Acceptable Use Policy
Last updated: September 5, 2026
This policy is part of our Terms of Service and applies to everyone who uses Argus. Breaching it is a breach of those terms.
Simnetiq Ltd is a company registered in England and Wales, so where this policy names a law it names the United Kingdom one. Most of the conduct below is unlawful almost everywhere under a different name, and section 4 says where the main differences are. This policy is not legal advice: it tells you where we draw the line and why, and it does not replace advice about the country you are in or the service you are reaching.
1. The principle
Argus is a general-purpose browser. Like any browser, it does what the person driving it tells it to. We do not supervise your sessions and we cannot see what you do inside them, so the responsibility for what you do with it is yours.
What follows is not a list of everything we disapprove of. It is the conduct we prohibit, and we prohibit it because it is unlawful or because it causes real harm to other people.
2. The two questions that decide almost everything
Would it be lawful done by hand? Imagine doing the same thing in an ordinary browser, on your own machine, one account at a time. If that would be lawful, running it through Argus — with a separate fingerprint, a proxy and an isolated cookie jar — does not make it unlawful. If it would be a crime or a civil wrong done by hand, Argus does not make it lawful either. The tool changes the scale and the traceability of what you do; it does not change what it is.
Who are you deceiving, and what do they lose? Nearly every prohibited use below has the same shape: someone is made to believe something false — that a review is from a customer, that a click was a real visitor, that a card belongs to you, that twenty accounts are twenty people — and they part with money, data, access or trust because of it. Separating two accounts of your own from each other deceives nobody. Passing them off as two strangers does.
A third question is answered in section 6: a service’s own terms of use are a contract between you and it, not a law. Breaching them can cost you the account. It does not, by itself, breach this policy.
3. What you must not do
Each heading names the United Kingdom law that makes the conduct unlawful. The list is not exhaustive, and where the law of your own country or of the service you are reaching is stricter, the stricter rule applies.
Break the law
- Anything unlawful in your jurisdiction or in the jurisdiction of the service you are reaching.
- Sanctions evasion, including using proxies to reach a service from, or on behalf of, a person or territory that UK, EU, US or UN sanctions cover (Sanctions and Anti-Money Laundering Act 2018 and the regulations made under it).
- Money laundering, or handling the proceeds of crime (Proceeds of Crime Act 2002, ss. 327–329).
Defraud people
- Obtaining money, goods, services or an advantage by a false representation, by failing to disclose what you are legally bound to disclose, or by abuse of position (Fraud Act 2006, ss. 2–4). This includes payment fraud, carding, and transacting with stolen financial instruments or credentials.
- Possessing, making or supplying tools, lists or accounts for use in fraud (Fraud Act 2006, ss. 6–7), and obtaining services dishonestly (s. 11).
- Identity theft, or impersonating a real person or organisation in order to deceive.
- Fake reviews, fabricated engagement, or manufactured consensus presented as genuine. Submitting or commissioning a fake review, and publishing reviews without reasonable steps to keep fake ones out, are banned commercial practices in the UK (Digital Markets, Competition and Consumers Act 2024, Schedule 20), in the EU (Unfair Commercial Practices Directive, Annex I) and in the US (FTC rule on consumer reviews, 16 CFR Part 465).
- Advertising, affiliate or incentive fraud — claiming payment for traffic, installs, leads or actions that were not what they were represented to be.
Access what is not yours
- Signing in to accounts you do not own and are not authorised to use, including with purchased, leaked or guessed credentials (Computer Misuse Act 1990, s. 1).
- Credential stuffing, brute forcing, or testing lists of stolen logins (Computer Misuse Act 1990, ss. 1–2; Data Protection Act 2018, s. 170).
- Exploiting a vulnerability, or accessing data or functionality a service has not made available to you (Computer Misuse Act 1990, ss. 1–3; in the EU, Directive 2013/40/EU; in the US, the Computer Fraud and Abuse Act, 18 U.S.C. § 1030).
