SERVICE_RULES / SPIDERFOOT.TOOLS

Terms of Service

Plain-language rules for using SpiderFoot.tools, interpreting OSINT results, and working responsibly with public-source data.

Last updated: September 5, 2026

These Terms apply when you access or use SpiderFoot.tools. By continuing to use the website or its research workflows, you agree to these Terms. If you do not agree, do not use the service. How personal information is handled is described separately in the Privacy Policy.

01 / INTRODUCTION

The agreement in brief

SpiderFoot.tools is an independent, browser-based service for selected open-source intelligence workflows. These Terms cover the public pages, scanners, optional account connection, and search-history features provided through this website.

You may use the service only within a lawful, authorized scope. These Terms do not give you permission to investigate a person, account, organization, or system when that permission is otherwise required.

02 / SERVICE_SCOPE

What SpiderFoot.tools currently provides

Username intelligence

Checks a username against bundled public-site definitions and supported API categories, then presents possible profile and account signals for review.

Email intelligence

Checks a validated email address across 18 supported account-context categories. Responses can include registered, not registered, unknown, or error states.

IP intelligence

Shows available Cloudflare-aware connection headers when no IP is entered. A submitted IPv4 or IPv6 address is validated and queried server-side through Cloudflare Radar for available network, ASN, organization, IP-version, and location context.

Public-web context and history

Indexed public-web references may appear where that feature is enabled and permitted for the visitor’s country. Username and email tasks can be retained as browser- or account-linked search history.

The current site does not provide phone lookup, domain reconnaissance, breach-database access, background checks, mailbox access, or credential verification.

More technical detail is available on About SpiderFoot.tools and the FAQ.

03 / INTERPRETATION_RULE

Research results are leads, not identity proof

  • A username match does not prove that two accounts belong to the same person.
  • A shared username, avatar, display name, biography, or writing style is not enough on its own to establish identity.
  • An email-related account signal does not prove that an address is active or controlled by a particular person.
  • The absence of a returned result does not prove that an account, record, or public reference does not exist.
  • An IP address, ASN, network operator, or geolocation estimate does not identify a specific person or precise physical location.
  • Third-party data and AI-assisted output can be stale, incomplete, duplicated, misclassified, or wrong.

Open original sources, check dates and context, compare independent evidence, and record uncertainty before relying on a material finding. The separate Methodology explains this verification approach.

04 / AUTHORIZED_USE

Use the service for a legitimate, authorized purpose

Appropriate uses can include self-auditing, defensive security, approved investigations, brand monitoring, fraud awareness, journalism, academic research, and reviewing an organization’s own public exposure. Whether a particular activity is permitted depends on the facts, the authorization you hold, applicable law, and the rules of the sources you access.

Use only the inputs and sources necessary for your research question, limit collection of personal data, and stop when the authorized task is complete.

05 / PROHIBITED_USE

Uses that are not allowed

Do not use SpiderFoot.tools to:

  • harass, stalk, threaten, dox, intimidate, or facilitate harm;
  • commit fraud, impersonate another person or organization, or obtain credentials;
  • access a non-public account or system, bypass authentication, or support unauthorized intrusion;
  • conduct unlawful surveillance or unlawful discrimination;
  • use an unverified result as the sole basis for an employment, housing, credit, insurance, legal, safety, or similarly high-impact decision;
  • send malware or attack traffic through the service;
  • overload the site, run unsupported automated collection, bypass rate limits, evade signed-request controls, or defeat other security restrictions.

The service helps retrieve and organize public-source signals. It does not authorize access to any private account, device, mailbox, network, or restricted system.

06 / EXTERNAL_DEPENDENCIES

Public sources and third-party services

Depending on the selected workflow, SpiderFoot.tools may rely on bundled public-site definitions, public websites, service-provider APIs, indexed web-search results supplied through Serper, Cloudflare request headers, Cloudflare Radar, Google OAuth, and feature-controlled external AI providers.

A submitted username, email address, IP address, or derived search query may be sent to the relevant service backend or external provider to perform the requested check. Those providers operate under their own terms and policies.

External sources can be unavailable, rate-limited, blocked by geography, protected by CAPTCHA, restricted by account state, or changed without notice. Pages can be deleted, response formats can change, and cached or indexed information can become stale.

A failed or missing result does not necessarily mean that the underlying account, record, or service does not exist.

07 / AI_ASSISTANCE

AI-assisted features

AI Search Results and AI Summary are disabled in the current public-interface configuration. If an AI feature is made available, it may organize findings, suggest additional public-web leads, or summarize scan context.

