Acceptable Use Policy

Where the boundaries are for crawling, outreach and AI output — and how we enforce them if you cross one.

Last updated: 5 September 2026

Keupera crawls websites, generates content that gets published under your name, and sends email to people we have never met. This policy sets out what you may and may not do with those capabilities. It forms part of the Terms of Service.

Contents

§1 Scope

1.1 This Acceptable Use Policy forms part of the Terms of Service at /legal/terms and applies to every user of the Services, including every Member of your Organisation and anyone acting through your API keys.

1.2 It exists for three reasons: the Services retrieve data from websites we do not control, generate content that is published under your name, and send email to recipients we have never met. Each of those creates a risk to someone other than you, and this policy sets out where the boundaries are.

1.3 Breach of this policy is a material breach of the Terms of Service. Our enforcement approach is set out in § 8.

1.4 Where a rule below is stricter than the law, treat the rule as the standard we hold you to contractually. Where the law is stricter, the law governs.

§2 General Prohibitions

You must not, and must not permit anyone else to:

  • use the Services for any unlawful purpose, or to store, generate, transmit or publish unlawful content
  • infringe the intellectual property, personality, privacy or contractual rights of any person
  • upload, transmit or generate malware, or any code intended to disrupt, damage or gain unauthorised access to a system
  • probe, scan or test the security or configuration of any system you do not own, without written authorisation from its operator
  • impersonate any person or organisation, or misrepresent your affiliation with one
  • harass, threaten, defame or incite violence against any person
  • generate or distribute material sexualising minors, or any other material whose creation or possession is unlawful
  • circumvent or attempt to circumvent authentication, quotas, rate limits or plan restrictions, including by creating multiple accounts to obtain repeated free allowances
  • reverse engineer, decompile or disassemble the Services, except to the extent this cannot lawfully be restricted
  • use the Services to build, train or benchmark a competing product, or publish a benchmark of the Services without our prior written consent
  • resell, sublicense or make the Services available to third parties as a standalone offering, except through agency use as the Terms of Service permit
  • impose a load disproportionate to normal use of your plan, or that degrades the Services for other customers

§3 Crawling and Analysis

The Services retrieve pages from websites at your instruction. The operator of each of those websites has rights, and you are the one instructing us.

3.1 Authority. Submit a website for a full audit only where you own it or are authorised by its operator. For competitor and prospect research, confine yourself to publicly accessible pages.

3.2 Volume and frequency. Do not configure repeated or high-frequency retrieval that could burden a third party's infrastructure. Our crawler rate-limits itself; do not attempt to defeat that by fragmenting jobs across projects or accounts.

3.3 Access controls. Do not use the Services to retrieve content behind a login, a paywall or any other access control, or to circumvent a technical protection measure. Do not submit credentials that are not yours.

3.4 Robots directives. Do not use the Services in a way designed to evade a robots.txt directive, a crawl-delay instruction, or an explicit request from a site operator that you stop.

3.5 Prohibitions. Never use the Services to crawl a site in order to harm, overload or disrupt it; to reproduce it substantially; or in breach of a court order, an injunction, a contract or a statutory prohibition binding on you.

3.6 Embedded widgets. If you embed our audit widget, visitors to your site can submit arbitrary addresses. You accept responsibility for that use. Monitor it, and tell us if it is being abused.

3.7 Stop requests. If a site operator asks you or us to stop crawling their site, we will honour that request and expect you to do the same. Tell us at legal@keupera.com if you receive one.

§4 Contact Data and Outreach Research

4.1 What the research does. Backlink and outreach research extracts contact names and email addresses published on public web pages. That is personal data, and the people concerned did not give it to you.

4.2 Your role. You are the controller of how that data is used. You must have a lawful basis under Art. 6 GDPR — in practice, legitimate interest, supported by a documented balancing test — and you must be able to demonstrate it.

4.3 Transparency. You must give the information required by Art. 14 GDPR, in practice at the point of first contact at the latest.

4.4 Objections. If a contact objects, or asks to be erased, you must comply promptly and must not contact them again. Tell us and we will remove them from your workspace.

4.5 No enrichment from unlawful sources. Do not combine our research output with data from purchased lists, scraped social profiles, or brokers whose sourcing you cannot account for.

4.6 No special categories. Do not use the Services to assemble data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sex life or sexual orientation, or data relating to criminal convictions.

§5 Email

Outreach and audit-result emails leave through your own mail server, under your own sending identity. You are the sender in law, and the obligations below are yours.

5.1 Consent in Germany and the EU. Under § 7(2) no. 2 UWG, advertising email requires the recipient's prior express consent — and this applies to business recipients, not only consumers. The existing-customer exception in § 7(3) UWG is narrow and will rarely cover cold outreach. A publicly listed business address is not consent. If you send to German recipients without consent, you are exposed to cease-and-desist claims, and so, by association, are we.

5.2 The United States. Under the CAN-SPAM Act you must use accurate header and sender information, use a non-deceptive subject line, identify the message as an advertisement where required, include a valid physical postal address, provide a clear opt-out mechanism, and honour opt-outs within ten business days. Penalties run per message.

5.3 Everywhere. Use accurate sender identification. Do not forge headers or use a misleading reply-to. Include a working, prominent means of opting out in every commercial message. Honour opt-outs permanently, across every campaign.

5.4 Lists. Do not send to addresses obtained from a purchased list, from indiscriminate harvesting, from a scraped directory you have no basis to use, or from any source you cannot account for.

5.5 Volume and reputation. Send at a rate your own mail server and domain reputation can sustain. Do not use the Services to send bulk unsolicited mail.

