Last updated: September 21, 2026
JustBrowser is an antidetect browser that lets you run many isolated browser profiles, each with its own fingerprint, proxy and storage. That capability is useful to people who manage their own accounts, protect their privacy, test software or do research. It can also be misused to defeat the anti-fraud systems of other people's platforms. This policy draws the line between the two. It applies to everyone who uses the JustBrowser desktop app, web dashboard, local API, cloud sync, team workspaces or proxy marketplace (together, "the Service"), operated by Velocity Digital Labs LLC ("we", "us").
This Acceptable Use Policy ("this Policy") is part of the JustBrowser Terms of Service at /terms and is incorporated into them by reference. If you use the Service, you agree to this Policy. If this Policy and the Terms conflict, the Terms control, except that this Policy governs which uses are permitted and prohibited.
"You" means the person or organisation that holds a JustBrowser account, and every person who uses the Service under that account, including team seats. "Profile" means a browser profile created or run in the Service. "Platform" means any third-party website, app, service or network that you reach through a profile.
This Policy is not a checklist that ends at the last bullet. If a use is not named here but is plainly of the same kind as something we prohibit, it is prohibited.
The Service is built to keep separate browser identities separate. Whether a given use is acceptable depends on two things: whether you are entitled to operate the accounts and systems involved, and whether the platform on the other end permits what you are doing.
Put simply: managing what is yours, or what you have been authorised to manage, within the rules of the platform you are using, is acceptable. Pretending to be someone you are not, getting back into a place you were removed from, or manufacturing activity that a platform or advertiser will treat as genuine, is not.
The following are examples of uses we consider legitimate, provided you also comply with section 3:
Sections 3 to 10 set out what you may not do. In outline, you may not use the Service to:
You must comply with the terms of service, community guidelines, advertising policies and other rules of every platform you access through a profile. You bear sole responsibility for that compliance. We do not review the rules of the platforms you use, we do not know which platforms you use, and we cannot tell you whether a given activity is allowed on a given platform. Isolating your accounts in separate profiles does not change what those platforms permit.
Nothing in the Service, in our marketing or in our support correspondence is a representation that any platform allows multiple accounts, automation or the use of an antidetect browser. Check the platform's rules yourself before you rely on the Service.
You may not use the Service to:
You may not use the Service to access any computer, server, account, network, API or data without authorisation, or to exceed the authorisation you have. This includes conduct that would violate the United States Computer Fraud and Abuse Act (18 U.S.C. § 1030), the equivalent laws of any state, and the equivalent laws of any other country, such as the United Kingdom Computer Misuse Act 1990 and the laws implementing the EU Directive on attacks against information systems.
In particular, you may not:
If you discover a vulnerability in the Service, tell us at [email protected] before you disclose it to anyone else and give us a reasonable time to fix it. Our security disclosure page at /security describes what is in scope, how to report, and the conditions under which good-faith research is not treated as a breach of this Policy (see section 9.1). We do not run a bug bounty programme.
Do not access, or attempt to access, other customers' accounts or data, and do not run scanning, automated attacks or load tests against our production systems outside the scope that /security describes. Section 9 applies to our infrastructure.
You may not use the Service to generate invalid traffic or to deceive any advertiser, publisher, ad network, affiliate network, attribution provider or measurement service. This prohibition applies whether you are paid for the traffic, whether the activity is automated or manual, and whether you act for yourself or for a client.
Prohibited conduct includes:
You may not use the Service to:
Profiles can hold cookies, sessions, saved logins and browser storage, and cloud sync moves those archives to our storage. If a profile contains personal data about people other than you, you are the controller of that data and you are responsible for it. You may not use the Service to collect, store, sync, share or otherwise process personal data of other people unless you have a lawful basis to do so under the data-protection laws that apply to you and to those people, such as the EU and UK GDPR, the California Consumer Privacy Act and similar laws.
In particular, you may not use the Service to build profiles of individuals from data they did not give you, to import cookies or sessions that belong to another person without their permission, or to share a profile with someone who is not entitled to see the data it contains. Our own handling of the data we hold about you is described at /privacy.
You may not use the Service if you are, or you act for, a person or entity that is the subject of sanctions administered by the United States (including the OFAC Specially Designated Nationals list), the United Nations, the European Union or the United Kingdom, or if you are located in or ordinarily resident in a country or region that is subject to a comprehensive US embargo. You may not use the Service, including proxies purchased through the marketplace, to provide services to, or to access platforms on behalf of, any such person, entity or jurisdiction.
Any export-control or sanctions provisions in the Terms at /terms also apply to your use of the Service. If those provisions and this section differ, the Terms govern.
The following apply to the Service, its software and its infrastructure, rather than to the platforms you visit through it. You may not:
Good-faith security research that complies with our security disclosure page at /security is not a breach of this section or of the reverse-engineering restriction, to the extent the research stays within the scope that page describes.
