Last updated: 2026-09-12 — Version v1.1
1. Scope
This Acceptable Use Policy ("AUP") sets out what you may and may not do with Screen Browser (the "Service"), operated by MiCCA OÜ ("we", "us"). It is part of the Terms of Service and applies to everyone who uses the Service, whether through the app, the API or the MCP endpoint, and to everyone acting on your organisation's behalf, including coding agents you connect.
2. Record only what you may record
The Service signs in to a web application with credentials you supply and records what it sees. You may only do this with applications you own or are authorised to record. Authorisation means the owner of the application has agreed, for example because it is your own product, an internal tool of your organisation, or a client's application that the client has asked you to document.
Before a project's first run, someone in your organisation attests in the app that the organisation may record that hostname. The attestation is recorded with who made it and when. Making a false attestation is a breach of this AUP and of the Terms.
3. Prohibited uses
You must not use the Service to:
- Sign in to or record an account that belongs to someone else without that person's authorisation, or record an application you are not authorised to record.
- Bypass, evade or interfere with access controls, bot detection, CAPTCHAs, web application firewalls, rate limits or any other protection of an application, including by disguising the recorder's traffic. If an application blocks the recorder, the right answer is to add the recorder to that application's allowlist, not to work around the block.
- Upload, distribute or cause the execution of malware, or use a run to attack, probe or overload any system.
- Produce or distribute content that is illegal, that infringes someone's intellectual property or privacy rights, or that is defamatory, harassing or deceptive.
- Record, collect or publish personal data of third parties without a lawful basis, including data of your own application's users that appears on screen, unless you have the right to include it in a video.
- Attempt to access, extract or interfere with data, runs, recording environments or credentials of other customers, or to escape the isolated environment a run is given.
- Sell, rent, share or transfer credits, accounts or API keys to anyone outside your organisation.
- Reverse engineer the Service, scrape it, or use it to build a competing product beyond what the law allows.
- Send us content that you know to be a security risk, or use failure reports to transmit material you have no right to share.
4. Recording environments and allowed hosts
Each run gets a fresh, isolated recording environment that can reach only your application's hostname, the hosts named in your guides, and the allowed hosts you list on the project. Do not list hosts you are not authorised to reach. Do not use guides to send the recorder to unrelated sites, and do not use the recorder to download data from an application at scale.
5. Credentials
Use accounts with no more access than the recording needs. Do not supply credentials that belong to someone else without their permission. If you are asked to record with a client's credentials, get that permission in writing. Rotate or remove credentials as soon as you no longer need the Service to hold them.
6. AI narration and captions
Narration and captions are generated automatically from your guide and the recorded pages. Check them before you publish. Do not use guides to make the narration state things about people or products that are false or misleading.
7. Reporting abuse
If you believe the Service is being used against an application without authorisation, or in any other way that breaches this AUP, write to [email protected]. Include the hostname, the time and anything else that helps us find the run. Application owners can also ask us to refuse runs against their hostnames at the same address.
We acknowledge abuse reports promptly and investigate them. We do not share the identity of the reporter with the customer unless the law requires it.
8. Enforcement
We may investigate suspected breaches, which can include reviewing attestations, run logs and the hosts a run reached. Depending on what we find, we may:
- stop or refuse individual runs;
- suspend a project, an API key or an account, with or without notice where the breach is serious or continuing;
- terminate the account under the Terms of Service;
- refuse future runs against a hostname at its owner's request;
- report unlawful activity to law enforcement and cooperate with lawful requests.
Credits used in runs that breached this AUP are not refunded.
9. Appeals
If your run, project or account was suspended and you believe we got it wrong, write to [email protected] with the details. We will look again and reply with a decision and its reasons.
10. Changes
We may update this AUP. Material changes are announced by email at least 14 days before they take effect, as described in the Terms. The version and date at the top identify the current text.