Privacy Policy
Last Updated: August 12, 2026
1. Introduction
Quality Network US LLC ("FineData," "we," "us," or "our") operates the FineData.ai web scraping API platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website at finedata.ai, use our API services, or interact with us in any way.
By accessing or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services.
2. Data We Collect
Data Category Overview
We collect two categories of data: Personal Data (information that identifies or can identify a natural person) and Non-Personal Data (aggregated, anonymized, or technical data that cannot identify an individual).
2.1 Personal Data — Account Information
When you create an account, we collect:
- Email address
- Name (if provided)
- Company name (if provided)
- Password (stored as a salted hash — we never store plaintext passwords)
2.2 Personal Data — Billing Information
When you subscribe to a paid plan, we collect:
- Payment method details (processed and stored by Stripe — we do not store full card numbers)
- Billing address
- Transaction history and invoice records
2.3 Personal Data — Technical Identifiers
When you use our API or visit our website, we may collect:
- IP address of the API caller or website visitor
- API key identifiers
- Support communications and emails
2.4 Non-Personal Data — Usage Metrics
We automatically collect the following operational data:
- API request metadata (timestamps, endpoints called, response status codes, token consumption)
- Target URLs requested (for rate limiting and abuse prevention)
- Error logs and performance metrics
2.5 Non-Personal Data — Website Analytics
When you visit our website, we may collect anonymized data:
- Browser type and version
- Operating system
- Pages visited and time spent
- Referring URL
- Approximate geographic location (country/region level, derived from IP)
2.6 MCP and API-Connected Agents
When you or an AI agent call our API directly or through the Model Context Protocol (MCP) server at mcp.finedata.ai, we receive:
- The target URL and request parameters (output formats, extraction rules, headers, and — for write requests — the HTTP method and body)
- The content of the requested page, which is fetched and passes through our infrastructure (rendering, anti-bot handling, extraction) in order to build the response returned to you
OAuth-connected agents. If you connect an MCP client to your account with OAuth instead of an API key, the client requests a subset of three scopes — scrape:write (fetch, async/batch submit, and cancel), jobs:read (poll job and batch status), and usage:read (read your token balance) — shown on the consent screen before you approve anything. The resulting token is confined to those endpoints only: it cannot create or manage API keys, change your plan, spend your wallet balance, or read your profile, regardless of which scopes were granted, because our API rejects tokens issued this way outside that fixed set of endpoints by default. The token expires after one hour and renews silently for up to 30 days. You can revoke a connected app at any time from your dashboard; changing your account password revokes every connected app immediately, the same way it ends every browser session.
3. Purpose, Legal Basis, and Retention
The following table maps each category of data we collect to its purpose, legal basis for processing, and retention period:
| Data Category | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Account info (email, name) | Provide and manage services | Contract performance | While your account is active; deleted or anonymized within 30 days of a verified deletion request (see below) |
| Billing data | Process payments, invoicing | Contract performance, Legal obligation | 7 years (tax/accounting) |
| Request audit trail (IP address, API key ID, method, path, target URL, status, timing) | Security, abuse prevention, metering, support | Legitimate interest, Contract performance | 365 days (detailed events); daily/hourly usage aggregates (no raw IP addresses) kept 3 years |
| Async / MCP job results (page content, screenshots) | Let you poll and collect job output | Contract performance | 24 hours, then auto-deleted |
| Async / MCP job metadata (options, status) | List and manage recent jobs | Contract performance | 7 days, then auto-deleted |
| OAuth connection (client registration, refresh token) | Keep an MCP client signed in to your account | Consent | Refresh token valid 30 days from issuance; deleted on revoke, password change, or expiry |
| Support communications | Customer support, dispute resolution | Contract performance | 2 years after last interaction |
| Website analytics | Improve website experience | Consent | 12 months (anonymized) |
| Marketing communications | Product updates, newsletters | Consent | Until consent withdrawn |
Where we rely on legitimate interest, we have conducted balancing tests to ensure our interests do not override your fundamental rights. You may request details of these assessments by contacting support@finedata.ai.
