1. Operator and agreement
Metarabbit is operated by James O’Reilly, a sole trader trading as Zumi Studios, CRO business-name registration 738695 (“Zumi Studios”, “Metarabbit”, “we”, “us” or “our”).
These Terms form a contract between us and the person or organisation using Metarabbit (“you”). You accept them when you expressly accept version 1.0 in the application or otherwise use the service after being asked to accept them. You must be at least 18. If you use Metarabbit for an organisation, you confirm that you have authority to bind it.
Our documentation, the plan and price shown at checkout, and the Data Processing Schedule below also form part of the contract. If they conflict, the checkout terms control price and plan limits, the Data Processing Schedule controls processing of customer personal data, and these Terms control everything else.
2. The service
Metarabbit accepts public HTTP or HTTPS URLs and returns structured page information such as titles, descriptions, favicons, Open Graph tags, and X/Twitter Card fields. When requested and included in your plan, it may also extract readable text and generate an AI summary. Public page information may be cached briefly, and a public preview image may be copied temporarily to our CDN.
Metarabbit is a technical intermediary. It does not publish, endorse, or take ownership of the target page. Page information and summaries can be incomplete, inaccurate, outdated, or removed by the publisher. You should check important output before relying on it.
3. Accounts and API keys
You must provide accurate account information, keep it current, and protect your Clerk account and API keys. API keys are confidential credentials: do not put them in browser code, public repositories, logs visible to others, or client applications where they can be extracted. Usage under a key is attributed to its organisation until the key is revoked.
Tell us promptly if you suspect unauthorised access. We may revoke a compromised key to protect you, publishers, and the service. You are responsible for people you authorise to use your organisation, subject to rights and remedies that cannot lawfully be excluded.
4. Acceptable use
You may integrate Metarabbit into your own products, services, and internal workflows. You must not:
- share, expose, sell, or transfer an API key outside your authorised team;
- evade quotas, publisher blocks, robots.txt, access controls, or security measures;
- submit private, sensitive, unlawful, or unauthorised content or attempt to reach private networks;
- use the service for malware, harassment, surveillance, infringement, privacy abuse, or unlawful discrimination;
- interfere with the service, probe it without permission, or impose an unreasonable load; or
- resell a substantially identical standalone metadata or summarisation API without our written permission.
You are responsible for having a lawful reason to submit each URL and for complying with applicable law, publisher terms, and intellectual-property and privacy rights. Ordinary commercial uses such as link previews, feeds, bookmarks, directories, publishing tools, and internal automation are permitted.
5. Automated fetching and publisher rights
Our crawler identifies itself as MetaRabbitBot and links to this section. Before a page is fetched or served from cache, Metarabbit checks the publisher's robots.txt rules for MetaRabbitBot, falling back to the * group. A disallow rule is respected. Temporary robots.txt failures fail closed, so the page is not fetched while the publisher's preference is uncertain.
We fetch only public HTTP(S) pages and block local and private-network targets. Public metadata and readable text are cached for up to 24 hours. Request records and copied preview images are retained for up to 30 days. A publisher or authorised domain representative may ask us to remove known cached/request data and block the verified origin. We verify control using DNS or a domain-associated contact before applying an origin-wide block.
Submit a publisher request through the form below or email support@zumistudios.com. Include the domain, your relationship to it, and the action requested. Good-faith rights and security reports will not be penalised.
6. Plans, billing, and cancellation
Free and paid plans have the request limits and features displayed before you choose them. Limits reset each billing period and do not roll over. We may apply reasonable technical rate limits to protect reliability. Unless we agree otherwise in writing, no service-level agreement applies.
Paid subscriptions are priced in USD and renew monthly or annually as shown at checkout. Checkout will show the total payable and any applicable tax before you place the order. Zumi Studios is not currently VAT registered and will not describe any invoice amount as VAT unless that position changes.
You may cancel at any time using the organisation billing controls or by contacting us. Cancellation takes effect at the end of the current paid period, and access continues until then. We do not normally prorate partial months or years, but this does not affect statutory withdrawal, refund, price-reduction, or defective-service rights. If we materially fail to provide a paid service and cannot fix it within a reasonable time, contact us for the remedy required by law.
