Privacy Policy

Last updated: June 7, 2026. We build for developers, and we keep only the data we actually need.

This Privacy Policy describes how Refetch(er) ("we", "us", or "our") collects, uses, retains, and discloses your information when you create an account, register API keys, and use the Refetch(er) scraper API service ("Service").

Our guiding principle is data minimization: we collect what is necessary to authenticate your requests, bill you accurately, keep the API reliable, and resolve billing or fraud disputes — and we delete the rest on a defined schedule. We do not sell your personal data, and we do not use it for advertising.

2. Information We Collect

We collect and process the following categories of data in connection with the Service:

  • Account information: Your email address, account name, a salted password hash, and email-verification status. If you sign in via Google OAuth, we receive your verified email address and profile name as returned by Google.
  • Billing details: Prepaid top-ups, debits, current balance, currency, country-routing metadata, and payment-provider transaction identifiers. We never see or store your card numbers — checkout is handled entirely by our payment processors (see Section 6).
  • Request metadata: For each API request we record an API-key hash (we never store raw API keys), a request identifier, the target URL submitted for scraping, the platform, response status code, latency, cost, and timestamp.
  • Technical & security data: Your IP address and browser user-agent are recorded with your dashboard sessions and are used for authentication, security, and abuse prevention.
  • Contact data: If you contact us through our forms or by email, we keep the name, email address, and message you provide.

3. Scraped Content & Targets

The core of the Service is fetching publicly available data from social platforms in real time and returning it to you.

  • We do not retain response content long-term. The data we scrape on your behalf is returned to you in the API response. We may temporarily retain full API responses for up to 7 days to debug errors, monitor performance, and ensure reliability, after which they are automatically deleted. Beyond that window we keep at most a non-reversible hash of the response, its byte size, and the status code — so we can verify a specific request if you later dispute a charge.
  • Target URLs you submit are stored as request metadata under the retention schedule in Section 5.
  • We do not attach your identity (email, account name, or API key) to the outbound requests our infrastructure makes to public sources.

4. How We Use Your Information

We use the information above only for the following purposes:

  • Service access: To verify your identity, maintain authenticated sessions, and enable dashboard and playground access.
  • Accurate billing: To calculate request debits at execution time and maintain a correct balance and transaction ledger.
  • Reliability & performance: To monitor routing times, scale infrastructure, and diagnose scraping errors.
  • Fraud & abuse prevention: To enforce rate limits, detect abuse, and defend against unauthorized use.
  • Dispute resolution: To investigate billing discrepancies and to respond to chargebacks or payment disputes.

We do not sell or rent your personal data, and we do not use it for advertising or profiling.

5. Data Retention & Deletion

We keep only what we need, for only as long as we need it. Our retention schedule is:

  • Scraped response content: May be retained for up to 7 days for debugging, performance monitoring, and reliability, then automatically deleted. Afterwards we keep at most a non-reversible hash, byte size, and status code.
  • Detailed request history (full target URL, request ID, status, latency, cost, platform, timestamp): retained for 30 days and visible in your dashboard.
  • After 30 days: the target URL is removed and replaced with a non-reversible fingerprint. We keep only minimal request metadata (request ID, timestamp, status, success, cost, platform) for up to 180 days for billing, fraud prevention, and dispute resolution.
  • Aggregated usage (per-day and per-month request counts and spend, by platform): retained for as long as your account is open so we can show your long-term usage history — without retaining the underlying URLs.
  • Financial records (transactions, top-ups, refunds, balances, and payment-provider identifiers): retained for the life of your account and thereafter as required by applicable accounting and tax obligations.
  • Security and access logs (IP address, user-agent): retained for up to 30 days, then deleted or anonymized.
  • Contact submissions: retained for up to 12 months.
  • Sessions and reset tokens: deleted shortly after they expire.
  • Backups expire on a rolling 30-day schedule.

Where we are subject to a legal hold or an active dispute, we retain the relevant records until the matter is resolved, which overrides the schedule above. You may request deletion of your account at any time (see Section 7); we will remove your personal data and keep only the financial records we are legally required to retain, in anonymized form.

6. Sharing & Sub-processors

We do not sell your personal data. We share data only with the service providers needed to operate the Service, and only as required by law:

  • Amazon Web Services (AWS): We host our systems on AWS.
  • PayPal: Our primary global payment processor. Card and wallet payments are handled directly by PayPal; we receive only a transaction reference and status.
  • Razorpay: Used to process payments for customers in India, because our global processor cannot accept domestic Indian payments. As with PayPal, payment details are handled by Razorpay, not by us.
  • Residential proxy network: To retrieve public data reliably, your requests are routed through a large, rotating pool of residential proxy IPs operated with third-party network providers. For security and competitive reasons we do not publicly identify the specific providers we use.
  • Legal obligations: We may disclose data when required by law or in response to a valid request from a public authority (such as a court or government agency).

7. Your Rights

Depending on where you live, you may have rights over your personal data, including the right to access, correct, delete, or export it, and to object to certain processing. These rights are recognized under regulations such as the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and India's Digital Personal Data Protection Act.

  • Access & portability: You can request a copy of the personal data we hold about you.
  • Correction: You can update your account name from the dashboard or ask us to correct other details.
  • Deletion: You can request deletion of your account; we remove your personal data and retain only the financial records we are legally required to keep, in anonymized form.
  • No sale or sharing: We do not sell or "share" personal information as those terms are defined under California law.

To exercise any of these rights, contact us at privacy@refetcher.com.

8. Data Protection

We implement appropriate technical measures to protect your information:

  • All browser interactions and API requests are encrypted in transit using standard Transport Layer Security (TLS/HTTPS).
  • API keys are stored only as SHA-256 hashes. If a key is leaked or compromised, you can revoke it instantly from the dashboard.
  • Passwords are stored as salted hashes; we never store them in plain text.

9. Cookies & Sessions

Refetch(er) uses cookies solely for necessary session authentication. We do not use advertising or analytics tracking cookies.

  • Dashboard session cookie: We set a cookie (refetcher_session) containing a cryptographically secure, random session token. It is flagged HttpOnly (inaccessible to browser JavaScript) and uses SameSite=Strict rules. It is served with the Secure attribute on production HTTPS hosts.
  • OAuth state cookie: A temporary state cookie protects the Google Sign-in flow against Cross-Site Request Forgery (CSRF). It is deleted immediately after the redirect flow completes.

10. International Transfers

Refetch(er) is operated from the United States. Your data is processed and stored on cloud infrastructure (including AWS), primarily in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. Where required, we rely on appropriate safeguards for such transfers.

11. Changes & Contact

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email.

For privacy questions or to exercise your rights, contact us at privacy@refetcher.com. For billing matters, contact billing@refetcher.com.