Skip to content
getsolvr

Legal

Acceptable use policy

This is the shortest of our three policies and the one most likely to affect you. It sets out what the API may be used for, and what will get an account closed.

Last updated 9 September 2026

The one rule

GetSolvr answers anti-bot challenges. That is a capability with legitimate uses and obvious dishonest ones, so we would rather be direct about the line than bury it.

You may only send us targets you are authorised to access in the way you are accessing them. Authorisation means you own the system, you have written permission from whoever does, or the access is clearly permitted by that system's own terms. If you are not sure which of those applies to you, assume none of them do.

We are not the authority on any other company's terms of service. Their rules govern what you may do with their platform, and nothing we sell you overrides that. Being able to reach a system is not the same as being allowed to.

What the service is for

These are the uses we built it for and are happy to support:

  • Security testing and research against systems you own, or that you have been engaged to assess.
  • Monitoring your own properties, including checking that your own protection is configured the way you think it is.
  • Quality assurance and automated testing of your own applications and their integrations.
  • Accessibility and availability work, where a challenge is preventing legitimate automated access to a service you are entitled to use.
  • Data collection that the target's own terms permit, or that you have written permission to carry out.

What is not allowed

The following will end your account. This list is not exhaustive, and we will not argue that something harmful was technically absent from it.

Against people

  • Credential stuffing, password spraying, or any form of account takeover. Testing stolen or leaked credentials against a login is the single clearest misuse of this product and the one we look for hardest.
  • Creating accounts in bulk on services that do not permit it, including for spam, fraud, or resale.
  • Harassment, stalking, or building profiles of individuals without their knowledge.
  • Collecting personal data you have no lawful basis to hold.

Fraud and financial harm

  • Payment fraud, carding, or testing stolen card numbers.
  • Buying inventory in a way the seller prohibits, including tickets, limited releases, and appointment slots, where doing so denies it to ordinary buyers.
  • Manipulating a market, an auction, a vote, or a ranking.
  • Evading a ban, a suspension, or a rate limit that was applied to you deliberately.

Against systems

  • Denial of service, resource exhaustion, or any traffic pattern intended to degrade a target rather than to read from it.
  • Accessing systems you have no authorisation for, whatever the technical means.
  • Distributing malware, phishing pages, or content designed to deceive.
  • Anything unlawful in your jurisdiction or the target's.

Against us

  • Reselling access, sharing API keys outside your organisation, or reselling solves as your own service without a written agreement.
  • Reverse engineering the service to reproduce it, or using it to build a directly competing product.
  • Deliberately misrepresenting what you are solving in order to get around this policy.

Proxies and infrastructure

Every solve runs through a proxy you supply. That is a technical requirement, because tokens are bound to the address that earned them, but it also means the egress is yours and so is the responsibility for it.

You are responsible for having the right to use the proxies you send us. If you are using a residential proxy network, you are responsible for it having obtained genuine consent from the people whose connections it resells. We do not audit that, and we cannot, but a proxy network built on compromised devices does not become acceptable because it reached us through your account.

How we enforce this

We keep a record of every solve for a limited period, including the target and the outcome. We use it for billing, support, and abuse investigation, and for nothing else. The privacy policy sets out exactly what is kept and for how long.

We do not pre-screen targets. We are not in a position to judge, request by request, whether you have permission for the thing you are asking us to solve, and pretending otherwise would be dishonest. What we do instead is act on what we can see and on what is reported to us.

Where we find a breach, our response is proportionate to it:

  • A warning, where the use looks like a misunderstanding rather than an intent, and stopping is straightforward.
  • Suspension of a key or an account while we look into something. Your balance is untouched during a suspension.
  • Termination for serious or repeated breaches. We refund the unused balance on a terminated account unless the account was used for fraud, in which case we will hold the funds while we work out who they belong to.

Where the law requires it, or where there is a credible risk of serious harm to a person, we will cooperate with law enforcement and we will not always be able to tell you first.

Reporting abuse

If you believe an account is using GetSolvr against your systems, contact us at [email protected] with the target, the approximate times, and anything from your logs that would help us identify the traffic. We will investigate and we will tell you the outcome.

We take these seriously. A service like this depends on not being the easiest tool for the worst use, and reports from the systems on the other end are the most useful signal we get.