Acceptable use policy
Last updated 13 August 2026
screen2api takes a picture of what somebody has on screen. That is genuinely useful and it is also exactly what surveillance software does, so the line between the two is drawn here rather than left to judgement.
The one rule that matters
Capture must be something the person on screen chose. Our SDK is built around that: a capture starts from a click, the editor shows exactly what will be sent, and nothing is uploaded until it is confirmed. You may configure those defaults, and you may capture on your own users’ behalf. You may not use this product to take a picture of somebody’s screen without them knowing.
Everything below follows from that, and none of it is negotiable by contract, plan tier, or how much you spend.
You must not
- Capture covertly. No silent or automatic capture with the editor disabled and no visible affordance, no capturing a page the person did not act on, no employee or student monitoring, no capture triggered by a timer or on an interval.
- Capture someone else’s site. The SDK runs on pages you control. Embedding it against a third-party property, or in an extension that injects it into sites your users visit, is out of bounds.
- Harvest credentials or payment details. Capturing a login form, a card entry field, an authenticator code or a password manager is prohibited whether or not it is deliberate — use
redactandexcludeso those regions never survive the render. - Build stalkerware. Anything designed to monitor a partner, family member, employee or child without their knowledge and consent.
- Capture children’s screens in a service directed at children under 13, or under 16 where local law sets that bar.
- Break the law with it — infringing copyright, stealing trade secrets, evading export controls or sanctions, or processing personal data you have no lawful basis to process.
- Attack the service. No probing other tenants, no attempting to read another organisation’s captures, no scraping, no deliberately exhausting quotas, no reselling raw API access as your own capture API.
Sensitive data
You may capture health, financial or otherwise sensitive data where you have a lawful basis and the person knows. We are not certified for regimes with their own technical regime — we are not a HIPAA business associate and will not sign a BAA, and we are not PCI DSS certified. Do not put cardholder data or protected health information through this service on the assumption that a certification covers it, because none does.
What we do about it
We do not read your captures. Files sit in a private bucket and nobody here opens them to go looking — which means enforcement is complaint-driven and evidence-driven, not surveillance of our own customers.
When something is reported to us, in rough order of severity:
- We contact you and ask what is going on. Most reports are a misunderstanding or a misconfiguration, and this is where they end.
- We may suspend a project or a key while we work it out. We will tell you why.
- For stalkerware, credential harvesting, or anything involving a child, we suspend first and ask afterwards.
- We terminate for repeated or deliberate breaches, and refund unused prepaid time unless the breach was deliberate.
Reporting a violation
Email abuse@screen2api.com. Tell us the site or the key if you can. If you believe someone is being monitored without consent, say so in the subject line and we will look at it the same day.
Security vulnerabilities go to security@screen2api.com instead — see the security page.
Relationship to the terms
This policy is part of the terms of service. Where the terms give us the right to suspend or terminate for breach, a breach of this policy is one.