Information We Collect
The data involved depends on whether you only visit the public website, use an account or start a specific data request. The main categories are:
- Account Information: Name, email address, profile picture and, where available, your organization, workspace and role
- Payment Information: Polar processes payment and invoice details as merchant of record. Crawl Foundry receives information such as the order reference, payment status, plan and amount to credit, but not your full card details
- Content Data: Imported keywords, lists, tags, domains, audit settings and results, exports, external data requests you start, and prompts and results from optional AI features
- Usage Data: Feature activity, job and error status, browser and device information, and technical connection data where needed for operations, security or measurement
How We Use Your Information
We process this data for defined purposes, including:
- Provide accounts, workspaces, the keyword database and site audits
- Bill paid data actions and match orders, invoices and job status
- Send service notices, security messages and transactional emails
- Answer support requests and investigate reported failures
- Measure the public website and signed-in product separately and improve the product
- Detect and investigate abuse, unauthorized access, billing errors and security incidents
Data Controller
The controller responsible for processing your personal data under the GDPR is:
Full provider details are listed in our Imprint.
Legal Basis for Processing
We process your personal data on the following legal grounds under Article 6 GDPR:
- Contract performance (Art. 6(1)(b) GDPR): Processing needed to provide your account, workspace, keyword database, site audits, data requests you start and any plan you purchase.
- Legitimate interest (Art. 6(1)(f) GDPR): Processing for service improvement, aggregate analytics, error tracking, and security monitoring, where your rights do not override these interests.
- Consent (Art. 6(1)(a) GDPR): Processing you have explicitly agreed to, such as marketing emails. You can withdraw consent at any time. Details on how we measure usage are in our Cookie Policy.
Storage and Security
Workspace data is stored in Crawl Foundry's Convex-based backend. Access checks use the signed-in person, their organization and their workspace role. A service provider receives data only for the part it performs in a given workflow.
We use technical and organizational safeguards, including access controls, protected transport, logging with redaction rules and limited permissions. No online service can promise that every risk has been eliminated.
Services and Recipients
Depending on the feature you use, the following services help provide Crawl Foundry. Not every service receives data on every visit or job:
- Clerk: Authentication and user management
- Polar.sh: Merchant-of-record payment processing, billing addresses, tax determination, subscriptions, invoices and receipts. Polar independently processes the transaction data required to sell the paid service.
- Convex: Real-time database and backend
- DataForSEO: External keyword, SERP, domain and backlink data when you start the corresponding data request
- Google Search Console: Optional read-only connection to a property you select; Crawl Foundry currently processes connection, property and coverage information
- OpenRouter/OpenAI: Processing of prompts and results when you run a feature that is explicitly identified as AI-assisted
- OpenAI ChatGPT/Codex: When you connect Crawl Foundry as an app to ChatGPT or Codex, Crawl Foundry sends the required inputs and requested results to OpenAI only after a tool call you initiate and within your workspace permissions. This can include domains, keywords, rankings, Search Console data, site audits, backlinks, competitor analysis, content, work status and billing status. Internal request, trace, organization and actor identifiers are not included in model output. OpenAI's own privacy terms also apply to its processing; you can disconnect the integration in OpenAI and Crawl Foundry.
- Langfuse: AI observability and debugging
- Inngest: Orchestration and retries for longer-running data and audit jobs; this can include job identifiers and the inputs required for that run
- Resend: Delivery of account, support, cancellation, withdrawal and other transactional messages
- Vercel: Hosting and delivery of the public website and web app, which involves technical connection and request data
- Umami: Self-hosted analytics for the public website and help center: page views, referrers, and campaign parameters, without cookies in the standard setup
- PostHog: Product analytics inside the signed-in app at app.contextter.com
- Sentry: Error tracking and monitoring
The privacy role depends on the transaction. Some providers process data on our behalf; Polar acts as an independent merchant of record for purchases and billing. The provider's own privacy notice also applies.
The public website and help center run on self-hosted Umami without analytics cookies in the standard setup. For details on cookies and measurement, see our Cookie Policy.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
After account deletion, we remove or anonymize data once it is no longer needed to provide the service. Billing records, transaction evidence, security logs and technically limited backups may remain longer because of legal retention periods, the defence of claims or backup cycles.
Your Rights (GDPR)
Where the legal conditions are met, you can exercise the following rights:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data
- Portability: Request transfer of your data
- Objection: Object to processing of your data
- Restriction: Request restriction of processing
- Complaint: Lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live, work, or where you believe an infringement occurred (Art. 77 GDPR).
To exercise these rights, please contact us at info@contextter.com
International Transfers
Some providers also process data outside the European Economic Area. Where no adequacy decision applies, we rely on appropriate safeguards, in particular standard contractual clauses, and consider the additional measures available for the service concerned.
Changes to This Policy
We update this policy when the product, providers or legal requirements change. The date above identifies the current version. Where required, we also use an appropriate channel to notify you of material changes.
Contact Us
If you have any questions about this Privacy Policy, please contact us at info@contextter.com