1Who is responsible
The controller for the personal data described here is the legal entity operating CaptchAPI. Its registered name, address and registration number are published on the contact page.
We have not appointed a Data Protection Officer, because our processing does not meet the thresholds in Article 37 of the GDPR. The contact point for any privacy question, and the address for data subject requests, is published on the contact page.
Our lead supervisory authority is the data protection authority of the country in which we are established. That authority will be named here on incorporation. You may complain to it, or to the authority where you live or work, at any time.
2What we collect
We collect the minimum needed to run an account, take a payment and operate the API safely.
- Account data: name, email address, password hash, company name and country. Provided by you at sign-up.
- Billing data: top-up amounts, invoice records, VAT identification number where you supply one, and the last four digits and expiry of a card. Full card numbers never reach our servers — they go directly to the payment processor.
- Crypto payment data: the payment identifier and the originating address, so a refund can be returned to where the money came from.
- API usage data: for each task, the task type, target URL, sitekey, timestamps, duration, outcome, cost, the API key used and the source IP address of the request.
- Technical data from this website: IP address, user agent and requested page, in server logs.
- Support data: the contents of messages you send us and our replies.
3What we deliberately do not collect
We do not store raw API keys — only a SHA-256 hash and a display prefix. Nobody here can read your key.
We do not retain solved tokens or cookie bundles beyond the five-minute window in which you collect them. After that they are discarded, not archived.
We do not run advertising trackers, do not sell personal data, do not share it with data brokers, and do not use it to train models.
We do not profile you or take automated decisions producing legal effects. Abuse investigations are carried out by a person looking at the evidence.
4Why we process it, and on what basis
Every processing purpose has a legal basis under Article 6 of the GDPR.
- Providing the service, running your account and processing tasks — performance of a contract.
- Billing, invoicing, and keeping accounting records — performance of a contract, and a legal obligation for the retention of accounting documents.
- Securing the service: rate limiting, fraud detection, abuse investigation, logging — our legitimate interest in operating a service that is not abused, balanced against your interest in not being monitored more than necessary.
- Answering support messages — performance of a contract, or our legitimate interest in replying to an enquiry.
- Service notices, incident notifications and material changes to terms — performance of a contract. These are not marketing and cannot be unsubscribed from while your account is open.
- Any marketing email — your consent, withdrawable in one click and never a condition of using the service.
5How long we keep it
Retention is set per category, not by a single blanket period.
- Solved tokens and cookie bundles: 5 minutes after the task resolves.
- Task metadata (type, target, timings, outcome, cost): 90 days for operational analysis, then aggregated into counts that identify nobody.
- Server and security logs, including IP addresses: 30 days, unless retained longer as evidence in an ongoing abuse or security investigation.
- Account data: for the life of the account, then 30 days after closure to allow recovery of a mistake.
- Invoices and accounting records: ten years, as required by accounting law. This obligation overrides a deletion request for those records specifically.
- Support correspondence: three years from the last message.
6Who else sees it
We use a small number of processors, each bound by a contract that meets Article 28 of the GDPR. The current list — hosting provider, payment processors for card and cryptocurrency, transactional email provider and error monitoring — will be published in full here, with each processor named and located, before the service opens to the public.
We do not otherwise share personal data. We will disclose it to a public authority only where we are legally required to, and we will tell you unless the law forbids it.
If our business is sold or merged, personal data may transfer to the acquirer. You will be told before that happens and given a chance to close your account and take your credit back.
7International transfers
Our infrastructure is hosted in the European Union. Where a processor transfers data outside the EEA, the transfer is covered by an adequacy decision or by the European Commission's standard contractual clauses, together with a transfer risk assessment.
You can ask us for a copy of the safeguards applying to a specific transfer.
8Your rights
Under the GDPR you have the rights below. Exercise any of them by writing to the contact address; we reply within one month and do not charge for it. We may ask you to confirm your identity, but only in proportion to the sensitivity of the request.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate.
- Erasure — deletion, except where we must keep a record by law, such as an invoice.
- Restriction — a pause on processing while a dispute about accuracy or legitimacy is resolved.
- Portability — your account and usage data in a machine-readable format.
- Objection — to processing based on our legitimate interests, including a right to object at any time and have us stop unless we can show compelling grounds.
- Withdrawal of consent — where consent is the basis, at any time, without affecting what was lawful before.
- Complaint — to your supervisory authority, without contacting us first.
10Security
Data is encrypted in transit with TLS. Passwords are hashed with a modern algorithm designed for the purpose, and API keys are stored only as SHA-256 hashes.
Access to production data is limited to the people who need it to operate the service, and every query in the application is scoped to the authenticated account.
If a breach is likely to result in a risk to your rights, we notify our supervisory authority within 72 hours and tell you without undue delay, with what we know and what we advise you to do.
11Children
The service is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16, and we delete it if we discover we have.
12Changes to this policy
We update this policy when our processing changes. Material changes are emailed to account holders at least thirty days before they take effect, and the date at the top of this page always reflects the current version.