Legal

Privacy Policy

Last updated 23 September 2026

What personal data crawlfeed handles, why, and your rights under UK and EU data protection law. Read it with our Terms of Service.

1.Who we are

crawlfeed is operated by Ilyas Abdulkadir, a sole trader established in Portugal, trading as crawlfeed (“we”, “us”). We are the controller of the personal data described in this policy under the EU General Data Protection Regulation (GDPR) and Portugal’s Law 58/2019, and, for people in the United Kingdom, under the UK GDPR and the Data Protection Act 2018.

Contact us about anything in this policy at support@crawlfeed.dev. Where the UK GDPR requires us to appoint a representative in the United Kingdom, their details will be published here.

2.Who this policy covers

This policy covers two groups of people:

  • Our customers: people who visit crawlfeed.dev, create an account on app.crawlfeed.dev or use the crawlfeed API. See sections 3 to 5.
  • People whose public data passes through our service: for example the owner of a public social media profile that a customer looks up. See section 6.

3.Data we collect about customers

CategoryWhat it includes
AccountEmail address, name, and a hashed password. If you sign in with Google or GitHub, the name, email address and profile picture that provider shares with us.
SecuritySession records with IP address and browser user agent, email verification status, and the result of a bot check (Cloudflare Turnstile) when you sign up.
API keysA one-way hash and a short prefix of each key, its name and when it was last used. We cannot read your full key after it has been shown to you.
UsageFor each API call: the route, platform, response status, credits charged, whether it came from cache, the provider used, how long it took, and when. We do not log the handles, ids or search terms you send.
BillingThe credit pack you bought, the order id, amount, currency and date. Polar processes your payment; we never see or store your card details.
CommunicationsEmails you send us and service emails we send you, such as verification.
ErrorsWhen something breaks in the dashboard or API: the page or route, your browser and operating system, and the technical error. API keys and cookies are removed first.
Analytics (only with consent)If you accept analytics cookies: the pages you visit and the buttons you use, with a random identifier stored in a cookie. Session recordings are off.

We use no advertising or cross-site tracking tools, and we do not sell personal data.

4.Why we use customer data, and our lawful basis

PurposeLawful basis (UK and EU GDPR)
Creating your account, running the API, metering and refunding creditsPerformance of our contract with you (Article 6(1)(b))
Service emails, such as verification and important changesPerformance of our contract with you (Article 6(1)(b))
Preventing fraud, abuse of the free credits, and keeping the service secureOur legitimate interests in protecting the service (Article 6(1)(f))
Keeping purchase and credit records for tax and accountingCompliance with a legal obligation (Article 6(1)(c))
Understanding overall usage to improve the service, using aggregated figuresOur legitimate interests in improving the service (Article 6(1)(f))
Finding and fixing errors in the dashboard and APIOur legitimate interests in a working, secure service (Article 6(1)(f))
Product analytics with PostHogYour consent (Article 6(1)(a)), given in the cookie banner and withdrawable at any time from “Cookie settings”

5.Arabic enrichment

If you add enrich=arabic to a request or call /v1/enrich, the text involved is sent to our AI provider to identify its dialect, sentiment, entities and topics. Results are cached against a hash of the text so a repeated text is not processed again. We do not enrich content from Reddit or Spotify, and we do not use enrichment to infer special category data about any person.

6.Public data about people on other platforms

crawlfeed retrieves publicly available data from the platforms listed on crawlfeed.dev when a customer asks for it. This can include personal data about the people who published it, such as a public profile’s name, handle, bio, profile picture, follower counts, posts, comments, video transcripts and public ads. We never access private accounts, content behind a login, or direct messages.

Where it comes from. The platforms themselves, either through their official APIs or through the data providers listed in section 8.

Why and on what basis. To deliver the results our customers request. We rely on legitimate interests (Article 6(1)(f)): ours in providing the service, and our customers’ in research, analytics and building products with public information. We limit what we collect to what a request needs, only handle data the person has made public, and require customers to use it lawfully (see our acceptable use rules).

How long we keep it. Results are cached for up to 24 hours so repeated requests are fast, and the original responses are archived for 30 days for debugging and are then deleted automatically. Once a customer receives data, that customer is responsible for its own use of it as a separate controller.

Your rights. If you think we hold data about you, you can ask us to access it, delete it, or object to our processing it at support@crawlfeed.dev. We will delete the copies we hold in our cache and archive. To remove content at its source, use the platform where you published it.