- Intercepting communications that are not addressed to you (Investigatory Powers Act 2016, s. 3).
Harm people
- Harassment, stalking, doxxing, or coordinated abuse of an individual (Protection from Harassment Act 1997; Online Safety Act 2023, ss. 179–181, which cover false and threatening communications).
- Sharing or threatening to share intimate images of a person without consent, or creating them (Online Safety Act 2023 and the Sexual Offences Act 2003 as amended).
- Child sexual abuse material, or content sexualising minors, without exception (Protection of Children Act 1978; Criminal Justice Act 1988, s. 160). We report it.
- Content or conduct promoting terrorism or violent extremism (Terrorism Act 2006, ss. 1–2).
- Distributing or deploying malware, ransomware, spyware or stalkerware (Computer Misuse Act 1990, ss. 3–3A).
- Encouraging or assisting any of the above (Serious Crime Act 2007, ss. 44–46).
Infringe rights
- Infringing copyright, database right, trade marks or other intellectual property (Copyright, Designs and Patents Act 1988; Copyright and Rights in Databases Regulations 1997; Trade Marks Act 1994), including circumventing a technological protection measure to reach content you have not been given access to (CDPA 1988, s. 296ZA).
- Collecting personal data in breach of data protection law, or processing personal data you have no lawful basis to process (UK GDPR, Articles 5, 6 and 14; Data Protection Act 2018, s. 170, which makes it an offence to obtain personal data without the controller’s consent).
- Sending unsolicited marketing to individuals without the consent the law requires (Privacy and Electronic Communications Regulations 2003, regs. 22–23; in the EU, the ePrivacy Directive; in the US, CAN-SPAM; in Canada, CASL). Section 5 says how this applies in practice.
Buy tickets with bots
- Using software to buy more tickets for a recreational, sporting or cultural event than the organiser’s limit allows, for resale. This is a specific criminal offence in the UK (Breaching of Limits on Ticket Sales Regulations 2018, made under the Digital Economy Act 2017, s. 106) and in the US (Better Online Ticket Sales Act 2016), and equivalents exist in several EU states, Canadian provinces and Australian states.
Damage the Service or other customers
- Attacking, overloading, or attempting to gain unauthorised access to our systems or to any service you reach through the Service (Computer Misuse Act 1990, s. 3).
- Reselling access to your workspace, or sharing a single workspace as a way of serving unrelated third parties.
- Circumventing the limits attached to your plan, or the mechanisms that enforce them.
4. Scenarios
These are the questions we are actually asked, answered. Allowed means the activity does not breach this policy — it may still breach a platform’s terms, and section 6 explains what that means. Not allowed means it does. Depends means the same activity is fine in one form and prohibited in another, and the third column says which.
