Imitation Engine

Legal

Acceptable Use Policy.

Imitation Engine reproduces other people’s websites with very little friction. That is the whole point of it, and it is exactly why this policy exists. One rule sits above the rest: you must be entitled to clone what you clone. This page spells that out, lists what is off limits, and explains what happens if you cross the line.

Effective
27 July 2026
Last updated
27 July 2026
Version
1.0

Scope

This Acceptable Use Policy (the “Policy”) forms part of the Terms of Service and applies to every use of Imitation Engine — the plugin, the command-line tools, the dashboard and the API. Capitalised terms have the meanings given in the Terms.

It applies to you and to anyone using your account, with or without your permission. Breaching it is a material breach of the Terms.

The permission rule

The one rule that matters most

Only point Imitation Engine at a site you own, or that you have the owner’s permission to clone, or that you otherwise have a clear lawful right to crawl and reproduce for your intended purpose.

If you are not sure you have that right, you do not have it for the purposes of this Policy. Get it in writing before you run a Command.

We do not, and cannot, check what you point the tool at. There is no allow-list, no target review and no compliance filter — the plugin runs on your machine, under your control, and our servers never see the pages it fetches. That design is deliberate, and it means the entire judgement about a Target is yours.

“I found it on the public internet” is not permission. Publicly reachable does not mean freely reproducible: copyright, database rights, design rights, trade marks, the site’s own terms of use and computer-misuse law all continue to apply to a page anyone can load.

Permitted use

The Service is built for one job: producing faithful, instrumented mirrors of web interfaces for reinforcement-learning training environments and similar engineering work. Typical permitted use looks like:

  • cloning surfaces of a product you or your employer own — your own app, marketing site, admin console or checkout;
  • cloning a third-party site under a written licence, contract or engagement that permits it, including work for a client who holds the rights or has secured them;
  • cloning sites whose licence expressly allows reproduction, or whose content is out of copyright or in the public domain;
  • cloning purpose-built demonstration, sandbox or benchmark sites published for that use;
  • internal engineering work — regression baselines, test harnesses, accessibility and performance study of your own surfaces.

In plain English

If your legal team would sign off on a screenshot-by-screenshot manual rebuild of the target, automating it with Imitation Engine is fine. If they would not, the automation does not make it acceptable.

Prohibited targets

Do not point the Service at any of the following, ever:

  • Systems you are not authorised to access. Anything behind a login, paywall, licence gate, IP allow-list, invitation or private beta that you have not been granted access to for this purpose.
  • Protected systems. Anything guarded by bot protection, CAPTCHA, rate limiting, device attestation, WAF rules, anti-scraping measures or DRM, where cloning would require evading those measures.
  • Banking, payment and financial interfaces — bank portals, card-network pages, payment processors, brokerages, wallets and exchanges. The overlap with phishing is too close to permit any of it.
  • Authentication and identity surfaces — login pages, SSO flows, OAuth consent screens, MFA prompts, password resets, KYC and identity-verification flows of any service you do not own.
  • Government, healthcare, education and utility portals where citizens, patients or students enter personal data.
  • Sites handling special-category or sensitive data — health records, biometrics, immigration, legal aid, sexual-health, support and crisis services, or anything serving children.
  • Personal and private surfaces — an individual’s account pages, inboxes, messaging apps, dating profiles, social feeds, or any page showing a private person’s data.
  • Illegal or infringing sites — piracy, stolen data, counterfeit goods, CSAM, terrorist content, or content unlawful where you or the site operate.
  • Anything where the owner has said no — a site whose terms forbid automated access or reproduction, whose robots directives disallow it, or whose operator has told you or us to stop.

The one exception to this list is a site in it that you own or operate, or for which you hold the owner’s documented written authorisation to test or clone. If you are unsure whether your authorisation is sufficient, assume it is not.

Prohibited conduct

Deception and impersonation

  • building or assisting phishing, credential-harvesting, fake-login, scam, fraud or social-engineering pages, whether or not deployed;
  • publishing, hosting or serving Output in a way that could lead anyone to believe it is the Target or is affiliated with, endorsed by or operated by the Target owner;
  • using a Target’s trade marks, brand or trade dress in a manner likely to cause confusion, dilution or passing off;
  • typosquatting, cybersquatting or serving Output on a domain designed to be mistaken for the Target’s.

Unauthorised access and circumvention

  • using stolen, borrowed, shared, purchased or leaked credentials, cookies, tokens or sessions, or credentials belonging to anyone but you;
  • defeating or attempting to defeat authentication, authorisation, paywalls, geofencing, bot detection, CAPTCHAs, licence checks or technical protection measures;
  • exploiting a vulnerability in a Target, or using the Service as part of reconnaissance for an attack;
  • anything that would constitute unauthorised access to a computer resource under the Information Technology Act, 2000 or an equivalent computer-misuse law elsewhere.

