Privacy Policy
Last updated: July 9, 2026
Crawl (the “Service”, “we”, “us”) provides web scraping APIs and related management interfaces. This policy explains how we collect, use and protect your (the “User”) information. By using the Service you agree to this policy.
1. Information we collect
- Account data: email, name and password hash provided at registration, plus basic information returned by OAuth logins.
- API keys: the plaintext of an API key is returned only once when created; we store only its SHA-256 hash.
- Usage records: timestamp, URL, credits debited, cache hit status and cost for each scrape request, used for billing and usage statistics.
- Payment data: subscriptions and payments are handled by Stripe. We keep only Stripe Customer / Subscription IDs and plan status; we do not store card numbers.
- Technical logs: IP, User-Agent and error records for security, anti-abuse and debugging.
We do not sell your personal information to third parties.
2. How we use information
- Provide, maintain and improve Service features.
- Calculate and debit credits, handle subscriptions and top-ups.
- Send account verification, password reset, service and transaction emails.
- Detect and prevent abuse, fraud and unauthorized access.
- Comply with legal obligations.
3. How scrape results are handled
The Service fetches publicly available webpages at your request and returns the content. Results may be cached temporarily in Redis to improve performance and reduce repeated fetching costs; cache is time-limited and not shared with other users. You are responsible for ensuring your use of scraped results complies with the target website's terms and applicable law.
4. Data retention and deletion
Account and usage data are retained while your account is active. After account termination we delete or de-identify data within a reasonable period, except where legal obligations require retention. You can delete API keys at any time from the dashboard; to delete your account, email the contact address below.
5. Third-party services
- Stripe: subscription and payment processing (subject to Stripe's privacy policy).
- Resend: transactional email delivery.
- RapidAPI: if you access the Service through the RapidAPI marketplace, RapidAPI handles subscription and user identification data under its own policy.
6. Security
API keys are stored as SHA-256 hashes; the database and cache are protected by secrets; the admin panel is role-gated and verified against the database. No internet transmission can be guaranteed fully secure, and we continually follow industry standards to strengthen protection.
7. Your rights
Depending on applicable law, you may have rights to access, correct, delete, restrict processing and portability of your data. To exercise these rights, email the contact address below and we will respond within a reasonable time.
8. Policy updates
Material changes to this policy will be posted on this page and the date updated; continued use of the Service constitutes acceptance of the updated policy.
9. Contact
Questions about this policy can be sent to [email protected].