Privacy Policy
This policy explains how Foundea GmbH ("we", "us") handles personal data when you use polyscrape.com (the "Service"), a pay-as-you-go REST API, MCP server, and dashboard that turns web pages, search results, and documents you choose into clean Markdown. We keep data collection to what we need to run the Service, and we never sell your data or use your inputs to train AI models.
1. Who we are
Foundea GmbH
Lise-Meitner-Str. 9, 89081 Ulm, Germany
Represented by Mahir Yildirim · Amtsgericht Ulm, HRB 731876 · VAT ID DE299284795
Contact: [email protected]
2. What we collect
You give us: your email address and account credentials; your name and basic profile info from Google if you use Google sign-in; payment details you enter at checkout (handled by Stripe; we never see your full card number); and any support messages you send.
You generate by using the Service: the request inputs you submit (the URLs you ask us to scrape, search keywords, and documents you upload to the Parser), the Markdown and other responses returned, your API key, and your usage and balance history.
We collect automatically: standard technical data such as your IP address, browser and device type, and server logs of pages and requests, kept to operate and secure the Service.
3. Why we use it, and our legal basis (GDPR)
- To provide the Service (Art. 6(1)(b)): create and authenticate your account, run API requests, manage your balance and top-ups, and provide support.
- To meet legal obligations (Art. 6(1)(c)): tax, accounting, and commercial-law requirements.
- For our legitimate interests (Art. 6(1)(f)): keeping the Service secure, preventing abuse and fraud, troubleshooting, and improving it using aggregated or de-identified data.
- With your consent (Art. 6(1)(a)): anything we ask you to opt into; you can withdraw consent at any time.
4. Sign-in, payments, and email
You can sign in with email and password or with Google. With Google sign-in we receive what we need to authenticate you (name, email, account identifier), never your Google password. Google's processing of your data is governed by the Google Privacy Policy.
Payments are processed by Stripe, which handles billing and fraud-prevention data under its own terms. We do not store full card details.
We use Mailgun to send transactional emails (account, login, password reset, billing, and support). We do not send marketing emails unless you have separately consented where required.
To protect signup and password-reset forms against bots, we use Cloudflare Turnstile. Turnstile processes technical data such as your IP address and browser characteristics to distinguish humans from automated traffic; it does not use advertising cookies. Legal basis: our legitimate interest in securing the Service (Art. 6(1)(f) GDPR).
5. Cookies
We use only essential cookies needed to log you in, keep your session, and protect the site. We do not use advertising or analytics cookies. If that ever changes, we will update this policy and request consent where required.
6. Who we share data with
We share personal data only with providers that help us run the Service, and only as needed:
- Stripe: payments
- Our residential proxy provider: scraping egress
- seonio: web search data
- Mailgun: transactional email
- Google: if you use Google sign-in
- Cloudflare: security and performance
- netcup: hosting
We may also disclose data where legally required. We do not sell, rent, or trade personal data.
To fulfil your scrape and search requests, the Service fetches the public web content you point us at. Scrape requests are routed through our residential proxy provider to retrieve the page or document you specify; search requests are run through seonio, which returns each result already converted to Markdown. We transmit only what is needed to carry out your request (such as the target URL or search keyword). You are responsible for having the right to access the content you request, and your use of third-party sites remains subject to those sites' terms.
7. Hosting and international transfers
We host with netcup on infrastructure located outside the EU/EEA, and some providers may process data outside the EU/EEA. Where that happens, we rely on a lawful transfer mechanism such as an adequacy decision (including the EU–US Data Privacy Framework, under which Stripe, Cloudflare, and Google are certified) or EU standard contractual clauses.
8. How long we keep it
We keep data only as long as needed, then delete or anonymize it unless the law requires longer:
- account data: while your account exists
- billing and invoice data: for the periods required by tax and commercial law
- request inputs, outputs, and usage history: as needed for account history, abuse prevention, and product features
- parsed documents: when you parse a document in the dashboard or hero widget, we store only the resulting Markdown and light metadata (filename, content-type, size, timestamp) for a rolling preview of your last 100 documents — never the original file. The API and MCP
parseendpoints are stateless: we convert your document and return the Markdown without storing it. - server logs and security data: for a limited period for security and operations
9. Security and children
We use appropriate technical and organizational measures to protect personal data, though no system can be completely secure. The Service is not directed at children under 16, and we do not knowingly collect their data. Contact us if you believe a child has provided data and we will review and delete it.
10. Your rights
If the GDPR applies to you, you have the rights of access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent. To exercise any of them, email [email protected]. You also have the right to lodge a complaint with a supervisory authority, usually in your country of residence or workplace.
11. Changes and contact
We may update this policy to reflect legal, technical, or business changes; the current version is always published here with the date below. Questions? Contact:
Foundea GmbH
Lise-Meitner-Str. 9, 89081 Ulm, Germany
Email: [email protected]
Last updated: July 2, 2026