跳到主要内容
Supermarket
返回能力市场
MCP Server
data
Apache-2.0

Douyin_TikTok_Download_API

🚀 抖音、TikTok 数据采集与无水印视频下载 API,自托管,支持 MCP 调用与 Docker 一键部署。| Self-hosted TikTok & Douyin scraper and no-watermark video downloader — async REST API, MCP server, CLI and web console for posts, profiles, comments and playlists. Self-healing identity pool, PostgreSQL archive, one docker compose up.

Evil0ctalEvil0ctal
92/ 100

公开评测 · 综合采用结论

证据充分,整体质量与安全表现优秀

查看评测依据 评测我的项目基于公开项目证据,非安全认证或安装推荐
20.4kstars
2.8kforks
最近更新 1天前
评测生成时间(北京时间)
本报告引擎
v3.14.0
当前引擎
v3.16.0

本报告与当前引擎使用不同规则;原分数不会自动更新,不同版本的分数不宜直接对比。

重新评测此项目

进入后确认来源与额度,提交才会创建任务。

Evaluation report

综合采用结论

92
A+
满分 100
值得推荐低风险
决策摘要

证据充分,整体质量与安全表现优秀

100%
高置信度
100
文档
100
安全
85
质量
100
活跃
65
采用
  • 基础评测完成+25/25确定性评分与静态安全扫描已完成
  • README 有效证据+25/2523,721 个去重后的有效字符
  • 独立证据来源+20/206 类非重复证据,重复文件不叠加
  • 仓库元数据+10/10已取得仓库状态与采用数据
  • 活跃记录+5/5已取得最近提交时间
  • AI 复核+15/15已完成结构化 AI 证据复核
How it works · 架构图

DTK 多入口与共享服务层

README 以组件与依赖关系描述 REST/MCP/CLI 共用 services 层,无明确时序,故用架构图

AI 提取 · 证据约束

左右滑动查看完整图示

DTK 多入口与共享服务层README 以组件与依赖关系描述 REST/MCP/CLI 共用 services 层,无明确时序,故用架构图调用选身份与限流发起请求归档解析结果控制台/REST/MCP/CLI入口services 业务层共享逻辑调度与身份池选择与限流抖音/TikTok 适配平台端点PostgreSQL+Redis归档与缓存
图示依据
  • • README 项目布局:src/dtk/services 为 REST、MCP 与 CLI 共享的业务层
  • • README 表格:REST、MCP、CLI 均基于同一 service layer
  • • README v4/v5 对比:PostgreSQL + Redis 归档所有解析结果
五维表现
自托管抖音/TikTok采集与无水印下载,REST/MCP/CLI/控制台四入口,能力矩阵与部署步骤具体;最大缺口是端点参考不在文档内、需自建实例查看,且无独立最小调用示例。
质量证据
  • README「What it can fetch」表:Douyin 的 Followers/Following 标 ❌,并说明未注册该端点
  • Quick start 给出 `docker compose -p dtk -f docker/compose.yml up -d` 与 `logs api` 打印 setup token
  • 「Where you get」表列出 REST `/api/v1/...` 93 operations、MCP `/mcp`、CLI `dtk --help`
  • 「Documentation」段声明端点参考不在 documents/,需在实例 `/docs`、`/swagger`、`/openapi.json` 查看
  • 「Updating」段声明 migrations 无自动 downgrade,升级前须备份数据库
采用建议
优势
  • 问题与用途描述
  • 有效 README
  • 安装或接入步骤
  • 可执行示例
  • 未发现已知高风险模式
关注点
  • 端点参考不在 documents/ 内,需访问自建实例的 /docs 或 /swagger 才能看到参数
  • README 未给出可直接复制的 REST/MCP 调用示例(仅描述 /api/v1/... 与 /mcp)
  • MCP 客户端配置细节指向 /mcp-guide,README 本身未展示配置片段
  • 无自动降级迁移,回滚需自行备份数据库
适合

需要自托管、无配额限制的抖音/TikTok 数据采集与归档、希望以 MCP 方式让 AI Agent 调用采集能力的开发者、需要无水印视频/图集批量下载与作者级批量采集、愿意用 Docker Compose 部署并自行运维 Postgres/Redis 的团队

