# Responsible Captcha Automation: Acceptable Use and Opt-outs

> When using a captcha solver is appropriate, what ZeroCaptcha's Acceptable Use Policy allows, and how site owners opt out or report abuse, all handled by people.

- Source: https://zerocaptcha.io/guides/responsible-captcha-automation
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

A CAPTCHA exists because a site owner chose to slow down automated traffic. A solving API
supplies the token that tells the site "a visitor passed", so it should only be used where the
automation itself is legitimate. This guide explains how ZeroCaptcha draws that line, what the
[Acceptable Use Policy](https://zerocaptcha.io/legal/acceptable-use) asks of every customer, and how site owners can
opt out or report misuse. Every step described here is handled by people, not by automatic rules.

## Legitimate uses

The policy lists what you may do, and it is ordinary engineering work:

- **Test, monitor or automate sites you own or run.**
- **Automate sites whose owner allows it**, in their terms or in writing, such as a supplier
  portal without an API.
- **Run security or quality tests you are authorized to run.**
- **Collect public data** where the law and the site's terms let you.

For your own sites, first check whether you need a solver at all. Cloudflare publishes testing
sitekeys that always pass in CI: see [Test Cloudflare Turnstile in CI](https://zerocaptcha.io/guides/test-cloudflare-turnstile-in-ci).

## What is not acceptable

The [Acceptable Use Policy](https://zerocaptcha.io/legal/acceptable-use) is the authority. In short, it rules out
solving challenges on a site you are not allowed to automate or whose owner has told you to stop;
taking over accounts, testing stolen passwords or card numbers, or any fraud; creating accounts,
reviews, votes or messages in bulk to deceive a site or its users; getting into systems or data
you have no right to; and overloading or disrupting a site. Every account accepts the policy when
it signs up, and you are responsible for every task your keys create.

## How enforcement works

ZeroCaptcha keeps enforcement simple and human:

1. **A blocklist, kept by hand.** Staff add a domain after a report, after a check of the logs, or
   when its owner opts out. Tasks for a domain on the blocklist are refused before any solving, at
   no charge, with `ERROR_DOMAIN_BLOCKED`.
2. **Account suspension, by a person.** When an account breaks the policy, staff may suspend it.
   A suspended account's keys are refused, with `ERROR_ACCOUNT_SUSPENDED`, and it cannot create
   tasks, keys or top-ups. Each action is recorded with its reason.
3. **No automatic category rules.** No kind of site is blocked on its own; each block is a
   decision a person made about a specific domain.

## For site owners: opting out

If you run a site and do not want ZeroCaptcha used against it, send a request from the
[opt-out page](https://zerocaptcha.io/opt-out): your domain, an address where we can reach you, and anything we should
know. A person checks that you speak for the domain, usually by writing to you, then adds it to
the blocklist by hand, or tells you why not. There is no account to create and nothing to pay.

## For anyone: reporting abuse

If you believe ZeroCaptcha was used against a site in breach of the policy, use the
[abuse report form](https://zerocaptcha.io/report-abuse): the site, what happened, and a link to evidence if you have
one. An address is optional, if you would like an answer. Staff read every report, and may block
the site or suspend an account as a result.

## For customers: staying on the right side

- **Know the site's terms** before you automate it, and keep a record of the permission you rely
  on.
- **Pace your traffic** as a courteous visitor would: see
  [Scraping a site with Cloudflare Turnstile](https://zerocaptcha.io/guides/cloudflare-turnstile-web-scraping).
- **Protect your keys**, so nobody else can send tasks in your name: see
  [Secure your captcha API keys](https://zerocaptcha.io/guides/secure-captcha-api-keys).
- **Treat `ERROR_DOMAIN_BLOCKED` as final.** Stop sending tasks for that site. The refused task
  costs nothing, and retrying it cannot succeed.

## Questions

Write to us from the [contact page](https://zerocaptcha.io/contact) with anything the policy does not answer. To see
what the API does for legitimate automation, start at the [Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver)
page, or read more [about ZeroCaptcha](https://zerocaptcha.io/about).

## Questions

### I own a site. How do I keep ZeroCaptcha from being used against it?

Send a request from the opt-out page with your domain and an address. Our staff check each request and add the domain to the blocklist by hand.

### What happens to a task for a blocked domain?

It is refused before any solving, and it costs nothing.

### How do I report misuse I have seen?

Use the abuse report form with the site, what happened and any evidence. Staff read every report and act on it by hand.
