webscrapingapi.dev
  • Docs
  • Site endpoints
  • Requests & board
  • Blog
Sign in Get a free key
Dashboard

Privacy

Privacy Policy

Last updated: September 21, 2026 · Controller: Jaeyoung, an individual · Terms of service

This policy explains what personal data webscrapingapi.dev ("the service") collects, why, how long it is kept, where it is stored and what you can do about it. It is written to satisfy the Personal Information Protection Act of the Republic of Korea, where the operator is based, and to be clear to users elsewhere. The short version: the service keeps your account details, a 30-day log of your requests without the pages themselves, and what you post on the board. It runs no advertising and sells nothing.

1. Who is responsible

The data controller and the person in charge of personal data protection is Jaeyoung, the individual who builds and runs the service. Contact: the board (for anything that should not be public, say so in the post and it will be handled privately).

2. What is collected, why, and for how long

DataPurposeKept
Account: email address, display name, sign-in provider (Google or email/password) and the identifier Firebase Authentication assigns. Passwords are handled by Firebase and never visible to the operator.To sign you in, to tie keys and quotas to you, to contact you about the service if necessary.Until you delete your account or it is removed after twelve months without activity.
API keys: a hash of each key, its prefix, its name, when it was created and last used, and its request count. The key itself is shown once at creation and not stored.To authenticate requests and let you manage your keys.Until you revoke the key or delete your account.
Request log: for each API request, the target hostname (not the full URL or query string), the response status, timing, credits used, whether rendering was used, the error code if any, and which key and account made it.To enforce quotas and rate limits, to show you your usage, to detect abuse and to fix broken endpoints.30 days, then deleted automatically.
Daily usage counters per account.Quota enforcement.Rolling; entries older than a few days are removed.
Board content: posts, comments, the site you request and its status, your display name shown next to them.To run the board and build requested endpoints.Until you delete them or the account is deleted. Public posts may remain visible in anonymised, summarised form if they document how an endpoint was built.

Legal basis: performance of the service you asked for (account, keys, logs, board), the operator's legitimate interest in keeping the service safe and within its cost limits (abuse detection), and your consent where the law requires it, which you give by creating an account.

3. What is not collected

  • The pages you fetch. Response bodies, full URLs and query strings are processed in memory and discarded. Only the hostname is logged.
  • Results from the site-specific endpoints are stored for up to 30 days so that other users asking for the same public page can be served without a new fetch. They are derived from public pages and are not linked to the user who requested them.
  • No advertising, analytics or tracking cookies. The only browser storage used is what Firebase Authentication needs to keep you signed in.
  • No payment data. The service is free and takes no payments.

4. Who else sees the data

  • Processors. The service runs on Google Cloud and Firebase (Google LLC), which store the data on the operator's behalf: authentication, the database, the request log and the servers. Google acts under its own data processing terms and does not use the data for its own purposes.
  • No sale, no sharing for marketing. Personal data is not sold, rented or shared with advertisers or data brokers.
  • Legal requests. Data may be disclosed if the law requires it or to protect the service or others from harm, and only to the extent necessary.
  • Public board. Anything you post publicly is, by design, visible to everyone and may be read by search engines and AI crawlers, which this site explicitly allows.

5. Where the data is stored (international transfer)

The data listed above is stored and processed in Google Cloud data centres in the United States (region us-central1) by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. It is transferred there over encrypted connections at the moment you sign in or make a request, for the purposes and periods in section 2. Google is bound by its Cloud data processing terms and standard contractual clauses. If you do not want your data transferred to the United States, do not use the service; there is no alternative region.

6. Your rights and how to use them

  • See and correct. Your account details, keys and usage are visible in the dashboard.
  • Revoke keys and delete posts yourself, at any time, in the dashboard and on the board.
  • Delete your account. Contact the operator (section 1) from the email address on the account. The account, its keys, its usage counters and its board content are deleted within 14 days; request-log entries expire on their own within 30 days.
  • Object or restrict. You can ask the operator to stop or limit processing, or withdraw consent, with the same contact. Withdrawing consent ends your use of the service.
  • Complain. Residents of Korea can contact the Personal Information Protection Commission (privacy.go.kr, 182). Residents of the EEA or the UK can contact their local supervisory authority.

7. Children

The service is not directed at children. You must be at least 14 years old to create an account. If an account belonging to a younger child comes to the operator's attention, it is deleted.

8. Security

All traffic is encrypted in transit. API keys are stored only as hashes, so a database leak would not reveal them. Access to the production project is limited to the operator with two-factor authentication. No system is perfectly secure; if a breach affecting your data is discovered, you will be told without undue delay.

9. Changes to this policy

Changes are published on this page with a new "last updated" date. Changes that expand what is collected or how it is used take effect only after being shown here for at least seven days.

© 2026 webscrapingapi.dev · Free, capped, no card.
  • Docs
  • Site endpoints
  • Requests & board
  • Blog
  • About
  • Dashboard
  • Terms
  • Privacy