Legal

Privacy Policy

Last updated 25 September 2026

This policy explains what CaptchaKraken LLC ("we") collects when you use the CaptchaKraken API and website, why, and what we do not collect. We have tried to make it specific enough to be checkable rather than broad enough to cover anything.

1. What we collect

Account information

Your email address, and — if you sign in with GitHub — your GitHub username and account identifier. Used to identify your account, issue keys, and contact you about the Service.

Usage metadata

For every metered inference response we record: a timestamp, the account and API key used, an opaque session identifier you supply, the puzzle class, credits charged and any reason a response was waived, prompt and completion token counts, how long the request took, the HTTP status, and an optional client label such as camoufox/0.4.11. This is what produces your usage history and your bill.

Payment information

Payments are processed by Stripe. We receive a transaction identifier, the amount, and the processor's fee. We never receive or store your card number.

Technical logs

Our servers and our CDN/reverse proxy record standard request metadata, including IP address, for security, abuse prevention, and diagnostics.

When you sign up

Free trial credits attract automated signups, so when you create an account we record what we need to tell a person from a farm of bots: your IP address and browser user agent; what GitHub tells us about the account (its age, and how many public repositories and followers it has); characteristics of your device and browser, combined into a fingerprint; how you interacted with our pages, such as pointer movement, typing rhythm and timing, but never what you typed; and which of our pages you viewed before signing up, and the page that referred you. The page list is kept in your own browser, in local storage, and reaches us only if you sign up.

We use this only to prevent abuse of the free credits: to decide whether a signup receives them, and to withdraw them or suspend an account where it is clearly part of an automated farm. We never sell it and never use it for advertising. The address, user agent, device details and interaction record are deleted 90 days after signup.

2. What we keep from a solve, and what we do not

A solve your client reports as successful is not retained. The screenshot is held for the duration of the request, passed to the model, and discarded. It is never written to our usage records, which store counts and classifications only, and our application logs deliberately never serialise request bodies.

A solve that fails may be kept, to make the model better at it. A wrong answer is invisible to us otherwise — we see a well-formed response either way, and only your browser knows whether the widget accepted it — so the puzzles the model is worst at are the one thing we cannot learn without keeping them. If we keep a failed solve we may use it to train and evaluate our models.

  • It is the captcha, not your page. Our solver screenshots the captcha widget itself and never the surrounding page, so what could be kept is a small crop of a puzzle and cannot contain your account screen or anything else on it.
  • It is bounded. Anything kept is deleted after a fixed retention window, and the store has a size ceiling above which the oldest is dropped.
  • You can switch it off. Ask us and we will disable it for your account, end to end — nothing is written for you at all, not even briefly. Write to support@captchakraken.com.
  • We do not sell or rent personal information to anyone.
  • We use no advertising trackers, no third-party analytics, and no tracking cookies. The public pages set no cookies at all. When accounts ship, a strictly necessary session cookie will be used for sign-in and nothing else.

3. Why we may process it

To provide the Service and perform our contract with you; to bill accurately and meet tax and accounting obligations; to secure the Service and prevent abuse (our legitimate interest); and to communicate with you about your account.

4. Who we share it with

We share only with processors necessary to run the Service:

  • Stripe — payment processing and fraud prevention.
  • GitHub — sign-in. Authenticating through GitHub tells us your account id, username and verified email address, and tells GitHub that you signed in to CaptchaKraken.
  • Hugging Face — only for Abyss Licence holders. The Hugging Face username you give us is sent to Hugging Face to grant, and later to withdraw, that account's access to the model's download.
  • Our hosting and infrastructure providers — servers, network, and backups.

We may also disclose information where legally required, or where necessary to investigate a violation of our terms.

5. How long we keep it

  • Submitted images: a successful solve is not retained beyond the request. A failed solve may be kept for up to 30 days and is then deleted, unless you have asked us to switch capture off for your account.
  • Usage and billing records: retained while your account is open and afterwards as long as required for tax, accounting, and audit purposes.
  • Technical logs: a short rolling window, typically weeks, then discarded.
  • Signup details (IP address, user agent, device fingerprint and characteristics, page interaction and page history): 90 days from signup. The resulting decision about trial credits is kept with the account.
  • Account details: until you ask us to delete them, subject to the above.

6. Your rights

You may ask us to access, correct, export, or delete your personal information, and to restrict or object to processing. Depending on where you live — for example under the GDPR or the Colorado Privacy Act — these may be legal rights rather than courtesies. Write to support@captchakraken.com and we will respond within 30 days. Note that we must keep billing records we are legally required to retain, even after an account is deleted.

7. Security

Traffic is encrypted in transit. API keys are stored only as hashes, never in recoverable form. Internal administrative endpoints are additionally protected by mutual TLS and are not reachable from the public internet. Access to production data is limited to those who need it. No system is perfectly secure, and we do not claim otherwise.

8. International transfers

We operate from the United States, and information is processed there. If you use the Service from elsewhere, you are sending it to the US.

9. Children

The Service is not for anyone under 18, and we do not knowingly collect information from children. If you believe we have, tell us and we will delete it.

10. Changes and contact

We will update this page if our practices change, and revise the date above. Questions, requests, or complaints: support@captchakraken.com, CaptchaKraken LLC, Colorado, USA.