不建议直接用于

需要 Bilibili 采集的用户(v5 已移除该平台)、不想自建实例、只想直接调用公开 API 的轻量使用者(演示站明确不可依赖)、无法提供 PostgreSQL 17+TimescaleDB 与 Redis 8 环境的场景

也有自己的公开项目?先看完证据,再用当前规则生成独立报告。

评测我的项目 →
文档证据
100/100
问题与用途描述10 分
有效 README12 分
安装或接入步骤14 分
可执行示例16 分
输入、参数或工具说明11 分
输出或结果说明9 分
限制、权限或边界12 分
错误处理或排障8 分
许可证信息5 分
结构化章节3 分
安全证据
低风险
未发现已知高风险模式

静态扫描不是安全保证,生产接入前仍应人工复核权限和数据边界。

方法、证据与局限展开
数据来源

GitHub Repository API

扫描范围

7 个文件 · 49,823 字符

评测引擎

v3.14.0 · AI 复核已启用(deepseek-flash)

局限
  • 静态评测不会安装或执行项目代码
  • 安全扫描基于高信号文件与已知模式,不能替代人工审计
  • 流行度只反映采用程度,不代表安全或工程质量

30 天热度趋势

README

Douyin_TikTok_Download_API

Douyin_TikTok_Download_API

English | 简体中文

🚀 A self-hosted data API for Douyin and TikTok. One docker compose up, an identity pool that maintains itself, and a REST API, MCP server and web console on top.

Open source, free, and it runs on your own machine — no signup, no quota, nobody else in the path. It fetches posts, authors, comments and search, downloads video and image albums without a watermark (it picks the clean stream the platform already publishes rather than stripping anything), and keeps what it collects in your own PostgreSQL.

GitHub license Release Version GitHub Star GitHub forks GitHub issues
CI CodeQL Last commit
Website Live demo Python MCP Docker Pulls Docker Image Size

💖 Sponsors

These sponsors paid to be here, and Douyin_TikTok_Download_API stays free and open because of it. To sponsor the project, see my GitHub Sponsors page.

TikHub.io - Global Social Data & API Marketplace

TikHub.io

Your Ultimate Social Media Data & API Marketplace

Professional data solutions for Douyin, Xiaohongshu, TikTok, Instagram, YouTube, Twitter, and more.
Real-time Data | Flexible APIs | Seamless Integration | Competitive Pricing with Discounts

Buy and sell custom APIs, services, and social media solutions on the
TikHub.io Marketplace, alongside developers, businesses and content creators.

Trusted by leading global influencer marketing and social media intelligence platforms

→ Visit TikHub.io  ·  API docs

🧩 REER — a forum for reverse engineering

REER

reer.dev

Somewhere to put what you work out. This project exists because people wrote down how a signature was built; the forum is for the next round of that — signatures, protocols, packers, anything taken apart.

Free, no advertising, and close to no rules beyond the obvious. Bilingual, English and Chinese. Register and post; nothing is gated.

🎬 What it looks like

The DTK console: overview, identities, scheduler, playground, library, downloads, API docs and MCP

One real call: paste a link, send it, get the normalised result back. The identity pool, the scheduler and the API reference it passed through on the way are all in the same console. The interface follows the browser's language, and both are written by hand rather than machine-translated. 中文界面

Try it without installing anything

https://demo.douyin.wtf is a live instance, open to everyone. Sign in — the login page fills the demo account in for you — and use the console: the playground, the scheduler, the library, the API reference. The same account comes with an API key you can call the scraping endpoints with, shown in plaintext on the API keys page.

It is read-only. Demo requests are not written to the request log or the archive, so the database of a public instance cannot be filled by strangers, and switching demo mode off ends every demo session and kills the key immediately.

Rate limit: 30 requests per 10 seconds. Go over it and you are cooled down for 10 seconds, during which every request is refused. It is a shared instance, and the identity pool behind it is the ceiling for everybody using it at once.

What the demo is for is deciding whether to run your own. It is not a service to build on — it can go down, be reset, or be switched off, and none of that will be announced.

