Terms of Service

The rules under which BuildAPI is provided. Last updated 8 September 2026.

The agreement

These terms are between you (or the organisation you represent) and BuildApi, who provides BuildAPI. By creating an account or using the service you accept them.

If you are accepting on behalf of a company, you are confirming you have authority to bind it.

Your account

You are responsible for what happens under your account, including anything done with credentials issued to it. Keep your password to yourself, and use two-factor authentication if it is available to you.

You must give accurate registration details and keep your billing contact current. We use that address for receipts, renewal notices and anything that affects your service — if it bounces, you will miss things that matter.

One person may hold one account. Teams are supported through organisation members and roles rather than shared logins, and sharing a single login across a team is both against these terms and a bad idea.

API keys and domains

Keys issued to you remain associated with your account and may not be resold, sublicensed or transferred to a third party without our agreement. Locking a key to a domain does not transfer ownership of the key.

Keys run in rolling thirty-day windows. On a live subscription the window renews automatically. If the subscription lapses, keys stop working at the end of the window then in effect, after the dunning period.

Client keys are visible to anyone who can read your site, and we treat them accordingly: their protection is the domain lock, not secrecy. Server keys are secrets and you are responsible for keeping them out of public repositories and client bundles.

You must prove control of a domain before a key bound to it will be authorised. If that proof lapses and is not restored, calls will be refused. That is the mechanism working as intended, not a fault.

Acceptable use

You may not use BuildAPI to:

  • break the law in your jurisdiction or ours;
  • gate access to material that is illegal to distribute;
  • attack, probe or overload our infrastructure, or anyone else’s through it;
  • circumvent your plan’s limits, including by creating multiple accounts to obtain additional allowance;
  • resell the service as your own without a written agreement.

Automated traffic against our gateway from your own systems is expected and fine. Automated traffic designed to test how much of it we will take is not.

Security scanning and testing

BuildAPI can run automated security scans — DNS and email-deliverability checks, and read-only web-layer checks — against a domain only after you have added it to your account and proven you control it. This is a hard limit of the software, and it exists for the reason below.

You may only scan what you are authorised to test. By verifying a domain and running a scan, you represent and warrant that you own that domain and the systems it resolves to, or are authorised by their owner to have them tested, and you authorise us to perform these automated checks on your behalf. You must not use these features against any domain, system or network you do not own or are not authorised to test — doing so may be a criminal offence in your jurisdiction and is a serious breach of these terms.

Our scans are non-destructive by design: they read public DNS and make ordinary GET requests to your own site. They send no attack payloads and attempt no exploit. Even so, the provider hosting your site, and the networks between us and it, may have their own rules about security testing, and it is your responsibility to ensure your use of these features complies with them.

Any active, intrusive or exploit-based testing we may offer in future will require your explicit, separate, written authorisation for each engagement — naming the targets in scope and the window — and you will remain solely responsible for confirming you are entitled to authorise it. Nothing in these terms grants that authorisation by default.

A scan result describes only the specific things it checked. A clean result is not a warranty that a domain or system is secure, and you must not represent it as one.

Plans, billing and renewal

Prices are quoted in US dollars. Where your payment processor settles in another currency, the converted amount is shown before you pay and appears on your receipt alongside the dollar price.

Card subscriptions renew automatically at the end of each term at the price then current for your plan. We attempt the charge on your renewal date; if it fails, your plan continues through a short dunning period during which we retry and email you, and lapses if it is not resolved.

Changing plan mid-term is prorated: you are credited for the unused part of what you have paid and charged the difference. The figure shown before you confirm is the figure charged.

Call allowances are pooled across your whole account, not per key, and reset on your subscription anniversary rather than the first of the month. Refused calls count towards your allowance.

We may change prices. An existing subscription keeps its price for the term already paid for; a change takes effect from the next renewal, and we will tell you before it does.

Refunds and cancellation

You may cancel at any time. Cancelling stops the subscription renewing; your plan continues to the end of the term you have paid for and then moves to the free tier. You may also end it immediately, in which case the remainder of the term is forfeited and is not refunded.

We do not offer refunds for partial periods as a matter of course. If the service did not work as described and we could not put it right, contact us — those we deal with on the facts.

