> Privacy Policy

Last updated: 3 April 2026

1. Controller Identity

UtilsForAgents (“we”, “us”, “the Service”) is operated by:

[Your Legal Entity Name]
[Street Address]
[City, Postal Code, Country]
Email: privacy@utilsforagents.com

Where we process data on behalf of our API users (the “Customer”), the Customer is the data controller and we act as a data processor. See our Data Processing Agreement for details.

2. What Data We Process

UtilsForAgents is a stateless API service. We do not create user accounts, require login, or set cookies. The data we encounter falls into these categories:

Data CategoryExamplesLegal Basis (GDPR Art.)Retention
API request payloadsJSON diffs, HTML, images, URLsArt. 6(1)(b) — contract performanceEphemeral — not stored after response
Image EXIF dataGPS coordinates, camera model, timestampsArt. 6(1)(b) — contract performanceEphemeral — processed in-memory only
Scraped image metadataEXIF, XMP, ICC, IPTC data removed by /scrub-metadataArt. 6(1)(b) — contract performanceDiscarded immediately upon scrubbing
Server access logsIP address, timestamp, request path, user-agent, status codeArt. 6(1)(f) — legitimate interest (security, abuse prevention)14 days
Error logsStack traces, request metadata (no payloads)Art. 6(1)(f) — legitimate interest30 days

3. Image Processing & Personal Data

Images uploaded to our endpoints may contain personal data embedded in EXIF metadata, including:

How we handle this:

We never store, log, or persist image binary data or extracted EXIF content. All processing is ephemeral: data exists only for the duration of the HTTP request/response cycle in an isolated V8 isolate, then is garbage-collected.

4. URL Fetching & Third-Party Content

Endpoints that fetch remote URLs (/v1/html/fetch-markdown, /v1/text/fetch-content, /v1/url/metadata) make outbound HTTP requests on behalf of the caller. We:

The caller (data controller) is responsible for ensuring they have the right to fetch and process the target URL’s content.

5. No Cookies, No Tracking

UtilsForAgents does not:

6. Sub-Processors

Sub-ProcessorPurposeLocationSafeguards
Cloudflare, Inc.Edge compute (Workers), CDN, DDoS protectionGlobal (data processed at nearest edge node)Cloudflare DPA, EU SCCs, ISO 27001, SOC 2 Type II

We will notify customers of any new sub-processor additions by updating this page and the DPA at least 30 days before engagement.

7. International Data Transfers

Cloudflare Workers execute at the edge location nearest to the caller. If the caller is in the EU/EEA, processing typically occurs within EU/EEA data centres. For transfers outside the EU/EEA, the following safeguards apply:

8. Data Subject Rights

Under GDPR, you have the right to:

Because UtilsForAgents is stateless and does not store request payloads, most data subject rights relating to API payloads are satisfied by design — we have no personal data to return, correct, or delete. For access log data, contact privacy@utilsforagents.com.

9. Data Retention

Data TypeRetention PeriodDeletion Method
API request/response payloads0 — never storedGarbage collected after request completes
Image binary data0 — never storedGarbage collected after request completes
Server access logs14 daysAutomatic rotation
Error/exception logs30 daysAutomatic rotation

10. Security Measures

11. Children’s Privacy

UtilsForAgents is a programmatic API service intended for developers and AI agents. We do not knowingly collect personal data from children under 16. If you believe a child has submitted personal data through our API, contact privacy@utilsforagents.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be noted with an updated “Last updated” date. Continued use of the Service after changes constitutes acceptance.

13. Contact

For privacy-related enquiries, data subject requests, or complaints:
privacy@utilsforagents.com

Data Protection Officer (if appointed):
[DPO Name] — dpo@utilsforagents.com