Legal
Acceptable Use
The scanner fetches other people’s websites on request, which makes it worth being precise about. This policy is part of the Terms of Service.
Draft last edited 2026-08-05. Not a review date.
Draft — not reviewed by counsel
This document is a working draft written by the Rebilder team for the owner and their lawyer to review. It has not been reviewed or approved by counsel, it is not yet a binding agreement, and passages marked TODO_OWNER are facts the owner still has to supply. Do not rely on it as legal terms until this banner is gone.
What Rebilder is for
- Installing the gateway on sites you own or are authorised to operate.
- Scanning public URLs — yours, a competitor’s, a customer’s, a page you are curious about — and reading the result yourself.
- Running the CLI and the MCP server on your own machine, in your own CI, against your own site.
- Publishing a badge for a domain you control and have verified.
- Building on the published ARS specification, including your own implementation of it.
Using the scanner
- Do not use the scanner to generate load against a site — scripted bulk scans of one target, distributed scans of the same host, or anything whose purpose is traffic rather than a result.
- Do not scan URLs behind a login, a paywall, or an authorisation you do not hold.
- Do not try to make the scanner fetch a private, internal, loopback or cloud-metadata address. It refuses, on every redirect hop, and attempting it is abuse regardless of whether it works.
- Do not evade the rate limits — rotating addresses, farming the bot challenge, or automating around the queue.
- Do not use our fetcher as a proxy or anonymiser for requests you would rather not make yourself.
Using a score
- Do not present a score as a certification, an audit, an endorsement, or a security or accuracy assessment. It measures format and retrievability, not whether the facts on a page are true.
- Do not publish a badge or claim a grade for a domain you do not control.
- Do not present a score as ours if you have altered it, and do not strip the measured-versus-heuristic labelling from a number you republish.
- Do not use a score about a third party as the opening of an unsolicited sales approach. We do not do that, and we will not have our number used to do it.
- Do not use the index, the badge or the score to harass, shame or extort a site operator.
General prohibitions
- Anything illegal, and anything designed to help someone else do something illegal.
- Attacking the service: probing, brute-forcing, exploiting, or reverse-engineering to defeat a security control. Reporting a vulnerability to security@rebilder.com in good faith is not this.
- Impersonating another person, another business, or another crawler operator.
- Sharing your account or API key with people outside your organisation, or reselling access to hosted analysis without a written agreement with us.
- Wiring the gateway to serve substantive values that did not come from your systems — invented prices, invented hours, invented eligibility rules. The validator discards them; doing it deliberately is a breach of this policy.
- Serving agents different substance from what you serve people, or feeding search crawlers something other than your canonical HTML, through anything we make.
- Feeding gateway events into a product that profiles individual visitors. The event schema has no field for a person, and adding one on your side is not a licence to do it on ours.
What we will not do
A company that grades other people’s websites has an obvious temptation, so our side of the rules is published on the same page as yours.
- We never publish anything about a named third party on a Rebilder ranking, index or badge without a verified opt-in from the domain owner.
- We never publish anything derived from an authenticated, merchant-supplied or locally-run scan.
- We never make outbound sales contact on the basis of a score.
- Removal from anything we published is free, self-serve and permanent, and it is never purchasable — there is no tier, upsell or negotiation that touches it.
- We never publish an aggregate over fewer than 25 independent sites, and that floor is not a setting we adjust to make a chart work.
- We never let your per-site data feed a negotiation engine, and we never build a cross-site price or discount-depth data product.
- We never degrade, sample, throttle or meter what an agent receives from your site, on any plan.
How we enforce this
- Most breaches get a rate limit or a bot challenge first — the ladder exists so a mistake costs you a delay rather than an account.
- We suspend an account that is attacking a third party immediately, and explain afterwards.
- For everything else we contact you, and close the account only if it continues.
- Repeated copyright infringement is handled under /legal/dmca.
- We do not owe a refund for a period you spent breaching this policy.
Reporting misuse
- Someone misusing Rebilder, or using our scanner against you: abuse@rebilder.com. Include the URL, the timestamps, and the log lines if you have them — our fetcher identifies itself honestly, so it is easy to confirm whether a request was ours.
- A vulnerability: security@rebilder.com.
- Something about your own site published where it should not be: privacy@rebilder.com. That route is free and we act on it before we verify, not after.
Other policies: Terms of Service · Privacy Policy · Sub-processors · Acceptable Use · Copyright and DMCA · Our scanner and crawler