Skip to main content

Website Scanner Terms of Use

The rules for the free website scanner, the public scan archive, and access through the API and the MCP server.

As of August 2026
On this page

1. Scope

1.1. These terms of use apply to the free website scanner operated by nebty GmbH, c/o BASE Coworking, Blütenstr. 15, 80799 Munich, Germany ("nebty", "we", "us") on nebty-id.com, and to the same service accessed through the API and the MCP server on tools.nebty-id.com (together, the "Service").

1.2. By using the Service you accept these terms. If you do not agree with them, please do not use the Service.

1.3. The Service is free, public, and usable without an account. There is no entitlement to use it.

1.4. How we process personal data is set out in our privacy policy.

2. What the Service Does

2.1. You submit a URL. The Service opens that page with an automated browser and stores a snapshot: a screenshot, the HTML source, and the page text. It adds DNS, hosting, and registrar data for the domain from public sources.

2.2. Every snapshot receives a permanent ID and a permanent link.

2.3. Snapshots are public by default. Anyone with the link can open them, and they appear in the searchable archive on our website.

2.4. With an API key, two further visibilities are available: unlisted (reachable through the link only, not listed in search) and private (readable only by the key that created the scan).

3. Acceptable Use

3.1. You may only submit URLs you are permitted to submit.

3.2. The following is prohibited in particular:

  • capturing or making accessible through the Service any material depicting child sexual abuse (CSAM, section 184b of the German Criminal Code) or youth pornography (section 184c);
  • capturing or making accessible other unlawful content, such as depictions of extreme violence, instructions for criminal offences, or terrorist propaganda;
  • distributing malware through the Service;
  • scanning pages that sit behind a login;
  • submitting URLs that contain session tokens, password reset links, invitation links, or other secrets;
  • scanning pages that hold personal data;
  • using the Service to attack, overload, or probe third-party systems;
  • circumventing rate limits;
  • automated mass scanning beyond the documented limits;
  • reverse engineering the Service or disrupting its operation.

3.3. If you breach these rules, we may block access at any time and without notice, and delete individual snapshots.

3.4. Content covered by the first bullet of section 3.2 is removed as soon as we become aware of it. We do not retain such content and do not keep copies of it. Where we are required to report, we notify the competent authorities and transmit the information they need. Data that does not itself contain such content, for example the time, the scan ID and the IP address, may be retained where that is necessary to meet those obligations. Please report suspected cases to [email protected].

4. Third-Party Content and Warning

4.1. A snapshot shows a third party's page. We do not review the pages we open before storing them, and we do not monitor them afterwards.

4.2. The archive can therefore contain unlawful, offensive, or explicit content. Anyone using the archive does so in the knowledge of this.

4.3. We are not the author of the captured content and do not adopt it as our own. A snapshot is neither a recommendation nor an assessment of the page it captured.

5. Removal and Reports

5.1. Anyone can ask for a snapshot to be removed. Write to [email protected] and state the scan ID. The scan ID is shown on the snapshot's result page.

5.2. Illegal content can be reported to the same address. For material depicting child sexual abuse, section 3.4 applies: we remove it immediately and do not retain it.

5.3. We may delete any snapshot at any time and for any reason, without prior notice.

6. Personal Data

6.1. Pages holding personal data must not be scanned (section 3). Even so, a snapshot can contain personal data, for example because that data was on the page we opened.

6.2. Affected persons can request erasure at [email protected]. The scan ID or the URL helps us find the snapshot.

6.3. The rights of affected persons and the way we process data are set out in our privacy policy.

7. Verifying a Snapshot

7.1. We record a SHA-256 checksum for every file stored with a snapshot. The record itself is signed with an Ed25519 key. We publish the matching public key, so the signature can be checked with standard tools, without an account and without a request to us.

7.2. This establishes two things: the record was issued by us, and neither the record nor the stored files have changed since it was signed.

7.3. It does not establish the time of capture. We hold the signing key and the clock, and no external timestamp authority under RFC 3161 is involved.

7.4. Nor does it establish that the site showed the same content to anyone else. A page can look different depending on the country it is loaded from, on the visitor, or on the A/B test group.

7.5. A signature is also no promise that a snapshot stays available. We may delete stored files and entire snapshots (section 5).

8. Availability

8.1. The Service is free. We give no availability commitment, and there is no service level agreement.

8.2. We may change, limit, or discontinue the Service at any time. The same applies to rate limits, the range of functions, and the contents of the archive.

9. Liability

9.1. The Service is provided "as is". We give no warranty as to the accuracy, completeness, or timeliness of the data shown.

9.2. In the context of fault-based liability, we shall only be liable for damages, irrespective of the legal grounds, in cases of intent and gross negligence.

9.3. We are liable without limitation for damages resulting from injury to life, body, or health, and in all cases of mandatory statutory liability, in particular under the German Product Liability Act, where a defect has been fraudulently concealed, and where a guarantee has been assumed.

9.4. The limitations of liability under para. 9.2 also apply to breaches of duty by or in favour of persons whose fault we are responsible for according to statutory provisions. Mandatory statutory limits on the exclusion of liability remain unaffected.

10. Changes to These Terms

We may update these terms, for example when the Service, the legal situation, or the technical basis changes. The version published on this page is the one that applies. As of August 2026.

11. Final Provisions

11.1. The law of the Federal Republic of Germany applies, to the exclusion of the UN Convention on Contracts for the International Sale of Goods (CISG).

11.2. As far as legally permissible, the exclusive place of jurisdiction for all disputes arising from or in connection with the use of the Service is Munich.

11.3. Should individual provisions be or become invalid, the validity of the remaining provisions is not affected.

11.4. The provider is nebty GmbH. Full provider details are in the imprint.

nebty GmbH
Contact: [email protected]

Imprint · Privacy Policy