Privacy Policy
Last updated: June 17, 2026
This Privacy Policy explains how Hunt Labs Inc ("ByteKit," "we," "us," or "our") processes personal data when we operate the ByteKit service, websites, dashboard, API, SDKs, CLI, documentation, support, billing, and related services (collectively, the "Service").
Capitalized terms not defined here have the meanings given in the Terms of Service or the Data Processing Agreement.
1. Roles and Scope
This policy covers personal data ByteKit processes as a controller for our own business purposes, including account administration, billing, support, security, fraud prevention, service telemetry, and website operations.
This policy does not govern personal data contained in content that a customer asks the Service to capture, transform, store, or return ("Captured Content"). For Captured Content, the customer is generally the controller and ByteKit acts as processor or service provider under the Data Processing Agreement.
If your personal data appears in Captured Content submitted by a ByteKit customer, please direct your request to that customer where possible. If you contact us, we will help route or support the request where we can identify the relevant customer.
2. Contact
| Purpose | Contact |
|---|---|
| Privacy and data rights | [email protected] |
| Security reports | [email protected] |
| Support | [email protected] |
| Legal notices | [email protected] |
| Mailing address | Hunt Labs Inc, 533 Hugo St, San Francisco, CA 94122, United States |
If applicable law requires ByteKit to appoint a data protection officer or an EU or UK representative, the relevant contact details will be listed here before publication.
3. Personal Data We Process
We process the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Account and identity data | Name, email address, profile information, OAuth identifiers, account role, authentication metadata | You, your organization, and our authentication provider |
| Billing and payment data | Billing contact, billing address, tax details, payment tokens, invoice and transaction history | You and our payment provider |
| Request metadata and usage data | Submitted URLs, request and response metadata, status codes, timing, retry outcomes, proxy or tier selection, API key attribution, usage rollups, logs | Your use of the Service |
| Communications data | Support messages, email communications, operational notices, message metadata | You and our communications providers |
| Website and device data | IP address, user agent, request headers, page interactions, documentation usage, network metadata | Your browser or device |
| Security and fraud-prevention data | Abuse signals, rate-limit state, enforcement history, suspected compromise indicators | Your use of the Service and our systems |
We do not seek to collect sensitive personal data about account holders in the ordinary course of providing the Service. Customers must not use the Service to capture sensitive personal data except where they have a lawful basis and any required written approval from ByteKit.
4. How We Use Personal Data
We use personal data to:
- provide, operate, maintain, and improve the Service;
- create and administer accounts, workspaces, authentication, members, and permissions;
- process payments, invoices, taxes, subscriptions, and usage-based charges;
- provide support and respond to requests;
- monitor reliability, latency, capacity, and service quality;
- detect, prevent, and respond to abuse, fraud, security incidents, and policy violations;
- enforce our agreements and protect our rights, customers, users, and third parties;
- comply with legal obligations and respond to lawful requests; and
- send service, security, billing, and administrative notices.
Where the GDPR, UK GDPR, or similar law applies, we rely on the following legal bases:
| Processing purpose | Legal basis |
|---|---|
| Account administration, authentication, service delivery, billing, and support | Performance of a contract |
| Security, abuse prevention, service reliability, product improvement, and enforcement | Legitimate interests |
| Tax, accounting, sanctions, legal process, and regulatory obligations | Legal obligation |
| Optional marketing or non-essential cookies, where used | Consent, where required |
5. AI and Service Improvement
By default, ByteKit may use request metadata, telemetry, usage data, and aggregate service data to evaluate, secure, train, and improve Service systems such as routing, retry behavior, anti-abuse systems, extraction quality, fraud detection, and reliability monitoring.
ByteKit does not use Captured Content to train models by default. If ByteKit offers an opt-in content-training feature, Captured Content will be used for that purpose only where the customer affirmatively opts in or agrees in writing.
ByteKit does not sell trained models, model weights, embeddings, or training datasets derived from customer Captured Content.
6. When We Disclose Personal Data
We disclose personal data only as needed for the following purposes:
- Service providers and sub-processors. We use third-party providers for hosting, storage, authentication, billing, email, networking, AI inference, and related operations. The third-party providers and Sub-Processors we use — including those that process account data and those that process Captured Content — are listed in the Data Processing Agreement.
- Customer direction. We may disclose data as instructed by a customer or account administrator.
- Legal compliance and protection. We may disclose data to comply with law, respond to valid legal process, enforce our agreements, protect rights and safety, or investigate abuse.
- Business transactions. We may disclose data in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate protections.
- Consent. We may disclose data where you consent or direct us to do so.
ByteKit does not sell personal data. ByteKit does not share personal data for cross-context behavioral advertising unless this policy is updated to describe that practice and provide any legally required choices.
7. International Transfers
ByteKit and its service providers may process personal data in the United States, the European Economic Area, the United Kingdom, and other countries where we or our providers operate. Where required, we rely on appropriate transfer mechanisms, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, Swiss adaptations, adequacy decisions, or other lawful mechanisms.
8. Retention
We retain personal data for as long as reasonably necessary for the purposes described in this policy, including to provide the Service, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and protect the Service.
Captured Content retention is governed by the Data Processing Agreement, customer settings, and any applicable order form.
When retention is no longer necessary, we delete, de-identify, or aggregate personal data unless we are required or permitted to retain it longer.
9. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also have the right to withdraw consent, opt out of certain processing, or complain to a data-protection authority.
To exercise rights over your ByteKit account data, contact us using the privacy contact in Section 2. We may need to verify your identity before responding.
If your request concerns personal data inside Captured Content submitted by a ByteKit customer, we may refer you to that customer or assist the customer in responding, depending on the circumstances and applicable law.
10. Cookies and Similar Technologies
ByteKit uses cookies and similar technologies that are necessary to provide the Service, keep you signed in, secure the Service, remember preferences, and understand basic website and documentation usage.
If ByteKit uses optional analytics, advertising, or similar non-essential technologies, we will provide any consent or opt-out controls required by applicable law.
11. Security
We use administrative, technical, and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Children
The Service is intended only for users who are at least 18 years old, consistent with the eligibility requirement in the Terms of Service. The Service is not directed to anyone under 18, and ByteKit does not knowingly collect account information from anyone under 18. Customers must not use the Service to collect children's personal data unless they have all required rights, notices, consents, and legal bases.
13. Changes
We may update this Privacy Policy from time to time. Material changes will be announced through the Service, by email, or by another reasonable method. The updated policy will apply from its effective date.