1.Who we are
crawlfeed is operated by Ilyas Abdulkadir, a sole trader established in Portugal, trading as crawlfeed (“we”, “us”). We are the controller of the personal data described in this policy under the EU General Data Protection Regulation (GDPR) and Portugal’s Law 58/2019, and, for people in the United Kingdom, under the UK GDPR and the Data Protection Act 2018.
Contact us about anything in this policy at support@crawlfeed.dev. Where the UK GDPR requires us to appoint a representative in the United Kingdom, their details will be published here.
2.Who this policy covers
This policy covers two groups of people:
- Our customers: people who visit crawlfeed.dev, create an account on app.crawlfeed.dev or use the crawlfeed API. See sections 3 to 5.
- People whose public data passes through our service: for example the owner of a public social media profile that a customer looks up. See section 6.
3.Data we collect about customers
| Category | What it includes |
|---|---|
| Account | Email address, name, and a hashed password. If you sign in with Google or GitHub, the name, email address and profile picture that provider shares with us. |
| Security | Session records with IP address and browser user agent, email verification status, and the result of a bot check (Cloudflare Turnstile) when you sign up. |
| API keys | A one-way hash and a short prefix of each key, its name and when it was last used. We cannot read your full key after it has been shown to you. |
| Usage | For each API call: the route, platform, response status, credits charged, whether it came from cache, the provider used, how long it took, and when. We do not log the handles, ids or search terms you send. |
| Billing | The credit pack you bought, the order id, amount, currency and date. Polar processes your payment; we never see or store your card details. |
| Communications | Emails you send us and service emails we send you, such as verification. |
| Errors | When something breaks in the dashboard or API: the page or route, your browser and operating system, and the technical error. API keys and cookies are removed first. |
| Analytics (only with consent) | If you accept analytics cookies: the pages you visit and the buttons you use, with a random identifier stored in a cookie. Session recordings are off. |
We use no advertising or cross-site tracking tools, and we do not sell personal data.
4.Why we use customer data, and our lawful basis
| Purpose | Lawful basis (UK and EU GDPR) |
|---|---|
| Creating your account, running the API, metering and refunding credits | Performance of our contract with you (Article 6(1)(b)) |
| Service emails, such as verification and important changes | Performance of our contract with you (Article 6(1)(b)) |
| Preventing fraud, abuse of the free credits, and keeping the service secure | Our legitimate interests in protecting the service (Article 6(1)(f)) |
| Keeping purchase and credit records for tax and accounting | Compliance with a legal obligation (Article 6(1)(c)) |
| Understanding overall usage to improve the service, using aggregated figures | Our legitimate interests in improving the service (Article 6(1)(f)) |
| Finding and fixing errors in the dashboard and API | Our legitimate interests in a working, secure service (Article 6(1)(f)) |
| Product analytics with PostHog | Your consent (Article 6(1)(a)), given in the cookie banner and withdrawable at any time from “Cookie settings” |
5.Arabic enrichment
If you add enrich=arabic to a request or call /v1/enrich, the text involved is sent to our AI provider to identify its dialect, sentiment, entities and topics. Results are cached against a hash of the text so a repeated text is not processed again. We do not enrich content from Reddit or Spotify, and we do not use enrichment to infer special category data about any person.
6.Public data about people on other platforms
crawlfeed retrieves publicly available data from the platforms listed on crawlfeed.dev when a customer asks for it. This can include personal data about the people who published it, such as a public profile’s name, handle, bio, profile picture, follower counts, posts, comments, video transcripts and public ads. We never access private accounts, content behind a login, or direct messages.
Where it comes from. The platforms themselves, either through their official APIs or through the data providers listed in section 8.
Why and on what basis. To deliver the results our customers request. We rely on legitimate interests (Article 6(1)(f)): ours in providing the service, and our customers’ in research, analytics and building products with public information. We limit what we collect to what a request needs, only handle data the person has made public, and require customers to use it lawfully (see our acceptable use rules).
How long we keep it. Results are cached for up to 24 hours so repeated requests are fast, and the original responses are archived for 30 days for debugging and are then deleted automatically. Once a customer receives data, that customer is responsible for its own use of it as a separate controller.
Your rights. If you think we hold data about you, you can ask us to access it, delete it, or object to our processing it at support@crawlfeed.dev. We will delete the copies we hold in our cache and archive. To remove content at its source, use the platform where you published it.
