ScreenshotNeo

BlogGuides

Are Website Terms of Use Enforceable for Web Scraping?

Website terms can restrict scraping when a contract was formed, but public access, login status, notice, and technical barriers all affect the analysis.

By the ScreenshotNeo team30 September 202610 min read

Are Website Terms of Use Enforceable for Web Scraping?

Short answer: Website terms of use can be enforceable against a scraper when the site can show that the scraper agreed to the terms—or had legally adequate notice—and the terms clearly cover the scraping at issue. Publicly accessible data does not automatically make scraping lawful, and a site’s objection does not automatically make public-page access unauthorized under every law. The outcome depends on the agreement, how it was presented, whether the scraper was logged in, what data and systems were involved, and the jurisdiction.

This is a U.S.-focused overview, not legal advice. The leading authorities discussed here are fact-specific decisions from the Ninth Circuit and the Northern District of California. Other countries may apply different contract, privacy, database, and computer-access rules.

1. Start with contract formation and notice

A terms page is not automatically a contract with every person who visits a website. A court may ask whether the site gave reasonable notice of its terms and whether the user took an action that showed assent. The exact presentation and applicable law matter.

How the terms were presented Why it matters for scraping
Click-through agreement during registration Often provides stronger evidence that the account holder accepted the terms, especially if the interface clearly links or displays them.
Terms accepted through an authenticated service May connect the scraper’s account use to the agreement. Check the actual terms, account history, and governing law.
Browsewrap link in a footer or other page area May be harder to enforce if a visitor was not given clear notice and did not take an action demonstrating assent.
No identified notice or assent The site may have difficulty establishing a contract with that visitor, but other legal theories or facts may still matter.

Do not assume that a link labeled “Terms” resolves the question. Look at where it appeared, whether it was visible at the time, what the user did, and whether the terms changed later. Keep the analysis tied to the specific version and flow the scraper encountered.

2. Determine whether access was public or authenticated

Courts have treated logged-out access to public pages differently from activity inside an account or behind a paywall. Logging in can provide evidence of assent and can make account-specific restrictions relevant. Accessing nonpublic data, using another person’s credentials, creating deceptive accounts, or circumventing technical controls also changes the risk analysis.

Public visibility, account access, and assent can change the legal analysis.
Public visibility, account access, and assent can change the legal analysis.

In hiQ Labs v. LinkedIn, the Ninth Circuit held that viewing public LinkedIn profiles was not access “without authorization” under the Computer Fraud and Abuse Act (CFAA) merely because LinkedIn objected and sent cease-and-desist notices. The court did not establish that every form of scraping is lawful; contract, trespass, and other claims remained separate questions. Read the Ninth Circuit’s 2022 hiQ opinion.

In Meta Platforms v. Bright Data, a 2024 Northern District of California order found no evidence of logged-in scraping and held that logged-out scraping of public Facebook and Instagram data did not breach the Meta and Instagram terms analyzed in that case. The order reasoned that an entity that did not use account access to scrape public data stood in the position of a visitor to whom those terms did not apply. That conclusion depended on the evidence and the particular terms; it is not a blanket rule for every website or scraper. Read the district court’s order.

A useful first-pass comparison is:

Scenario Contract and access questions
Logged out, public page, no clear assent Was there adequate notice? Do the terms bind visitors? What other claims or restrictions apply?
Logged-in account, accepted terms Did the agreement prohibit automated collection, and did the conduct fall within that wording?
Paywalled or account-only information What access did the account authorize? Did the scraper exceed account permissions or breach conditions?
CAPTCHA, IP block, or other barrier bypassed Could circumvention, deception, or access restrictions create additional exposure beyond contract?

3. Read the actual anti-scraping language

Terms vary. A policy may prohibit automated access generally, copying particular content, competitive use, account sharing, or bypassing limits. Read the operative agreement rather than relying on a summary, robots.txt, a banner, or a cease-and-desist letter. Check whether it applies to visitors, registered users, or both, and whether it covers the collection method and purpose at issue.