7. Consumer withdrawal rights
If you are an EU/EEA consumer buying online, you will generally have 14 days from entering a paid service contract to withdraw without giving a reason. Before immediate paid access begins during that period, checkout must ask you to request immediate performance. If you then withdraw, we may charge only the lawful proportion for service supplied up to your notice. If the service has been fully supplied within the period after your express request and acknowledgement, the law may end the withdrawal right. None of this limits stronger mandatory rights.
You can withdraw using any clear written statement or this model form:
To: James O'Reilly trading as Zumi Studios, 51 Bracken Road, Sandyford, Dublin, D18 CV48, Ireland; support@zumistudios.com.
I give notice that I withdraw from my contract for the Metarabbit service. Ordered on: [date]. Consumer name: [name]. Consumer address: [address]. Signature (only if sent on paper): [signature]. Date: [date].
We will handle a valid withdrawal and any refund within the period and using the payment method required by applicable law.
8. Ownership and feedback
We and our licensors own Metarabbit, including its software, branding, documentation, and service design. We grant you a limited, non-exclusive, non-transferable right to use it during your account term in accordance with these Terms. You retain ownership of your applications, submitted URLs, configurations, and other materials you provide. Publishers and other third parties retain their rights in target-page content.
If you voluntarily give feedback, you allow us to use it to improve Metarabbit without payment or restriction, but we will not publicly identify you as its source without permission.
9. Confidentiality and data protection
Each party will protect the other's non-public business, technical, and security information using reasonable care and use it only for the contract. This does not cover information that is public without breach, already lawfully known, independently developed, or lawfully received from another source. A party may disclose information where legally required after giving notice where lawful and practicable.
Our Privacy Policy explains processing for our own purposes. Where we process personal data on your documented instructions, the Data Processing Schedule below applies.
10. Availability and service changes
We operate Metarabbit with reasonable skill and care and aim for dependable availability, but no internet service is uninterrupted. Publishers, networks, Cloudflare, Clerk, Stripe, and other dependencies may fail or change. Scheduled maintenance, security work, lawful restrictions, and events outside reasonable control can affect the service.
We may improve or change features and limits. We will give reasonable advance notice if a change materially reduces a paid plan during its current term, unless urgent security, legal, or provider action makes advance notice impracticable.
11. Suspension and termination
We may proportionately suspend affected keys, features, or an account for non-payment, material breach, unlawful use, publisher-rights abuse, or a credible security risk. We will normally explain the reason and give a reasonable opportunity to fix the issue. We may act immediately where delay would risk harm, legal non-compliance, or service security.
You may stop using the service and delete your organisation through Clerk. Deletion removes active account data, API keys, request records, and copied images, subject to records we must retain for contracts, finance, disputes, or law. Sections that by their nature should survive termination do so, including ownership, confidentiality, accrued payment obligations, liability, and dispute terms.
12. Warranties and liability
We will provide the service with reasonable skill and care. Subject to mandatory law, the service is otherwise provided on an “as available” basis and we do not promise that third-party content, extracted metadata, summaries, or uninterrupted availability will always be accurate or suitable for a particular purpose.
For business customers, neither party is liable for indirect or consequential loss, lost profit, lost revenue, lost business opportunity, or loss of goodwill that was not a direct and reasonably foreseeable result of the breach. Each party's aggregate ordinary liability arising from the service is limited to the greater of €100 or the fees you paid us in the 12 months before the event giving rise to the claim.
Those exclusions and caps do not apply to fraud, fraudulent misrepresentation, wilful misconduct, death or personal injury caused by negligence, liability under data-protection law that cannot be limited, your obligation to pay valid charges, or anything else the law does not permit us to exclude. If you are a consumer, these Terms do not exclude or restrict mandatory statutory rights or remedies, including rights relating to conformity of digital services.
13. Business indemnity
This section applies only if you use Metarabbit for a trade, business, craft, or profession. You will indemnify us against a third-party claim to the extent it results from your knowing unlawful use, infringement through material you provide, or material breach of section 4. We must promptly notify you, allow you reasonable control of the defence and settlement, and provide reasonable cooperation at your cost. You may not settle in a way that admits fault by us or imposes a non-monetary obligation on us without consent. This section does not cover loss caused by us.
