docs/md_v2/privacy.md
Last updated: April 20, 2026
Crawl4AI ("we", "us", "our") provides web crawling, scraping, and structured data extraction services through our open-source library, hosted API ("Crawl4AI Cloud"), dashboard, integrations, and Workspace add-ons. This Privacy Policy explains what we collect, how we use it, and the choices you have.
By creating an account or using our services, you agree to this Policy.
Crawl4AI is operated by CRAWL4AI, located at 38 Beach Road, #26-12, South Beach Tower, Singapore 189767. Contact: [email protected].
We collect only what we need to operate the service.
Account information — when you sign up via Google or GitHub OAuth, we receive your email address, display name, profile picture URL, and a stable account identifier from the provider. We do not receive or store your password.
Usage data — for jobs you submit (crawls, extractions, enrichments, screenshots, scans), we record: the input URLs or keywords, the configuration you chose, timestamps, billable credits consumed, status, and links to results stored in our object storage. We retain results for the period defined by your plan (typically 30 days).
API keys — when you generate an API key, we store a hashed version on our servers. The plaintext is shown to you once at creation and never stored in retrievable form afterwards.
Operational logs — request method, path, status code, latency, IP address, user agent, and request ID. Used for debugging, abuse prevention, capacity planning, and security incident response.
Payment information — handled by our payment processor (Stripe). We do not store full card numbers; we keep only the customer reference, plan, and the last four digits of the card for display.
Cookies — minimal session cookies for authentication and CSRF protection. We do not use third-party advertising cookies.
We do not sell your personal information. We do not use the contents of pages you crawl, the keywords you submit, or the results we extract for advertising or to train third-party machine-learning models.
Our Google Workspace add-ons run within your Google account using Apps Script. Specifically:
PropertiesService, which is encrypted at rest by Google and scoped to your Google account.We share information only when needed to run the service:
We use TLS in transit, encryption at rest for stored objects and database backups, scoped service credentials, network isolation, and least-privilege access controls. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you without undue delay.
We host primarily in the EU (Hetzner) and the US (AWS). When we transfer personal data across regions, we rely on standard contractual clauses or other legally recognised transfer mechanisms.
Depending on where you live, you may have the right to:
To exercise any of these rights, email [email protected]. We will respond within 30 days. We will not discriminate against you for exercising these rights.
Our services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
We may update this Policy from time to time. Material changes will be announced via email and through an in-product notice at least 14 days before they take effect. The "Last updated" date at the top reflects the latest revision.
Questions, complaints, or requests:
Crawl4AI 38 Beach Road, #26-12, South Beach Tower, Singapore 189767 [email protected]