Skip to content

New Official SDKs for TypeScript, Python and Go

SerpKite
Get API key

Privacy Policy

Effective 3 October 2026.

This policy explains what personal data Anastasia Klimova, trading as SerpKite, 1732 Oberon Crescent, Mississauga, Ontario L4X 2K8, Canada ("SerpKite", "we") collects when you use serpkite.com, the dashboard at app.serpkite.com and the API at api.serpkite.com, why, how long we keep it, and what rights you have. The short version: we collect what we need to run your account and bill you, we never log your query text, results are cached only briefly under a hashed key, and we don't sell data.

1. Controller and processor

We are the controller for account, billing, website and security data. For personal data contained in the queries you send and the results we return to you, we act as your processor under the Data Processing Addendum.

2. What we collect

DataExamplesWhyKept for
AccountEmail, name, avatar URL; linked GitHub or Google account ID and verified email; team membershipSign-in, account security, service emailUntil you delete your account
AuthenticationHashed session and sign-in tokens, session IP address and user agentKeep you signed in, let you review and revoke sessions, detect abuseSession lifetime (up to 30 days), then deleted
API keysSHA-256 hash of each key, key name and prefix, last-used timeAuthenticate API requestsUntil you revoke the key or delete your account
Usage metadataTimestamp, endpoint, status code, credits, latency, cache hit, key ID, request ID. Never the query textBilling, spend caps, usage dashboards, abuse prevention, debugging31 days, then deleted
Credit ledger and ordersCredit grants, charges and refunds; pack purchased, amount, Paddle order IDBalances, accounting, disputesKept after account deletion as an anonymised accounting record, no longer linked to your email or name. Invoices and tax records are kept by Polar, our merchant of record, as the law requires
Deleted-account recordSHA-256 hash of your normalised email address, and the deletion time. Never the address itselfStop the free sign-up credits from being claimed again by deleting and re-creating an account (legitimate interest in preventing abuse)Kept after deletion; it can't be turned back into your address
SettingsSpend cap, alert thresholds, auto-recharge, webhook URL and signing secretProvide the features you configureUntil changed or account deletion
Team invitesInvitee email, hashed invite tokenLet the invitee join your teamUntil revoked or the team owner deletes the account; invite links expire after 7 days
Playground rate limitsIP address of website playground visitors, as a counter keyPrevent abuse of the no-login demo24 hours
Support emailMessages you send usAnswer youas long as needed to resolve your request and any follow-up, then deleted
Product analyticsPages viewed (without query strings), product events, pseudonymous IDUnderstand and improve the productSee section 5

We do not receive or store card details; payments are processed by Paddle, our merchant of record, under its own privacy policy. Encrypted database backups are kept for 30 days, so deleted data disappears from backups within that time.

3. Search queries and results

  • Query text is never logged. It is not written to application or database logs, usage records, analytics or the request log in the dashboard.
  • Result cache. To deduplicate identical requests, each successful result is stored in an in-memory cache (not persisted to disk) for up to 6 hours by default, 30 minutes for news, 1 hour for web pages and 24 hours for autocomplete, then it expires automatically. The entry is stored under a SHA-256 hash of the normalized request (endpoint, query, country, language, location, device, page and filters), so the query text is never stored as a key, and the entry holds the result, not your identity or API key. Entries are shared: an identical request from anyone produces the same key.
  • What max_age controls. A cached result is only returned to you when you send max_age and the entry is younger than it. Without max_age (or with 0) you always get a live result. Results are written to the cache either way. Raw HTML (include_html) is never cached.
  • Batch jobs. The request of a batch job is stored until the job runs and then cleared. Its result is kept for 24 hours so you can fetch it or receive it by webhook, then deleted.

We don't use your queries or results to train models, and we don't share them with anyone except the subprocessors needed to fetch results (section 6).

4. Legal bases (EEA/UK)

  • Contract: account, authentication, API service, billing.
  • Legitimate interests: security, fraud and abuse prevention (including free-tier abuse), service improvement, and server-side account events used for product analytics (section 5).
  • Legal obligation: tax and accounting records.
  • Consent: analytics cookies and browser analytics on the website and dashboard (see section 5 and the Cookie Policy). You can withdraw consent at any time.

5. Analytics

We use PostHog, hosted in the EU, for product analytics.

  • Website and dashboard: only with your consent. A banner asks once, and the choice is stored in the sk_consent cookie for 12 months across serpkite.com and app.serpkite.com. PostHog is not loaded, and sets no ph_* cookies or storage, until you click Accept. If you decline, it never loads.
  • Privacy signals. If your browser sends Global Privacy Control or Do Not Track, we treat it as Decline and don't show the banner.
  • Withdrawing. Use "Cookie settings" in the website footer or on the Cookie Policy, or Settings → Cookies in the dashboard. Analytics stops at once, the pseudonymous ID is reset and PostHog's cookies and storage are deleted.
  • Server-side account events (such as sign-up, key creation and purchases) are sent by our backend without any cookie, on the basis of our legitimate interest in understanding how the product is used. You can object by emailing us.

Session recording is disabled. Query strings are removed from every URL before an event is sent, so analytics never contains query text, API keys or invite tokens. PostHog keeps analytics events for up to 12 months.

6. Who we share data with

We use a small set of service providers (subprocessors) for hosting, email, payments, logging and analytics. The current list, with purposes and locations, is on the Subprocessors page. Proxy providers carry the outbound request to the search engine and therefore see the query text in transit, but not your identity or account. We don't sell personal data and don't share it for cross-context behavioral advertising. We may disclose data if required by law, to protect our rights, or in a merger or acquisition (with notice to you).

7. International transfers

Some providers are established or process data outside the EEA/UK (see the locations on the Subprocessors page). Where they do, we rely on an adequacy decision (including the EU-US Data Privacy Framework and its UK extension, for providers certified under it) or on the European Commission's Standard Contractual Clauses with the UK Addendum, together with the provider's supplementary security measures.

8. Security

API keys, session tokens and sign-in tokens are stored only as hashes. All traffic is encrypted in transit. Our servers accept no inbound connections except through Cloudflare Tunnel. More on the security page.

9. Your rights

Depending on where you live (including under Canada's PIPEDA, the GDPR, UK GDPR and CCPA/CPRA), you can ask to access, correct, export or delete your personal data, object to or restrict processing, and withdraw consent. You can delete your account yourself from the dashboard; this deletes your account data, keys, settings, ledger and usage records. To exercise other rights, email [email protected]. We'll respond within 30 days. You may also complain to your data protection authority, or to the Office of the Privacy Commissioner of Canada.

10. Children

The Service is not directed to children and we don't knowingly collect data from anyone under 16.

11. Changes

We'll post updates here and email account holders about material changes before they take effect.

12. Contact

Privacy questions: [email protected]. Postal address: Anastasia Klimova, trading as SerpKite, 1732 Oberon Crescent, Mississauga, Ontario L4X 2K8, Canada.

Last updated: 3 October 2026