Legal

Acceptable Use Policy

What you may and may not point PageReflect at. The rules about authority over audited sites are the ones that matter most, and breaking them is grounds for immediate termination.

Version
1.0
Effective
August 13, 2026

This Acceptable Use Policy is part of the Terms of Service. Capitalized terms have the meaning given there. It applies to every way you reach the Service, including the web app, the API, the CLI, and the MCP server.

PageReflect sends automated requests to whatever site you tell it to. That is a capability that can be misused, so the boundaries below are strict and we enforce them.

1.Authority over the sites you audit

We do not verify who owns a Target Site. You do. Before you submit a URL, on every occasion, you must have the right to do so.

  • Audit only sites you own, sites you are authorized by the owner or operator to audit, or sites you are otherwise legally permitted to audit.
  • If you are an agency or consultant, get authorization from your client before adding their site, and keep a record of it. A signed statement of work naming the domain is usually enough.
  • Comply with whatever terms of service, acceptable use policy, contractual restriction, or law governs the Target Site. Those obligations are yours, not ours.
  • Do not use the Service to audit a competitor's site, a site you are in a dispute with, or a site whose operator has told you or us to stop.

Page discovery reads your sitemap and sitemaps referenced in robots.txt. It does not apply robots.txt crawl directives such as Disallow or Crawl-delay, and it may retry a request when a site refuses our identified crawler. If you do not have authority over a Target Site, that behavior can put you in breach of that site's terms or of a computer-misuse law. Do not submit sites you do not control.

2.Sites you must not submit

  • Sites requiring authentication that you are not entitled to use, and sites where you would supply credentials you were not issued.
  • Sites behind a paywall, access control, or licensing restriction you would be circumventing.
  • Government, healthcare, financial, or critical infrastructure systems you do not operate.
  • Sites whose operator has issued you or us a cease and desist, blocked our crawler by written request, or otherwise withdrawn permission.
  • Any host on a private, internal, loopback, link-local, or cloud metadata address. The Service blocks these, and attempting to reach them through DNS tricks or redirects is a violation whether or not it succeeds.

3.Volume and interference

We may throttle, queue, or refuse Runs to protect the Service, our providers, or a Target Site, including when we receive a credible complaint from a site operator.

  • Do not schedule audits at a frequency intended to load, degrade, or deny service to a Target Site, and do not distribute audits of the same target across multiple organizations or accounts to increase throughput.
  • Do not use the Service as part of a denial-of-service attack, a stress test of infrastructure you do not own, or any campaign against a specific target.
  • Do not circumvent quotas, rate limits, plan gating, or trial restrictions, including by creating multiple accounts.
  • Do not automate the web interface in place of the API, or scrape the Service itself.

4.Security testing

PageReflect is a measurement tool, not a penetration testing tool. Do not use it to probe for vulnerabilities, enumerate hidden paths, fuzz inputs, or test access controls on any system, including your own. Do not use it to stage, deliver, or relay an attack.

You may test the security of PageReflect itself only under a written agreement with us. Report findings to security@pagereflect.com. We will not pursue good-faith researchers who follow that process, stay within their own account, and do not access other customers' data.

5.Content and conduct

  • Do not upload, store, or transmit malware, or content that is unlawful, infringing, defamatory, or that you have no right to.
  • Do not use the Service to harass, stalk, or build a profile of an individual, including by repeatedly auditing a personal site.
  • Do not misrepresent a Report as an independent certification, an audit opinion, or a compliance determination when delivering it to a client. Reports are automated measurements; the Terms say so and so should you.
  • Do not remove or alter attribution in a Report except through branding features included in your plan.

6.Lead capture obligations

If you enable lead capture on a shared report, you are the controller of the personal data visitors submit and we are your processor under the Data Processing Addendum. That makes the following your responsibility, not ours.

  • Provide your own privacy notice at the point of collection, identifying you as the controller and explaining what you will do with the data.
  • Obtain any consent required in the visitor's jurisdiction before collecting, and before sending marketing to the address collected.
  • Only request fields you actually need. Do not configure fields that solicit special category data, government identifiers, payment card numbers, or health information.
  • Handle access, correction, and deletion requests from those visitors. Route them to us only where we hold data you cannot reach.
  • Ensure any webhook or Slack destination you configure is one you control and is appropriate for personal data.

7.Enforcement

We may investigate suspected violations and may suspend or terminate access, cancel Runs, block a Target Site, or refuse service, with or without notice depending on severity. A violation of the authority requirements in Section 1 is grounds for immediate termination without refund.

Where a site operator complains, we may disclose the organization responsible for the Runs and the timestamps involved. We may also preserve and disclose records where required by law or where necessary to protect any person's rights.

Suspension for a violation does not relieve you of fees already owed, and does not limit our other remedies, including the indemnity in the Terms.

8.Reporting abuse

If you operate a site and believe PageReflect traffic is unwanted or abusive, email abuse@pagereflect.com with the domain and approximate timestamps. We will identify the responsible organization, stop the traffic, and block future Runs against your domain on request. Our crawler identifies itself as PageReflectBot.

Report suspected security issues to security@pagereflect.com. Report other violations of this policy to support@pagereflect.com.

9.Changes

We may update this policy as the product and the threat landscape change. Material changes are announced as described in the Terms. The version and effective date at the top identify the current text.

Acceptable Use Policy, PageReflect