Where a refund is issued to a card, it goes back to the card that paid. How quickly it appears is a matter for your bank rather than for us.

Paying in cryptocurrency

Where cryptocurrency payment is offered, you send funds directly to an address we publish. There is no intermediary holding the money and no transfer can be reversed — by us, by you, or by anyone else.

You are responsible for sending the exact amount quoted, on the network named, to the address shown on the payment page. The amount is how a payment is identified. If you send a different amount, use a different network, or send after the watch period, funds are not automatically credited. Contact us with the transaction hash and we will credit what actually arrived.

The countdown on the payment page is a rate lock, not a deadline: it fixes the exchange rate. Transfers that arrive after it expires are still credited at the locked rate for the duration of the watch period.

Crypto subscriptions do not renew automatically, because there is no stored instrument to charge. You renew them the same way you paid.

Availability and outages

We aim to keep the service available and we do not promise it always will be. No uptime figure is guaranteed except where one is stated in a separate written agreement.

The service is designed so that our being unreachable does not immediately take your site down: an authorisation is issued as a signed token your application can hold for several days. If we are unavailable, your integration should continue on that token. A refusal from us is different from silence from us, and your integration should treat them differently — this is described in the documentation.

We may perform maintenance, and will avoid doing so at a time we expect to be busy where we reasonably can.

Intellectual property

We and our licensors own BuildAPI, its software, its interfaces and its trademarks. These terms give you a limited, non-exclusive, non-transferable right to use the service while your account is in good standing, and nothing more. The API keys issued to you are licensed for your use, not sold to you.

You keep ownership of your own content and data. You grant us only the limited licence we need to host, process and display it in order to run the service for you — and no right to use it for anything else.

The client library and code snippets we give you to install are provided so you can run the service; you may use and modify them for that purpose. The runtime verification snippet must not be altered to defeat the check it performs, as the licence covering your key sets out.

Your data

How we handle personal data is set out in our Privacy Policy, which forms part of these terms.

For some features — visitor insights, and the security scans above — we act as your data processor: you decide what is collected and why, and we process it on your instructions to provide the feature. Where you need a data processing agreement to use these features lawfully, contact us and we will put one in place.

You are responsible for having a lawful basis to collect what you collect through the service, and for telling your own users about it where the law requires — the bot check and visitor insights run on your visitors, in your name.

Suspension and termination

We may suspend or close an account that breaches these terms, that is being used to attack our systems, or where we are required to by law. Where circumstances allow it we will tell you first and give you a chance to put it right.

You may close your account at any time. On closure your keys stop working and your data is deleted on our ordinary retention schedule. Export anything you want to keep before you close it.

Liability

The service is provided as it is. To the extent the law permits, we exclude implied warranties of merchantability and fitness for a particular purpose.

We are not liable for indirect or consequential loss, lost profits, or lost data. Where we are liable, our total liability is limited to what you paid us in the twelve months before the claim.

Nothing here excludes liability that cannot lawfully be excluded, including for fraud or for death or personal injury caused by negligence.

BuildAPI is one control among several. It gates access to what you wire it to gate. It is not a substitute for authenticating your own users, securing your own servers, or backing up your own data.

Indemnity

You will indemnify us against claims, losses, liabilities and reasonable costs arising from your breach of these terms, your misuse of the service, the content you gate or serve through it, or — in particular — your use of the security-scanning features against any target you were not authorised to test.

This does not apply to the extent a claim is caused by our own breach of these terms or our negligence, and nothing in it requires you to cover liability the law does not allow us to pass on.

Governing law and disputes

These terms, and any dispute arising out of them or the service, are governed by the laws of the jurisdiction in which BuildApi is established, whose courts have jurisdiction — except where mandatory consumer-protection law where you live gives you rights, or a forum, that this cannot take away.

Before starting formal proceedings, please contact us: most disputes are quicker to resolve directly, and we will engage in good faith to do so.

Changes to these terms

We may update these terms. If a change materially affects your rights we will tell you by email before it takes effect. Continuing to use the service after that is acceptance of the updated terms.

The date at the top of this page is when it last changed materially.

Contact

BuildApi
2999 Brown Street
Pleasanton, CA 94566
support@buildapi.app

See also our Privacy Policy.