| Running several accounts | ||
|---|---|---|
| An agency manages separate client accounts on one social network, each in its own profile. | Allowed | Ordinary agency work. Nobody is deceived, and most platforms provide for it. |
| A brand runs one account per market, region or language on the same service. | Allowed | Each account represents who it says it does. |
| Keeping a personal account and a work account on the same service unlinked from each other. | Allowed | Privacy from the platform’s own correlation, not deception of anyone. |
| Re-registering after a platform banned you, against its rules, to keep trading. | Depends | Not unlawful in itself in the UK; a contract matter between you and the platform, which will close the new account too. It becomes prohibited if the new account hides who you are from customers, evades a court order or a regulator’s ban, or is used to keep selling goods that were removed for a safety reason. |
| A network of accounts that pose as unrelated people to praise a product, a cause or a candidate. | Not allowed | Manufactured consensus is a misleading commercial practice (DMCCA 2024; UCPD; FTC Act s. 5) and, aimed at an election, may breach electoral law. |
| Accounts in another real person’s name, or using their photographs, without their consent. | Not allowed | Impersonation to deceive (Fraud Act 2006, s. 2), and often harassment or defamation of the person impersonated. |
| E-commerce and marketplaces | ||
| Selling the same catalogue through several marketplace storefronts you legitimately own. | Allowed | Each storefront is yours and says so. |
| Opening new seller accounts to get around a marketplace’s suspension of one of them. | Depends | A contract dispute with the marketplace, not a crime — unless the new account conceals the trader’s identity from consumers (Consumer Contracts Regulations 2013; E-Commerce Regulations 2002 require it to be shown) or is used to keep selling recalled or counterfeit goods. |
| Buying limited-release goods across many accounts where the retailer allows one per customer. | Depends | For most goods, a breach of the retailer’s terms and nothing more. Prohibited for event tickets (see below), and whenever the orders use false details or someone else’s payment method. |
| Placing orders with stolen card data or purchased identity packages. | Not allowed | Fraud Act 2006, ss. 2 and 6; Proceeds of Crime Act 2002. |
| Checking whether stolen cards are still live by making small purchases. | Not allowed | Fraud Act 2006, ss. 6–7: possessing and using articles for fraud. |
| Reviewing your own products, or paying for reviews, presented as if from customers. | Not allowed | Fake reviews are banned outright (DMCCA 2024, Sch. 20; 16 CFR Part 465). |
| Buying your own products through many accounts to inflate sales rank. | Not allowed | A misleading commercial practice, and usually a fraud on the marketplace’s ranking and fee systems. |
| Filing false complaints against a competitor’s listings from many accounts. | Not allowed | Malicious falsehood and, where done for gain, fraud by false representation. |
| Advertising and affiliate marketing | ||
| Running ad accounts for several clients, each in its own profile with its own payment method. | Allowed | Ordinary agency work. |
| Checking how your own ads and landing pages render from another country through a proxy. | Allowed | Quality assurance. You are looking at your own material. |
| Warming up new ad accounts you own with ordinary activity before scaling spend. | Allowed | Not deception; platform terms may still limit how many accounts one advertiser may hold. |
| Cloaking: showing a reviewer a compliant page and real visitors a different one. | Not allowed | A misleading commercial practice and a fraud on the network, which pays and approves on a false representation. |
| Generating clicks, installs, leads or sign-ups that are not what they are billed as. | Not allowed | Fraud Act 2006, s. 2. |
| Cookie stuffing, forced clicks, or otherwise taking affiliate credit for sales you did not refer. | Not allowed | Obtaining commission by false representation, and where it alters another system’s data, Computer Misuse Act 1990, s. 3. |
| Tickets and limited releases | ||
| Buying tickets for yourself and friends, within the published limit, from your own account. | Allowed | This is what the sale is for. |
| Buying more tickets than the event’s limit through multiple accounts or automation, for resale. | Not allowed | A criminal offence in the UK (Breaching of Limits on Ticket Sales Regulations 2018) and the US (BOTS Act 2016), with equivalents elsewhere. |
| Reselling tickets you bought lawfully, where resale is permitted. | Depends | Lawful where the organiser and local law allow it and the required information is disclosed (Consumer Rights Act 2015, s. 90); not a use of Argus at all in most cases. |
| Scraping and data collection | ||
