Back home

Acceptable Use Policy

Last updated 16 August 2026

This Acceptable Use Policy (“Policy”) explains what is and is not allowed when using Favicons (the “Service”). It forms part of the Terms of Service.

Intended use

You may use the Service to:

  • Request favicon images for legitimate domains via the documented endpoints
  • Hotlink or embed those image URLs in applications, sites, emails, and similar products
  • Force-refresh a cached favicon within the published rate limits when you need a newer copy
  • View public pages such as the home page and leaderboard

Prohibited use

You may not use the Service to:

  • Attack, scan, or overload this Service or any third-party system
  • Attempt to bypass rate limits, authentication, or other protective controls
  • Use the refresh endpoint as a general-purpose proxy, scraper, or denial-of-service tool
  • Request domains or resources in a way intended to cause harm, harassment, or illegal activity
  • Interfere with caching, storage, or other users’ access to the Service
  • Misrepresent the Service as belonging to another party, or remove notices that identify Favicons where attribution is reasonably expected
  • Violate applicable law, including intellectual property, privacy, and computer misuse laws

Automated access

Reasonable automated use of the image endpoints is allowed and expected. You must still honor rate limits, back off on errors, and avoid traffic patterns that degrade the Service for others. High-volume or abusive automation may be throttled or blocked without notice.

Third-party websites

When the Service fetches a favicon, it contacts third-party sites on your behalf. Do not use the Service to target sites you are not permitted to access, or to evade those sites’ own access controls.

Enforcement

We may investigate suspected violations and respond with rate limiting, temporary blocks, permanent blocks, deletion of cached data, or other measures we consider appropriate.

Reporting

Report abuse or security concerns via GitHub Issues. Do not disclose security vulnerabilities publicly before we have had a reasonable chance to respond.