Skip to content

Now in the official shadcn registry directory.

Start free

Acceptable Use Policy

What you may and may not do with the ai2 site, registry, MCP server and tools.

Last updated: 2026-07-24Version 1.1

1. Scope

This Acceptable Use Policy ("AUP") sets out the conduct that is permitted and prohibited when you access or use the ai2 website at ai2.design, together with the open-core component registry, the documentation, the MCP server for AI agents, the free tools we provide (including the Extractor, the Theme Generator and the Inspiration Gallery), and the paid surface: checkout, licence keys, the licence portal and the delivery of paid downloads (collectively, the "Service").

The Service is operated by BEY AGENCY LTD ("we", "us" or "our"), a private limited company registered in England and Wales under company number 16435596, whose registered office is at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

This AUP forms part of, and should be read together with, our Terms of Service. A breach of this AUP is a breach of the Terms of Service and may lead to the consequences described in section 8. The version identifier and the date of last update are shown at the top of this document.

This AUP applies to every user of the Service, whether a human visitor, an organisation or an automated client such as an AI agent, and whether or not you have created an account.

2. General prohibited conduct

You must not use the Service, and must not allow or enable any other person to use the Service, to do any of the following:

  • Engage in any activity that is unlawful, fraudulent or tortious, or that breaches any applicable law or regulation in England and Wales or in any jurisdiction from which you access the Service.
  • Infringe the intellectual property, privacy, publicity, confidentiality, trade-secret or other rights of any third party, or submit material you do not have the right to submit.
  • Distribute, host, link to or execute malware, viruses, worms, trojans, ransomware, phishing payloads or any other harmful or malicious code.
  • Harass, threaten, defame, stalk or otherwise harm any individual, or send unsolicited commercial communications (spam) through or by reference to the Service.
  • Deceive or mislead others, including by falsifying headers, forging identifiers or misrepresenting your identity or the origin of a request.
  • Misrepresent any affiliation with, sponsorship by or endorsement from ai2 or BEY AGENCY LTD, or use our names, marks or branding in a way that suggests such a relationship where none exists.
  • Exploit, endanger or attempt to solicit any person under the age of eighteen.
  • Share, publish, sell, lend or otherwise make a paid licence key available beyond the seats your plan covers. The key is a credential rather than a coupon: anyone holding it can reach your downloads, and use beyond your seat count falls outside the licence granted to you.
  • Redistribute, rehost, resell or publish a paid product you obtained through a licence, or circulate a download link or remix link we sent you. Those links are issued to you personally and are not for onward distribution.
  • Automate or bulk-request downloads, or attempt to exceed or evade the download quota described in section 5, including by rotating IP addresses, using multiple licence keys or distributing requests across clients.
  • Attempt to guess, brute-force or validate licence keys that were not issued to you, or probe the licence portal, checkout or download endpoints for keys, orders or customer data belonging to anyone else.

3. Registry and API use

The component registry is provided free of charge and is served in the shadcn registry format, installed by consumers through the shadcn command line tool (for example, npx shadcn add @ai2/<name>) or through the MCP server. You may use the registry for its intended purpose, namely installing and using the components in your own projects under the applicable licence.

In connection with the registry and any related endpoints you must not:

  • Access the registry other than through the intended installation flow, or use automated means to abuse, overload or degrade the endpoints.
  • Scrape, harvest, mirror or systematically download registry content at scale, or issue volumes of requests beyond what normal installation requires.
  • Resell, sublicense, rehost or republish the free registry, in whole or in substantial part, as your own kit, catalogue or competing repository.
  • Circumvent, disable or interfere with any security measure, authentication step, rate limit or other technical protection applied to the registry or its endpoints.
  • Probe, scan or test the vulnerability of the registry, or breach or attempt to breach its security, except under the responsible-disclosure route described in section 7.

4. Extractor input rules

The Extractor accepts a public URL that you submit, loads it in a headless browser and returns design tokens. Results are held for a limited period at a private link and then deleted. Because the Extractor fetches and renders the target you provide, the following rules are strict conditions of use.

You may submit a URL to the Extractor only if all of the following are true:

  • The URL points to publicly accessible content that you have the right to analyse.
  • The target does not require authentication, a login, a session or any credential that you do not lawfully possess.
  • The target is not private, internal or otherwise restricted, and is not an intranet host, a localhost or loopback address, a link-local or cloud-metadata endpoint, or any other non-public or internal network resource.

