Privacy Policy
Last updated: August 4, 2026
1. What this covers
This policy explains what data the Web to Markdown API and its landing page process, what we deliberately do not keep, and who else touches your data as part of running the Service.
2. What the API processes
Each conversion request sends us either a target URL or a block of raw HTML — the input you ask us to convert — along with your API key for authentication. That input is fetched or parsed, converted to Markdown, and returned to you in the same response.
We do not store the converted output. The source HTML/URL and the resulting Markdown are held only in memory for the duration of the request and are not written to a database or persisted anywhere after the response is sent.
3. Logs and telemetry
Like any API, we keep operational logs to run the service, debug issues, and enforce rate limits: things like the request path, method, HTTP status, response time, and the customer ID associated with your API key. Our logging layer automatically redacts fields that look like secrets — API keys, tokens, passwords, authorization headers, cookies, and signatures are replaced with a placeholder before a log line is ever written or shipped anywhere. Logs are kept only for as long as needed to operate and troubleshoot the Service, and are not used for advertising or sold to third parties.
Separately, a short-lived record of webhook event IDs is kept for up to 30 days purely to avoid double-processing a payment notification that a payment provider re-sends; it does not contain the content you convert.
4. API keys
An API key is shown to you in plain text only once, at the moment it is issued (typically by email after a purchase). From then on we only store a one-way cryptographic hash of the key, never the key itself, so it cannot be recovered from our systems even by us.
5. Billing data and Polar.sh
All payments are processed by Polar.sh, acting as the Merchant of Record. Your payment details (card number, billing address, etc.) are collected and stored by Polar, not by us. We receive a webhook notification from Polar containing your customer ID, email, and subscription status, which we use solely to issue or update your API key and plan. Refer to Polar's own privacy policy for how they handle payment data.
6. Infrastructure
The Service runs on Cloudflare Workers, with Cloudflare KV used to store hashed API keys, rate-limit counters, and the webhook idempotency record described above. Cloudflare acts as our infrastructure provider and processes data only to run the Service on our behalf.
7. Your choices
You can ask us to revoke your API key at any time, which stops further requests from being authenticated. Since we don't retain converted content, there is no content history to delete on our side beyond your account and billing records held with Polar.
8. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected by updating the date at the top of this page.
9. Contact
Account, billing, and privacy questions: carlosfu.invers@gmail.com (a temporary contact address while a dedicated support inbox is set up).
Bugs and technical issues: open an issue on GitHub.