API Terms of Use
The Insitive API is licensed for individual property lookups inside your own product or workflow. It is not a way to obtain a copy of our data. These terms say plainly what that means, what you may cache, and what we will do if a key is used to enumerate or mirror a dataset.
These API Terms of Use ("API Terms") govern programmatic access to the property intelligence services operated by Applied AI Pty Ltd (ABN 90 668 168 830, ACN 668 168 830), trading as Insitive ("we", "us"), including the endpoints served from https://api.insitive.com.au, the sandbox at https://sandbox.insitive.com.au, and any API key issued by us ("Key"), whether an ins_live_ production key or an ins_test_ sandbox key.
Effective Date: 27 August 2026 | Version: 1.0
Relationship to our Terms of Service
These API Terms sit alongside our Terms of Service and Privacy Policy, which continue to apply. Where a term of the Terms of Service and a term of these API Terms both address programmatic access, these API Terms prevail for that access. Nothing here reduces your rights under the Australian Consumer Law.
Who is bound
Acceptance is recorded against the Insitive account that requests or rotates a Key. That account holder accepts these API Terms on behalf of the organisation the Key is used by, and is responsible for the use of every Key issued to it — including use by its own developers, contractors and end users. If you are accepting for an organisation, you confirm you are authorised to do so.
A note on this document. This is our own plain-language statement of the conditions we sell API access under. It has been written to be read by the developer doing the integration. It is not legal advice to you, and it has not been settled by external counsel; where you need certainty for a large or unusual deployment, ask us for a written agreement rather than relying on an inference from this page.
Subject to these API Terms and to payment of the fees for your plan, we grant you a limited, non-exclusive, non-transferable, revocable licence to call the API to perform individual lookups — a request about a specific property, address, parcel or locality that you have a genuine reason to look up — and to use each response inside your own product, service or internal workflow.
Uses inside the lookup licence
- Answering a question about a property a user of your product has searched for, selected, listed, transacted on, or otherwise has a real interest in.
- Enriching records in your own system for properties you already hold — your listings, your portfolio, your clients' sites, your work in progress.
- Producing a report, valuation, feasibility, quote or similar deliverable for a specific property and a specific customer, and keeping that deliverable as a record of the work.
- Displaying a response to the end user who prompted the lookup, including inside a paid product of your own, provided the attribution obligations in section 5 are met.
- Reasonable development, testing and quality assurance against your own integration, preferably using an
ins_test_sandbox key.
The test we apply is simple: each call should be traceable to a property someone actually cared about. A licence to look up properties one at a time is not a licence to acquire the dataset one call at a time.
You must not, directly or through any third party:
- Systematically enumerate. Iterate over addresses, parcel or lot identifiers, coordinates, grids, tiles, postcodes, suburbs, or any other sequence or list in order to retrieve records you have no specific reason to look up — including exhaustively retrieving a dataset, a state, a local government area, a suburb, or any other defined geographic area.
- Mirror, replicate or warehouse. Assemble, maintain or refresh a copy of any dataset we serve, or a substantial part of one, in your own store, data lake, warehouse or search index.
- Build a derived, competing or resale dataset. Use responses — alone, in aggregate, or as training, seed, validation or reference data — to produce a dataset or model that substitutes for, competes with, or is licensed, sold or otherwise supplied to others in place of, our services.
- Redistribute raw responses. Pass API responses, or bulk extracts of the data in them, to any third party — including affiliates, resellers, customers and public feeds — other than displaying a response to the end user whose own lookup produced it.
- Share, resell or sublicense a Key, use one Key to serve another organisation's traffic, or use several accounts or Keys to exceed a limit or to disguise a pattern of use that would otherwise breach these API Terms.
- Evade controls. Circumvent rate limits, quotas, authentication, metering or caching controls; strip or falsify attribution; or misrepresent the origin of the data.
Volume alone is not what we object to — a busy product makes a lot of calls, and that is what plans are for. The prohibition is on the shape of the use: retrieval that is driven by a list rather than by demand, and retention that accumulates into a copy of the source.
Third-party data
Some data we serve is licensed to us, or made available under an open-data licence, on terms that themselves restrict redistribution and bulk extraction. Breaching these API Terms can put us in breach of those upstream licences, which is why the prohibitions above are absolute rather than negotiable per call.
A real integration has to hold responses for a while. A rule that forbade all retention would be unworkable, so this section states the allowance explicitly rather than leaving you to guess where the line is.
Operational cache
You may store a response for a property you legitimately looked up, and reuse it inside your own systems, for up to 90 days from the time of the call. Within that window you may cache it, index it for your own retrieval, and serve it to the users of your product without calling us again. After 90 days, delete it or refresh it with a new call.
