Who is responsible
The controller of your personal data is the operator of serper.live, based in Ukraine. Contact for anything about your data: [email protected]. We answer within 30 days.
What we collect and why
We collect only what the Service needs. There is no advertising, no tracking pixels and no third-party analytics on the website.
| Data | Why | Legal basis |
|---|---|---|
| Email address, password (stored as a salted hash), interface language | To create and secure your account, sign you in and send password reset emails | Performance of the contract |
| Keyed hashes of your IP address (the address itself is not stored) | Rate limits for sign-in and registration and the daily limit of the free playground | Legitimate interest: preventing abuse |
| Request history: query text, market, language, device, status, price, timing | To run and bill requests and show you your history | Performance of the contract; accounting obligations |
| API token names and prefixes (tokens are stored only as hashes) | So you can recognise and revoke tokens | Performance of the contract |
| Balance, ledger entries, cryptocurrency payments: asset, network, amount, our deposit address, transaction id and the sending address reported by our payment provider | To credit deposits, bill requests and keep financial records | Performance of the contract; legal obligations |
| Email correspondence with us | To answer your requests and handle refunds or disputes | Legitimate interest; performance of the contract |
Your search queries are sent to Google to run the live search. Your IP address, email or account details are never sent to Google. We may also use any of the data above to enforce our Terms, prevent and investigate fraud and abuse, comply with legal obligations, establish or defend legal claims and, in aggregated or anonymised form, to improve the Service.
Cookies
We use only first-party cookies that are needed for the website to work or that store a choice you made. No consent banner is shown because none of them is used for tracking or advertising.
| Cookie | Purpose | Lifetime |
|---|---|---|
sl_session | Keeps you signed in | 30 days |
sl_csrf | Protects forms against cross-site request forgery | Session |
sl_theme | Remembers the light or dark theme you chose | 1 year |
Who else processes your data
We do not sell personal data and share it only with providers that are needed to run the Service, each for its own purpose:
- Cloudflare: DNS and proxy in front of the website and the API. Cloudflare sees your IP address and connection metadata to protect against attacks.
- Binance: receives your cryptocurrency deposits. Binance sees the blockchain transaction, including the sending address, and we read the deposit history through its API to credit your balance.
- Our email provider: delivers password reset emails to the address on your account.
- Our hosting provider: stores the servers and the database that run the Service.
- Authorities and professional advisers: only where the law requires it or to establish or defend legal claims.
Some of these providers operate outside Ukraine and outside your country. Where a transfer of personal data requires safeguards under the law that applies to you, we rely on the provider's standard contractual terms.
How long we keep data
- Account data: while your account exists. After closure we delete the account and its tokens.
- Request history, ledger and payment records: while your account exists, and afterwards for as long as accounting and tax law requires financial records to be kept.
- Rate-limit events with hashed IP addresses: 2 days. Playground attempts are kept as request records with a hashed IP address.
- Sessions: 30 days, or until you sign out. Password reset links: 30 minutes.
- Email correspondence: as long as needed to handle the matter and for a reasonable period afterwards.
- Any data may be kept longer where it is needed to comply with a legal obligation, to resolve a dispute or to establish, exercise or defend legal claims.
How data is protected
All traffic is encrypted with TLS. Passwords are stored as salted scrypt hashes and API tokens as SHA-256 hashes; neither can be recovered from the database. Sessions are bound to a hashed cookie, forms are protected against cross-site requests and the website ships a strict Content Security Policy. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you as the law requires.
Your rights
Depending on the law that applies to you (including the GDPR for residents of the European Economic Area and the Ukrainian data protection law), you can:
- access the personal data we hold about you and receive a copy in a portable format;
- ask us to correct inaccurate data;
- ask us to delete your data or restrict its processing, where we have no overriding legal obligation to keep it;
- object to processing based on legitimate interest;
- lodge a complaint with your data protection authority.
To exercise these rights, email [email protected] from your account email address. You can see your request history, ledger and tokens in your account at any time.
Children
The Service is intended for adults and businesses. We do not knowingly collect data from anyone under 18; if you believe a minor has created an account, contact us and we will delete it.
Changes to this policy
We may update this policy when the Service changes. The date at the top shows the current version. For material changes we notify you by email or with a notice on the website before they take effect.