Legal

Privacy Policy

Last updated: March 28, 2026

We believe privacy is a right, not a feature. This policy explains exactly what data we collect, why, and how long we keep it. No surprises.

🚫We never sell your data
🔒Encrypted at rest & in transit
🍪Essential cookies only
🗑️Delete your data anytime

Contents

1. Overview2. Data We Collect3. How We Use Your Data4. Data Storage & Security5. Third-Party Services6. Cookies7. Data Retention8. GDPR & CCPA9. Children's Privacy10. Changes to This Policy11. Contact

1. Overview

uncaptcha.dev ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data. By using uncaptcha.dev, you agree to the collection and use of information in accordance with this policy. We will never sell your personal data.

2. Data We Collect

We collect the following categories of information: Account information • Email address (required for account creation) • Name (optional, provided by you or via OAuth) • Profile picture (optional, from OAuth providers only) • Hashed password (if using email/password login) Usage data • API request logs: timestamp, CAPTCHA type, site key, page URL, response time, success/failure status • API key identifiers (prefix only — full keys are never logged) • Browser and device type when accessing the dashboard • IP address (for rate limiting and abuse prevention, retained for 30 days) Payment information • Transaction IDs and order references from PayPal • Subscription plan and billing status • We do not store full card numbers — payment details are handled entirely by PayPal OAuth data (if you sign in with Google or GitHub) • Email address and display name provided by the OAuth provider • We do not receive or store OAuth access tokens beyond the authentication flow

3. How We Use Your Data

We use the data we collect exclusively to operate and improve the service: • Authenticating you and securing your account • Processing API requests and returning CAPTCHA solutions • Billing, invoicing, and fraud prevention • Sending transactional emails (account alerts, billing receipts, usage warnings) • Monitoring service health and debugging errors • Improving solve accuracy and API performance • Complying with legal obligations We do not use your data for advertising, profiling, or sale to third parties.

4. Data Storage & Security

Your data is stored in Supabase (PostgreSQL), hosted in a SOC 2-compliant cloud environment. All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). API keys are stored as one-way hashed values — we cannot recover a key once created. Passwords are hashed with bcrypt. Access to production databases is restricted to authorized personnel only, and all access is logged and audited.

5. Third-Party Services

We share data with the following service providers only as necessary to deliver the service: • Supabase — database hosting and authentication • PayPal — payment processing (subject to PayPal's Privacy Policy) • Vercel — web application hosting (anonymized request logs only) • Google OAuth / GitHub OAuth — only used if you choose to sign in with these providers We do not share your data with any other third parties. Our service providers are contractually bound to use your data only to provide services to us.

6. Cookies

We use minimal, essential cookies only: • Authentication session cookie — keeps you logged in during a browser session • No advertising cookies • No third-party tracking cookies • No analytics cookies by default If we add analytics in the future, we will update this policy and provide an opt-out mechanism.

7. Data Retention

We retain your data for the following periods: • Account data: retained while your account is active, and for 30 days after deletion (to allow recovery) • API request logs: 90 days rolling window • IP addresses: 30 days for rate limiting purposes • Payment records: 7 years as required by financial regulations • Deleted accounts: fully purged within 30 days of deletion request You may request deletion of your account and associated data at any time. See Section 9 for your rights.

8. GDPR & CCPA

If you are located in the European Economic Area (EEA), UK, or California, you have the following rights: GDPR (EU/UK) rights: • Right to access — request a copy of all data we hold about you • Right to rectification — correct inaccurate personal data • Right to erasure ("right to be forgotten") — request deletion of your data • Right to data portability — receive your data in a machine-readable format • Right to object — object to processing based on legitimate interests • Right to restrict processing — limit how we process your data CCPA (California) rights: • Right to know what personal information is collected and how it is used • Right to delete personal information • Right to opt-out of the sale of personal information (we do not sell data) • Right to non-discrimination for exercising your CCPA rights To exercise any of these rights, contact us at uncaptcha.dev@gmail.com. We will respond within 30 days.

9. Children's Privacy

Our service is intended for users aged 16 and older. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered address at least 14 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.

11. Contact

For privacy-related questions, data requests, or concerns, contact our privacy team at: Email: uncaptcha.dev@gmail.com We aim to respond to all privacy inquiries within 5 business days.

Questions about this Privacy Policy or want to exercise your data rights? Email us at uncaptcha.dev@gmail.com. We respond within 5 business days.