Skip to content

Privacy Policy

Last updated: August 28, 2026

Applies to: the CaptchaSonic browser extension (Chrome Web Store item ID dkkdakdkffippajmebplgnpmijmnejlh), the CaptchaSonic API, and captchasonic.com.

CaptchaSonic is a CAPTCHA-solving assistant. To solve a challenge, the extension must send limited information about the page containing that challenge to our solving service. This policy describes exactly what is collected, when, why, who it is shared with, and how long it is kept.

1. Summary of data collected by the extension

DataCollected whenWhyWhere it goesRetention
Website URL / visited URL (full page URL of the page containing the CAPTCHA)Only when a supported CAPTCHA is detected and a solve is attemptedMany CAPTCHA providers bind a token to the page URL; the solve fails without itapi.captchasonic.com30 days
Host name / domain (e.g. example.com)Only when a solve is attemptedAggregate CAPTCHA-solving reliability metrics, so we can detect and fix solvers that break on a given siteaccess.captchasonic.com (our self-hosted analytics)30 days
CAPTCHA website key / site keyOnly when a solve is attemptedRequired by the CAPTCHA provider to generate a valid tokenapi.captchasonic.com30 days
CAPTCHA challenge content — the challenge images, canvas/video frames, and the challenge question text rendered inside the CAPTCHA widgetOnly when a solve is attemptedThis is the puzzle our model solvesapi.captchasonic.comDeleted after the solve completes; retained up to 7 days only if flagged for accuracy review
Device fingerprint — a SHA-256 hash derived from canvas, WebGL, and audio rendering signals plus user agent, platform, language(s), CPU core count, device memory, touch points, color depth, screen resolution and time zoneOnce per device, refreshed periodicallySecurity and abuse prevention, including detecting unauthorized API-key sharing, credential resale, automated abuse, and fraudulent use of prepaid creditsapi.captchasonic.comDuration of the account, then 90 days
Device ID (random identifier generated on install)On installTies usage to a single installation for rate limitingapi.captchasonic.comDuration of the account
API key and account username/emailWhen you enter your API keyAuthentication and credit accountingapi.captchasonic.comDuration of the account
Technical context — extension version, browser user agent, browser language, screen dimensions, event timestampsWith each solve eventDebugging and compatibilityaccess.captchasonic.com30 days
Error diagnostics — error message and a truncated stack trace (max 500 characters)Only on a failed solveBug fixingaccess.captchasonic.com30 days

1.1 Service usage data

  • API Logs: We retain API request logs for up to 30 days to troubleshoot errors and verify usage counts.
  • Account Metadata: Email address and billing history are stored securely for account management.
  • Payment Data: All financial transactions are processed by PCI-DSS compliant third parties (e.g., Stripe, Triple-A). We do not store full credit card or crypto wallet private keys.

1.2 What the extension does not collect

  • We do not collect your general browsing history. No webpage URL, host name, page content, or CAPTCHA data is transmitted from pages where no supported CAPTCHA is being processed. The content script loads on all sites solely to detect CAPTCHA widgets, and it stays silent otherwise. The device fingerprint and device ID described above are account-level anti-abuse identifiers: they contain no URL and no page content, and they are not a record of the pages you visit.

    The extension may technically access webpage URL and host information while inspecting pages for supported CAPTCHA widgets; however, this information is transmitted to our servers only when required to process a CAPTCHA-solving request. Access for detection and transmission to our servers are separate things, and only the latter results in any data leaving your browser.

  • We do not read, collect, or transmit page content outside the CAPTCHA widget — no form fields, no passwords, no page text, no cookies, no full-page screenshots.
  • We do not collect keystrokes, clipboard contents, financial information, health information, or personal communications.
  • We do not use the collected data for advertising, ad targeting, credit scoring, or lending.
  • We do not sell, rent, trade, or transfer your data to third parties for their own purposes.

2. Why the extension needs access to websites

CaptchaSonic's single purpose is to detect and solve supported CAPTCHA challenges. CAPTCHAs can appear on websites across the internet, so the extension requires broad website access to detect supported CAPTCHA widgets wherever they appear.

The extension does not use this access to collect general browsing history, track websites visited, or build advertising profiles. URL and host information is transmitted only when required to process a CAPTCHA-solving request.

3. Legal basis (GDPR)

  • Performance of a contract (Art. 6(1)(b)) — website URL, site key and CAPTCHA challenge content: the service cannot be delivered without them.
  • Legitimate interests (Art. 6(1)(f)) — device fingerprint, device ID, error diagnostics and CAPTCHA-solving reliability metrics, for fraud prevention, abuse prevention and service reliability. You may object at any time via [email protected].
  • Contract / legitimate interests — account email and billing records.

4. Sharing and service providers

Data collected by the extension is primarily processed on CaptchaSonic-operated infrastructure at api.captchasonic.com and access.captchasonic.com.

We do not sell, rent, or provide collected extension data to third parties for their independent purposes.

Payment Data: All financial transactions are processed by PCI-DSS compliant third parties (e.g., Stripe, Triple-A). We do not store full credit card or crypto wallet private keys.

Our analytics are self-hosted on our own infrastructure. We do not use Google Analytics or any third-party advertising or tracking SDK in the extension.

We may also disclose data where required by a valid, legally binding subpoena or court order, or to protect the rights, property or safety of CaptchaSonic, our users, or the public.

5. Retention and deletion

Website URLs (visited URLs) and host names associated with CAPTCHA-solving requests are retained for up to 30 days for the purposes described in this policy, including service operation, security, troubleshooting, and CAPTCHA-solving reliability.

Other retention periods are listed in the data collection table in Section 1.

Account records are kept while the account is active and deleted within 30 days of a deletion request, except where a longer period is required by law or for fraud investigation.

6. Your rights

Depending on your location (GDPR, UK GDPR, CCPA/CPRA and similar laws) you have the right to access, correct, delete, port, restrict or object to processing of your personal data, and to withdraw consent. Exercise any of these by emailing [email protected]; we respond within 30 days.

California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA. See our Do Not Sell or Share My Personal Information page. We honor the Global Privacy Control (GPC) signal on captchasonic.com.

7. Security and data handling

  • All extension-to-server traffic is encrypted with TLS 1.3.
  • Backups are encrypted at rest with AES-256.
  • API keys are stored locally in the browser extension storage and transmitted only to api.captchasonic.com.
  • Automated threat detection guards against unauthorized access.

8. Chrome Web Store User Data Policy compliance

CaptchaSonic's use and transfer of user data received through the Chrome extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use user data only as necessary to provide, secure, maintain, and improve the extension's disclosed CAPTCHA-solving functionality.

9. Cookies and tracking on captchasonic.com

Essential storage is always on; analytics and marketing storage stay off until you opt in. The full breakdown is in our Cookie Policy.

If your browser broadcasts the Global Privacy Control (GPC) signal, we automatically opt you out of analytics and marketing storage and persist that choice.

10. Children

CaptchaSonic is not directed at children under 13 (under 16 in the EEA) and we do not knowingly collect their data.

11. Changes

Material changes to this policy will be announced on captchasonic.com and reflected in the "Last updated" date above.

12. Contact