Skip to content
flatbrowser

contractual · part of the Terms

Acceptable Use Policy

A general-purpose browser is a dual-use tool. This is the short list of uses we refuse, and the commitments we make in return.

draft 2026-10-04 · unreviewed

1. Scope

This policy is part of the Terms of Service and applies to every session started with your API keys, whether by you, your staff, your customers or your automation. Enforcement, and the automated part of detection, is described in Terms §6.

2. Prohibited uses

You may not use the Service for, or in connection with:

  1. Credential stuffing, account takeover, or any attempt to authenticate with credentials you are not authorised to use.
  2. Circumventing authentication, paywalls or technical access controls.
  3. Accessing sites that technically oppose automated access for your use — a robots.txt disallow that applies to it, an ai.txt opt-out, or a CAPTCHA — and passing authentication walls or other access controls you are not authorised to pass. If a site says no by technical means, the answer is no here too. Logging in to your own applications, or to accounts you are authorised to use for automation, is not affected.
  4. Government websites, and sites primarily used by minors.
  5. Child sexual abuse material, and any other content or activity unlawful under EU or Member State law.
  6. Spam, phishing or pretexting.
  7. Load generation, denial-of-service or stress testing against systems you do not own.
  8. Port scanning or network reconnaissance of third-party systems (also prohibited by our upstream provider, and our own liability under their terms).
  9. Cryptocurrency mining (also prohibited by our upstream provider).
  10. Use by, or on behalf of, sanctioned parties (OFAC SDN list, EU consolidated list).
  11. Reselling raw browser capacity as a competing service.

Item 3 is not us being precious. Under the EDPB’s 2026 scraping guidelines, collecting from a site that technically opposes automated access undermines your own legitimate-interest balancing test — so that use would put your compliance at risk as much as ours. Running logged-in end-to-end tests against your own product, or automating an account you are authorised to automate, is ordinary use.

3. What you warrant

  • You are the data controller for any personal data you collect through the Service.
  • You have a legal basis for that collection and can evidence it.
  • You comply with the terms and technical signals of the sites you visit.
  • You keep your API keys confidential and revoke leaked keys promptly.

4. What we commit to in return

These are product commitments, not marketing. They are what keeps us a processor rather than a joint controller of your collection, and they are load-bearing for both sides:

  • We never define what you collect: no target lists, no pre-built site-specific scrapers, no “we will write the selector for you”.
  • We never operate accounts on third-party sites, and we never hold third-party credentials on your behalf.
  • We never store or resell data your sessions retrieve.
  • We log metadata, never page content or response bodies.
  • We do not sell anonymity from law enforcement: we keep metadata logs, publish an abuse contact, and cooperate with lawful requests.

5. What we reserve

  • Recording connection metadata as described in Terms §6 and the privacy policy.
  • Refusing REST calls to hostnames on our blocklist and making those hostnames unresolvable inside browser sessions (also behind your own proxy), refusing private-network targets, rate-limiting traffic volume after notice, and suspending or terminating accounts under Terms §§6 and 12 — with a statement of reasons under Terms §7.
  • Cooperating with lawful requests from authorities, and informing law enforcement where we become aware of a suspected criminal offence involving a threat to life or safety.

6. Egress, your own proxies and future features

Sessions reach the internet from the datacenter IP addresses of our hosts, or through an upstream proxy you configure. A proxy you bring is your provider and your responsibility: this policy applies to proxied traffic exactly as to direct traffic, and our blocklist applies to it too. We sell no proxy traffic and run no residential or datacenter proxy pool.

Managed residential egress, if and when we offer it, will not be self-serve: it will require a registered company, a verified corporate email domain, a written use case, a funded account and a human compliance review before activation, with traffic bound to an agreed target allowlist. That split is deliberate and permanent.

7. Reporting a violation

If someone is misusing our infrastructure, tell us through the abuse report form or at [PLACEHOLDER: abuse email — DSA Art. 16 notices]. Reports are read by a human, and we confirm receipt.