1The rule
You may use CaptchAPI to solve a CAPTCHA on a system only if you own that system, or you hold current written authorisation from the person who does, covering the activity you are performing.
This is not boilerplate. A CAPTCHA is a technical measure a site operator has chosen to deploy. Removing it without authorisation may be unlawful in most of the jurisdictions we operate in, and it is against this agreement everywhere.
If you cannot name the person who authorised your testing, you are not authorised.
2What the service is for
These are the uses the service was built for, and the ones we support.
- Automated testing of your own applications, including end-to-end suites that would otherwise be blocked by your own CAPTCHA.
- Penetration testing and security research under a signed engagement, within the agreed scope and window.
- Quality assurance and monitoring of systems you operate, such as checking that a sign-up flow still works from outside your network.
- Accessibility work: automating a flow for users who cannot complete a visual or audio challenge, on a service you run.
- Load and resilience testing of your own infrastructure, with our prior agreement where the volume is unusual.
- Academic and industry research into CAPTCHA effectiveness, on targets you control or with the target operator's consent.
3What is prohibited
The following are prohibited outright. This list is illustrative, not exhaustive — an activity is not permitted merely because it is missing from it.
- Credential stuffing, password spraying, brute forcing, or any attempt to access an account you do not own.
- Mass or fraudulent creation of accounts, including for promotional abuse, referral fraud, review manipulation or evading a ban.
- Automated purchasing that is unlawful where it takes place, including ticket resale in jurisdictions that prohibit automated buying.
- Sending spam, or any bulk unsolicited messaging, including via forms protected by a CAPTCHA.
- Scraping in breach of applicable law, a court order, or a contract you are bound by.
- Circumventing a paywall, licence check, age verification or access control you have no right to pass.
- Payment fraud, carding, money laundering, or testing stolen payment instruments.
- Attacks on the availability of a third-party system, including using our capacity as part of a denial-of-service.
- Targeting government, emergency, healthcare, election or critical infrastructure systems in any way not covered by a written engagement with their operator.
- Any activity involving child sexual abuse material, human trafficking, or the harassment or stalking of an individual.
- Use by, or for the benefit of, a person or entity subject to applicable sanctions, or from a sanctioned territory.
- Reselling or sublicensing access to the API without a written agreement with us.
5Your proxies, your responsibility
When you supply proxy credentials with a task, we route a real browser through them. You warrant that you have the right to use that egress and that the proxy provider's own terms permit the traffic you are sending.
Traffic sent through a proxy is still your traffic. Using one does not transfer responsibility to us or to the proxy operator, and it does not make an unauthorised target authorised.
6Volume and fairness
The default concurrency limit exists so that one customer's spike does not become another customer's latency. Ask us before a load test and we will raise it for the window; hit the ceiling without warning and it looks like an incident from our side.
Deliberately circumventing rate limits — by spreading traffic over multiple accounts, for example — is a breach of this policy independently of what you were solving.
7Reporting abuse
If you operate a system and believe a CaptchAPI customer is targeting it without authorisation, report it. Send the target domain, the approximate times, and any evidence identifying the traffic. The abuse address is published on the contact page.
We investigate every report a person can act on. We will tell you that we received it and that we acted, but we will not disclose the identity of a customer to you — that is for a lawful request or a court to compel.
Reports from a site operator are the single most useful signal we get, and we treat them accordingly.
8How we enforce this
Enforcement is proportionate to what we find, and it is carried out by a person, not automatically.
A first, apparently inadvertent breach usually gets a warning and a conversation. A serious or repeated breach gets keys disabled and the account suspended. A breach involving fraud, attacks on infrastructure, or material in the last two categories of the prohibited list gets immediate termination.
Where we terminate an account for breaching this policy, unused credit is not refunded. In every other case it is — see the refund policy.
We keep evidence relating to an investigation for as long as the investigation is open, and we cooperate with lawful requests from competent authorities. We will not hand over customer data on an informal request.
9If you are unsure
Ask before you run it. Describe the target and the authorisation you hold and we will tell you plainly whether it is within this policy. A question costs you an email; getting it wrong costs you an account.
We would rather turn away business than have our capacity used against someone who never agreed to it.
10Changes
We update this policy as new patterns of abuse appear. Material changes are notified by email at least thirty days in advance, except where a change is needed immediately to address active harm.