Privacy Policy
Effective date: September 30, 2026
At URLpipe (urlpipe.dev), your privacy is important to us. This Privacy Policy explains what we collect when you visit this website or use the API, how we use it, and how we protect it. Please read it carefully.
Who is responsible for your data
The data controller is Aliat Partner S.L., tax id B67412916, Calle Àlaba 61, 6º 2ª, 08005 Barcelona, Spain. For anything about your data, email privacy@urlpipe.dev.
Information we collect
When you create an account, we collect:
- Email address: used for sign-in, password resets, and important service notices.
- Password (hashed with bcrypt — we never see the plaintext).
- Optional profile information you provide (name, timezone).
- If you sign in with Google or GitHub, the name and verified email address that provider shares with us.
When you buy a paid plan, Stripe collects your card, billing address and — if you give one — your VAT number. We receive the billing details and a reference to the card, never the card number itself.
When you use the API, we also collect and store:
- The URLs you submit and the request options accompanying them.
- The result we return to you, kept for your dashboard's request history.
- Operational metadata: timing, success/failure, IP address of the calling client, user-agent.
When you sign in to the dashboard, we store a session record (IP address, browser, country) to keep you signed in and to investigate unusual sign-ins on your account.
How we use your information
We use the information we collect to:
- Operate the Service: authenticate you, route requests, return results, and bill the right plan.
- Show you your usage and request history in the dashboard.
- Enforce per-organization monthly quotas.
- Send transactional emails (sign-in, password reset, plan or quota notices).
- Investigate abuse, security incidents, and bugs.
We do not sell, rent, or share your personal information with third parties, except as needed to operate the Service (see "Third-party providers" below) or when required by law.
Data we fetch from third-party URLs
When you submit a URL, our infrastructure fetches and renders that page — possibly executing its JavaScript — and caches the result against your organization so you can read it back from the dashboard and be served it again for free. That cached result is yours alone: it answers your organization's requests and nobody else's, no other account is served it, and deleting your organization deletes it. We treat that data as yours; we do not use it to train models, and we do not share it with anyone outside the providers needed to deliver the Service to you.
Where your data is stored
Account data, request history, and operational logs are hosted on infrastructure located in the European Union. Deleted projects and accounts are removed promptly, on a schedule that allows for routine backup rotation.
We do not keep account data indefinitely for accounts nobody uses. A free-plan organization with no sign-in and no API request for six months is treated as dormant: we notify its administrators, and 30 days later the organization and its request history are deleted. Any activity during those 30 days cancels it. See the terms for the full policy.
Pages are fetched and rendered on our own infrastructure. The URLs you submit are not passed to a third-party rendering service.
The one step that can be processed outside the European Union is the language model behind the AI endpoints (/summarize and /keywords). An organization can close that gap: turning on EU data residency in the dashboard sends those calls to an endpoint that decrypts and processes them inside the EU and routes only to EU providers, with no fallback outside it. Every other endpoint is processed in the EU whatever the setting, because none of them calls a model at all. See the data residency documentation.
Third-party providers
We use a small number of third parties to operate URLpipe. Each only receives the data needed to perform its function and is contractually bound to protect it:
- Language-model providers — process page content for the AI endpoints (/summarize and /keywords). Content is sent over TLS, only to providers that neither log nor retain prompts and do not train on them. Organizations with EU data residency turned on are served only by providers operating inside the European Union. No other endpoint sends page content to a model.
- Stripe — payments, invoices and VAT calculation for paid plans.
- SMTP2GO — transactional email delivery.
- Cloudflare Turnstile — a bot check on the sign-up form.
- Google and GitHub — sign-in, only if you choose to use them.
- Honeybadger and Scout APM — error reports and performance monitoring, which can include the request that failed.
- Hosting and storage providers in the European Union — run the application and persist your account and request data.
Cookies
We use cookies strictly necessary to keep you signed in and to protect against cross-site request forgery. We do not use advertising or third-party tracking cookies. The public pages of the site are measured with Plausible, a self-hosted analytics tool that sets no cookies and stores no personal data; it does not run in the dashboard or on the sign-in pages.
Data security
We take reasonable technical and organizational measures to protect your information — TLS everywhere, hashed passwords, least-privilege internal access. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
Your rights
Subject to applicable law (including the EU General Data Protection Regulation), you have the right to:
- Access, update, or delete your personal information from your account, or by contacting us.
- Object to or restrict certain processing of your personal information.
- Receive a copy of your personal information in a portable format.
- Lodge a complaint with your local data protection authority.
You can delete your account at any time from Account settings, and your whole organization — its projects, API keys, and request history — from Organization settings. Both take effect immediately and cannot be undone.
Children's privacy
URLpipe is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have inadvertently done so, we will delete it.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notification. The effective date at the top of this page will always reflect the latest version.
Contact
Questions about this Privacy Policy or your data? Email privacy@urlpipe.dev.