1. Who is responsible
ScrapeAtlas is operated by OD. Media & Technology LLC, License No. 2431901.01, Sharjah Media City, Sharjah, United Arab Emirates. We determine how account, security and service-administration information is used. Contact admin@fddigital.net about this policy or a privacy request. Other products operated by our company have their own privacy notices.
2. Account and support information
Registration provides us with your email address and authentication information. You may also supply a display name. Supabase manages authentication, including password verification, session records and account recovery. If you choose an available Google or GitHub sign-in option, we receive the identity and basic profile information that provider supplies for authentication. Sign-in does not authorize us to read your private mail or repositories.
We keep API-key identifiers, names, prefixes, hashes, creation and expiry dates, and revocation records. A new key's full secret is displayed once; our key database retains its hash rather than a recoverable copy. Support correspondence includes what you choose to send. Please omit passwords, API secrets and unnecessary personal information.
3. Requests and operational records
To fulfil an API call, we process its inputs, which may include a public URL, search phrase, account handle or pagination token. The gateway authenticates your key and forwards the supported request to the relevant retrieval service. Information needed to fetch a page passes through the source platform and any transport or proxy provider used for that request; your ScrapeAtlas API key is not sent to the source platform.
Our application usage records describe activity through account and key identifiers, endpoint, time, response status, duration and usage counts. They exclude search text, target handles and URLs, response content and plaintext credentials. Hosting and authentication services may separately process network and security information, such as IP addresses and browser details, when delivering or protecting the service.
4. Information from public sources
Depending on the endpoint, a response can contain published names, usernames, biographies, posts, comments, public contact details, links, images, engagement figures or other fields described in our API documentation. The source is the public platform page or public interface requested by the customer. We do not require a customer's social-platform password or provide access to private messages or account-only content.
Retrieval workers process source content for the current request and do not keep a database, response cache or archive of it. A customer receiving a response can retain its own copy and is responsible for its subsequent use. Public visibility does not remove a person's privacy rights or give a customer unrestricted permission to reuse their information.
If your information appears in a response, you may contact us without having a ScrapeAtlas account. Our Public Data Notice explains the request process. Identify the relevant public page and explain your request; do not send identity documents unless we ask for an appropriate verification step. We will assess requests to correct, delete, restrict or object to processing under applicable law. We cannot edit the original platform or erase copies held independently by customers; requests concerning those copies should also go to their respective operators.
5. Why we process information
We use account information to provide access, operate sessions and keys, answer support requests and send account or security messages. Operational records help us enforce limits, diagnose failures, measure service reliability and investigate abuse. If you buy a paid service, order and transaction records are used for fulfilment, accounting and handling payment questions.
Where data-protection law requires a legal basis, we use the basis applicable to the activity: fulfilling our agreement with you, meeting a legal duty, consent where required, or legitimate interests where recognized and balanced against individual rights. Public-data retrieval requires a lawful basis appropriate to the request; a customer's instruction alone does not override privacy law. Where we act as a processor for an agreed customer workload, the customer's lawful instructions and any required data-processing agreement govern that processing.
6. Providers and disclosures
Supabase supplies our account and authentication infrastructure. Hosting, email delivery and network providers support operation of the service. Where configured, Tinybird stores account-linked operational usage measurements with a 30-day retention policy. Where configured, PostHog receives sanitized retrieval-error categories and technical status information, without request inputs or source content. Our website loads fonts from Google Fonts, so Google receives the network information needed to deliver those files. A payment provider identified at checkout handles any payment credentials; do not send card details to support.
We give providers information needed for their role and apply appropriate contractual restrictions where they process it for us. A sign-in or source-platform provider may also handle information for its own purposes under its own privacy notice. We may disclose information to comply with a lawful demand, address fraud or security threats, establish or defend legal claims, or transfer the business with applicable privacy protections.
We do not sell customer account information or use it for cross-context advertising. Our API supplies public platform information as described above; any statutory rights concerning that activity can be exercised through the same contact address.
7. Browser storage and communications
With your separate referral consent, Affonso records referral visits and stores a referral cookie for 30 days. After a verified signup, we share your verified email address and referral identifier with Affonso to attribute purchases. Stripe shares attributed payment activity with Affonso for commission reporting. You can reset referral consent by clearing ScrapeAtlas cookies and site data in your browser settings. Opening your partner dashboard also shares your verified email with Affonso to create or open your partner membership. Authentication uses browser storage to keep you signed in and complete secure sign-in flows. Dashboard previews may keep temporary state for the current browser session. Blocking or clearing this storage can sign you out or reset those settings. If you accept analytics, Google Analytics and PostHog measure visits and page engagement on our public website and documentation using cookies and browser/device information. PostHog also measures signup-link clicks and website performance. Both receive the public page address and the referring site’s origin; we strip URL query strings and fragments. PostHog processes this website data in its EU Cloud project without person profiles or session recordings. We do not load Analytics on login, account, dashboard or API playground pages, and do not send account identifiers, API inputs or form contents. Advertising storage and personalization are disabled. You can reject analytics or withdraw consent through “Cookie preferences” at the bottom of public pages. We remember your choice for 180 days in browser storage; Google Analytics cookies expire after at most 180 days without renewal; PostHog cookies expire after 180 days and can renew with activity. Declining does not affect access to the service. Google explains its processing at How Google uses information from sites or apps that use its services.
Account verification, recovery and important service messages are part of operating your account. If we send optional promotional messages, you can decline them using the supplied unsubscribe method or by contacting us.
8. How long information is kept
Account information is retained while we operate your account. You can request account deletion by email; deleting the account removes its associated keys and account-linked usage from the active control-plane database. Inactive key metadata and raw API usage have a 30-day retention policy and are removed through our operational purge process. Separately stored usage analytics expire under the same 30-day policy; requests for earlier erasure are assessed under applicable law. These periods concern our application records; authentication-provider audit records follow that provider's applicable retention settings.
Support, transaction and security records may remain where needed to resolve a matter, prevent abuse or satisfy a legal retention requirement. Any backup copies are restricted to recovery and expire under the applicable backup schedule; restored systems must reapply account deletions. We do not keep retrieved platform content as a customer archive. Ask us for information about the retention applicable to a particular request.
9. Security and international processing
Access controls, hashed API-key storage, encrypted public connections and separation of customer accounts help protect information. No service can promise that every security incident will be prevented. We respond to incidents and give notices when applicable law requires them.
Our operator is in the UAE, and our infrastructure and providers can process information in other countries. Where a transfer is restricted by applicable law, an appropriate lawful transfer mechanism is required, such as approved contractual safeguards or a recognized adequacy arrangement. Contact us for information about the arrangements relevant to your data.
10. Your choices and rights
Depending on the laws that apply, you may request access, correction, deletion or a portable copy of personal information, restrict or object to processing, withdraw consent, or exercise rights concerning sale or sharing. Withdrawing consent does not undo processing that was lawful before withdrawal. You may also complain to the competent data-protection authority.
Send requests to admin@fddigital.net. We may need proportionate information to verify identity or authority, and will respond within the period required by applicable law. Legal exceptions may limit a request; we will explain any applicable limitation. We do not penalize you for exercising a privacy right.
11. Age requirements and policy updates
ScrapeAtlas accounts are intended for adults aged 18 or over. If you believe a child has supplied account information, contact us so we can investigate. Requests concerning a child's information on a public source can also be raised through the public-data process above.
We will date and publish revisions here and provide additional notice of material changes where appropriate or legally required. An updated notice does not itself replace consent where consent is required. The Terms of Service explain the conditions for using ScrapeAtlas.