Privacy Policy
Last updated: June 28, 2026
This Privacy Policy explains how CrawlBit (the "Service") collects, uses and protects your information. CrawlBit is an SEO and AI visibility audit tool. By using the Service you agree to this Policy.
1. Who we are (data controller)
The Service is operated by MindoLabs LLC ("we", "us"), a limited liability company registered in the State of Wyoming, United States. We are the controller of the personal data described here. For any privacy question or request, contact support@crawlbit.app.
2. Information we collect
- Account information. When you create an account we store your email address and a securely hashed password. If you sign in with Google, we receive your name, email address and Google account identifier from Google.
- Audit data. The website URLs you submit, the audit results we generate, your tracked sites and the historical score snapshots we keep to show your progress over time.
- Billing information. Payments are processed by Stripe. We do not see or store your full card number. We store only your plan, subscription status and Stripe customer reference.
- Communications. If you enable email or Telegram digests, we store the destination needed to deliver them.
- Marketing leads. If you ask us to email you a result or checklist from a free tool, we store the email address you provide and the fact that you opted in.
- Technical data. Basic request information such as IP address, used for rate limiting and security.
3. How we use your information
- To provide and operate the Service: run audits, track sites, generate reports and recommendations.
- To authenticate you and keep your account secure.
- To process subscriptions and billing.
- To send the monitoring digests, alerts and checklists you opt into.
- To prevent abuse and protect the Service.
4. Legal bases (GDPR)
If you are in the European Economic Area or the UK, we rely on the following legal bases: performance of a contract to provide the Service to account holders; consent for marketing emails and any optional communications (you can withdraw it at any time); and our legitimate interests in keeping the Service secure and preventing abuse (for example, short-term use of IP addresses for rate limiting).
5. Third-party services
We share the minimum data needed with service providers (processors) that help us run CrawlBit:
- Replit hosts the application and stores its data on our behalf (United States).
- Anthropic processes the publicly available page content we audit to generate AI analysis and recommendations.
- Stripe processes payments.
- Resend delivers transactional, digest and checklist emails.
- Google provides optional sign-in (OAuth).
- Telegram delivers optional alerts if you connect it.
We do not sell or share your personal data, and we do not use it for cross-context behavioural advertising.
6. International data transfers
We operate from outside the European Economic Area, and our hosting and most of our providers are located in the United States. When you use the Service, your personal data is transferred to and processed in the United States and other countries where our providers operate. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. By using the Service you understand that your data will be processed in these locations.
7. Cookies
We use only strictly necessary cookies: a session cookie to keep you signed in, and a short-lived cookie to protect the Google sign-in flow against cross-site request forgery. We do not use advertising, analytics or cross-site tracking cookies, so no cookie banner is required to use the Service.
8. Data retention
- Account data is kept while your account is active and deleted when you delete your account.
- Sessions expire after 30 days.
- Marketing leads are kept for at most 24 months, then automatically deleted, or sooner if you unsubscribe.
- Shareable reports are rotated automatically; we keep only a limited number.
- Technical/security data (such as IP addresses) is kept only briefly for rate limiting and abuse prevention.
9. Your rights
You can access and download your account data and delete your account at any time from Settings. You may also ask us to correct your data, object to or restrict certain processing, or withdraw consent for marketing (every marketing email has an unsubscribe link). To exercise any right, use the controls in Settings or email support@crawlbit.app.
If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority. As our European user base grows we will designate a representative under Article 27 GDPR; until then, please reach us at the email above.
10. California privacy rights (CCPA/CPRA)
We are below the thresholds that make the CCPA mandatory, and we do not sell or share personal information. As a matter of good practice, California residents may still request access to or deletion of their personal information using the controls in Settings or by emailing us, and we will not discriminate against you for exercising these rights.
11. Security
Passwords are stored hashed, never in plain text. The Service is served over HTTPS. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your data.
12. Children
CrawlBit is a business tool not directed at children under 16, and we do not knowingly collect their data.
13. Changes to this Policy
We may update this Policy from time to time. We will revise the "Last updated" date above when we do.
14. Contact
Questions about this Policy? Email support@crawlbit.app. CrawlBit is a product of MindoLabs LLC.