4. Data We Do Not Collect or Store
This is important and worth emphasizing:
- A synchronous request is not stored. The
/api/v1/scrapeendpoint (and the MCPscrape_urltool) streams the result straight back to you; we do not write the page content to a database or cache. - An asynchronous job is held only long enough for you to collect it. Queued work (async scrape, batch, or the MCP
scrape_async/batch_scrapetools) stores its result — including any requested screenshot — for up to 24 hours so it can be polled and retrieved, then it is deleted automatically. See Data Retention for the exact periods. - We do not index or reuse scraped results. Each request is a fresh fetch performed on your behalf. We do not build search indexes or datasets from the pages our users extract, and we never sell or otherwise share the content of your requests with third parties.
- We do not sell your personal data. We have never sold personal information and have no plans to do so.
5. AI and Automated Processing
Our Service includes AI-powered features for structured data extraction. We are transparent about how AI interacts with your data:
- No model training on your data. We do not use the content of your API requests or responses to train, fine-tune, or otherwise improve any machine learning or AI models. Your scraping data is never incorporated into training datasets.
- Real-time processing only. AI features process web page content in real time to extract structured data. Content is not stored, cached, or logged beyond the immediate delivery of your API response.
- Aggregated service analytics. We use anonymized, aggregated metrics (request volumes, feature adoption, error rates) to improve our service. This data cannot identify individual users or their scraping targets.
- No automated decision-making about individuals. We do not use AI or automated processing to make decisions that produce legal effects concerning you or significantly affect you (within the meaning of GDPR Article 22). Our AI features are data extraction tools under your control.
6. Third-Party Services
We use the following categories of third-party services (sub-processors) that may process your data:
Payment processing
Card payments are processed by Stripe in compliance with PCI DSS Level 1 — we never see or store your full card number (Stripe Privacy Policy). Depending on the payment method you choose, we may route your payment through one or more additional payment gateway partners, including for cryptocurrency payments. Every payment partner receives only the transaction data needed to process your payment — never your API requests or scraping data.
Billing and usage metering — Lago
Processes API usage data to calculate token consumption and generate invoices.
Proxy network providers
To fetch a target page we route the request through a datacenter, ISP, residential, or mobile proxy network operated by one of several proxy vendors we contract with. These providers see the target URL and the traffic needed to complete the request; they do not receive your FineData account, billing, or contact information.
CAPTCHA-solving providers
When a target page presents a CAPTCHA (reCAPTCHA, hCaptcha, Cloudflare Turnstile), we send the challenge to a third-party solving service to obtain a solution. These providers receive only the CAPTCHA challenge data required to solve it, not your account data.
Identity verification (KYC)
For account flows that require identity verification for compliance purposes, we use a dedicated KYC provider to process the identity documents and data you submit for that flow. This applies only where such verification is required, not to every account.
Infrastructure hosting — AWS and Hetzner
Our application and data infrastructure runs on Amazon Web Services and Hetzner. See International Data Transfers for hosting regions.
Email — AWS SES and an email-verification service
Transactional email (account, billing, and security notifications) is sent via Amazon SES. At signup, we check that the email address you provide is in a valid, deliverable format using a third-party email-verification API, which receives the email address for that check only.
Analytics
We use a tag-management/analytics setup to understand website traffic patterns, loaded only after you accept the analytics cookie in our cookie banner. We do not use it for advertising or to analyze your API requests.
8. Data Retention
- Account data: Retained for as long as your account is active.
- Billing records: Retained for 7 years as required by tax and accounting regulations.
- Request audit trail: Detailed events (IP address, API key ID, request method/path/target URL, status, timing) are retained for 365 days for security, abuse prevention, and support, then automatically purged. Daily and hourly usage aggregates derived from this trail — which do not retain raw IP addresses — are kept for 3 years for billing disputes and long-term abuse analysis.
- Async / MCP job results and metadata: Job output (including page content and any requested screenshot) is retained for up to 24 hours so it can be retrieved, then deleted. Job metadata (request options and status, used to list recent jobs) is retained for up to 7 days, then deleted. A synchronous request is never stored.
