Privacy
Last updated 31 July 2026
This covers two different things, and it is worth keeping them apart: what we hold about you, the person using the API, and what we hold about the domains we read.
What we hold about you
- Your account: email address, name if you give one, and your organisation.
- Your API keys, stored hashed, and when each was last used.
- Request records: which domain was asked for, when, from which key, the status we answered with, and how long the read took. This is how metering and rate limits work.
- Anything you send us by email.
We hold this to run the service, meter it, bill it and keep it from being abused — a contractual and legitimate-interests basis, not consent. We do not sell it, and we do not use it for advertising.
What we hold about the domains we read
When a domain is sampled, we open that company's own public pages, measure what renders and store the result — logos, colour values, font families, a screenshot used to produce them, and the confidence figures. This is business identity published by a company to anyone with a browser, and in most cases it is not personal data at all.
That result is cached, and the cache is shared across the whole service. It is served to any other caller who asks for the same domain, so a domain read once for one customer is answered from the cache for every customer after that. There is one entry per domain, not one per account, and the entry does not record who asked for it first.
A small site can carry personal data on its public pages — a sole trader's name in a logo, a photograph used as a mark. If that has ended up in an entry, the removal process is the same one a brand owner uses, and it is on the removal and DMCA page. We check that the person asking controls the domain, then an operator applies the removal; after that the API refuses the read and the domain cannot be sampled again.
Who else processes it
We use a small set of providers to run the service, each on their own terms: a cloud host and blob store (Vercel), a database (MongoDB Atlas), a background-job runner (Inngest), a hosted browser used to render the pages we measure, and Google's Gemini models for the parts of an extraction that need a model. Some are outside the UK and EEA, and those transfers rely on the standard contractual clauses. When paid plans open we will add a payment processor and name it here.
How long we keep it
- Account records: while the account is open, and for as long afterwards as tax and accounting law requires.
- Request records: rolling, and trimmed once they are no longer useful for metering, billing or abuse investigation.
- Cache entries: we set no expiry date on one. An entry goes stale on a schedule and is re-read the next time somebody asks for that domain, so a redesign does not sit behind an old answer — but the entry itself stays until it is removed under the process above.
- A removal deletes the entry outright, from both stores that hold it: the shared cache the API answers from, and the sampler's own store. No copy of the brand's data is left on either. What we keep instead is a separate removal record, held against the domain rather than against the brand — who asked, who verified control of the domain, when it was applied and why. That record, not anything left behind in the cache, is what stops the domain being read again.
- Our internal record of an extraction — that we ran one, what the page gave us and what it cost — is kept after a removal as an audit trail. It is never served to a caller.
Your rights
If you are in the UK or the EEA you can ask for a copy of what we hold about you, ask us to correct it, ask us to erase it, object to our processing it, or ask for it in a portable form. Write to hello@extractbrand.com. A person reads it and answers — there is no automated request portal, and no queue you can watch. If you are not satisfied with how we handle it, you can complain to the Information Commissioner's Office.
Cookies
The marketing pages set no analytics or advertising cookies. Signing in sets a session cookie, which is the only cookie the product needs.
Contact
hello@extractbrand.com reaches the people who run the service.