Legal
Privacy Policy
Last updated 24 September 2026
This policy explains what we collect when you use Fastcrawl, why we collect it, and how long we keep it. It covers the API and the fastcrawl.net website. It does not cover the third-party sites you ask us to fetch.
1. What we collect
Account data. Your email address, and — if you sign in with Google — your Google display name. Your API keys are stored only as a cryptographic hash; we never store the key itself and cannot show it to you again.
Request logs. For each API call we record the timestamp, the endpoint, the HTTP status, the target URL you asked us to fetch, the duration, the error code if the call failed, whether the response came from cache, which engine path served it, the request mode, your user agent, and a request identifier.
Truncated IP address. We store your client IP with the last part removed — for IPv4 the final octet is zeroed (203.0.113.47 is stored as203.0.113.0); for IPv6 the interface identifier is zeroed (2001:db8:1234:5678::). This gives us coarse geography and abuse detection without keeping an address that identifies your device.
Billing data. Your subscription status, plan, and metered usage counts. Card details are handled entirely by Stripe and never reach our servers.
2. What we do not do
- We do not sell your personal data, and we do not share it for advertising.
- We do not store the raw API key you were issued.
- We do not use your scraped content to train models.
- We do not set advertising or tracking cookies on the API.
3. Why we process it
- To provide the service — serving your requests, caching responses, and returning results (performance of our contract with you).
- To meter and bill — counting billable requests so your invoice is correct.
- To keep it working and safe — diagnosing failures, spotting abuse, and preventing it (our legitimate interests).
- To meet legal obligations — tax and accounting records.
4. Cached content
Fetched pages are cached so that repeat requests are fast and cheap. The default cache lifetime is 48 hours, and you can control it per request with themaxAge parameter. Cached content is public web content that we fetched because you asked us to; it is keyed by URL and is not scoped to your account.
5. Who else is involved
- Stripe — subscription billing and payment processing.
- Cloudflare — edge network, request routing, and headless page rendering for pages that need JavaScript.
- Google Analytics — aggregate traffic measurement on the fastcrawl.net website (not on API calls).
- Google Sign-In — optional sign-in, if you choose it.
- An LLM provider — only for the
/extractendpoint, which asks a model to structure page content. When you call it, the fetched page content (truncated to 30,000 characters) and your extraction prompt are sent to that provider. If you never call/extract, nothing is sent. - Our hosting provider — servers and database that store the data described above.
6. Cookies
The API itself uses no cookies — authentication is by bearer token. The website sets a short-lived cookie during Google sign-in to protect the login flow, and loads Google Analytics for aggregate traffic counts. We use no advertising cookies.
7. Retention
Request logs are kept while your account is active and afterwards for as long as we need them as the record behind your billing and to investigate disputes. We do not currently run an automatic expiry on this table, so treat the retention as indefinite for now — you can ask us to delete them (see below). Cached content expires on its cache lifetime. Billing records are kept as long as tax law requires.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to complain to your local data-protection authority. Email[email protected] and we will respond within 30 days. There is no self-service account-deletion button yet. Email us and we will delete your account and revoke your keys for you; request logs tied to billing are kept only as long as we are required to retain them.
9. Security and international transfers
Traffic is encrypted in transit, API keys are hashed at rest, and access to production data is limited. Our providers operate globally, so your data may be processed outside your country, including in the United States, under the safeguards those providers offer. No system is perfectly secure; we cannot promise absolute security.
10. Children
Fastcrawl is a developer tool and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes and contact
We will update the date at the top when this policy changes, and notify material changes by email or in the dashboard. Questions or requests:[email protected]. See also ourTerms of Service.