14. Changes to these Terms
We may update these Terms as the service, providers, or law change. We will post the new version, preserve earlier versions, and give at least 30 days' email notice before a materially adverse change takes effect where practicable. Urgent security or legal changes may take effect sooner. Where law or the nature of a change requires fresh agreement, we will ask you to accept the new version before continuing to use the service.
15. Law and disputes
Please contact us first so we can try to resolve a concern fairly. For business customers, Irish law governs the contract and the courts of Dublin, Ireland have exclusive jurisdiction. Consumers keep the benefit of mandatory law and court rights in their country of residence. Nothing in these Terms prevents either party seeking urgent injunctive relief or using a regulator or statutory dispute process available to them.
16. Contact and complaints
Write to James O’Reilly trading as Zumi Studios, 51 Bracken Road, Sandyford, Dublin, D18 CV48, Ireland, or email support@zumistudios.com. The email address and enquiry form are monitored on business days and we aim to reply promptly. If you lose internet access after contacting us electronically, you may use the postal address.
17. Data Processing Schedule
17.1 When this schedule applies
This schedule applies where you are a controller (or processor acting for another controller) and Zumi Studios processes personal data in submitted URLs, public-page content, or API output on your behalf. For GDPR purposes you are the controller and we are the processor, unless the law assigns different roles for a particular activity.
17.2 Processing details
| Subject matter and purpose | Retrieving public pages, extracting metadata/readable text, optionally summarising it, returning results, securing the API, and providing transient caches. |
|---|---|
| Duration | For the service term and the documented retention periods: page cache up to 24 hours and request/result/copied-image data up to 30 days, unless earlier deletion or lawful retention applies. |
| Nature of processing | Collection, transmission, retrieval, parsing, structuring, optional AI inference, temporary storage, disclosure back to you, and deletion. |
| Personal-data types | Submitted URLs, public webpage text and metadata, names or identifiers appearing in public content, API results, request identifiers, timestamps, and security logs. |
| Data subjects | Your users and personnel, webpage authors or subjects, and other people whose information appears on a submitted public page. |
17.3 Instructions and controller obligations
We will process this data only to provide and secure Metarabbit, in accordance with your documented use of the API and these Terms, unless EU or Member State law requires otherwise. If legally allowed, we will tell you before processing required by law. You are responsible for lawful instructions, transparency to data subjects, an appropriate legal basis, responding to publisher restrictions, and avoiding unnecessary sensitive or private data. We will tell you if an instruction appears to infringe applicable data-protection law.
17.4 Confidentiality and security
People authorised to process customer data are subject to confidentiality. We maintain measures appropriate to the risk, including TLS, hashed API-key storage, authentication and access controls, local/private target blocking, robots.txt and verified publisher blocks, bounded fetch sizes and timeouts, segregated bindings, limited retention, deletion jobs, and operational logging. No system is completely secure, and measures may evolve while maintaining an appropriate level of protection.
17.5 Subprocessors and transfers
You give general authorisation for the subprocessors listed in the Privacy Policy, currently Cloudflare for hosting, storage, AI inference, Turnstile, and transactional email; Clerk for identity and subscription management; Stripe for payment processing; and Google Workspace for support email. We remain responsible for their data-protection obligations to the extent required by law. We will give reasonable advance notice of a material new subprocessor where possible so you can raise a substantiated data-protection objection. Protected international transfers use an applicable adequacy decision, Data Privacy Framework, standard contractual clauses, or another lawful safeguard.
17.6 Assistance and incidents
Taking account of the processing and information available to us, we will reasonably assist with data-subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. We will notify you without undue delay after becoming aware of a personal-data breach affecting data we process for you and provide available information needed for your obligations. Assistance beyond ordinary service information may be charged at a reasonable agreed rate where the law permits.
17.7 Deletion, return, and audit information
At the end of the service, we will delete or return processor data at your choice where technically available, except where law requires retention. Normal automated deletion follows the periods above; active account deletion removes request records and copied images earlier. We will provide information reasonably necessary to demonstrate compliance, including current security and subprocessor information. No more than once annually, unless an incident or regulator reasonably requires more, you may request a proportionate audit. Audits must protect other customers, confidentiality, and security and should use existing reports before an onsite inspection.
Questions about this schedule can be sent to support@zumistudios.com. The current public Terms are always available at https://www.metarabbit.dev/terms.

