Acceptable Use Policy

Effective date: 2026-08-05 Last updated: 2026-08-05

Draft — pending counsel review. This document is a working draft prepared for public Beta. It will be replaced by a counsel-reviewed final Acceptable Use Policy before general availability. It is not legal advice. Nothing in this Beta draft creates additional obligations beyond those already imposed by applicable law.

This Acceptable Use Policy (the "AUP") governs how you may use the AllAPI platform — the HTTP API at api.allapi.io, the developer dashboard at app.allapi.io, the documentation at docs.allapi.io, the Model Context Protocol (MCP) tools, and any related subdomain (collectively, the "Service") operated by Legal Eye Yazılım A.Ş., trading as "AllAPI" ("we", "us", "our").

This AUP is incorporated by reference into, and forms part of, the Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service. A breach of this AUP is a breach of the Terms of Service. It applies to all users, all tiers (free, mini, standard, pro, business, enterprise, and max), all API keys, and all MCP tools, and to every request you make through the Service.

We take firm action against illegal, abusive, or non-compliant use. Where use of the Service is unlawful, we will preserve relevant evidence and cooperate with law enforcement and competent authorities as required or permitted by law.


1. General principle

1.1 The Service is provided for legitimate, lawful purposes only. You may not use the Service for any purpose that is unlawful, fraudulent, deceptive, harmful, or abusive, or that is prohibited by this AUP.

1.2 You are responsible for all activity conducted under your account or with your API keys, whether or not you authorized it, and whether the activity is your own or that of any end user, customer, employee, contractor, or agent to whom you provide access.

1.3 If you are uncertain whether an intended use is permitted, contact us at [email protected] before you build on it. Absence of a specific prohibition in this AUP does not imply permission where the use is otherwise unlawful.


2. The public-data boundary (core clause)

The Service retrieves only publicly available data through anonymous, unauthenticated requests (Terms of Service §2.2). The following restate that boundary as affirmative obligations you accept.

2.1 You must not use the Service to obtain, or attempt to obtain, any data that sits behind a login, authentication step, paywall, subscription, membership, or any other access control, and you must not use the Service to circumvent, disable, defeat, or bypass any such control.

2.2 You must not use the Service to collect, or attempt to collect, non-public, restricted, private, or internal information of any Upstream Source or third party. The Service returns only data that any member of the public can reach without an account; you must not use it to reach data that the public cannot.

2.3 You must not use the Service to authenticate to, log into, act on behalf of an account on, or otherwise transact under any credential of an Upstream Source, and you must not supply the Service with any third party's account credentials, session tokens, or cookies.

2.4 You must not use the Service to bypass or defeat authentication, digital rights management (DRM), paywalls, rate controls, or captchas, or to interfere with any technical protection measure of an Upstream Source or third party.


3. Prohibited uses — attacks and platform integrity

You must not use the Service to:

3.1 Conduct or facilitate any denial-of-service (DoS) or distributed-denial-of-service (DDoS) attack, or otherwise flood, overload, or degrade any system, network, service, or user.

3.2 Perform credential stuffing, password spraying, brute-force, or enumeration attacks against any account, system, or Upstream Source.

3.3 Probe, scan, penetration-test, or map the vulnerabilities of any network or system without express authorization from its owner.

3.4 Introduce, distribute, or facilitate malware, ransomware, spyware, worms, viruses, exploit code, or any malicious payload.

3.5 Interfere with, disrupt, or attempt to gain unauthorized access to the Service, its infrastructure, other users' accounts, or any Upstream Source or third-party system, network, data, or user.


4. Prohibited uses — data protection and privacy (KVKK / GDPR)

This Section governs personal data of natural persons that may appear inside Service responses. You must not use the Service to:

4.1 Re-identify any individual, or combine, cross-reference, or enrich returned data to build, augment, or infer profiles of natural persons.

4.2 Harvest personal data at scale without a valid lawful basis under applicable data-protection law.

4.3 Build, operate, or support surveillance, stalking, harassment, doxxing, or intimidation tooling, or any tool whose purpose or foreseeable use is to track, target, or endanger an individual.

4.4 Process special-category or sensitive personal data (as defined in KVKK Art. 6 / GDPR Art. 9 — including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health, sex life, or sexual orientation) without a valid lawful basis and all safeguards the law requires.

4.5 You are solely responsible for determining the lawful ground for, providing any required notices in respect of, and honoring the data-subject rights attaching to, any personal data you obtain through the Service. We are not the source of that data and do not warrant a lawful basis for your downstream processing. This restates and does not limit Terms of Service §6.3 and this AUP §9.

4.6 Make solely automated decisions producing legal or similarly significant effects on individuals (KVKK Art. 11 / GDPR Art. 22) without the safeguards required by law, including meaningful human review.


5. Prohibited uses — content and intellectual property

You must not use the Service to:

5.1 Infringe any third party's **copyright, sui generis database right, trademark, publicity or likeness right, moral right, or trade-secret right. In particular, reselling, republishing, or redistributing the copyrighted expression of an Upstream Source (for example the full text of articles, reviews, lyrics, chart compilations, or aggregated editorial scores) carries materially greater exposure than exposing bare facts, metadata, headlines, short snippets, or links back to the source**. The "publicly available" nature of data does not by itself grant you any copyright licence in it.

5.2 Fail to honor the attribution and share-alike conditions of open-licensed Upstream Sources (for example CC-BY, CC-BY-SA, ODbL). Where a source's licence requires attribution or share-alike, you must preserve that attribution and comply with those licence terms in your own use and any redistribution.

5.3 Generate, store, or distribute child sexual abuse material (CSAM), content that sexually exploits or endangers minors, or any content that is illegal to possess or transmit under applicable law.