You must not use the Extractor to facilitate infringement of any third party's rights, to bypass an access restriction or paywall, or to probe, scan, overload or attack any third-party system. We may refuse, throttle, block or delete any request or result at our discretion, and we may decline to process a target we consider unsuitable or unsafe.

5. Rate limits and fair use

The free tools are subject to fair-use limits so that the Service stays available to everyone. The Extractor is rate-limited on a per-IP basis to roughly two runs per rolling twenty-four hours, and extraction results are retained for approximately two hours at a private link before deletion. Paid downloads carry their own limit, currently twelve downloads per rolling twelve hours, counted against your licence rather than your IP address so that a shared office connection does not consume someone else's allowance. Checkout, licence validation, the subscribe form and the contact form are rate-limited too, at levels we tune against abuse rather than publish.

You must not bypass, or attempt to bypass, any rate limit, session limit or anti-abuse measure, whether by rotating IP addresses, distributing requests across clients or any other technique. We may adjust the limits and retention periods at our discretion and without notice in order to protect the reliability and security of the Service.

6. AI agents and automated clients

The MCP server and the registry are designed to be used by AI agents and other automated clients. If you operate such a client, you are responsible for its behaviour and you must ensure it complies with this AUP.

  • Identify your client honestly, and do not forge, spoof or omit identifying information in order to disguise automated traffic.
  • Respect the rate limits, fair-use expectations and any published guidance on request volume and frequency.
  • Do not use an automated client to scrape at scale, to circumvent protections, or to place load on the Service beyond what the intended use requires.
  • Ensure that any content your client submits, including any URL sent to the Extractor, complies with the rules in sections 2 and 4.

7. Security research and responsible disclosure

We welcome good-faith security research. If you believe you have found a vulnerability, please report it privately to hi@bey.agency with enough detail for us to reproduce and assess it, and allow us a reasonable period to investigate and remediate before any public disclosure.

Good-faith research does not permit live exploitation. You must not access, alter, delete or exfiltrate data that is not yours, degrade or disrupt the Service, run automated scanning that affects availability, or use a finding for any purpose other than reporting it to us. Testing must stay within the minimum needed to demonstrate the issue.

8. Consequences of violation

We may investigate suspected breaches of this AUP and respond in the manner we consider appropriate and proportionate. Depending on the seriousness of the breach, our response may include one or more of the following:

MeasureWhen it may apply
WarningA first or minor breach where we consider that notice is sufficient to bring conduct back into compliance.
ThrottlingReducing your request rate or limiting access to a tool where usage is abusive, excessive or degrades the Service for others.
SuspensionTemporarily blocking access to some or all of the Service while we investigate or await your remediation.
TerminationPermanently withdrawing access to the Service for a serious, repeated or unremedied breach.
ReferralReporting conduct to the relevant authorities and cooperating with law enforcement where the breach may be unlawful.

We are not obliged to warn you or to give notice before acting, and we may act immediately where a breach is serious or where the security or reliability of the Service is at risk. Nothing in this section limits any other right or remedy available to us at law.

9. Reporting violations

If you become aware of conduct that breaches this AUP, please report it to hi@bey.agency with "AUP report" in the subject line. Please include enough detail for us to identify and assess the conduct, such as the relevant URL, request or account and a description of what occurred.

10. Changes to this policy

We may update this AUP from time to time to reflect changes in the Service, in our practices or in applicable law. The current version, together with its version identifier and date of last update, is always published at this page. Your continued use of the Service after a change takes effect constitutes acceptance of the updated AUP.

11. Contact

This AUP is issued by BEY AGENCY LTD, a company registered in England and Wales under company number 16435596, whose registered office is at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

For questions about this AUP, to make a report or to reach us on any other legal matter, contact hi@bey.agency or hello@ai2.design. This AUP and any dispute or claim arising out of or in connection with it are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Operator and legal contact

ai2 (ai2.design) is operated by BEY AGENCY LTD, a private limited company registered in England and Wales (company number 16435596), registered office 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

Questions about this document can be sent to hi@bey.agency or hello@ai2.design. Both addresses reach the same team.

Go to contact
Other policies