Skip to content

New Official SDKs for TypeScript, Python and Go

SerpKite
Get API key

How we collect data

People ask whether a SERP API is legal. Our honest answer: collecting public, logged-out search results is widely done and has favorable case law in the US, but it isn't risk-free, and the law is moving. So here is exactly what we do and don't do. This page is not legal advice.

What we collect

The public search results page that anyone sees on the open web without an account, for the query, country and language you request: titles, links, snippets, and the page's public features such as People Also Ask, news, maps listings and shopping results. For /webpage and include_content, the public HTML of the page you ask for, converted to Markdown.

Our rules

  1. Logged-out only. We never use Google accounts (or any account) for collection, never accept a search engine's terms with collection infrastructure, and never collect anything behind a login, paywall or access control.
  2. No crawler impersonation. We never identify as Googlebot or any other search crawler. We render public pages the way a standard browser does.
  3. Only what the page shows. We return the title, link and snippet the results page displays, not the full content of the underlying sites, unless you explicitly ask us to fetch a public page.
  4. No re-hosting of licensed content. We return image URLs, not copies of images. We don't re-host Knowledge Panel images, and we don't offer bulk extraction of licensed content (such as Reddit threads) through search results.
  5. Proxies, never our own servers. Every request to a search engine goes out through proxy providers, never directly from our servers or from Cloudflare.
  6. Consented proxy sources. We only use reputable proxy vendors that give written attestations that their IPs are ethically sourced with user consent, and we use more than one. We don't use "SDK botnet" pools.
  7. Rate discipline. We deduplicate identical queries with short-lived caching and never generate synthetic traffic.
  8. No query logs. We never log your query text. Results are cached briefly under a hashed key, and usage metadata is kept for 31 days. Details in the Privacy Policy.

Where the law stands (September 2026)

  • hiQ v. LinkedIn and Meta v. Bright Data: scraping public, logged-out pages carries low risk under the CFAA and contract claims; logged-in or account-based scraping carries high contract risk. That's why rule 1 exists.
  • Google v. SerpApi (N.D. Cal.): filed December 19, 2025 under DMCA §1201. Dismissed on July 20, 2026; claims over non-copyrighted results were dismissed with prejudice. Google's amended complaint of August 10, 2026 focuses on licensed content. That's why rule 4 exists.
  • Reddit v. SerpApi, Oxylabs, AWMProxy and Perplexity (S.D.N.Y.): motions to dismiss mostly denied on July 31, 2026; the case proceeds to discovery.

We track these cases and will update this page as they develop. A longer write-up is on the blog.

What we don't claim

We don't claim immunity, and we don't offer a "legal shield". If we ever offer an indemnity, it will be capped and backed by an insurer, and we'll say exactly what it covers. We are not affiliated with Google or any other search engine.

Your part

You decide what to search for and what to do with results. Follow the Acceptable Use Policy: no resale, no people-search that harms individuals, no republishing of copyrighted content, no attempts to reach content behind a login. If your results include personal data, data protection law applies to your processing.

Questions and reports

Legal questions or concerns about collection: [email protected]. Rights holders who want to raise an issue can reach us at the same address.

Last updated: 3 October 2026