What we collect when you use SolveGate, why, how long we keep it, and the controls you have.
We collect what we need to run the service and bill it accurately — and not much else. We don't sell your data.
To provide and meter the service, prevent abuse and fraud, provide support, send service and incident notifications, and meet legal obligations. We don't use your data to train models for third parties.
To solve a challenge we process the sitekey and target URL you send. Returned tokens are single-use and short-lived.
We don't want a permanent record of every target you solve. Request URLs and sitekeys are retained only briefly for delivery, debugging, and abuse investigation, then dropped from hot storage.
We share data only with subprocessors that help us run the service — cloud hosting, our payment processor, and email/notification delivery — under contract. We disclose data to authorities only when legally compelled. We never sell personal data.
Keys are stored hashed, data is encrypted in transit and at rest, and access is scoped and logged. No system is perfectly secure, but we work to keep the surface small — which is part of why we only do two gates.
Depending on where you are, you can request access to, correction of, or deletion of your personal data, and object to certain processing. Email privacy@solvegate.io and we'll respond within the timeframe the law requires.