AI output is generated content, not verified evidence. It may omit relevant context, combine unrelated facts, cite a weak source, or state something incorrectly. Return to the original public source and verify every important claim.

Do not treat AI output as identity verification or as legal, investigative, security, employment, financial, medical, or other professional advice. Do not use it by itself for a high-impact decision. Research articles follow the separate Editorial Policy.

08 / USER_INPUTS

You are responsible for the data you submit

You must have an appropriate basis and any required permission to submit a username, email address, IP address, or support correspondence and to research the resulting sources. SpiderFoot.tools cannot determine whether you hold that authority.

Do not submit passwords, authentication codes, API keys, private mailbox contents, payment details, health information, government identifiers, or other sensitive data that the requested workflow does not need. Do not use the service to publish or expose another person’s private information.

You are responsible for how you preserve, share, or act on any output you obtain.

09 / ACCOUNTS_AND_HISTORY

Browser-linked history and optional Google connection

The site assigns a first-party browser identifier. When a username or email task starts, a user record and search-history record may be created for that identifier even if you have not connected Google. Available result states and task output can then be saved to that history.

You may optionally connect Google OAuth. The site uses the returned account identifier and basic profile information to associate the website account; it does not receive the password used with Google. Keep access to your device, browser profile, and connected Google account secure.

Current history pages let you review username and email tasks. The IP workflow is not included in that history interface. There is no self-service history-delete control in the current site. Logging out clears the site’s identifier cookie from that browser; it does not by itself delete stored account or history records. Data requests can be made through the contact route described in the Privacy Policy.

10 / AVAILABILITY

Availability, partial results, and service changes

A scanner may time out, return an unknown or error state, show fewer results, or become temporarily unavailable because of maintenance, network conditions, source blocking, API changes, rate limits, geographic restrictions, or abuse-prevention controls.

Input validation and signed-request checks can reject malformed or unauthorized requests. Public-web context can also be unavailable in countries restricted by the current configuration.

Workflows, source coverage, categories, interfaces, and third-party integrations may change as the service and its external dependencies change. A temporary failure does not establish that the underlying source is permanently unavailable.

11 / ACCURACY_AND_RESPONSIBILITY

No guarantee of completeness or professional conclusions

SpiderFoot.tools does not guarantee that every public account will be found, every returned match is correct, every source is current, every IP field is precise, every provider will remain available, or every scan is complete.

You remain responsible for checking the original evidence, choosing a proportionate conclusion, complying with the rules that apply to your work, and deciding whether qualified professional advice is needed.

The service is provided as a research aid. SpiderFoot.tools is not responsible for a decision made solely from an unverified result, for third-party content, or for disruption caused by an external source. This does not remove any right or responsibility that cannot be excluded under the law that applies in the circumstances.

12 / CONTENT_AND_LICENSES

Original work, open-source components, and third-party material

Rights in the site-specific interface, original copy, graphics, original research, benchmark materials, and original software components remain with their respective SpiderFoot.tools rights holder to the extent those elements are original. Unless a separate notice says otherwise, normal access to the website does not grant permission to republish that original material as your own.

The bundled username definition file contains its own attribution list and Creative Commons Attribution-ShareAlike 4.0 notice. That material remains subject to that notice. The bundled ThinkPHP framework carries its Apache 2.0 notice, and other open-source libraries remain under their respective licenses.

Public profiles, search results, provider responses, screenshots of external services, third-party datasets, external articles, logos, names, and trademarks belong to their respective rights holders. Displaying or linking to them does not transfer ownership to SpiderFoot.tools and does not imply endorsement.

13 / PROJECT_RELATIONSHIP

Independent from the SpiderFoot open-source project

SpiderFoot.tools is an independent third-party OSINT web service. It is not affiliated with, endorsed by, or operated by the SpiderFoot open-source project or its maintainers.

The original SpiderFoot project’s name, code, documentation, and other assets remain subject to the rights and licenses stated by that project. Its official public repository identifies its code as MIT-licensed. Nothing in these Terms changes or replaces that license.

14 / PRIVACY_CONTACT_UPDATES

Privacy, corrections, and changes to these Terms

Privacy

The Privacy Policy explains search inputs, identifiers, account data, history, analytics, cookies, external providers, retention, and available requests. It forms the privacy notice for the service; those details are not repeated here.

Questions and corrections

For reporting guidance, see Contact. Send an inaccurate technical description, false positive, broken source, copyright concern, account-data request, security issue, or question about these Terms to [email protected]. Do not include unnecessary personal data, credentials, or secrets.

Updates

These Terms may be updated when the service, its external providers, or its operating rules change. The date at the top of this page records the latest published revision. If you do not agree with an updated version, stop using the service.