Privacy policy
Effective date: 2026-07-13
We collect the minimum needed to run the service and nothing more. This page tells you exactly what we collect, what we don't, and how long we keep it.
crtlog does not have user accounts. There is no registration, no login, and no session cookies. The service is fully anonymous. API keys increase your rate limits but do not identify you — we store only a one-way hash of the key itself.
What we collect
- API keys — requested via email, stored as one-way hashes. We cannot use them on your behalf. The email address you send the request from is retained only for our internal audit log.
Email communications
We do not operate a dedicated mail server. Emails sent to our contact address (e.g. API key requests) are forwarded to the owner's personal mailbox and processed manually. Your email address and message are subject to the privacy practices of the owner's email provider (e.g. Gmail). We recommend you do not include sensitive personal information in these messages.
What we do NOT collect
- Your IP address is checked briefly for anonymous rate limiting, then discarded. We do not store it.
- Your browser User-Agent is not stored or linked to you.
- Your search history is not logged, stored, or analyzed.
- We do not use third-party analytics, trackers, advertising, or cookies.
Third-party services
We do not use any third-party services for data processing, analytics, or email delivery.
Tor access
For additional privacy at the network layer, the API is accessible via a .onion (Tor) hidden service. Contact us to request the address — an API key is required.
Server logs
We keep operational logs (server logs, backup logs) for 7 days, then they roll off automatically. These logs are used only for debugging and capacity planning.
Changes to this policy
We may update this policy. The current version will always be posted here with the effective date.
Contact
For privacy questions or data deletion requests, email .