Legal

Privacy Policy

Mentorsko Ltd is the controller of personal data processed through gsearch.dev. This policy explains what we collect and why.

Effective date: August 12, 2026

1. Data we collect

The data we process depends on how you use the service.

  • Account data: Google account identifier, email address, display name, profile image, sign-in records, and account settings.
  • Service data: plan, credit balance, API key name and prefix, a one-way hash of each API key, request status, timing, credit use, and result count.
  • Search activity: query text when query anonymization is off, plus request metadata. Turning anonymization on removes stored query text for that account and prevents new query text from being saved.
  • Billing data: Stripe customer, subscription, invoice, Checkout, and payment references, amounts, status, and refund details. Stripe handles full card and bank payment details.
  • Contact data: the name, email, company, volume range, and message you submit. The contact form sends this to our business inbox and does not store it in the application database.
  • Security data: IP address, session and anti-abuse identifiers, essential cookies, and technical logs needed to protect and operate the service.

2. Why we use data

We use personal data only for defined service and business purposes.

  • To create and secure accounts, authenticate requests, provide search results, apply credits, and support customers under our contract with you.
  • To send account emails and payment notices. If you choose the paid plan email option when you register, we may email you after seven days, after one month, and then every two months while your account is still on the Free plan. You can decline it when you register. You can stop the series from your account or from the opt-out link in every email.
  • To process payments, invoices, refunds, tax records, and accounting obligations.
  • To prevent abuse, investigate faults, enforce service limits, and improve reliability based on our legitimate interests in running a safe service.
  • To meet legal obligations and respond to valid legal requests.
  • To use consent where applicable law requires it. You may withdraw consent without affecting earlier lawful processing.

3. Service providers and transfers

We share data only as needed with providers that support hosting, databases, authentication, payment, email, abuse prevention, and search delivery. They process data under their own terms or our instructions, depending on their role.

Some providers may process data outside the European Economic Area. Where required, we use an adequacy decision, contractual safeguards, or another lawful transfer mechanism.

We may also disclose data when required by law, to protect users and the service, or as part of a business transaction subject to suitable confidentiality protections.

4. Retention

We keep account and service data while the account is active and for a reasonable period afterward when needed for support, security, disputes, or legal obligations. Billing and tax records may be kept for the period required by law.

We delete or anonymize data when it is no longer needed for these purposes. Retention can vary by record type, legal duty, and the need to establish or defend a claim.

5. Cookies and automated controls

gsearch.dev uses essential session and security data for sign-in, account protection, rate limiting, and bot prevention. We do not use advertising cookies or sell personal data.

Automated controls may block abusive traffic, reject an invalid request, or enforce account and rate limits. We do not use these controls to make decisions that produce legal or similarly significant effects about a person.

6. Your rights

Depending on the law that applies, you may ask for access, correction, deletion, restriction, portability, or an objection to certain processing. You may also withdraw consent where consent is the legal basis.

Send a request to [email protected]. We may need to verify your identity before acting on a request. You may also complain to the Bulgarian Commission for Personal Data Protection or another competent supervisory authority.

7. Security, children, and changes

We use technical and organizational safeguards designed to protect personal data. No online service can guarantee absolute security, so tell us promptly if you believe an account or API key is compromised.

The service is not directed to children. Do not create an account if you cannot lawfully agree to these terms in your country.

We may update this policy when the service or legal requirements change. We will post the new effective date and give additional notice when a material change requires it.