| Collecting public, non-personal data — prices, listings, availability, rankings — from pages that need no login. | Allowed | Lawful. Keep to a rate the site can absorb, and treat its robots rules and terms as the contract matter they are. Substantial extraction from an EU or UK database can engage database right. |
| Monitoring your own listings, rankings, reviews or ad placements. | Allowed | Your own material. |
| Academic, journalistic or public-interest research on public platforms. | Allowed | Research and journalism exemptions exist in UK and EU data protection law; they do not cover publishing dumps of personal data. |
| Collecting personal data — names, roles, contact details — about individuals from public pages. | Depends | Lawful only with a lawful basis under UK or EU GDPR (usually legitimate interests, with a recorded balancing test), a route for individuals to learn you hold their data (Art. 14) and to object to it. What you then send them is governed by the outreach rows below. |
| Scraping pages behind a login you hold, in breach of the site’s terms. | Depends | Where the data is what any logged-in user sees, this is a contract dispute with the site. Where you reach data the site did not make available to you, it can be unauthorised access (Computer Misuse Act 1990, s. 1). Never resell or republish other account-holders’ personal data. |
| Getting past a paywall or access control to reach content that was never offered to you. | Not allowed | Circumventing a technological protection measure (CDPA 1988, s. 296ZA) and, for gated systems, unauthorised access (CMA 1990, s. 1). Solving a captcha on a page you are otherwise entitled to see is a different thing — see section 5. |
| Republishing scraped articles, images or full product descriptions as your own. | Not allowed | Copyright and database right infringement (CDPA 1988; 1997 Regulations). |
| Scraping at a rate that slows or takes down the target. | Not allowed | Impairing the operation of a computer (Computer Misuse Act 1990, s. 3). Intent to collect data is no defence to a denial of service. |
| Email and outreach | ||
| Emailing named business contacts at their work addresses from your own domain, identifying yourself and offering an opt-out. | Allowed | UK PECR treats corporate subscribers differently from individuals; UK GDPR duties still apply. Several EU states and Canada (CASL) require consent even for business addresses, so check the recipient’s country. |
| Cold email to individuals or sole traders who have not consented. | Not allowed | PECR 2003, reg. 22 (unless the narrow soft opt-in applies); ePrivacy Directive art. 13 in the EU. |
| Sending from mailboxes you do not own, forging the sender, or using purchased lists. | Not allowed | Fraud, PECR, CAN-SPAM, and every mail provider’s own policy. The product’s sending steps refuse addresses on your suppression list and cap each mailbox; working around those is itself a breach. |
| Bulk direct messages or comments across many accounts. | Depends | Spam under most platforms’ rules, which is your risk. Prohibited when the content is misleading, harassing, or pretends to come from unrelated people. |
| Betting, gaming and finance | ||
| Holding accounts at several bookmakers or exchanges, each in your own name. | Allowed | Nothing false is represented. |
| Several accounts at one operator using other people’s identities to claim sign-up bonuses. | Not allowed | Fraud Act 2006 and cheating at gambling (Gambling Act 2005, s. 42); the identity holders are also victims. |
| Masking your location to bet with an operator that is not licensed where you are. | Depends | May be unlawful for you locally and will void winnings under the operator’s terms. Prohibited where you give false information at identity verification — that is fraud — or where the operator is barred from your country by sanctions. |
| Farming crypto airdrops or promotions with many wallets and accounts you control. | Depends | Not unlawful in itself. Prohibited where it relies on false identity documents, on other people’s identities, or on reaching a service from a sanctioned territory. |
| Buying, selling or renting identity-verified accounts. | Not allowed | Identity fraud, and facilitating money laundering (POCA 2002, s. 328). |
| Offering investment, brokerage or payment services without the licence your country requires. | Not allowed | Financial Services and Markets Act 2000, s. 19, and its equivalents everywhere. |
| Security testing | ||
| Testing systems you own, or have written authorisation to test, within the agreed scope. | Allowed | Authorisation is what the Computer Misuse Act turns on. Keep the scope document. |
| Bug bounty work within a programme’s published scope and rules. | Allowed | The programme is the authorisation. Outside its scope, it is not. |
| Probing a third party’s login for weak passwords “to help them”. | Not allowed | CMA 1990, s. 1. Good intent is not authorisation. |