🚀 v4 vs v5

v5 is a rewrite. It started from an empty branch and inherits no v4 code.

v4's real problem was never a shortage of features — it was that the API would die quietly and nobody would know. A cookie expires, a signature algorithm changes, an endpoint gets rate-limited, and you find out when someone files an issue. v5 puts "you can see it" and "it heals itself" ahead of features.

v4v5
Where identities come fromYou copy cookies out of a browser into config.yamlA headless browser mints guest identities, and the pool tops itself up when usable ones run low
How requests go outStraight out, as they arriveHealth tiers, quantised LRU rotation, one in-flight lock per identity, a token bucket per (identity, endpoint), a circuit breaker per endpoint
When something breaksYou wait for a bug reportOne structured record per request, live health for every identity and endpoint, visible in the console
Call styleSynchronous — send and waitAsynchronous by default (202 + task_id); add ?wait= to go back to synchronous
What is keptNothing; parsed and discardedPostgreSQL + Redis. Everything parsed is archived, so a post deleted upstream is still here
Access controlNone; anyone can call itAPI keys with scopes and roles, managed in the console
InterfaceA single PyWebIO pageA React console: identity pool, scheduler, library, downloads, logs, diagnostics
Ways inRESTREST, MCP and a CLI, all over the same service layer
SigningX-Bogus, A_Bogusa_bogus, X-Bogus, X-Gnarly, X-Dynosaur in pure Python, with a browser fallback
Deploymentpip install -r requirements.txt + python start.pydocker compose up, three images
PlatformsDouyin, TikTok, BilibiliDouyin, TikTok

Bilibili is the one thing that went backwards: v5 does not have it yet. It shares neither the signing nor the identity machinery with Douyin and TikTok, so the rewrite left it out for now.

Still on v4?

v4's code stays on the v4 branch, the image is still published, and one command brings it up:

docker run -d --name dtk-v4 --restart unless-stopped \
  -p 8080:80 evil0ctal/douyin_tiktok_download_api:V4.1.2

Then open http://localhost:8080; the API reference is at /docs. Port 8080 is deliberate — v5 binds 8000, so the two versions can run side by side on one machine.

Replace the Douyin cookie before you use it. v4 has no identity pool, and the cookie baked into the image expired long ago, so Douyin endpoints answer 400 until you put your own in:

docker cp dtk-v4:/app/crawlers/douyin/web/config.yaml ./douyin-web.yaml
# replace the Cookie line with one from your browser, then save
docker rm -f dtk-v4
docker run -d --name dtk-v4 --restart unless-stopped -p 8080:80 \
  -v "$PWD/douyin-web.yaml:/app/crawlers/douyin/web/config.yaml" \
  evil0ctal/douyin_tiktok_download_api:V4.1.2

TikTok's two config files are at /app/crawlers/tiktok/web/config.yaml and /app/crawlers/tiktok/app/config.yaml, and are mounted the same way.

To keep it under Compose instead, one file is enough — with douyin-web.yaml already copied out next to it, or Docker will create a directory under that name and the app will fail to read its config:

# compose.yml
services:
  app:
    image: evil0ctal/douyin_tiktok_download_api:V4.1.2
    container_name: dtk-v4
    restart: unless-stopped
    ports:
      - "8080:80"
    environment:
      TZ: Asia/Shanghai
    volumes:
      - ./douyin-web.yaml:/app/crawlers/douyin/web/config.yaml
docker rm -f dtk-v4   # the container from the run above holds the name
docker compose -p dtk-v4 up -d

main is v5 now and latest follows main, so pin the tag to stay on v4. V4.1.2 is the last v4 release; the branch merged a few PRs after it (Bilibili downloads, cookie hot-reload), and that code is published under the commit tag 5be4838.

There is no guided installer for v4 — the script in Quick start below installs v5. What is above is all v4 gets: the branch still takes PRs, but nothing new is built on it, and a fresh install should start on v5.

Building this together

There are a few group chats around my open-source projects. If you want to work on this one, or just talk shop, add me on WeChat at Evil0ctal with the note github 交流 and I will add you.

The groups are for learning from each other. No advertising and nothing illegal — they are for making friends and talking about the work.

📦 What it can fetch from Douyin and TikTok

CapabilityDouyinTikTok
One post (video or image album)✅✅
Author profile✅✅
An author's posts✅✅
An author's liked posts✅✅
Mixes / playlists✅✅
Comments✅✅
Comment replies✅✅
Followers❌✅
Following❌✅

Douyin serves its follower and following lists only to a signed-in session, so those two endpoints are not registered at all: an endpoint that always returns an empty page is worth nothing. Importing your own logged-in cookies widens what the rest can see, too.

