Acceptable use policy
ScreenshotBolt opens user-supplied URLs in a browser worker. These rules protect users, target websites, and the infrastructure that runs the capture service.
Last updated: September 28, 2026Allowed use
You may use ScreenshotBolt for legitimate previews, design review, documentation, responsive checks, accessibility review, client work, and other lawful tasks involving public pages you are authorized to access.
Prohibited requests
You must not use ScreenshotBolt to:
- Reach localhost, private IP ranges, cloud metadata services, an internal network, or another non-public target.
- Submit passwords, cookies, access tokens, API keys, or credentials in a URL or page intended for capture.
- Probe, scan, attack, overload, scrape aggressively, or interfere with a target website or network.
- Bypass a paywall, login, CAPTCHA, bot protection, geo-block, or other access control without permission.
- Capture or distribute content that violates privacy, copyright, trademark, publicity, confidentiality, or other rights.
- Create deceptive evidence, impersonation material, harassment, fraud, phishing pages, or other harmful content.
- Send requests designed to exhaust browser, queue, storage, bandwidth, or rate-limit resources.
- Use automated high-volume traffic against the public form instead of an authorized API plan.
Safety controls
The service may validate DNS answers, block private network addresses, restrict protocols, reject selected hostnames, limit request rates, cap queue size, bound screenshot dimensions, and stop slow or oversized captures. A blocked request does not mean the target page is unsafe; it means the public renderer cannot safely process it under its current rules.
Enforcement
The operator may reject a request, remove a result, limit an IP address or API key, suspend access, preserve relevant logs, or contact a hosting provider when necessary to protect the service or comply with law.
Reporting an issue
The production deployment should publish a security and abuse contact. Include the task ID, target hostname, approximate time, and a concise description. Do not send passwords, tokens, or private system details in a report.