In its 2022 discussion of LinkedIn’s User Agreement, the Ninth Circuit quoted language barring users from scraping or copying profiles and information, and from using manual or automated software, scripts, robots, or other processes to access, scrape, crawl, or spider the service. The significance is not that the same wording controls every case; it illustrates why the exact promise and evidence of assent matter. The opinion describes the terms and contract record.

  1. Find the version in force when collection occurred.
  2. Identify the clause that covers automated access, copying, reuse, or account use.
  3. Determine who accepted it and how assent was recorded.
  4. Compare the clause with the actual actions: URLs requested, account status, data collected, rate, and any barriers encountered.
  5. Review choice-of-law, forum, notice, and dispute clauses, while remembering those provisions do not answer every substantive question.

4. Keep CFAA analysis separate from contract analysis

The CFAA is a federal computer-access statute. Whether public-page access is “without authorization” under that statute is a different question from whether the scraper broke a contract. The Ninth Circuit’s hiQ decision addressed public LinkedIn profiles and the CFAA; it did not erase terms a scraper had accepted or resolve every state-law claim.

That distinction is central: a person may have a favorable argument on one legal theory and still face another. A site may assert breach of contract, trespass to chattels, copyright, privacy, or other claims, depending on the data, conduct, and jurisdiction. Do not translate “not CFAA unauthorized access in this fact pattern” into “all scraping is permitted.”

5. Assess the whole collection pattern

Contract enforceability is only one part of the practical risk. Evaluate the collection against these facts before building a scraper or continuing an existing one:

  • Access: Is each page public without login, or does collection use an authenticated or paid area?
  • Assent: Did a user accept terms, create an account, or receive clear notice?
  • Method: Are requests ordinary page fetches, or do they bypass CAPTCHA, blocks, or other controls?
  • Scale and purpose: Is this limited research or high-volume commercial extraction?
  • Data: Is the material personal information, copyrighted content, or ordinary public business information?
  • Jurisdiction: Where are the site, scraper, users, and affected people located, and what law governs?

These details can affect contract claims and other legal regimes. Public visibility is relevant, but it does not settle copyright, privacy, data-protection, database-rights, or contractual questions.

6. A cautious workflow for developers

  1. Define the data and purpose. Document exactly which fields are needed and why. Avoid collecting unrelated personal data.
  2. Review access conditions. Read the terms, API rules, account restrictions, and any relevant notices. Record the version and date.
  3. Prefer an authorized interface. Check whether the site offers an API, export, license, or permission process that covers the intended use.
  4. Keep access within permission. Do not treat a public URL as permission to enter accounts, paywalls, or technical barriers.
  5. Limit requests and retention. Use conservative rates, collect only necessary fields, and set a retention period appropriate to the purpose.
  6. Stop and reassess when blocked. A CAPTCHA, access denial, cease-and-desist, or account restriction is a signal to review the legal and technical basis before continuing.
  7. Escalate high-risk cases. Get jurisdiction-specific legal advice for authenticated systems, personal data, commercial-scale collection, or a dispute with the site.

This workflow is a risk-management aid, not a guarantee of legality. The legal result depends on facts and governing law.

A documented workflow keeps scope, access conditions, and the saved record clear.
A documented workflow keeps scope, access conditions, and the saved record clear.

7. Troubleshooting common assumptions

Assumption or issue Why it can fail Practical next step
“The pages are public, so the terms cannot apply.” Public access may matter, but an account holder may have separately assented to restrictions, and other claims may apply. Check login state, account history, notice, the actual clause, and other relevant laws.
“The terms are online, so every visitor agreed.” A posted link does not by itself prove notice or assent in every jurisdiction or interface. Preserve the page and flow as presented, including how prominent the terms were and what action followed.
“A cease-and-desist makes public access unauthorized under the CFAA.” hiQ rejected that theory for the public LinkedIn profiles before it, but did not resolve contract or all other claims. Analyze each legal theory separately and get counsel if the notice concerns ongoing collection.
“I was logged out, so no terms could bind me.” Other notice, assent, conduct, or legal theories may matter; the Meta order is specific to its record and terms. Verify whether the scraper or organization had an account, accepted terms, or used account-derived access.
“The terms prohibit scraping, so the clause is automatically enforceable.” Formation, notice, scope, governing law, and evidence still matter. Review the exact agreement and how the parties interacted.
“The site did not block my requests, so the activity is allowed.” Absence of a technical block does not establish permission or settle contract, privacy, or intellectual-property claims. Use the site’s stated access terms and seek permission or legal review where needed.