Load, scale and harm

  • bulk or industrial-scale harvesting, mirroring or content aggregation, whether for resale, SEO, model training or a dataset;
  • running crawls at a volume, concurrency or frequency that degrades a Target, its infrastructure or its costs — deliberately or through carelessness;
  • any denial-of-service, stress-testing or flooding activity against a Target you do not own;
  • collecting personal data of a Target’s users, scraping contact details, or extracting data for spam, profiling or resale.

Against the Service itself

  • sharing, reselling, renting, sublicensing or multiplying a seat, or operating the Plugin as a service for other people;
  • tampering with the Plugin, spoofing the machine identifier, cycling accounts or tokens, or otherwise evading metering, quotas or rate limits;
  • attacking, probing, scanning, overloading, reverse engineering or bypassing our API, authentication or billing;
  • using the Service to build or improve a competing product, or to generate published benchmarks without our written consent;
  • uploading malware, or using the Service in a way that exposes us or our providers to legal or reputational risk.

Crawl etiquette

Even on a Target you are entitled to clone, crawl like a good citizen. You are responsible for the traffic the Plugin generates from your machine and your network.

  • Leave robots.txt respect enabled. The tooling honours it by default, and disabling it on a site you do not own is a breach of this Policy.
  • Keep concurrency, page caps and depth limits at sane values. Crawl production surfaces during quiet hours where you can.
  • Back off on errors, and stop immediately on 429, 403 or any block signal rather than retrying around it.
  • Do not trigger destructive interactions — form submissions, purchases, deletions, invitations, emails, messages or payments — on any Target that is not a sandbox you control.
  • Stop when asked. If a Target operator asks you to stop, stop immediately, whatever you believe your rights to be.

Using the output

Our disclaimer of ownership in the Output says nothing about the Target’s rights in the material it reproduces. When you use Output:

  • keep it internal to your training, testing or engineering use unless you hold the rights to publish it;
  • replace third-party trade marks, logos, licensed fonts, stock imagery and copy before any external distribution;
  • check the licences of any dependency, font or asset the Plugin downloaded, and remove anything you cannot use;
  • strip any personal data that was captured incidentally from a live page;
  • never present the Output publicly as, or in place of, the Target;
  • never serve the Output at a domain, or in a context, that implies it is the Target.

Seats and metering

One subscription equals one person and one Claude Code identity. Using your own laptop, desktop, workstation and a container is expected. What is not permitted is spreading a seat across colleagues, shared CI accounts, bots, rotating hosts or any arrangement whose effect is that more than one person is working from a single subscription.

Usage allowances are per plan and per metering window. Attempting to get around them — with extra accounts, repeat trials, token cycling, spoofed machine identity or a patched plugin — is treated as the same kind of breach as taking the usage without paying, and we may recover its value.

Complaints and takedown requests

If you are a site owner and you believe someone has used Imitation Engine against your site, write to legal@imitationengine.com with the URLs involved, the dates and times, the source addresses if you have them, and what you believe happened. We will look into it promptly.

What we can do is bounded by how the product works. The plugin runs on the customer’s own machine and fetches your pages directly from their network — we do not proxy that traffic, keep logs of it, host any copy of your site, or hold the Output. We can act on the account: warn it, suspend it, revoke its token, terminate it, and respond to lawful process. We cannot remove a copy we never had, and we take no position on the merits of any dispute between you and a customer.

We may pass a complaint, and the identifying information accompanying it, to the account holder concerned so they can respond, and we may disclose account information where the law requires it or a valid legal process compels it.

Enforcement

We may act on a suspected breach of this Policy at our sole discretion, with or without prior notice, and without investigating or adjudicating any underlying dispute. Depending on severity we may:

  • ask you to explain or to stop;
  • revoke your Plugin Token;
  • suspend or rate-limit your account;
  • delete affected Projects;
  • terminate your subscription immediately and permanently;
  • refuse you service in future, under any account; and
  • report the matter to law enforcement or a regulator where we believe that is warranted or required.

Important

Termination or suspension for a breach of this Policy carries no refund of any kind, including for the unused remainder of a paid period, and we are not liable for any loss you suffer as a result. Your indemnity under the Terms continues to apply to everything you did before we acted.

We may choose not to enforce this Policy in a given instance without waiving the right to enforce it later. Nothing here obliges us to monitor use, and we do not.

Reporting abuse

Everything reaches one address: legal@imitationengine.com. Start your message with what it is about so it is triaged correctly:

  • Abuse — misuse of the Service, or a complaint that someone has cloned your site. Include URLs, dates and times, and source addresses if you have them.
  • Security — a vulnerability in our own systems. See the disclosure policy and safe harbour before you test anything.
  • Support — anything else, including questions about whether a particular use is permitted. Ask before you run the crawl, not after.

Questions about this document? Write to legal@imitationengine.com. This page is provided for transparency and does not constitute legal advice.