Skip to content
Help
English
Security and anti-fraud

How does Spy Blocker stop image theft and content scraping?

How the Spy Blocker app blocks copying, right-click, and developer tools, bans desktop scrapers by IP, and how to release a banned visitor from the Spies list.

What Spy Blocker is

Spy Blocker is a free security app by Storeep that protects your storefront against image theft and content scraping. When it is active it disables the actions competitors and bots use to copy your photos and product text, and it bans any desktop visitor who tries. You install it from the Apps market, then switch it on in its settings.

Installing and activating

  1. Open Apps (you need the Apps permission).
  2. Find Spy blocker in the Security & Privacy collection and open it.
  3. Click Install.
  4. Open its settings again and turn on the Activate toggle.
  5. Click Save.

The Activate toggle is the only setting. There are no per-market options: once it is on, protection applies across your whole store. The store owner viewing their own store in preview is never flagged, so you cannot ban yourself while testing.

What triggers a ban

While Spy Blocker is active, these actions block the visitor and ban them:

  • Copying any text or image outside a form field. The copy is cancelled and the visitor is banned. Copying inside a form (for example a customer's own checkout entries) is allowed and never bans.
  • Leak-source and developer-tools keyboard shortcuts: save page (Ctrl/Cmd+S), view source (Ctrl/Cmd+U), print (Ctrl/Cmd+P), and the developer-tools keys F12 and Ctrl/Cmd+Shift+I, J, or C. The shortcut is blocked and the visitor is banned.
  • Opening developer tools. Spy Blocker checks roughly twice a second; when it detects an open inspector it clears the page, bans the visitor, and reloads to your blocked page.

Right-click is also disabled storefront-wide so the "Save image as" and "Inspect" menu never appears, and every image is made non-draggable with pointer interaction disabled. Suppressing the menu on its own does not ban; the ban fires on the copy, shortcut, or developer-tools events listed above.

Desktop only

Spy Blocker targets desktop visitors. Bans are rejected for mobile browsers, and the developer-tools check runs only on devices with a fine pointer (a mouse). Mobile shoppers browse normally and are never banned, so the protection does not get in the way of phone buyers.

What a banned visitor sees

After a trigger the page reloads and your store serves its blocked page to that session on every future visit, until you release the ban.

The Spies list

The app settings show a Spies table of every banned session on your store, newest first, 20 rows per page. Each row shows:

  • IP: the address, with the detection date and time in your store timezone.
  • Country: the flag for that IP.
  • Browser, OS, and Device: the visitor's environment at the moment of detection.
  • VPN/Proxy: shown as Detected or Undetected.

Releasing a visitor (Delete spies)

To let a banned visitor back in:

  1. Tick the checkbox on each row you want to free.
  2. Open the gear (cog) menu above the table.
  3. Click Delete spies.

This releases the ban immediately by marking those sessions as no longer banned, so the visitor can shop again. There is no separate "remove from list" step: deleting a spy and lifting its ban are the same action.

How it relates to Banned sessions and Shield

Every Spy Blocker ban is an IP ban, so it also appears in Settings > Banned sessions under the IP type. The Spies table and Banned sessions list the same IP bans, and you can release a ban from either place. Device-type bans come from the separate Shield app, not Spy Blocker. Bans stay in force even after you disable or uninstall Spy Blocker: turning the app off stops new detections but never releases existing bans. For the full unban workflow, see Sessions and banned sessions.