| Credential stuffing with leaked username and password lists. | Not allowed | CMA 1990, s. 1; Data Protection Act 2018, s. 170. |
| Privacy, research and personal use | ||
| Browsing with a coherent fingerprint and a proxy so that trackers cannot link your sessions. | Allowed | Privacy from commercial tracking is a purpose of the product. |
| Reporting from, or reading the press of, a country that censors it. | Allowed | See our page for journalists for the limits of what a browser can protect. |
| Watching a streaming catalogue licensed for another country by masking your location. | Depends | A breach of the service’s terms and not a crime for the viewer in the UK; some countries treat it differently. We do not supply proxies and take no position on the service’s response. |
| Getting around a personal block, a restraining order or a no-contact condition to reach a specific person. | Not allowed | Protection from Harassment Act 1997; contempt of court. |
| AI, agents and automation | ||
| Letting the assistant or an automation drive accounts and workflows that are yours. | Allowed | Automating your own work is what the automation features are for. |
| A bot that converses with the public without saying it is a bot, where disclosure is required. | Depends | Required in the EU for AI systems that interact with people (AI Act, art. 50) and in California for commercial or electoral bots; elsewhere a platform rule. Never present an automated account as a human to sell or to influence a vote. |
| Submitting applications, entries or complaints in bulk on behalf of people who did not ask you to, or to flood a form. | Not allowed | Fraud by false representation and, for the flooding, CMA 1990, s. 3. |
| The Service itself | ||
| Sharing a workspace with your own team, clients’ accounts included. | Allowed | Workspaces exist for this, within the seat count of your plan. |
| Building internal tools on the local API and MCP server for your own organisation. | Allowed | That is what the API is for. Keys are yours to scope and revoke. |
| Reselling seats, running a “shared login” business, or serving unrelated customers from one workspace. | Not allowed | Terms of Service, section 4. |
| Working around plan limits or the mechanisms that enforce them. | Not allowed | Terms of Service, section 4. |
Outside the United Kingdom. The same lines are drawn elsewhere under other names. In the European Union: the GDPR and ePrivacy rules, the Unfair Commercial Practices Directive, the Digital Services Act’s rules on manipulation of platforms, and Directive 2013/40/EU on attacks against information systems. In the United States: the Computer Fraud and Abuse Act, the FTC Act and the FTC’s consumer-review rule, CAN-SPAM, the BOTS Act and state law such as California’s bot-disclosure statute. Where your country or the service’s country goes further than this policy, the further rule is the one that applies to you.
5. What this policy does not prohibit
We would rather say this than leave it ambiguous. Argus exists to run more than one account at a time, on services that would otherwise link them, and the following are ordinary uses of it:
- Operating several accounts on a service, where that service allows it or where the accounts belong to different clients, brands, markets or regions.
- Separating identities — a distinct fingerprint, proxy and cookie jar per profile — including specifically so that two accounts of yours are not associated with each other.
- Solving captchas on pages you are otherwise entitled to reach, including with the third-party extensions listed in the application. A captcha is a nuisance filter, not an access control, and solving one is not unlawful in itself. Using a captcha solver to get into somebody else’s account is prohibited for the reason the account is, not the captcha.
- Automating your own work in your own accounts, and scraping data that is lawfully accessible to you.
- Privacy from tracking, including from the fingerprinting and port scanning that commercial detection services perform.
None of that is a licence for the conduct in section 3. Running twenty accounts is fine. Running twenty accounts to post fake reviews is not, and the thing that makes it not fine is the fake reviews.
6. Your obligations to other services
A service’s own terms are a contract between you and it, not between you and us. Using Argus in a way that breaches a platform’s terms is a matter between you and that platform: it may suspend or close your account, withhold balances, or refuse you in future, and we cannot get any of that back for you. That risk is yours, and you should assume it before you rely on an account you cannot afford to lose.
Two things turn a terms breach into a policy breach: when the platform’s rule is also the law (ticket limits, fake reviews, identity verification), and when the breach is the means of deceiving or harming someone else. Section 4 marks those cases.
