Trust

Data sources and compliance

Last updated 24 September 2026

Where crawlfeed’s data comes from, what we never collect, what we keep and for how long, and how to ask us to remove something.

1.The short version

  • Public data only. We return what anyone can see without an account: public profiles, public posts and comments, public videos and their transcripts, public app and store listings, and public ad libraries.
  • No logins, ever. We never sign in to a platform, use anyone’s account or cookies, or access private accounts, content behind a login, or direct messages. A private account is reported as not found.
  • Official APIs first. Where a platform offers a public API we can use, we use it.
  • Fetched on request, kept briefly. We fetch data when a customer asks for it. We do not build or sell a database of people, and what we keep is deleted on a fixed schedule.
  • Customers are bound by rules. No stalking, harassment, spam, profiling people for decisions about them, or attempts to reach non-public data.

2.Where the data comes from

Every response says where its data came from in meta.source: official, own or upstream. There are three kinds of source.

SourcePlatforms
Official platform APIsYouTube (YouTube Data API), Bluesky (AT Protocol public API), GitHub (REST API), Hacker News (official API), Apple App Store (Search and Lookup API), and Reddit profiles (Reddit Data API, used under Reddit’s commercial access)
Third-party data providersTikTok, Instagram, X, Facebook, Threads, LinkedIn, Twitch, Pinterest, Spotify and the other social, video, music and ad-library platforms we list, plus Reddit posts, comments and search. Also the extended operations on every platform, such as video transcripts and ad libraries
Public pages we fetch ourselvesTelegram public channel previews (t.me/s/), Linktree pages and Snapchat public profiles, requested like a normal visit, sometimes through a proxy network

Data providers are businesses that retrieve public data on our behalf under their own terms. We send them only what a request needs, such as a handle, a post id or a search term, and we accept only public results from them. The full list of platforms and operations is in the documentation.

3.What we never collect

  • Content from private accounts, closed groups or private channels.
  • Anything behind a login.
  • Direct messages, email addresses or phone numbers that people have not published.
  • Anyone’s account, password or session cookies. The only credentials we use are our own developer API keys for the official APIs listed above.

4.What we store and for how long

WhatWhyKept for
Results cacheRepeated requests are answered without asking the platform again1 minute to 1 hour for most results; up to 24 hours for transcripts, summaries and a few other slow-changing results
Original responsesDebugging and checking data quality30 days, then deleted automatically. Reddit and Spotify are never archived
AI enrichment resultsNot paying twice for the same analysis30 days. We keep the analysis, not the text that was analysed
Request logUsage history and billing for our customersWhile the customer’s account exists. It records the route and platform, never the handle or search term

Caching also keeps load on the platforms low: popular results are served from our cache rather than fetched again.

5.Platform rules we follow

  • Reddit. Reddit profiles come from Reddit’s Data API under its commercial access. Reddit content is never archived and never sent to an AI model.
  • Spotify. Spotify content is never archived and never sent to an AI model.
  • Any platform. We stop serving a platform, or part of one, when its terms or the law require it.

6.AI features

Summaries and text enrichment run only when a customer asks for them, on data that is already public. They exclude Reddit and Spotify content and never infer sensitive traits such as health, religion, ethnicity or sexual orientation. Details are in the Privacy Policy.

7.What customers agree to

Every customer accepts our acceptable use rules. Among other things, they may not:

  • stalk, harass, threaten, dox or intimidate anyone;
  • profile individuals to make decisions about their employment, housing, credit or insurance;
  • infer or collect sensitive data about people, such as health or religion;
  • send spam or unsolicited marketing;
  • try to obtain non-public data or access private accounts;
  • infringe anyone’s intellectual property.

A customer that receives personal data is responsible for its own lawful use of it and must delete it when the law requires. We may suspend or close accounts that break these rules.

8.Removal requests and concerns

If data about you appears in our results, email support@crawlfeed.dev to access it, delete it or object. We delete the copies in our cache and archive. To remove the content itself, delete or restrict it on the platform where you published it; once it is no longer public, we can no longer return it.

Platforms and rights holders with a concern about how their data or content is used can reach us at the same address. We look at every report and act on valid ones, including by limiting or stopping what we serve.

How we handle personal data in general is set out in the Privacy Policy.