Privacy at a glance
No saved search content
Queries, fetched URLs, and response content stay out of our logs and usage history.
Useful account records
Balances, billing history, and request details help you manage the service.
You can leave
Delete your account from settings. Retained financial records lose their account link.
About this policy
Searchbase Cloud is the hosted service for Searchbase. This policy describes how we handle information submitted through the website, dashboard, REST API, and MCP service.
Your search content
Searchbase Cloud does not store or log search queries, fetched URLs, request bodies, response bodies, raw API keys, or raw authentication tokens in usage records, application logs, traces, metrics, or public error responses.
Requests are processed to provide the service. Search providers receive the information needed to search, and fetched websites receive requests for their content. This policy describes Searchbase Cloud’s own data handling.
Account and security information
We store your email address, local account ID, and the Hanko identity mapping needed for account access. Hanko Cloud processes authentication information, including your primary email address and its verification status, email codes, passkeys, session data, and device-trust data when you choose to trust a device.
Hanko retains the IP address and user agent used to establish a session for security and audit purposes. Searchbase Cloud may log user-agent and other request metadata for platform operations and account security. This does not extend to search or crawl inputs, and we do not store or log raw email codes or session tokens. Application logs are stored with Scaleway in Europe and kept for 7 days.
Authentication sessions use a persistent cookie with a maximum duration of 12 hours, no configured idle timeout, and up to five concurrent sessions. If you choose to trust a device, Hanko may retain device-trust information for up to 30 days.
Usage and payment records
Each billed gateway operation records its request ID, optional trace ID, operation, transport, outcome, error class, HTTP status class, duration, charged amount, timestamp, and optional trusted country code. Gateway logs, traces, and metrics use bounded operational metadata such as method, route, status, duration, operation, transport, outcome, error class, and charged amount.
Payment records include the payment intent, checkout and order identifiers, credit amount, top-up fee, currency, status, and timestamps. Credit-ledger records contain amounts, kinds, and timestamps, including credit that expired or was forfeited at account deletion. We record when we last warned you that unused credit is about to expire. Creem handles payment details, buyer invoicing, and indirect tax as merchant of record. We do not store payment-method details.
How we use your information
- Account access: account information gives you access to your Searchbase Cloud dashboard.
- Payments: payment and credit records let us process prepaid top-ups, maintain your balance, and resolve payment issues.
- Service communication: we email you before unused credit expires, and we may send requested product updates or important information about Searchbase Cloud.
- Site improvement: optional PostHog analytics and privacy-safe operational events help us understand whether the website and service work correctly. The browser analytics script is included only when browser analytics is enabled.
Hosting and service providers
The managed application infrastructure is hosted on Scaleway in Europe. European application hosting does not mean every service provider or requested website processes data exclusively in Europe.
- Hanko Cloud acts as our authentication service provider and processes authentication and session data on our behalf. It sends sign-in emails, including email codes, and enabled security notifications.
- Creem acts as merchant of record for credit purchases, including buyer invoicing and indirect tax. We send your verified account email to pre-fill checkout.
- PostHog processes optional website and product analytics when enabled.
- Scaleway Transactional Email sends our transactional email from Europe, currently credit expiry warnings. Each warning contains your account email address, balance, and expiry date, and is sent as plain text without tracking.
Optional gateway telemetry contains operational metadata and is exported through OTLP/HTTP only when configured.
Storage and account deletion
Account, API-key, payment, credit, reservation, and usage records are stored in PostgreSQL using only the fields needed to operate the service.
After Hanko confirms deletion of your profile, we delete the local account, identity mapping, and API keys. Payment intents, credit-ledger records, gateway reservations, and usage records needed for financial and operational history may remain, but their account and API-key links are removed. Retained usage records do not contain search or crawl content.
Account deletion is available in account settings.
Your choices and contact
We do not sell your data. You can ask for access to, correction of, or deletion of personal information associated with your account.
For privacy questions or requests, email support@searchbase.md.