- OAuth connections: A refresh token is valid for up to 30 days from issuance and is deleted immediately when you revoke the connection from your dashboard, change your password, or let it expire.
- Website analytics: Retained for up to 12 months in anonymized form.
Requesting deletion of your data. To request deletion of your account and the personal data associated with it, email support@finedata.ai with the subject line "Data Deletion Request". After we verify your identity, we delete or irreversibly anonymize your personal data within 30 days, except where we are legally required to keep it — for example, billing records, which are retained for 7 years for tax and accounting purposes.
9. Data Security
We implement industry-standard security measures to protect your data:
9.1 Technical Measures
- All data in transit is encrypted with TLS 1.2+
- Data at rest is encrypted using AES-256
- API keys are hashed and never stored in plaintext
- Access to production systems is restricted to authorized personnel with multi-factor authentication
- Network segmentation and firewall protection
- Regular security audits and dependency vulnerability scanning
- Automated intrusion detection systems
9.2 Organizational Measures
- Access to personal data is restricted on a need-to-know basis
- Regular security training for all team members
- Vendor security assessments for all sub-processors
9.3 Incident Response
We maintain a documented incident response process. In the event of a security breach involving personal data:
- We will notify affected users without undue delay, and within 72 hours where required by law (aligned with GDPR Article 33)
- We will provide details about the nature and scope of the breach, likely consequences, and measures taken to address it
- We will cooperate with relevant regulatory authorities as required
While we take all reasonable measures to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. To report a suspected vulnerability or security incident, contact security@finedata.ai — see our Security page for our responsible disclosure process.
10. International Data Transfers
Quality Network US LLC is based in the United States. When you use our services, your personal data may be transferred to and processed in the United States and other countries where our infrastructure is located.
To ensure adequate protection for data transferred from the EEA/UK, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs) — We use the European Commission's Standard Contractual Clauses as the primary mechanism for EU/EEA data transfers
- Supplementary measures — Encryption of data in transit and at rest, access controls, and continuous monitoring
- Hosting regions — Our primary infrastructure is hosted in EU (Frankfurt) and Germany via AWS and Hetzner. Only billing and account management may involve US-based processing
For detailed information about our international data transfer mechanisms, see our GDPR Compliance page.
11. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Correction / Rectification — request correction of inaccurate or incomplete data
- Deletion / Erasure — request deletion of your personal data (subject to legal retention requirements)
- Portability — receive your data in a structured, machine-readable format (JSON or CSV)
- Restriction — request that we limit processing of your data in certain circumstances
- Objection — object to processing of your data based on legitimate interest
- Withdraw Consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
- Opt-Out — opt out of marketing communications at any time via unsubscribe links or by contacting us. We do not sell personal data, so no opt-out for data sales is necessary
- Lodge a Complaint — file a complaint with a supervisory authority in your jurisdiction if you believe your rights have been violated
To exercise any of these rights, contact us at support@finedata.ai. We will respond within 30 days (extendable to 90 days for complex requests, with notice).
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act and the California Privacy Rights Act (CCPA/CPRA) provide you with additional rights regarding your personal information. You have the right to:
- Know what personal information we collect about you and how it is used
- Request deletion of your personal information
- Opt out of the sale of personal information (we do not sell personal information)
- Non-discrimination for exercising your privacy rights
To make a CCPA request, email support@finedata.ai with the subject line "CCPA Request." We will verify your identity before processing the request.
13. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) provides you with enhanced data protection rights. For detailed information about our GDPR compliance, please see our dedicated GDPR Compliance page.
Our legal bases for processing personal data include: performance of a contract (providing services you've requested), legitimate interest (improving our services, preventing fraud), consent (where you've opted in), and legal obligation (tax and regulatory compliance).
14. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact us at support@finedata.ai.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account) and by posting a notice on our website. We encourage you to review this page periodically. Continued use of our services after changes are posted constitutes your acceptance of the revised policy.
16. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us:
Quality Network US LLC
30 N Gould St STE R
Sheridan, WY 82801
United States
Privacy inquiries: support@finedata.ai
Security reports: security@finedata.ai — see our Security page
General: info@finedata.ai
Phone: +1 (332) 214-8125