Skip to content
getsolvr

Legal

Privacy policy

What we collect, why we collect it, how long we keep it, and the things we deliberately do not store at all.

Last updated 9 September 2026

The short version

We hold the minimum we need to run a metered API and bill it correctly. That means an account, a record of each solve, and a payment history. We do not sell data, we do not share it for advertising, and we do not use the content of your requests for anything other than delivering and billing them.

Two things are worth knowing up front because they are unusual, and both are covered in detail below: we never store your proxy credentials, and we never store your API key. Neither is a policy promise we are asking you to take on trust. They are not in the database because the code strips them before anything is written.

What we never store

Your proxy credentials

Every solve runs through a proxy you supply, and that string usually contains a username and password. It is passed straight to the solving engine and is never written to our database.

Where we keep a debug capture of a solve, the proxy is redacted first: the scheme, the host and the port survive, and the credentials are replaced with ***. So a record might read http://***@proxy.example.com:8080, which is enough to help you debug a dead exit and useless to anyone who steals it.

Your API key

Keys are stored as a SHA-256 hash alongside a short preview of the first few characters. The full key is shown to you once, at creation, and never again. We cannot recover it, print it, or hand it to anyone who asks, because we do not have it.

Your payment details

Card numbers go to Stripe and never reach our servers. Cryptocurrency payments go to Cryptomus. We store the outcome of a payment, its amount, and a reference, and nothing that could be used to charge you again.

What we do collect

Account information

  • Your name and email address.
  • A hash of your password, if you signed up with one. Never the password itself.
  • If you signed in with Google or Discord, the identifier and email that provider gives us. We do not receive your password from them.
  • Whether your email is verified, and whether two factor authentication is on.

Solve records

For each request you send us we record:

  • The target URL you asked us to solve.
  • The vendor, the challenge type, and which mode you used.
  • The outcome, the error reason if it failed, and how long it took.
  • Whether a proxy was used, as a yes or no. Not which one.
  • The IP address the request came from.
  • Whether it was billed, and what it cost.

The token bundle itself is held only long enough to deliver it to you, and is covered under retention below.

Billing records

  • Payments, their amount, method, and status.
  • A ledger of every movement in your balance, which is what lets you audit your own spend.

Administrative records

When someone on our side takes an action on an account, such as adjusting a balance or changing a concurrency limit, we log what was done, who did it, when, why, and the IP it came from. This exists so that changes to your account can be explained afterwards.

Why we hold it

Every item above exists for one of four reasons:

  • To deliver the service you asked for. We cannot return a solve without knowing what you asked us to solve.
  • To bill you accurately. Metering per solve requires a record per solve, and you can check ours against your own.
  • To keep the service safe. Solve records and IP addresses are what let us investigate abuse when a target reports it, as set out in the acceptable use policy.
  • Because the law requires it. Payment and accounting records have statutory retention periods that override our own preference to delete things.

Where a legal basis is needed, ours is the performance of our contract with you for the first two, and our legitimate interest in operating a service that is not trivially abusable for the third.

How long we keep it

Retention here is short on purpose. Holding short-lived credentials for longer than they are useful is a liability with no upside for anyone.

  • Token bundles: 72 hours. They are single use, bound to the IP that earned them, and valid for minutes. After 72 hours the result is stripped from the record entirely.
  • Solve records: 180 days. The target, outcome and timing, so you can look back over roughly six months of your own traffic.
  • Hourly usage summaries: 62 days. Aggregated counts, with no individual request in them.
  • Daily usage summaries: 400 days. The same, at lower resolution, so year on year comparisons survive.
  • Account and billing records: for as long as the account is open, and afterwards for as long as accounting law requires.

Deletion runs on a schedule rather than on request alone, so a record inside its window will still be there until the window passes.

Who else sees it

We use a small number of providers, and each one sees only what it needs:

  • Stripe, for card payments. They receive your payment details directly and we receive only the result.
  • Cryptomus, for cryptocurrency payments, on the same basis.
  • Google and Discord, only if you choose to sign in with them, and only to confirm who you are.
  • Our hosting provider, which runs the servers the application and database sit on.

The solving engine runs on our own infrastructure rather than a third party's, so your targets and proxies are not passed to another company to process.

We do not sell personal data, we do not share it with advertisers, and we do not run third party analytics or advertising trackers on this site.

We will disclose information where the law compels us to, or where there is a credible risk of serious harm to someone. Where we are allowed to tell you, we will.

Your rights

Depending on where you live, you can ask us to:

  • Give you a copy of what we hold about you.
  • Correct anything that is wrong.
  • Delete your account and the data we are not required to keep.
  • Restrict or object to particular processing.
  • Export your data in a portable format. Your solve history is already exportable as CSV from the logs page, without asking us.

Email us and we will respond within 30 days. There is no charge for a reasonable request. If you are unhappy with how we handle it, you can complain to your local data protection authority.

Security

  • Everything is served over TLS.
  • Passwords are hashed, and API keys are hashed. Neither is recoverable.
  • Two factor authentication is available on your account and we recommend it.
  • Administrative actions are logged with the person who took them.
  • Access to production data is limited to the people who need it to run the service.

No system is perfectly secure. If we suffer a breach affecting your personal data we will tell you and the relevant authority as quickly as we can, with what we know and what we are doing about it.

If you have found a vulnerability, please report it to us before disclosing it. We will work with you and we will not take action against good faith research.

Cookies

We use cookies for one thing: keeping you signed in and protecting forms against cross-site request forgery. They are essential to the service working and there is no advertising or tracking cookie to opt out of, which is why you have not been shown a consent banner.

Contact

For anything in this policy, including a request under the rights section, contact [LEGAL ENTITY NAME] at [REGISTERED ADDRESS] or by email at [email protected].

We update this page when what we do changes. The date at the top is when the text last changed, and for anything material we will email you rather than relying on you noticing.