This policy sets out what you may and may not do with Heedly. It forms part of the Terms of Service.
1. Allowed
- Monitoring sites, feeds and servers that you own or are authorised to monitor.
- Using the API and webhooks within your plan limits.
- Adding clients’ sites as an agency, with their written authorisation.
- Letting an AI assistant create an account for you, at your request and with your own email address.
2. Not allowed
- Load, stress or denial-of-service testing of any target.
- Scanning for vulnerabilities, guessing admin or hidden URLs, or probing networks.
- Monitoring sites or servers you are not authorised to monitor, or adding private or internal addresses.
- Circumventing rate limits, plan limits or ownership verification; sharing API keys; reselling the service without agreement.
- Using the service to harass, to collect personal data, or for anything illegal.
- Interfering with the security or availability of Heedly.
3. HeedlyBot behaviour
HeedlyBot makes at most one request per second and two simultaneous connections per host, honours robots.txt and Crawl-delay, and never checks a site more than once a minute. Only the crawler reads robots.txt; uptime, trial and speed checks are single ordinary visits. A host can ask us to stop at any time through the abuse form: we then put it on a block list, and no check of any kind visits it or its subdomains afterwards.
A page speed check started on our website opens the home page once and downloads up to 20 of the files that page links to (without running scripts), then stops. The same site can be tested at most six times an hour.
4. Enforcement
We may pause checks, suspend accounts and report unlawful activity. Complaints are reviewed and handled through the abuse form.