Media downloads, the content archive, counter snapshots, collections and a watchlist are built in; none of them needs another service.

🔗 Which Douyin and TikTok links it accepts

Paste whatever you have — a short link, a post URL, or the whole caption a platform app puts on your clipboard:

https://v.douyin.com/L4NpDJ6/
https://www.douyin.com/video/7126745726494821640
https://www.douyin.com/jingxuan?modal_id=7660875690212492466
https://www.tiktok.com/@evil0ctal/video/7156033831819037994
https://www.tiktok.com/t/ZTR9nkkmL/
2.84 nqe:/ <caption> https://v.douyin.com/L4FJNR3/ <sentence telling you to open the app>

Short links are followed and a link buried in a caption is extracted. A post id is also checked against the platform's own encoding first, so an id that cannot exist is refused here rather than costing an upstream request.

⚗️ Built with

ServicePython 3.12 · FastAPI · SQLAlchemy 2.0 (async) · Alembic · Typer · structlog
Transportwreq (browser TLS fingerprint emulation) · httpx
DataPostgreSQL + TimescaleDB · Redis
ConsoleReact 19 · TypeScript · Vite · TanStack Query · wouter · i18next
Signinga_bogus, X-Bogus, X-Gnarly and X-Dynosaur in pure Python
Identity mintingCloakBrowser, headless, in a container of its own, called over HTTP
DownloaderGo 1.23, standard library only, statically linked into a scratch image
Authargon2id password hashing · API keys with scopes
ProtocolsREST (OpenAPI) · MCP (streamable-http) · CLI
Toolinguv · ruff · mypy · pytest · Docker Compose

Nothing beyond Postgres and Redis is required. No Kafka, no Elasticsearch, no object store, no Kubernetes.

CloakBrowser is pinned to a specific commit. That pin is a security control — see docker/Dockerfile.browser.

🗂 Project layout

First, what dtk is. Douyin_TikTok_Download_API is a mouthful, so the code says DTK instead: Douyin + TiKTok. The two platforms, and not the download or API halves of the name.

It is the Python package (src/dtk/), the command (dtk --help), the prefix on every environment variable (DTK_SECRET_KEY and friends), the Compose project name (-p dtk), and the three letters in the console's title bar. Where you see dtk, it means Douyin_TikTok_Download_API.

Douyin_TikTok_Download_API/
├── src/dtk/                the service; all of it lives here
│   ├── api/                FastAPI routes, auth, OpenAPI localisation
│   ├── platforms/          Douyin and TikTok adapters: endpoints, params, parsers
│   ├── signing/            a_bogus / X-Bogus / X-Gnarly / X-Dynosaur
│   ├── transport/          outbound requests, response classification
│   ├── identity/           identity minting and health
│   ├── scheduler/          identity selection, token buckets, circuit breakers
│   ├── services/           the business layer, shared by REST, MCP and the CLI
│   ├── worker/             async tasks, callbacks, scheduled collection
│   ├── db/                 SQLAlchemy models and Alembic migrations
│   ├── ops/                diagnostics, backups, health checks, alerting
│   ├── media/              downloader client
│   ├── models/             one content model across both platforms
│   ├── urls/               link recognition, short-link expansion, id validation
│   ├── mcp/                MCP server
│   ├── cli/                the dtk command line
│   ├── i18n/               server-side English and Chinese strings
│   └── core/               settings, logging, error types
├── web/                    the React console, built into the app image
│   └── src/
│       ├── pages/          one file per console page
│       ├── components/     design system and shared components
│       └── locales/        console English and Chinese strings
├── docker/                 three Dockerfiles, compose, and two sidecars
│   ├── browser_rpc/        Python, wrapping CloakBrowser
│   ├── downloader/         Go, the media download sidecar
│   └── compose.yml
├── documents/              user documentation, 17 pages in each language
├── tests/                  unit / integration / contract / replay
├── scripts/                smoke.sh
├── .github/workflows/      CI and Docker image publishing
├── alembic.ini
├── pyproject.toml
└── Makefile

⚡️ Quick start: self-host it with Docker

If you would rather not think about it, the guided script asks a few questions and brings the stack up — it works out your distribution, checks for Docker, and scales the resource limits to the machine:

curl -fsSL https://raw.githubusercontent.com/Evil0ctal/Douyin_TikTok_Download_API/main/install/install.sh -o install.sh
less install.sh    # reading it first is a good habit
bash install.sh

Afterwards the same script is the operations tool. Run it again and it finds the install and opens a menu: status, upgrade (compared against the latest GitHub release), passwords, an extra administrator, backup and restore, runtime settings, disk cleanup, stop or uninstall. --manage goes straight there.

