Data we collect
We collect account profile data from sign-in, API key and webhook credential metadata, credit and billing records, request logs, usage aggregates, feedback submissions, monitor configuration, and operational logs needed to secure and operate the service. When site measurement is enabled, Google Analytics also receives page measurement described below.
API keys
We store hashed API keys and metadata such as prefix, status, creation time, and last-used time. To support dashboard Reveal, Copy, and playground requests, API key plaintext may also be stored encrypted at rest and opened only by server-side dashboard actions.
We record API key plaintext disclosure events, including Reveal, Copy, and playground use, so account owners and operators can audit sensitive-key access.
Billing
Payments are processed through Stripe. xfetch stores Stripe customer, checkout, subscription, and webhook identifiers needed to grant credits, show subscription status, and reconcile billing.
API usage
We record request metadata such as method, path, endpoint key, status code, latency, credits charged, and public error code. We do not use public docs or responses to expose service implementation details.
For hosted MCP tool calls, the same request log may also contain the schema-validated tool arguments, including search queries, result limits, usernames or IDs, modes, and pagination tokens. Account owners can access their own request-log rows, and authorized operators use the records to operate, debug, analyze, and improve the service.
The request-arguments field does not separately copy request headers, the API key or Authorization value used to authenticate the request, or the complete JSON-RPC request body. Values supplied inside tool arguments are stored exactly as produced by schema parsing.
Monitors and feedback
If you use dashboard monitors, we store selected or resolved account references, monitor status, delivery channel names and URLs, encrypted generic-webhook signing secrets, test status, and delivery usage aggregates needed to operate the feature.
If you send dashboard feedback, we store the feedback type, message, status, and account association for operator triage.
Site measurement
When configured, xfetch uses Google Analytics 4 to understand traffic sources and landing pages. Analytics storage is enabled without an xfetch measurement popup, while advertising storage, Google Signals, advertising personalization, and advertising data collection remain disabled. xfetch does not use a Google Ads destination or set an xfetch-owned measurement identifier.
Google Analytics sets first-party _ga and _ga_* cookies for up to 30 days from the first visit and uses pseudonymous client and session identifiers. It may process standard request, device, page-location, and referrer information to provide aggregate reports. xfetch does not send account, billing, API key, API request, or Monitor data to Google Analytics, and it does not link GA4 events to signed-in accounts.
xfetch no longer stores a separate website-acquisition table or its own source/landing event log. Hosting and security providers may still process standard network and device data needed to deliver requests, prevent abuse, and operate their services.
Service providers
We use infrastructure, database, payment, authentication, and Google Analytics services to operate hosting, billing, API delivery, sign-in, abuse prevention, and site measurement.
Contact
Privacy questions can be sent through the contact channel listed on the site footer.