contract you are bound by.
  • Circumventing a paywall, licence check, age verification or access control you have no right to pass.
  • Payment fraud, carding, money laundering, or testing stolen payment instruments.
  • Attacks on the availability of a third-party system, including using our capacity as part of a denial-of-service.
  • Targeting government, emergency, healthcare, election or critical infrastructure systems in any way not covered by a written engagement with their operator.
  • Any activity involving child sexual abuse material, human trafficking, or the harassment or stalking of an individual.
  • Use by, or for the benefit of, a person or entity subject to applicable sanctions, or from a sanctioned territory.
  • Reselling or sublicensing access to the API without a written agreement with us.

4Proving authorisation

We may ask you, at any time, to evidence your authorisation for a specific target: a scope document, a signed engagement letter, an ownership record for the domain, or a written permission from the operator.

You must be able to produce it within five working days. Being unable to is treated as a breach of this policy, and the affected keys are suspended until it is resolved.

We do not require this evidence in advance, because most of our customers test their own systems and we are not going to make them file paperwork to do it. We ask when something looks wrong.

5Your proxies, your responsibility

When you supply proxy credentials with a task, we route a real browser through them. You warrant that you have the right to use that egress and that the proxy provider's own terms permit the traffic you are sending.

Traffic sent through a proxy is still your traffic. Using one does not transfer responsibility to us or to the proxy operator, and it does not make an unauthorised target authorised.

6Volume and fairness

The default concurrency limit exists so that one customer's spike does not become another customer's latency. Ask us before a load test and we will raise it for the window; hit the ceiling without warning and it looks like an incident from our side.

Deliberately circumventing rate limits — by spreading traffic over multiple accounts, for example — is a breach of this policy independently of what you were solving.

7Reporting abuse

If you operate a system and believe a CaptchAPI customer is targeting it without authorisation, report it. Send the target domain, the approximate times, and any evidence identifying the traffic. The abuse address is published on the contact page.

We investigate every report a person can act on. We will tell you that we received it and that we acted, but we will not disclose the identity of a customer to you — that is for a lawful request or a court to compel.

Reports from a site operator are the single most useful signal we get, and we treat them accordingly.

8How we enforce this

Enforcement is proportionate to what we find, and it is carried out by a person, not automatically.

A first, apparently inadvertent breach usually gets a warning and a conversation. A serious or repeated breach gets keys disabled and the account suspended. A breach involving fraud, attacks on infrastructure, or material in the last two categories of the prohibited list gets immediate termination.

Where we terminate an account for breaching this policy, unused credit is not refunded. In every other case it is — see the refund policy.

We keep evidence relating to an investigation for as long as the investigation is open, and we cooperate with lawful requests from competent authorities. We will not hand over customer data on an informal request.

9If you are unsure

Ask before you run it. Describe the target and the authorisation you hold and we will tell you plainly whether it is within this policy. A question costs you an email; getting it wrong costs you an account.

We would rather turn away business than have our capacity used against someone who never agreed to it.

10Changes

We update this policy as new patterns of abuse appear. Material changes are notified by email at least thirty days in advance, except where a change is needed immediately to address active harm.