Details in install/README.md. The manual route follows.

There are two ways to install this; below is the recommended one. For the by-hand route, see Without Docker.

HowWho forFull steps
Docker Compose (recommended)Almost everyone, production includedInstallation · First install
By handDocker is not an option, or you are changing the codeFor development · On bare metal

Installing from mainland China? Switch your mirrors before you start, or the pull will most likely time out: Network preparation in mainland China.

You need Docker and Docker Compose. Start by cloning the repository — the compose file, the Dockerfiles and the migrations all live in it, and the default branch is v5:

git clone https://github.com/Evil0ctal/Douyin_TikTok_Download_API.git
cd Douyin_TikTok_Download_API

Nothing in the repository ships a default password or key, so write .env next:

POSTGRES_PASSWORD=$(openssl rand -hex 24)
REDIS_PASSWORD=$(openssl rand -hex 24)
cat > .env <<EOF
DTK_SECRET_KEY=$(openssl rand -base64 48)
POSTGRES_PASSWORD=${POSTGRES_PASSWORD}
REDIS_PASSWORD=${REDIS_PASSWORD}
DTK_DATABASE_URL=postgresql+asyncpg://dtk:${POSTGRES_PASSWORD}@postgres:5432/dtk
DTK_REDIS_URL=redis://:${REDIS_PASSWORD}@redis:6379/0
EOF
docker compose -p dtk -f docker/compose.yml up -d
docker compose -p dtk -f docker/compose.yml logs api   # prints the setup token

Open http://127.0.0.1:8000 and use the token from the log to create the first administrator.

Where the image comes from

By default it is built locally: the first up compiles the application image from the Dockerfile in this repository, which takes a few minutes. To skip that, point compose at the published image instead:

export DTK_IMAGE=evil0ctal/douyin_tiktok_download_api
export DTK_IMAGE_TAG=latest
docker compose -p dtk -f docker/compose.yml pull
docker compose -p dtk -f docker/compose.yml up -d

The pull is not optional: these services declare both image and build, so compose builds from the local Dockerfile whenever the image is not already on the machine rather than reaching for a registry.

Images are published for linux/amd64 and linux/arm64, so Apple Silicon and a Raspberry Pi both run natively. The browser container is not published: it installs CloakBrowser from a pinned commit, and that pin is a security control that should be yours to choose, so it stays a local build.

Without Docker

Supported, and it is how the project itself is developed. You provide PostgreSQL 17 (with the TimescaleDB extension — a plain postgres:17 will not do), Redis 8, Python 3.12 and uv, plus Node 22 if you build the console. Two sets of steps:

What the containers were doing for you — a non-root user, memory and CPU ceilings, a read-only root filesystem, process supervision — you put back yourself. That section lists them one by one.

Where to look next

What you want to doWhere
Size a machine, change the container limitsThree sizes · Changing the limits
Turn on the browser container or the downloader sidecarThe two optional profiles
Put TLS and a reverse proxy in frontBehind a reverse proxy
Understand how the environment is actually readEnvironment variables
Confirm an install is genuinely healthyVerifying an install
Read the compose file line by linedocker/README.md

🖥 What you get: console, REST API, MCP and CLI

Entry pointWhereWhat it is
Web console/Identity pool, scheduler, library, downloads, logs, diagnostics
API reference/docsSwagger UI inside the console, English and Chinese
Bare reference/swagger, /redocNo login required
REST API/api/v1/...93 operations
MCP/mcpShares the service layer with REST; client setup at /mcp-guide in the console
CLIdtk --helpSame

The main capabilities:

  • Parse a link, share text, short link, or a bare post id
  • Archive everything parsed, so a post deleted upstream is still here
  • Download media to your own disk, in bulk by author, skipping what you have, with duplicate cleanup
  • Watch an author or a post and re-collect it on a timer
  • iOS Shortcut support at /api/v1/ios/shortcut

🔄 Updating to a new release

The console keeps an eye out for you: system.check_updates is on by default, and if a newer release exists you get one notice after signing in, at most once a day. That request goes from your browser to GitHub — the server never sends anything outward, so it does not tell anyone this instance exists. Turn it off in Settings if you would rather it did not.

