Privacy Policy
Version 1.2, last changed 3 October 2026.
This policy says what we keep about the people and companies who use ZeroCaptcha, and about the site owners who write to us. We run ZeroCaptcha on our own servers: your data is in our database and our backups, not in a cloud service's, and we use no advertising or analytics trackers. This website sets no cookies.
What we keep, and for how long
Your account
- Your email address, and a hash of your password (Argon2id): never the password itself. Kept while you have the account.
- Which version of the Terms and the Acceptable Use Policy you accepted, when, and from which IP address. Kept while you have the account.
- Your sessions: the dashboard's cookies, which only sign you in, and for each session the browser, such as "Chrome on Windows", and its IP address, which you can see in Settings. A session ends after 24 hours without use or 30 days at most, and is deleted a week later.
- Two-factor and passkey settings, if you turn them on; an authenticator's secret is kept encrypted.
- Billing details, if you give them: a company name, a postal address and a tax ID, printed on your receipts. Nobody needs them to pay.
Your API keys and tasks
- For each key: its name, scopes and allowed addresses, a hash of the key, its first and last characters, and when and from which IP address it was last used. Kept with the account.
- For each task: the page address, the site key, the action and data you sent, the domain, the result and its times. Task records are deleted a month at a time, 90 days after the end of the month they were created in: a task is kept for about 121 days at most. A month that still holds a task whose charge is not settled is kept until it is, and our staff are alerted when that takes more than 14 days.
- Your usage totals: for each day and each month, how many tasks you created, how many were solved and failed, and what they cost. They hold no page address or task data, and are kept with the account, so your usage and receipts stay complete after the task records go.
- A proxy's address and password, if a task uses one: deleted as soon as the task finishes.
- A solved token: deleted 10 minutes after it expires.
Payments
- You pay top-ups on the checkout page of our payment processor, NOWPayments, which handles your payment under its own privacy policy. From it we keep each invoice and payment: the amount, the coin and network, the transaction hash and the status. We never hold your wallet's keys.
- Your balance, every charge and credit, and your receipts: kept for as long as the law requires us to keep financial records.
Emails, requests and logs
- Emails we send you, such as a link to verify your address or a receipt: the address and what it said, kept a week after sending.
- Email you send to our addresses, such as support@zerocaptcha.io or billing@zerocaptcha.io, and messages you send from the dashboard's Support page or our contact form: the message, its headers and attachments, and the replies our staff write, kept 365 days after the last message of its conversation, then deleted. When it comes from the address of someone on an account, it goes when the account is deleted.
- Our servers' logs: the IP address, time and path of each request, and what the API did with it, including security events such as sign-ins and refused keys, with the client's IP address. We use them to run the service, to investigate abuse, and to fix faults. They are kept for 30 days, then deleted.
- Counters that limit how often an address can try something, such as signing in: kept as a hash of the address or email, for minutes.
- If you ask us to opt a site out: the domain, your email address and your message, kept as the record of what was asked and decided.
- Encrypted backups of the database, kept for 30 days.
Who else sees it
- Our solving servers get what a task needs: the page address, the site key and, if you use one, your proxy. They are ours.
- NOWPayments, for the payments you make through it.
- The mail server that sends our emails, for each email's address and content.
- Our staff, to support you, handle abuse reports and keep the books. Every change they make to an account is recorded.
- Anyone the law requires us to give it to. We do not sell or rent your data.
Your choices and rights
You can see and change your email address, password, sessions, keys and billing details in the dashboard. Its Settings page downloads a copy of your data as a JSON file: an owner's copy covers the account, and a member's covers them.
An owner deletes the account from Settings, confirmed with their password or a passkey. It happens at once: its API keys stop working, its queued tasks are cancelled without charge, and everyone on it is signed out. We erase its people's email addresses, password hashes, sessions, two-factor and passkey settings and policy acceptances, its billing details, its messages to support and the email its people sent us, its team's activity log and its name. We keep what the law and our books require: the balance's charges and credits and the top-ups, under the name "Deleted account", the receipts as they were issued, with the details printed on them, and task records until they are deleted as above, without their tokens. A balance left on a deleted account is not refunded, as top-ups are final. Copies in our encrypted backups go when the backups do, within 30 days.
To correct anything you cannot change yourself, or with any other question about your data, write to privacy@zerocaptcha.io from your account's address.
Security
Traffic to ZeroCaptcha is encrypted, passwords and keys are stored only as hashes, secrets we must keep are encrypted, and backups are encrypted. Tell us of a security problem at security@zerocaptcha.io: our security policy says how.
Changes
We publish a new version of this policy here, with a new version number and date.