Acceptable Use Policy

Last updated 11 October 2026

Bug Smash drives real browsers, signs in to sites and records what it sees. That's powerful, so it comes with rules. This policy is part of our Terms of Service, and applies to everyone in your workspace and to the coding agents you connect.

Test only what you're allowed to test

Point Bug Smash (test runs, personas, missions, the CLI's browser, --attach and saved logins) only at websites, apps and environments that you own, or that their owner has authorised you to test. If you test for a client, get their permission first. Use accounts you're entitled to use: your own, or test accounts made for the purpose.

Don't use Bug Smash to

  • scrape, crawl or copy content or data from sites you aren't authorised to test;
  • load-test, stress-test or flood any site, or run anything that could degrade a service for its other users;
  • try passwords, guess credentials, take over accounts, or use logins or cookies that aren't yours to use;
  • get around another party's CAPTCHAs, bot protection, rate limits, paywalls or access controls (--attach is for your own sites that block automated browsers, not anyone else's);
  • probe for or exploit security vulnerabilities in systems you aren't authorised to test;
  • make purchases, send messages, or create content on real third-party services in ways that harm them or their users;
  • break any law, or anyone's rights, including privacy, intellectual property and computer-misuse laws.

Be careful with personal data

  • Prefer test environments and test data. Screenshots, traces and logs capture whatever is on the page.
  • Don't send us special categories of data (such as health, biometric or government ID data), full payment card numbers, or passwords, unless they're hidden first. Paint over private details in the extension before sending, and leave out screenshots where needed.
  • If your content includes other people's personal data, you need a lawful basis to collect it and to share it with us. See the DPA.

Don't misuse the Service itself

  • No uploading malware or unlawful, infringing, harassing or sexually explicit content.
  • No attacking, overloading or probing Bug Smash, its API or other customers' data, except through our vulnerability disclosure process.
  • No sharing accounts, reselling access, or creating accounts to get around plan limits or a suspension.
  • No automated access beyond the API, CLI and extension we provide, and respect the API's rate limits.

What happens if the rules are broken

We may remove content, revoke tokens, or suspend or close the accounts involved, without a refund, and may report illegal activity to the authorities. Where it's safe to, we'll tell you first and give you a chance to fix it.

To report misuse of Bug Smash, including a test run hitting your site that you didn't authorise, write to support@bugsmash.dev.