Work-product records
The 90-day window does not force you to destroy your own records. Where a response was used to produce a deliverable for a specific property and customer — a report, a valuation, a feasibility, a quote, an audit trail — you may retain that deliverable, and the response data embedded in it, for as long as you need it for record-keeping, professional indemnity, dispute or statutory retention purposes.
Conditions on both allowances
- The retained data stays inside your own systems and is used for the purpose it was looked up for. Retention is not a route around section 3.
- A cache that grows into a copy of a dataset, or that is populated ahead of demand, is mirroring under section 3 no matter how short its expiry.
- Data cached under the operational allowance is deleted when your access ends. Work-product records may be kept, but may not be used to serve new lookups after termination.
- Cached data can be stale.
source_freshnessin the response tells you the age of what we served; you are responsible for how long you rely on a cached answer. - Personal information in a response is subject to the Privacy Act 1988 (Cth) and our Privacy Policy. These allowances do not extend any right to retain personal information beyond what that law permits.
Parts of what we serve are derived from open government data supplied under licences that require the source to be credited — state cadastral and planning data, the Geocoded National Address File (G-NAF) under Creative Commons Attribution 4.0 International (CC BY 4.0), building footprints under the Open Data Commons Open Database License (ODbL), and others.
Where a response carries attribution, it does so in two places: the attribution and license fields in the JSON body, and the X-Insitive-Attribution and X-Insitive-License response headers. Whenever you display, publish or otherwise make that data available to your own users, you must reproduce the supplied attribution and comply with the named upstream licence. You must not remove, obscure or alter it.
The required credit differs by state and by dataset, which is why we return it per response rather than publishing one static notice for you to copy. Take it from the response.
We record and analyse API usage — request volumes, timing, the spread and sequence of the properties and areas requested, and similar patterns — to operate the service, meter it, and identify use that looks like systematic enumeration, mirroring or dataset extraction rather than genuine lookups.
Where we reasonably believe a Key is being used in breach of these API Terms, we may throttle it, suspend it, or terminate access, and we may do so immediately and without notice where the use is causing harm, risking a breach of an upstream data licence, or extracting at scale. Otherwise we will contact you first and give you a reasonable opportunity to explain or correct the use.
We may also require you to delete data obtained in breach of these API Terms and to certify that you have done so. Fees already incurred remain payable; suspension for breach does not entitle you to a refund of the period suspended. A suspension decision can be reviewed by contacting us — see section 9.
Bulk extracts, dataset snapshots, statewide or area-wide coverage, feeds, redistribution rights and permission to build a derived dataset are not part of any self-service plan. They are available only under a separate written agreement with us.
Such an agreement sets the datasets, the geography, the refresh cadence, the permitted uses, the upstream licence obligations we must pass through, and the fee. If the work you have in mind needs whole-of-area data, ask us — the answer is often yes on the right terms, and it is a great deal cheaper than being throttled halfway through a crawl.
Buying a higher-volume plan does not convert a lookup licence into a bulk licence. Quota buys you more lookups, not a different permission.
Accepting these API Terms
You must accept the current version of these API Terms before we issue you a new Key or rotate an existing one through the developer portal. We record which version you accepted, when, and from where, against your Insitive account. Declining simply means no new Key is issued; it does not disturb a Key you already hold.
Keeping a Key secure
- A Key secret is shown once, at creation. We store only a hash and cannot recover it — rotate if you lose it.
- Keep Keys out of client-side code, public repositories and shared documents.
- Tell us promptly if a Key is exposed. You are responsible for calls made with your Key until it is revoked.
Changes to these API Terms
We may publish a new version of these API Terms. Each version carries its own version number and effective date, shown at the top of this page. Material changes will be notified to the email address on your account, and you will be asked to accept the new version the next time you visit the developer portal or issue or rotate a Key. Continuing to call the API after a new version takes effect means you accept it.
Availability
We aim for high availability but do not warrant uninterrupted service. Current availability, per-dataset coverage and incident history are published at insitive.com.au/status. Breaking API changes ship as a new major version with a minimum 12-month deprecation window.
Data accuracy
API responses are supplied for information. They are assembled from government and third-party sources and from our own modelling, and are not a substitute for a title search, a survey, a planning certificate or professional advice. Our Property Data Disclaimer applies to data obtained through the API.
Liability
The limitation of liability in our Terms of Service applies to API access. To the maximum extent permitted by law, our total liability for any claim relating to the API does not exceed the API fees you paid us in the twelve months before the claim. Nothing in these API Terms excludes, restricts or modifies any guarantee, right or remedy that cannot be excluded under the Australian Consumer Law.
Governing law
These API Terms are governed by the laws of Victoria, Australia, and you submit to the exclusive jurisdiction of the courts of Victoria.
Contact
Questions about these API Terms, a suspension, or a written agreement for bulk access: admin@insitive.com.au.