7. Personal data you collect
If you use Argus to collect information about identifiable people — scraping profiles, building lead lists, enriching contacts — you are a controller of that data under the UK GDPR, the EU GDPR or whichever law applies to you, and the obligations are yours, not ours. In outline:
- You need a lawful basis before you collect, and “it was public” is not one. For business prospecting, the usual basis is legitimate interests, and it requires you to have weighed your interest against the individual’s and to be able to show that you did.
- People have the right to know you hold their data (Article 14), normally within a month of you obtaining it or at first contact, and to object. Keep a way to honour both.
- Do not collect special-category data — health, religion, sexual orientation, political opinion, trade-union membership, biometrics — unless a specific condition applies to you. Prospecting is never such a condition.
- Keep only what you need, for as long as you need it, and secure it. The desktop application’s datasets live on your device and in your workspace; what you export from them is your responsibility.
- Obtaining personal data from a service without its consent, or selling data obtained that way, is a criminal offence in the UK regardless of what you do with it afterwards (Data Protection Act 2018, s. 170).
8. Email and messaging
The application can send email through mailboxes you connect, and can hand opt-in broadcasts to an email service provider over your own key. The rules differ by who you are writing to:
- Individuals and sole traders in the UK and the EU need prior consent, except under the narrow soft opt-in for existing customers of similar products. Cold email to them is prohibited (PECR 2003, reg. 22).
- Employees at their work addresses may be emailed in the UK without prior consent, provided you identify yourself, give a valid address and honour opt-outs. Several EU countries, Canada and Australia are stricter and the recipient’s law is the one that applies.
- Everywhere, the sender must be genuine, the subject must not mislead, there must be a working unsubscribe, and suppression requests must be honoured. The United States adds these requirements under CAN-SPAM even for cold business email.
- The email service providers the application integrates with prohibit cold outreach and scraped lists under their own policies, and enforce it by closing accounts. The application routes cold mail through your own mailboxes for that reason; do not put a scraped list through a broadcast.
9. Where the Service is not offered
The Service is not offered in territories under comprehensive UK, EU or US sanctions, and section 2 of the Terms of Service lists them. Using proxies to reach it from one of those territories, or to reach any service on behalf of a sanctioned person, is a breach of this policy in addition to being a breach of sanctions law.
10. If you are not sure
Ask. Write to support@simnetiq.store and describe the workflow — what the accounts are, who they belong to, what the automation does and who sees the result. We do not need the name of the target service to answer, and we will not ask for credentials. We answer these questions, and a workflow we have said is fine in writing is one we will not later suspend you for.
11. How we enforce this
We do not monitor your browsing, and the profile, fingerprint and cookie data in the desktop application stays on your device unless you turn on cloud sync — and with workspace encryption on, what is synced is ciphertext we cannot read. In practice we learn about a breach when someone reports it, when a payment provider, a platform or law enforcement contacts us, or when abuse affects our own systems.
When we do, the response is proportionate: usually we will contact you and ask you to stop, and give you a reasonable time to do so. For serious breaches — anything in the “harm people” list, fraud, unauthorised access, ticket bots, sanctions — we may suspend or terminate an account immediately and without notice, and we will not refund the term.
We report child sexual abuse material to the authorities without exception. For other conduct we cooperate with law enforcement where we are legally required to, and we respond to requests for customer data only on valid legal process from a UK court or authority, or its equivalent under a mutual legal assistance arrangement. We may preserve account records while such a request is pending. Our Privacy Policy says what records exist to be requested — which is less than most people assume.
12. Reporting abuse
If you believe someone is using Argus to do something in section 3, tell us at support@simnetiq.store. Include enough detail for us to identify the account or the activity: the service concerned, what happened, when, and any account names or addresses you saw. We read every report and reply to every one that leaves us a way to. Complaints about copyright or trade marks have their own procedure on the copyright page.
13. Changes
We may update this policy as the Service changes or as new kinds of abuse appear. The “Last updated” date above tells you when it last changed, and changes that narrow what you may do take effect with notice under section 16 of the Terms of Service.