Proxies purchased through the in-app marketplace are third-party allocations that we resell. When you buy one, you must also comply with the acceptable use terms of the provider that fulfils it (currently DataImpulse or Oxylabs). The provider receives a pseudonymous identifier derived from your account id so it can attach the allocation to you; we never send it your name or email. Everything in this Policy applies to traffic you send through a marketplace proxy or through any proxy you configure yourself.
In addition, you may not use a proxy obtained through the Service to hide the origin of activity that this Policy prohibits, to attack or scan the proxy provider's or anyone else's network, or to send traffic that causes the provider to suspend the allocation. Allocations are non-refundable once delivered, and if a provider terminates an allocation because of your conduct, you are not entitled to a refund or replacement; see /refund.
A team workspace lets an owner invite members as seats at no charge. A seat may only open profiles that the owner has shared into the workspace; every member sees the same shared set. Profiles can also be shared directly from one user to another, with view-only or launch permission as the owner chooses.
The owner of a team account is responsible for every seat in it and for everything done through profiles that the team shares. This means the owner must ensure that each member has read and complies with this Policy, that profiles are only shared with people entitled to operate the accounts they contain, and that access is removed promptly when a member leaves. A breach of this Policy by a seat is treated as a breach by the owner, and we may suspend or terminate the whole team account in response.
When you share a profile directly with another user, whether with view-only or launch permission, you are responsible for making sure that person is permitted to see or use the accounts and data inside it, and you remain responsible for that profile's use until you revoke the share.
The desktop app exposes a local REST API on your own machine, protected by a bearer token that is generated on that machine and stays there. That local token is separate from the API tokens you can issue in the web dashboard, which authenticate calls to our cloud API and are stored against your account with the time they were last used. Automation does not change what is permitted. Anything you may not do by hand under this Policy you may not do through either API, through a script, or through third-party automation tools connected to it.
Keep both kinds of token private. If the local API token is exposed, regenerate it from the app's API settings, which invalidates the old token.
If you believe someone is using JustBrowser in breach of this Policy, or that the Service is being used to harm you or your platform, email [email protected]. This address is monitored by Velocity Digital Labs LLC.
To help us act, include as much of the following as you can: what you observed, when it happened, the platform or system affected, any account names, email addresses, IP addresses or other identifiers involved, and any evidence you are able to share. We may not be able to act on a report that gives us nothing to match against our records.
We do not collect browsing history or page content from inside profiles and we do not open synced profile archives, so we usually cannot see what a user did on your platform. What we can do is match the identifiers you give us against our account, registration, device-session, team, billing and proxy-marketplace records and the profile summaries described in the Privacy Policy at /privacy, and act on our own account. A profile summary tells us a profile's name, settings and the sites it holds saved logins for, not what was done on those sites.
We may investigate any suspected breach of this Policy. Where we reasonably believe a breach has occurred or is likely, we may take any of the following actions without prior notice, in our discretion:
We may disclose account information (including the IP address, user agent and email address logged when the account was registered), desktop device session records (IP address, user agent, device name and operating system, app version and last-seen time), billing and proxy-marketplace purchase records, API token records, team and sharing records, the profile summaries described in the Privacy Policy and support correspondence in response to a subpoena, court order, warrant or other lawful request, or where we believe in good faith that disclosure is necessary to prevent harm, protect our rights or comply with the law. Where the law permits and it is practical, we may tell you before we disclose. Synced profile archives are encrypted at rest and we do not open or read them in the ordinary course; details of what we hold, including the profile summary stored alongside each archive, and how long we keep it are at /privacy.
You are responsible for the consequences of your use of the Service, including any account bans, loss of access, financial loss or legal claims that result from activity that breaches this Policy or a platform's rules. The limitation of liability and indemnity provisions of the Terms at /terms apply.
We may update this Policy as the Service, the law and the platforms our customers use change. When we do, we will post the updated version at /acceptable-use with a new "last updated" date and, for changes that narrow what you may do or reduce your rights, notify account holders by email before they take effect. A change takes effect on the date shown on the updated Policy, or on any later date stated in the notice. Continued use of the Service after a change takes effect means you accept the updated Policy.
The notice period in the Terms at /terms applies to changes to the Terms themselves; changes to this Policy are notified as this section states.
Velocity Digital Labs LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, USA.
Abuse reports, legal notices and questions about this Policy or the Terms: [email protected]. Privacy questions and data-subject requests: [email protected]. To delete your account, email [email protected] from the address on the account; we delete your data within 30 days except where law requires retention. Refunds: see /refund; refund requests go to [email protected]. Security vulnerabilities in the Service: [email protected]; see /security.
We'd like to use Google Analytics, a Google service, to understand how our website is used. It sets two cookies in your browser and runs only if you click Accept. You can change your choice at any time with Cookie settings. Cookie Policy
Sign-in cookies and the cookie that remembers this choice are always on; the website needs them to work.
Google Analytics, a Google service, helps us understand how our website is used. It sets two cookies, _ga and _ga_TVZHQ99TZW. It is now onoff in this browser. If your browser sends a Global Privacy Control or Do Not Track signal, it stays off. Cookie Policy