Legibl

Acceptable use policy

This page is served to anyone, without an account, and is linked from the footer of every page on this site. It sets out what Legibl may be pointed at, what it may not, and what happens when we find out it has been.

Last updated 6 August 2026. Applies to every account and every API key.

The rule

You may use Legibl against systems you own, or systems whose operator has authorised you to access them in the manner you are accessing them. Everything below follows from that sentence. It is about authorisation, not about which industry you are in: the same request can be legitimate from the system's own operator and an intrusion from anyone else.

Permitted

  • Automated testing and monitoring of systems you operate, including your own captcha-protected forms.
  • Accessing a third party's system with that party's documented permission — a contract, a written authorisation, or a scope you were engaged under.
  • Accessibility tooling that acts for a person who is entitled to the access and cannot complete a visual challenge.
  • Retrieving data you are entitled to retrieve, where the operator permits automated access and you stay within any rate the operator sets.

Prohibited

Using Legibl for any of the following ends an account, immediately and without refund of unused credit.

  • Access without authorisation. Defeating a captcha in order to reach a system you have no permission to reach. This is the one that matters, and it is not cured by the data being public.
  • Credential stuffing, password spraying, or account takeover of any kind, against anyone.
  • Mass account creation — registering accounts in bulk on a service that requires a human to register, whether for spam, for resale, or to farm promotional credit.
  • Payment fraud. Card testing, carding, gift-card enumeration, or any use adjacent to stolen payment instruments.
  • Spam. Submitting to contact forms, comment forms, review systems or sign-up flows you have no relationship with.
  • Ticket and inventory scalping where the operator's terms prohibit automated purchase.
  • Interfering with a system's availability — request volumes that degrade the target, whether or not that was the intent.
  • Circumventing a technical access control other than the captcha itself in order to use our solution, including authentication, IP blocks or licence enforcement.
  • Anything unlawful in your jurisdiction or the target's, and anything that would make us party to it.

You are responsible for your targets

We do not verify that you have authorisation, and nothing about being able to submit a task implies we believe you do. The obligation is yours, and it applies to every key issued under your account including keys held by your own customers if you resell.

Reporting misuse

If you believe Legibl is being used against a system you operate, tell us. The reporting form requires no account and no payment relationship with us, or write to abuse@legibl.com. Reports are acknowledged within one business day.

Useful reports name the target — a domain, a URL, a form — and describe what you observed. We can act on a target without knowing which customer it was, because we attribute traffic per target domain.

Enforcement

  • We can block a target. Traffic is attributed per target domain, so a domain can be refused for every account at once, which is the fastest remedy available to us and does not depend on identifying who was responsible.
  • We can suspend a key or an account while we look into a report.
  • We terminate for the prohibited uses above. Unused credit on a terminated account is not refunded where the termination is for a prohibited use.
  • We respond to lawful requests from law enforcement and from operators pursuing a legal remedy, and we retain enough per-target attribution to answer them.

Changes

We will update this page as the service changes. Material changes are notified to the address on the account before they take effect. The date at the top is the version in force.