5.4 Remove, obscure, alter, or falsify any attribution, X-Request-Id, source indication, notice, watermark, or metadata returned by the Service, or misrepresent the origin or provenance of any data.


6. Prohibited uses — fraud, abuse, and commercial integrity

You must not use the Service to:

6.1 Send or facilitate spam, bulk unsolicited messaging, or mass-messaging in violation of anti-spam or electronic-communications law.

6.2 Commit or facilitate advertising fraud, click fraud, impression fraud, or affiliate fraud.

6.3 Manipulate search rankings, app-store rankings, trending signals, votes, polls, or recommendation systems, or generate fake clicks, impressions, or traffic.

6.4 Impersonate or spoof any person, entity, brand, or domain, or misrepresent your affiliation with any person or entity, for fraudulent or deceptive purposes.

6.5 Create or operate fake accounts, fake engagement, fake reviews, fake followers, or other inauthentic activity, or manipulate engagement or reputation metrics on any platform.

6.6 Conduct automated ticket purchasing (scalping), inventory hoarding, or other automated acquisition that violates a seller's terms or applicable law.

6.7 Operate or support illegal gambling or any activity requiring a licence you do not hold.

6.8 Resell, sublicense, white-label, rebrand, or wrap the Service or its output as if it were your own; build a competing gateway or substantially similar aggregation service using the Service; or resell proxy, egress, or streaming access obtained through the Service.

6.9 Circumvent tier limits — including by operating multiple accounts, rotating API keys, rotating proxies or IP addresses, or coordinating across tenants — to exceed the rate limits or quotas applicable to your tier (see §8).


7. Prohibited uses — legal, sanctions, and export control

You must not use the Service:

7.1 In any manner that violates any applicable law or regulation, including the laws of the Republic of Türkiye, the European Union, and any jurisdiction from which you access or in which you use the Service.

7.2 In violation of any economic sanctions or trade-control regime (including those administered by the United Nations, the European Union, the United States (OFAC), and the United Kingdom), or for the benefit of any sanctioned, embargoed, or denied party or any person in a comprehensively embargoed jurisdiction.

7.3 In violation of any export-control law, including by exporting, re-exporting, or transferring data or technology in breach of such law.

7.4 You represent that you are not, and are not acting on behalf of, a person on any applicable sanctions or denied-party list, and that you will not provide access to the Service to any such person.


8. Volume, fair use, and scraping in your own use

8.1 Each tier carries a published per-minute rate limit (RPM) and monthly quota (see Plans & Pricing and Rate Limits). You must operate within the limits applicable to your tier.

8.2 Even within your published limits, we may throttle abusive or antisocial patterns — non-cache-friendly re-fetching, coordinated bursts, or repeated calls to walled upstreams — applied narrowly and explained on request.

8.3 You must not use the Service to scrape, crawl, or extract data at scale in violation of an Upstream Source's own terms, robots.txt directives, or applicable law in your own downstream use. The Service's anonymous access model governs how AllAPI reaches data; it does not authorize your own high-volume extraction or redistribution where that would breach a source's terms or the law. You remain responsible for your own conduct and volume.

8.4 You must not attempt to reverse-engineer, decompile, disassemble, or derive the source code, models, prompts, or internal architecture of the Service itself, except to the limited extent applicable law expressly permits notwithstanding this restriction.


9. Downstream-use responsibility

9.1 You are solely responsible for ensuring that your use of any data returned by the Service complies with:

9.2 We provide data "as retrieved" from Upstream Sources and grant you no rights in third-party content (Terms of Service §6.3). The normalized JSON envelope is a convenience of format and is not a warranty that you may reproduce, resell, or otherwise use the underlying content.


10. Data-subject removal and abuse reporting

10.1 Data-subject removal. If you are an individual whose personal data appears in Service responses, or you act on such an individual's behalf, you may request suppression or removal by writing to [email protected] with the subject line "Privacy request". We act on valid requests and can suppress data at our layer; we are not the origin of the data and cannot delete it at the Upstream Source. See the Privacy Policy for how requests are handled, identity verification, and response times.

10.2 Abuse reporting. To report suspected abuse of the Service — including any use prohibited by this AUP — contact [email protected]. Where possible, include the relevant X-Request-Id and a description of the conduct.

10.3 Investigation and cooperation. We may investigate suspected violations, review relevant operational metadata, preserve evidence, and cooperate with law enforcement and competent authorities as required or permitted by law.


11. Consequences of violation

11.1 If we determine, in our reasonable discretion, that you have violated this AUP, we may — without prior notice and without refundthrottle, suspend, or terminate your access; revoke your API keys; disable your account; and take any other action we consider appropriate.

11.2 We may report violations to law enforcement or competent authorities, preserve relevant evidence, and pursue any other remedy available to us at law or in equity.

11.3 The remedies in this AUP are cumulative and in addition to any other rights or remedies available to us, including under the Terms of Service. We are not liable to you for any action taken in good faith to enforce this AUP.


12. Changes to this AUP

12.1 We may update this AUP from time to time. Material changes will be announced on the dashboard and, where we hold your email address, by email.

12.2 Changes required for safety, security, legal, or regulatory reasons may take effect immediately. Your continued use of the Service after a change takes effect constitutes acceptance of the updated AUP.


Contact

The Service is operated by Legal Eye Yazılım A.Ş., a joint-stock company incorporated in Türkiye (Trade Registry No. 1020744, Tax ID / VKN 6081733803), registered office: Sultan Selim Mah. Yamaç Sk. No:6 İç Kapı No:3, Kağıthane / İstanbul, Türkiye, trading as "AllAPI".

Include an X-Request-Id (from any Service response) when reporting a specific issue.