5.6 Records. Keep records sufficient to demonstrate your lawful basis, your opt-out handling, and the content of what you sent.

5.7 Our right to intervene. We may impose volume limits, throttle sending or suspend the feature where we have reasonable grounds to believe it is being misused. We will normally warn you first, but we will act without warning where recipients are being harmed.

§6 AI Features and Generated Content

6.1 Review before publishing. AI output can be inaccurate, defamatory or infringing while appearing entirely plausible. Review it. Where you enable automatic publishing, you accept that unreviewed output will reach a live website under your name, and you accept responsibility for it.

6.2 Do not generate: unlawful content; defamatory statements about identifiable people or businesses; material designed to deceive as to its origin or authorship in a way that causes harm; content impersonating a person or organisation; synthetic media presented as a genuine recording of a real person; or content about an identified individual that you have no lawful basis to produce.

6.3 Do not misrepresent. Do not present machine-generated material as human-authored where a law, a platform rule or a professional obligation requires disclosure. Requirements differ by jurisdiction and by platform; it is your responsibility to know which apply to you.

6.4 Do not use the Services to manipulate. No mass generation of near-duplicate pages built solely to manipulate rankings or AI answers; no coordinated inauthentic content; no fabricated reviews, testimonials, citations, statistics or sources.

6.5 Third-party terms. Our AI providers impose their own usage rules. Use that would breach those rules also breaches this policy.

6.6 No safety circumvention. Do not use prompts designed to defeat the safety measures of an underlying model, and do not use the Services as a route to obtain output the provider would refuse directly.

§7 API, Automation and Integrations

7.1 Keys. Keep API keys confidential. Do not embed them in client-side code, mobile applications, public repositories or anything a third party can read. Rotate a key immediately if it may have been exposed.

7.2 No sharing. Do not share keys outside your Organisation, and do not use one Organisation's key to serve another party's workloads.

7.3 Limits. Do not evade quotas by rotating keys, creating additional accounts or distributing requests across identities. Do not retry failed requests in a tight loop.

7.4 Webhook addresses. An inbound workflow webhook address is a capability: anyone holding it can trigger your workflow. Do not publish it. Regenerate it if it may have been exposed.

7.5 Third-party applications. Our authorisation server supports dynamic client registration, so applications we have not reviewed can request access to your account and are shown to you as unverified. Grant access only to applications you trust, and review your connected applications periodically.

7.6 Automated resale. Do not use the API or MCP server to provide a substantially equivalent service to third parties, or to build a product whose primary value is our output.

7.7 Plugins. Keep the WordPress and Framer plugins updated. Do not modify them in a way that removes attribution, security checks or rate limiting.

§8 Sharing, Embeds and Lead Capture

8.1 Share links are public. Anyone with the link can open a shared report without signing in. Do not share a report about a website that is not yours, or that contains anything you would not publish.

8.2 Embeds. A widget you embed runs on your site, under your privacy notice, and is your responsibility — including its accessibility and the notices shown around it.

8.3 Lead capture. Where a widget collects an email address, you are the controller. Display your own privacy notice at the point of capture, have a lawful basis for the collection and for any follow-up, and do not treat the submission timestamp we record as evidence of consent.

8.4 Branding. Unless you hold the add-on that permits removal, keep Keupera branding visible and unaltered in embedded widgets and shared reports.

§9 Enforcement

9.1 Proportionality first. Where we identify a breach we take the least intrusive step that resolves it, escalating only as necessary: notice to you; throttling; suspension of the affected feature; suspension of the Account; termination.

9.2 Immediate action. We may go straight to suspension or termination where the conduct is unlawful, endangers the security or availability of the Services, causes ongoing harm to third parties, or repeats a breach we have already raised with you.

9.3 You will always be told why. Every enforcement step is accompanied by a statement of reasons under Art. 17 of the Digital Services Act, setting out what we did, the facts we relied on, the ground we relied on, its scope and duration, and how to contest it. See /legal/notices.

9.4 Contesting a decision. Write to legal@keupera.com within six months. A human reviews the decision. If we were wrong, we reverse it without undue delay. Your right to go to court, or to an out-of-court dispute settlement body certified under Art. 21 DSA, is unaffected.

9.5 No refund for termination for cause. Where we terminate for a material breach of this policy, fees already paid are not refunded. Where we suspend and the suspension proves unjustified, we credit the affected period.

9.6 Cooperation. Where a third party asserts that your use of the Services has harmed them, we may pass on your contact details where we are legally required to do so, and we will tell you when we do unless the law prevents it.

§10 Reporting Abuse

10.1 How to report. If you believe the Services are being used in breach of this policy, write to legal@keupera.com. Include the specific address or account concerned, what you believe is happening, and how we can reach you.

10.2 Illegal content. To report content you consider illegal, use the notice and action procedure at /legal/notices, which sets out what a notice must contain and what we do with it.

10.3 Security. To report a vulnerability, write to security@keupera.com. We will acknowledge your report, keep you informed, and will not pursue researchers who act in good faith and give us a reasonable opportunity to respond before disclosure.

10.4 Unwanted email. If you received an unwanted message sent through the Services, tell us at legal@keupera.com. We will identify the customer responsible, require them to stop, and act under § 9 if they do not.

10.5 Unwanted crawling. If our crawler is retrieving your site and you want it to stop, write to legal@keupera.com with the domain. We will block it. You can also disallow KeuperaSEOBot and KeuperaUXBot in your robots.txt.

10.6 Changes. We may update this policy in line with § 26 of the Terms of Service. The version in force is always the one published here.