← Back to ExtractAPI
Privacy Policy
Effective: July 22, 2026
1. What We Collect
When you use ExtractAPI, we collect:
- Account data: Email address, billing information (processed by Stripe, not stored by us), and API key metadata
- Usage data: URLs submitted, timestamps, response status, response time, and bytes returned
- Technical data: IP address, user agent, and request headers (standard server logs retained for 30 days)
- Funnel data: optional source/referrer and UTM campaign fields, plus a short-lived random session identifier used to measure signup and activation steps
2. What We Don't Collect
We do not collect, store, or sell:
- Passwords or credentials
- Personal browsing history
- Advertising cookies or cross-site tracking profiles
- The full content of pages you extract (only structured metadata is returned)
3. How We Use Data
We use collected data for:
- Providing and improving the service
- Usage tracking and billing
- Detecting and preventing abuse
- Diagnosing technical issues
- Understanding which acquisition and onboarding steps lead to a successful extraction
4. Data Retention
- Request logs: Retained indefinitely for billing, debugging, and abuse prevention. Logs include URL, status, response time, and bytes returned.
- API usage statistics: Retained monthly for billing purposes (aggregate counts per key per month).
- API keys: Hashed at rest in the primary table. Pending (unclaimed) keys are encrypted at rest and auto-deleted after 24 hours.
- Welcome emails: Delivered email HTML bodies are purged after successful delivery. Failed email attempts retain the body until delivery succeeds or max retries exhausted.
- Account data: Retained until account deletion request.
- Database backups: Hourly snapshots retained 48 hours, daily 14 days, weekly 4 weeks. Backups may contain encrypted pending key material.
- Funnel events: Forwarded to PostHog only when the operator configures a project key; event properties are allow-listed and exclude page content, API keys, and email addresses.
5. Third-Party Services
We use Stripe for payment processing. Stripe's privacy policy applies to payment data they process. If enabled, PostHog receives the limited funnel events described above. We do not share usage data or extracted URLs with third parties.
6. Data Security
API keys are stored hashed. All API traffic uses TLS encryption. Database access is restricted to the application only. We follow industry-standard security practices but cannot guarantee absolute security.
7. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us. We will respond within 30 days.
8. No Sale of Data
We do not sell, rent, or share personal data with third parties for their marketing purposes.
9. Changes
We may update this policy. Material changes will be notified via email or service announcement.
10. Contact
For privacy-related inquiries: [email protected]