8. ScreenshotNeo for permitted capture workflows

For developers who need visual records of pages they are authorized to access, ScreenshotNeo is a website screenshot API and MCP server. A screenshot is not a substitute for permission to access or collect a site, and it does not resolve the legal questions above. Its capture options include custom headers, cookies, user agents, selector waits, full-page capture, and PDF output; use those only where your access and intended use are authorized.

When the job is a permitted screenshot rather than extracting page data, a capture API can avoid maintaining browser infrastructure. ScreenshotNeo returns PNG, JPEG, WebP, or PDF from a GET request. See the ScreenshotNeo API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({
  access_key: 'YOUR_API_KEY',
  url: 'https://stripe.com'
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('shot.webp', new Uint8Array(await res.arrayBuffer()));

Replace the example target with a page you are allowed to capture. Keep API keys on the server, not in client-side code. The JavaScript example uses Bun’s file writer; in Node.js, write the returned bytes with writeFile from node:fs/promises.

9. Or skip the browser setup

One GET request returns a screenshot or PDF, without you provisioning and maintaining a browser:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts cookie banners and removes 60+ known consent platforms, newsletter popups, and chat widgets before the shot; each step can be turned off. Bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, with the page verdict and billing status in response headers. Its MCP server gives AI agents tools to take screenshots, get page information, and capture PDFs. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000.

Sign up for 1,000 free screenshots a month, with no card required.

10. Reliability, performance, and cost considerations

For an in-house browser scraper, reliability work includes browser version management, page timeouts, retries, concurrency limits, storage, and handling pages that change or fail to load. Retries should be bounded: retrying a blocked or disallowed page does not make access permissible and can increase load. Cache results where reuse is appropriate, and keep an audit trail of URLs, timestamps, account context, and collection purpose.

For screenshot capture, decide whether you need a viewport image or a full-page image, whether to wait for a selector or network idle, and whether lazy-loaded content must be present. Longer waits and larger pages increase capture time and resource use. Cache stable results when suitable, and treat a screenshot as a point-in-time record rather than a durable representation of a changing page.

ScreenshotNeo plans are Free: 1,000 shots per month; Starter: $5 for 3,000; Growth: $15 for 15,000; Pro: $39 for 60,000; Scale: $99 for 250,000; and Business: $249 for 1,000,000. Yearly billing gives two months free, and every feature is on every plan. Check the documentation for current request options and response details before integrating.

11. Frequently asked questions

Can a website sue me for scraping data that is public?

A site can bring a claim, but whether it succeeds depends on the agreement, access, data, conduct, and applicable law. Public availability alone does not answer every claim.

Does a cease-and-desist make public scraping unauthorized?

In hiQ, the Ninth Circuit did not treat the notice as making access to public LinkedIn profiles unauthorized under the CFAA. A notice may still matter to other legal theories and should be reviewed in context.

Is scraping against a site’s terms illegal?

A terms violation can support a contract claim if a binding agreement covered the conduct. Whether other laws were violated is a separate, fact-specific question.

Do terms apply if I scrape while logged out?

They may be harder to apply absent assent or adequate notice, and courts have ruled for logged-out public scraping on specific records. That does not create universal immunity, particularly where other conduct or claims are involved.

Does a favorable U.S. case protect scraping in another country?

No. The cited decisions are U.S. authorities, and other jurisdictions may have different contract, privacy, database, and computer-access rules.