Skip to content

New Official SDKs for TypeScript, Python and Go

SerpKite
Get API key

Is scraping Google legal? How SerpKite collects data

Where the law stands in September 2026 (Google v. SerpApi, Reddit v. SerpApi, hiQ, Meta v. Bright Data), what's still unsettled, and the rules SerpKite follows. Not legal advice.

SerpKite team 3 min read

On this page

“Is it legal?” is one of the first questions people ask about any SERP API, and it should be. This post is our honest answer: what courts have said, what’s still open, and exactly how we collect data.

Not legal advice

We’re an engineering team, not your lawyers. This is a summary of public cases as of late September 2026 and of our own practices. If your use case carries legal risk, talk to counsel.

The short answer

Collecting publicly available, logged-out search results is widely done and has some favorable case law in the US. It is not risk-free, and the law is actively moving. The riskiest areas are collecting content behind a login and redistributing licensed copyrighted content that appears in results.

What the cases say

hiQ v. LinkedIn and Meta v. Bright Data are the precedents people cite most. Broadly, they suggest that scraping public, logged-out pages carries low risk under the US Computer Fraud and Abuse Act and contract claims, while logged-in or account-based scraping carries high contract risk, because you’ve agreed to terms.

Google v. SerpApi (N.D. Cal.), filed December 19, 2025, alleged circumvention of Google’s anti-bot system under DMCA §1201. On July 20, 2026 the court dismissed it. Claims about non-copyrighted results (titles, links, snippets) were dismissed with prejudice. The court did find Google had standing and had plausibly alleged circumvention, and allowed an amendment. Google’s amended complaint, filed August 10, 2026, focuses on licensed content such as Knowledge Panel images and content Google licenses from Reddit. A hearing on SerpApi’s second motion to dismiss is expected around October 13, 2026. SerpApi operates normally; there is no injunction.

Reddit v. SerpApi, Oxylabs, AWMProxy and Perplexity (S.D.N.Y.): on July 31, 2026 the motions to dismiss were mostly denied, and the DMCA §1201 and civil-conspiracy claims are proceeding to discovery. Notably, proxy providers were named too.

So two federal courts are currently leaning in different directions. Plain SERP facts look well protected in one district; extracting licensed content via search results is a live risk in the other.

How SerpKite collects data

These are operating rules, not marketing copy:

  1. Logged-out only. We never use Google accounts for collection and never collect anything behind a login.
  2. Public results page only. We return what a logged-out visitor sees: titles, links, snippets and the page’s public features.
  3. No crawler impersonation. We never pretend to be Googlebot or any other crawler. We render public pages like a standard browser.
  4. Licensed-content carve-outs. We return image URLs, not re-hosted images. We don’t re-host Knowledge Panel images, and we don’t offer “extract Reddit threads through Google”.
  5. Proxies, from consented sources. Requests go out through proxy providers, never directly from our servers or from Cloudflare. We use reputable vendors with written sourcing and consent attestations, and more than one of them.
  6. Rate discipline. Identical queries are deduplicated with short-lived caching. We don’t generate synthetic traffic.
  7. No query logs. We never log your query text. Results are cached for a few hours under a hashed key, and usage logs keep metadata only, for 31 days.

What we ask of customers

Our Acceptable Use Policy prohibits reselling the raw service as a competing search engine, multi-accounting, and any illegal use, including people-search for stalking or harassment. You are responsible for how you use results; for example, if you store snippets that contain personal data, GDPR applies to you.

What we don’t claim

We don’t offer a “legal shield” and we won’t advertise one until an insurer backs it. We’d rather tell you precisely what we do and don’t do, and let you and your counsel judge the risk.

The canonical version of this policy lives at How we collect data. Security practices are on the security page.

Related posts

3 min read

Introducing SerpKite

A Google search API built for AI agents: clean JSON or Markdown, official TypeScript/Python/Go SDKs, native LangChain, CrewAI and MCP, and credits that never expire.

Start building

Get your API key in 30 seconds

2,500 free credits, then 1,000 every month. No credit card.