At CrafyCAPTCHA (operated by Maximiliano Nicolás Alemandi, doing business as Crafy Holding, hereinafter "we", "our" or the "Company"), we respect your privacy and are committed to protecting the personal information of our clients and the end-users who interact with our Service. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website or use our platform, widget, and SDKs.


1. Our Role (Controller vs. Processor)

For the purposes of data protection laws such as the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA):

2. Legal Basis for Processing

Under the GDPR, we rely on the following legal bases to process personal data:

3. Information We Collect

3.1. Information from Our Clients (Developers and Administrators)

When you create an account, use our management API, or contact support, we collect:

3.2. Information from End-Users (Visitors of protected sites)

To determine if traffic originates from a legitimate human or an automated bot/script, our widget analyzes traffic. We adhere to the principles of Privacy by Design:

4. Use of Information

We use the collected information for the following purposes:

5. Data Sharing and Sub-processors

We do not sell or rent personal data. We only share information with trusted third-party sub-processors necessary for our infrastructure:

5.1. Critical Infrastructure Sub-processors

5.2. Local Processing (Zero Data Sharing)

Unlike other anti-bot services, CrafyCAPTCHA uses local databases for Geo-location (MaxMind GeoLite2) and Threat Intelligence (FireHOL). Your end-users' IPs are processed entirely within our own servers and are never sent to third-party APIs for enrichment.

5.3. Legal Requirements

We may disclose information if reasonably necessary to comply with a law, regulation, legal process, or enforceable governmental request.

5.4. Crafy Holding Services

We share information with other platforms of the Crafy Holding group to provide operational and support services.

6. Data Retention

7. Data Security

We implement industry-standard security measures including TLS/HTTPS encryption for all data in transit, irreversible cryptographic pseudonymization of IP addresses, and strict access controls to our infrastructure to protect your data from unauthorized access, loss, or alteration.

8. Privacy Rights and GDPR Article 11 Exception

Depending on your jurisdiction, Clients of CrafyCAPTCHA have the right to access, correct, delete, or restrict the processing of their personal data. To exercise these rights, email our Data Protection Officer at [email protected].

Note for End-Users (GDPR Article 11): Because we strictly pseudonymize IP addresses using irreversible cryptographic hashing and do not track users across sites, we cannot link a hash back to a specific identifiable human being. Therefore, in accordance with Article 11 of the GDPR, the rights of Access, Rectification, and Erasure are not directly actionable by us, as we lack the information to re-identify the data subject. Please direct any privacy requests to the owner of the website you visited.

9. International Data Transfers

Our primary servers are located in the United States. When providing the Service, information may be transferred outside the Client's or End-User's country of origin. We ensure such transfers are conducted under adequate legal safeguards, including the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs). The Company is established in Argentina, which benefits from an adequacy decision by the European Commission for the purposes of international data transfers.

10. Crafy Account

If you choose to create an account on our Service, your account and certain associated personal data will be managed by Crafy Account (a service owned by Crafy Holding). By using our Service, you acknowledge and expressly consent that your information will be jointly governed by this Privacy Policy and the Crafy Account Privacy Policy.

11. Children's Privacy (COPPA)

Our Service is intended for businesses and developers and is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information without parental consent, please contact us, and we will take steps to remove that information.

12. California Privacy Rights (CCPA/CPRA)

If you are a resident of California, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

To exercise your CCPA rights as a Client, please contact our support team. We will verify your request by matching the identifying information you provide with the information we have on file.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data handling practices, please contact us: