Legal

Privacy Policy

What we collect when you visit scrapingbot.io or use the API, why we collect it, who sees it, how long we keep it, and how to get a copy or have it deleted.

ScrapingBot
On this page

ScrapingBot (“we”, “us”) runs scrapingbot.io and the ScrapingBot API and MCP server. This policy covers the personal information we handle about visitors and customers. It does not cover the data you collect with the API; for that, see Data you collect with ScrapingBot.

We don’t sell personal information, and we only collect what we need to run the service, bill for it, keep it secure, and understand how people find and use it.

What we collect

Your account

  • Name and email address you give us when you sign up, and your password, which we store only as a salted hash (bcrypt). If you sign up with Google, Google tells us your name, email address and Google account ID, and we don’t get a password.
  • API keys we create for you, and team memberships and invitations if you use teams.
  • Where you came from when you signed up: the referring site, the first page you landed on and any campaign tags in the link (such as utm_source or an ad click ID), so we know which pages and ads bring customers.

Billing

Payments are handled by Stripe. Your full card number goes to Stripe, never to us. We keep the card brand, last four digits and expiry date Stripe gives us, your plan and subscription status, invoices and the credits you have bought and used.

API and MCP usage

For each request we log the time, the API key, the endpoint or target URL, the parameters needed to run it, the status, how long it took, any error, and the credits charged. That log is how we bill, show you your usage, refund failed calls and fix problems. The results of a request (the scraped page or data) are kept for 24 hours so you can fetch them again by job ID, then deleted.

Visiting the website

  • Product analytics and session recordings. Our pages record page views, clicks, scrolling, performance timings and errors, and record sessions so we can see where the site is confusing or broken. Recordings capture what is on the page and what you type, except passwords and fields we mark as secret, such as your API keys. When you are signed in, the recording is linked to your account. We store your approximate location (city, region, country) worked out from your IP address, not the address itself. Browsers that send Do Not Track are not recorded.
  • Advertising. We run ads on ChatGPT and measure ads with Google. When you arrive from one of our ads, we keep the ad’s click ID in a cookie for 30 days. If you then sign up, start using the API or buy a plan, we tell that ad platform so it can measure the ad: we send the click ID, the type of event (and the amount for a purchase), a one-way hash of your account number, and your IP address and browser user agent at sign-up. We never send your name or email. Our site also loads the Google tag for Google Ads measurement, which sets Google’s own cookies.
  • Abuse prevention. To stop automated sign-ups and abuse of the free tools, we keep a one-way hash of your IP address for 1 day (sign-ups) or 7 days (free tool limits).

Support and email

If you write to us by email or through the chat on the site, we keep the conversation so we can help you. We send account emails (such as welcome, password reset, team invitations and low-credit warnings) and a few getting-started tips in your first weeks. Every tip email has an unsubscribe link.

Cookies

  • connect.sid: keeps you signed in. Expires after 30 days without a visit.
  • sb_attr: remembers the ad or campaign link that brought you, for 30 days, so a later sign-up is credited to it.
  • An analytics visitor ID (first-party, 1 year) that ties page views and recordings to one browser.
  • Cookies set by the Google tag for ad measurement.

You can block or delete cookies in your browser. The site works without the analytics and advertising cookies; signing in needs connect.sid.

How we use it

  • To run the API, the dashboard and your account, and to charge the right amount.
  • To keep the service secure and stop fraud and abuse.
  • To answer support requests and send the emails described above.
  • To understand which pages, ads and features work, and to fix what doesn’t.
  • To meet legal, tax and accounting obligations.

Where the GDPR or UK GDPR applies, we rely on performing our contract with you (running your account and the API), our legitimate interests (security, product analytics, measuring our ads, improving the service), and legal obligations (tax and accounting records).

Who we share it with

We share personal information only with service providers who process it for us, and only what each needs:

  • Stripe, for payments and invoices.
  • Our email delivery provider, to send account and getting-started emails.
  • Cloudflare, which sits in front of the site and API for performance and security and sees the traffic passing through it.
  • OpenAI: for the ChatGPT endpoint and AI extraction, the prompt and page content you send are processed by OpenAI to produce the answer. Separately, OpenAI and Google receive the ad measurement events described above.
  • Data and infrastructure providers that help fetch pages and public data. They receive the request parameters needed to run your request (for example a URL, a username or a search term), never your account details.
  • Authorities, if the law requires it, and a buyer or successor if the business is ever sold or merged, under this same policy.

Under California law, sending ad measurement events to an ad platform can count as “sharing” for advertising. To opt out, email us and we will stop doing it for your account. You can also block the Google tag and cookies in your browser.

How long we keep it

  • Account, billing records and invoices: while your account is open, then as long as tax and accounting law requires.
  • API usage logs: 400 days. Request results: 24 hours. Job records: 30 days. Error logs: 90 days.
  • Website analytics events: 180 days. Session recordings: 14 days.
  • Hashed IP addresses: 1 day (sign-ups) or 7 days (free tools).
  • Support conversations: as long as we need them to help you and keep a record of what we agreed. Ask and we will delete them.

Your choices and rights

Email [email protected] from your account’s email address to ask for a copy of your data, to correct it, or to close your account and delete it. We will answer within 30 days. Depending on where you live (for example the EU, the UK or California), you may have further rights, such as to object to or restrict some processing, to take your data elsewhere, or to complain to your data protection authority. We won’t treat you differently for using them.

You can change your name, email address and password in your account settings, and stop tip emails with the link in any of them.

Data you collect with ScrapingBot

When you use the API to collect public data, you decide what to collect and what to do with it, and you are responsible for it under the laws that apply to you. We process that data only to run your requests and keep it no longer than described above (24 hours for results). If you need a data processing agreement for that role, email us.

Security and transfers

Traffic is encrypted with HTTPS, passwords are hashed, API keys are masked in our recordings, and access to production data is limited to the people who run the service. No system is perfectly secure; if a breach affects your data, we will tell you as the law requires. We and our providers may process data in the United States and other countries; where the law requires, transfers rely on safeguards such as the EU Standard Contractual Clauses.

Children

ScrapingBot is a tool for developers and businesses and isn’t meant for anyone under 16. We don’t knowingly collect their information; if you think we have, email us and we will delete it.

Changes

We will update this page when what we collect or how we use it changes, and change the date at the top. If a change matters, we will also email account holders before it takes effect.

Contact

Questions or requests: [email protected]. See also our Terms of Service.

Start scraping in the next five minutes.

100 free credits, no credit card. One API key works for websites, TikTok, Instagram, Google, Amazon and ChatGPT.