Legal

Privacy Policy

Last updated: September 2026

1. Scope

This policy describes what data Domsect collects through the Extract API (https://api.domsect.io/v1/extract), this website, and related dashboards — and how we use it.

It applies to account holders, API users, and visitors. It does not cover the target websites you choose to extract: we are not responsible for those sites' data practices. Compliance responsibility for your target URLs rests with you (see ToS §6).

2. Data we collect

• Account data: when you sign in with GitHub OAuth or email, we receive your name, email address, and public profile identifiers. A GitHub account must be at least 30 days old to receive the one-time trial grant; we record that age check.

• Verification and anti-abuse data: Turnstile challenge results, device fingerprint identifiers (visitor_id, generated in-browser for one-time trial grants), and one-time-email domain checks. These exist to stop multi-account abuse and automated harvesting of free credits.

• Billing data: subscription status, tier, credit balances, and ledger events (grants, consumption, refunds) are recorded in our billing ledger. Payments are processed by Stripe; we do not store full card numbers. We record a card fingerprint hash to detect the same physical card used across accounts.

• Usage data: API request metadata — target URL, tier, parameters such as the us_soil flag, timestamps, request status, and credits consumed — is logged for metering, debugging, and abuse detection. Failed requests (404s, blocks, timeouts) are logged without charge.

• Support correspondence: emails you send to [email protected] and your replies to abuse notices.

3. What we do not collect

We do not ask for, and you must not submit, credentials, paywalled content, or private documents through the service (see ToS §4).

We do not store the extracted content of target pages as a dataset for resale; structured results are returned to your API call and kept only as operational logs described in section 2.

We do not collect government identifiers, health records, precise geolocation, or children's data. The service is not directed at children under 13, and we do not knowingly collect data from them.

4. Cookies and local storage

• Session: NextAuth JWT session cookie, required to stay signed in.

• Human verification: a single-use ds_human cookie marking a passed Turnstile challenge before sign-in, claim, or sandbox application.

• Device identification: a visitor_id generated by FingerprintJS and kept in sessionStorage (with a random localStorage fallback) to detect duplicate trial grants; it is submitted only at the moment you claim a trial grant.

We do not run advertising trackers and do not sell browsing data.

5. How we use your data

• To operate the service: metering credits, routing requests, issuing and revoking API keys, and enforcing rate limits.

• To prevent abuse: detecting duplicate accounts, card reuse, and sandbox fraud; enforcing the Acceptable Use Policy.

• To communicate: billing notices, plan changes, abuse warnings, and replies to support requests.

• To improve reliability: aggregate, de-identified usage statistics (for example, cache-hit rates and tier mix).

6. Subprocessors and data location

We use a small set of infrastructure providers, each processing only what it needs: Stripe (payments and subscription billing), Supabase (account and ledger database), Cloudflare (DNS, edge termination, Turnstile, and Pages hosting), GitHub (OAuth sign-in), and Oracle Cloud Infrastructure (extraction compute).

Extraction compute currently runs in data centers in the Asia-Pacific region; the API dispatch layer serves requests from North America. For requests submitted with us_soil: true, we guarantee zero cross-border data transfer: all data processing, DOM stripping, machine learning inference, and ledger logging are performed entirely within servers physically located in the United States, and offshore failover is strictly disabled (requests fail-fast at 0 credits if US capacity is unavailable). Billed at 2× credits. This guarantee covers our internal compute and processing infrastructure; fetching the public target URL itself travels the public internet to wherever the target site is hosted.

7. Sharing and disclosure

We do not sell your personal data. We disclose it only:

• to the subprocessors listed in section 6, under contract, to operate the service;

• when required by law, court order, or valid government request;

• to protect the service against abuse, fraud, or security threats, or to enforce the ToS and AUP;

• in connection with a merger, acquisition, or asset transfer, with notice to you.

8. Retention

Account and billing records are retained for as long as your account is active and as required by applicable tax and financial-record laws. Operational usage logs are retained for a limited period for metering and abuse investigation, then deleted or aggregated. If you close your account, we delete your account profile and revoke keys; records we are legally required to keep are archived and access-restricted.

9. Your rights

You may request a copy of the personal data we hold about you, ask us to correct it, or request deletion of your account and associated profile data. Write to [email protected] with the account email; we respond within 30 days. Deletion does not apply to records we must retain under section 8, or to data already disclosed under section 7.

10. Security

We apply commercially reasonable safeguards: TLS in transit (Cloudflare Full Strict), service-role keys kept server-side, API keys stored hashed, and least-privilege database access. No system is perfectly secure; we do not warrant against all breaches, and you remain responsible for keeping your own API keys confidential.

11. Changes to this policy

We may update this policy; material changes take effect 30 days after posting at this URL, and continued use constitutes acceptance. The version history of legal documents is kept with each update.

12. Contact

Privacy questions or data requests: [email protected].