Acceptable Use Policy
Last updated: 2026-06-07. Effective: 2026-06-07.
This Acceptable Use Policy ("AUP") describes activities that are not permitted on ZI² Discover (the "Service"). It is part of the Terms of Service and applies to everyone with access to the Service, including users invited to a workspace by an account owner. If you violate the AUP we may suspend or terminate access, without refund.
1. General prohibitions
You must not use the Service to:
- Violate any law, regulation, or third party's rights, including intellectual property, privacy, and publicity rights.
- Host, store, transmit, or scan content that is illegal where you operate, where the target site is hosted, or in Germany.
- Generate, distribute, or facilitate distribution of malware, ransomware, exploit kits, phishing kits, or similar payloads.
- Send spam, unsolicited bulk communications, or use the Service to compose or test spam-evasion strategies.
- Infringe copyright, trademark, trade secret, or patent rights, or use the Service to publish content you do not have the right to publish.
- Attack third parties through the Service — including using our crawler or AI probes to denial-of-service, fingerprint, or harvest data from a target.
- Attempt to access another tenant's data, bypass authorization, escalate privileges, or otherwise circumvent the Service's multi-tenant isolation.
- Share account credentials. Each human user must have their own account; workspace seats are not transferable between people.
- Resell, white-label, or sublicense the Service without a written reseller agreement signed by ZI².
- Scrape the Service itself — including the marketing site, the dashboard, or the public API beyond the documented usage — except for indexing by major search engines that respect
robots.txt. - Use the Service to develop a competing product through systematic extraction of our findings, rules, or AI probe responses.
- Misrepresent your identity, your authority to use a domain, or your relationship to a customer.
- Engage in conduct that is harassing, threatening, defamatory, obscene, or hateful toward our staff or other users.
2. Crawler-specific rules
The scanner can crawl large amounts of content quickly. To keep it useful for everyone and harmless to target sites, you must follow these rules:
- Only scan sites you own or have explicit written permission to scan. Adding a domain to a workspace constitutes a representation under section 7 of the Terms that you have that authority. Sites that fail ownership verification may be limited to surface checks only.
- Respect
robots.txt on the target. Our crawler does this by default; do not attempt to configure it otherwise. If a target updates its robots.txt to disallow our user agent, the crawl will stop. - Stay within reasonable rates. Default per-host concurrency is conservative. You may not coordinate multiple workspaces to bypass it.
- Identify your crawler. Our user agent is
ZI2DiscoverBot/1.0 (+https://discover.zi2.app/bot). Do not request that we forge a different user agent. - No scanning of legally protected systems — for example, government systems where unauthorized access is criminalized, paywalled content you are not subscribed to, or sites bound by a non-disclosure agreement you have not satisfied.
- Respect target complaints. If a site operator credibly objects, we may pause or revoke your right to scan it while we investigate. You agree to cooperate.
3. AI probe rules
AI probes consume third-party API budget and pass queries through providers we list in the Privacy Policy. You must use them honestly:
- Queries must relate to your Verified Sites. Probes exist to test whether your content is discoverable by AI engines, not as a general-purpose AI search tool.
- No automated abuse of probe budgets. Do not script the dashboard, do not rotate workspaces to evade per-tenant caps, do not submit duplicative or random queries to consume budget without purpose.
- No malicious enumeration of competitors. You may benchmark publicly visible AI-citation results against competing brands — that is core to the product. You may not use probes to harass a competitor, fabricate citations, or assemble queries designed to defame or mislead.
- No prompt-injection campaigns. You may not use probes to push payloads designed to manipulate downstream consumers of a provider's output.
- No content that violates a provider's policy. The Anthropic, OpenAI, Google, Microsoft, and Perplexity acceptable-use policies apply to the queries we forward. Forbidden content there is forbidden here.
- Research outside discoverability: if you intend to use probes for academic research or for purposes other than improving discoverability of your sites, contact [email protected] first so we can confirm the use is compatible.
4. Fixer and applier rules
The Service can ship code or content changes back to your stack. You are responsible for the systems you connect:
- Authorize the applier only for sites and repositories where you have the right to make changes.
- Configure authority levels deliberately. The default authority gate per rule severity is published in our documentation; raising authority above default is your decision.
- Review pull requests and applied changes. The Service is a tool, not your engineer of record.
- Do not use the applier to introduce content (for example, hidden text, cloaking, or deceptive structured data) that would violate a search engine's webmaster guidelines.
5. API rules
- Keep API keys secret. Rotate immediately if leaked.
- Use a reasonable concurrency and respect the rate-limit headers we return.
- Do not use the API to mirror tenant data into a competing product.
- Do not test the API with destructive operations against production tenants you do not own.
6. Reporting violations
If you believe someone is abusing the Service — including using our crawler against a site you operate without permission, sending probe traffic that looks like abuse, or impersonating a brand — please tell us at [email protected]. Include the target domain, the timestamps, and a description of what you observed. We will acknowledge within 2 business days.
7. Enforcement
We investigate suspected AUP violations on a risk-proportionate basis. Our typical path is:
- Notice: for non-urgent first-time issues, we send a written notice describing the problem and asking you to fix it within a stated period.
- Throttle: we may reduce crawl concurrency, probe quotas, or applier privileges while we investigate.
- Suspension: for serious or unresolved violations, we suspend access. Suspension does not pause billing for any cycle already in progress; service credits are at our discretion.
- Termination: for severe, repeated, or unresolved violations, we terminate the account under section 13.4 of the Terms. No refund is owed for fees attributable to AUP violations.
- Immediate action: for active abuse that puts us, our customers, or a third party at risk (for example, active malware distribution, active attack from a workspace, or a credible legal demand) we may suspend or terminate without prior notice.
We may report unlawful activity to law enforcement and preserve evidence under legal hold.
8. Changes to this AUP
We will post any changes on this page and update the "Last updated" date. Material changes are announced at least 30 days in advance by email and in-app, except where a change is required immediately by law or by an active threat, in which case the change takes effect on posting.
9. Contact
For AUP questions, contact [email protected]. For abuse reports, contact [email protected].
See also:
Terms ·
Privacy ·
Security ·
DMCA ·
Cookies