7.Free tools
The free tools on crawlfeed.dev/tools work without an account. When you use one that looks something up, we receive the link you entered and your IP address. We use the IP address only to limit how many lookups each visitor makes per day, and we store it only as a one-way hash. Cloudflare Turnstile checks that you are not a bot. Results are cached for up to 24 hours. Calculators run entirely in your browser and send nothing. Our lawful basis is legitimate interests: providing the tools and protecting them from abuse.
8.Who we share data with
We use the following service providers, who process personal data only on our instructions:
| Provider | What they do for us | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting of the website, dashboard and API; database, cache and file storage; verification emails; bot protection (Turnstile); fallback AI model | Global network; United States |
| Polar Software, Inc. (Polar) | Checkout, payment processing, invoicing and tax, as merchant of record | United States |
| OpenRouter, Inc. and the model provider it routes to | Arabic text enrichment, only when you request it | United States |
| Functional Software, Inc. (Sentry) | Error monitoring: technical details of failures in the dashboard and API (the page or route, browser, and error). API keys and cookies are removed before sending | European Union (Germany) |
| PostHog, Inc. | Product analytics on crawlfeed.dev and the dashboard, only if you accept analytics cookies | European Union |
| Google LLC and GitHub, Inc. | Sign-in, only if you choose "Continue with Google" or "Continue with GitHub" | United States |
To fulfil a request, we send the handle, id or search term it names to the relevant data source. These sources do not receive your account details:
- Data providers: Third-party services that retrieve public data from social, video, music, shop and ad-library platforms, including a back-up provider for some platforms
- Proxy network: A network provider that routes pages we retrieve ourselves
- Official platform APIs: The platforms’ own public APIs, where they offer one
We may also disclose data where the law requires it, or to protect our rights, our customers or the public.
9.International transfers
Some of our providers are in the United States or operate globally. Where personal data leaves the UK or the European Economic Area, we rely on an adequacy decision (including the EU-US Data Privacy Framework and its UK Extension, where the provider is certified), or on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum. You can ask us for details at support@crawlfeed.dev.
10.How long we keep data
| Data | Kept for |
|---|---|
| Account, API keys and usage history | While your account is open; deleted when you delete the account in Settings, or within 30 days of asking us by email |
| Sessions | Until you sign out or the session expires |
| Purchase and credit records | 6 years, for tax and accounting obligations |
| Cached API results | Up to 24 hours |
| Archived API responses | 30 days |
| Support emails | Up to 2 years after the conversation ends |
| Error reports (Sentry) | Up to 90 days |
| Analytics events (PostHog) | Up to 12 months |
11.Your rights
Under UK and EU GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have your data deleted;
- restrict how we use it;
- receive data you gave us in a portable format;
- object to processing based on legitimate interests;
- withdraw consent, where we rely on consent.
You can delete your account yourself under Settings in the dashboard. To use any of the other rights, email support@crawlfeed.dev from the address on your account. We reply within one month. It is free, unless a request is clearly unfounded or excessive.
You can complain to a data protection authority. Our lead authority is Portugal’s Comissão Nacional de Proteção de Dados (cnpd.pt). You can also complain to the authority in the EU country where you live or work, or, in the UK, to the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to help first.
12.Cookies
Strictly necessary, set without asking because the service cannot work without them: on app.crawlfeed.dev, a session cookie that keeps you signed in; on the sign-up form and the free tools, Cloudflare Turnstile’s cookies that tell people from bots; and crawlfeed_consent, which remembers your cookie choice for 6 months on both crawlfeed.dev and app.crawlfeed.dev.
Analytics, only if you accept: PostHog’s cookies (names starting ph_), which hold a random identifier so visits can be counted. Rejecting sets none of them and loads nothing from PostHog. You can change your mind at any time from “Cookie settings” in the site footer or the dashboard’s account menu. We use no advertising cookies.
13.Security
All traffic is encrypted in transit. Passwords and API keys are stored as one-way hashes. The single exception is the first key we create for a new account, which is stored encrypted until you have copied it once and is then deleted. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.
14.Children
crawlfeed is not for anyone under 18, and we do not knowingly collect personal data from children.
15.Changes to this policy
If we change this policy in a way that matters, we will tell you by email or in the dashboard before the change applies. The date at the top shows when it was last updated.