Privacy.

What KrabyData keeps about you, why, and for how long.

Draft of 23 September 2026

Draft for review. This text has not been reviewed by a lawyer and does not bind anyone yet. The points in it are the ones that will stay; the wording will change.

Who is responsible

PentaLab SRL, Brussels, Belgium. Write to data@pentalab.be to see, correct or delete what we hold about you.

What we keep

With your key

The email address the key was issued to, the plan, when the key was created, last used and revoked, and a hash of the key. The key itself is never stored. We keep this while the key exists and for as long as billing law requires after.

How much you use it

A count of requests per key per UTC day, for the quota and for billing.

Each request

One line per request: the time, the key's prefix (its first eight characters after kd_), the path asked for, the status of the answer and how long it took. Never your IP address, and never the whole key. The lines are deleted after 90 days. The web server in front of the API keeps no access log.

When you ask for a key

The email address and the use you describe are kept in memory for one hour, until you open the confirmation link. Your IP address is used in memory to limit how many requests one connection can make, and is never written anywhere. When the key is created, the use you described is sent to us by email so we know who uses the API; it is not stored in the database. If you never open the link, nothing is left after the hour.

What we do not do

No cookies, no analytics, no advertising, no third-party scripts on this site. We do not sell or share your address. Emails go through our mail provider's relay, which processes them only to deliver them.

Your rights

Under the GDPR you may ask for a copy of your data, its correction or its deletion (deleting the email revokes the key), and complain to the Belgian Data Protection Authority.