7.Free tools

The free tools on crawlfeed.dev/tools work without an account. When you use one that looks something up, we receive the link you entered and your IP address. We use the IP address only to limit how many lookups each visitor makes per day, and we store it only as a one-way hash. Cloudflare Turnstile checks that you are not a bot. Results are cached for up to 24 hours. Calculators run entirely in your browser and send nothing. Our lawful basis is legitimate interests: providing the tools and protecting them from abuse.

8.Who we share data with

We use the following service providers, who process personal data only on our instructions:

ProviderWhat they do for usLocation
Cloudflare, Inc.Hosting of the website, dashboard and API; database, cache and file storage; verification emails; bot protection (Turnstile); fallback AI modelGlobal network; United States
Polar Software, Inc. (Polar)Checkout, payment processing, invoicing and tax, as merchant of recordUnited States
OpenRouter, Inc. and the model provider it routes toArabic text enrichment, only when you request itUnited States
Functional Software, Inc. (Sentry)Error monitoring: technical details of failures in the dashboard and API (the page or route, browser, and error). API keys and cookies are removed before sendingEuropean Union (Germany)
PostHog, Inc.Product analytics on crawlfeed.dev and the dashboard, only if you accept analytics cookiesEuropean Union
Google LLC and GitHub, Inc.Sign-in, only if you choose "Continue with Google" or "Continue with GitHub"United States

To fulfil a request, we send the handle, id or search term it names to the relevant data source. These sources do not receive your account details:

  • Data providers: Third-party services that retrieve public data from social, video, music, shop and ad-library platforms, including a back-up provider for some platforms
  • Proxy network: A network provider that routes pages we retrieve ourselves
  • Official platform APIs: The platforms’ own public APIs, where they offer one

We may also disclose data where the law requires it, or to protect our rights, our customers or the public.

9.International transfers

Some of our providers are in the United States or operate globally. Where personal data leaves the UK or the European Economic Area, we rely on an adequacy decision (including the EU-US Data Privacy Framework and its UK Extension, where the provider is certified), or on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum. You can ask us for details at support@crawlfeed.dev.

10.How long we keep data

DataKept for
Account, API keys and usage historyWhile your account is open; deleted when you delete the account in Settings, or within 30 days of asking us by email
SessionsUntil you sign out or the session expires
Purchase and credit records6 years, for tax and accounting obligations
Cached API resultsUp to 24 hours
Archived API responses30 days
Support emailsUp to 2 years after the conversation ends
Error reports (Sentry)Up to 90 days
Analytics events (PostHog)Up to 12 months

11.Your rights

Under UK and EU GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have your data deleted;
  • restrict how we use it;
  • receive data you gave us in a portable format;
  • object to processing based on legitimate interests;
  • withdraw consent, where we rely on consent.

You can delete your account yourself under Settings in the dashboard. To use any of the other rights, email support@crawlfeed.dev from the address on your account. We reply within one month. It is free, unless a request is clearly unfounded or excessive.

You can complain to a data protection authority. Our lead authority is Portugal’s Comissão Nacional de Proteção de Dados (cnpd.pt). You can also complain to the authority in the EU country where you live or work, or, in the UK, to the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to help first.

12.Cookies

Strictly necessary, set without asking because the service cannot work without them: on app.crawlfeed.dev, a session cookie that keeps you signed in; on the sign-up form and the free tools, Cloudflare Turnstile’s cookies that tell people from bots; and crawlfeed_consent, which remembers your cookie choice for 6 months on both crawlfeed.dev and app.crawlfeed.dev.

Analytics, only if you accept: PostHog’s cookies (names starting ph_), which hold a random identifier so visits can be counted. Rejecting sets none of them and loads nothing from PostHog. You can change your mind at any time from “Cookie settings” in the site footer or the dashboard’s account menu. We use no advertising cookies.

13.Security

All traffic is encrypted in transit. Passwords and API keys are stored as one-way hashes. The single exception is the first key we create for a new account, which is stored encrypted until you have copied it once and is then deleted. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.

14.Children

crawlfeed is not for anyone under 18, and we do not knowingly collect personal data from children.

15.Changes to this policy

If we change this policy in a way that matters, we will tell you by email or in the dashboard before the change applies. The date at the top shows when it was last updated.