Updating is a pull and a restart. If you installed with the script, run it again and pick Upgrade:

bash install.sh --manage    # pick 2

By hand it is:

cd /opt/dtk && git pull

# Running the published images (recommended): point DTK_IMAGE_TAG at the new one
docker compose -p dtk -f docker/compose.yml pull api worker downloader
docker compose -p dtk -f docker/compose.yml run --rm migrate
docker compose -p dtk -f docker/compose.yml up -d

Building locally instead? Swap pull for build. migrate runs on every start and Alembic is idempotent, so running it separately is only about getting the schema up before the containers switch over.

Your data stays put. The named volumes (postgres-data, redis-data, media-data) survive a rebuild, so the identity pool, the archive, the settings and the API keys are all where you left them.

The browser image only needs rebuilding when docker/Dockerfile.browser or the CloakBrowser pin changes, which a normal version bump does not touch.

To go back, set DTK_IMAGE_TAG to the previous sha- or version and up -d again. Migrations have no automatic downgrade — back the database up before upgrading, which is the only rollback that always works.

📖 Documentation

Read it online at douyin.wtf — the same 17 pages, rendered, searchable and in both languages. The markdown source is in documents/ and is what the site is built from, so the two never disagree.

New here: Quick start · Concepts · Console overview

Running it: Installation and deployment · Configuration reference · Operations · Troubleshooting · Security

Building against it: REST API guide · MCP and AI agents · CLI reference · Contributing

The endpoint reference is not in there: it is generated from the code that serves the requests, so your own instance is the copy that is never out of date. Find it at /docs inside the console, or at /swagger, /redoc and /openapi.json without a login. Both languages.

中文文档:documents/README.zh-CN.md

Reading this with an LLM? llms.txt is the whole documentation set as one annotated index, in the llmstxt.org format.

📮 Contact

IssuesGitHub Issues — public, keeps its history, and anyone who has hit the same thing can answer
EmailEvil0ctal1985@gmail.com — reaches one person; best for anything that does not belong in public
Author@Evil0ctal

Before asking, read Troubleshooting and include the output of the Diagnose page or dtk diagnose. It answers most of what a maintainer would otherwise have to ask you.

⭐️ Star history

Star History Chart

Started 2021/11/06 · GitHub @Evil0ctal

📄 Licence

Apache License 2.0.

You may use, modify and distribute this project, including commercially and inside closed-source products. The grant is irrevocable. In return the licence asks you to:

  • Keep the licence text and the NOTICE file, which carries the copyright notice, with any copy you distribute
  • State what you changed, in files you modified
  • Accept that it comes with no warranty

A request from the author

This project is given away, and it stays free because sponsors pay for it rather than users. If you are making money from it, please consider sponsoring instead of only taking.

This is a request, not a licence condition — Apache 2.0 permits commercial use, and nothing above takes that back.

☕️ Support the author

The sponsors above pay for the project. This section is for the person who maintains it, and is entirely optional.

NetworkAddress
SolanaHvtkxmDERbNXfCoojpdFAYN5mSWowjpXgedsG9eF7y9z
Tron (TRC20)TQwSM2vjcnrdRU7gY7KNp2tCgMnK33azkT
Ethereum (ERC20)0x2f210FdfD981B59eC130370E5b1Aa8A6a06fb5Ad
BNB Smart Chain (BEP20)0x2f210FdfD981B59eC130370E5b1Aa8A6a06fb5Ad
Bitcoinbc1q785j55cxlnjqe8lkwy8cq57t8t9vn3ak9tlsfy

These networks carry the usual major tokens. USDT on Tron (TRC20) or Solana is the easiest to receive, and the cheapest to send.

Send only on the network an address is listed under. A transfer on the wrong chain cannot be recovered by anybody. Ethereum and BNB Smart Chain share one address on purpose: both are EVM chains, and the same key controls it.

GitHub Sponsors works too.

What you are responsible for

This fetches data from platforms that have their own terms, and it runs on your machine under your control. Respect those terms and applicable law, respect the people whose content you collect, do not use it to harass anyone, and do not redistribute work that is not yours. Nobody else can enforce any of that for you.