JupiterFetch

Last updated September 27, 2026

Privacy

What JupiterFetch stores when you use the site, the API or the MCP connector, who else handles it, how long it is kept, and how to have it deleted.

Operator

Who runs JupiterFetch, and how to reach us.

JupiterFetch is operated by PerfSpot LLC, a Delaware limited liability company. This policy covers jupiterfetch.com, the JupiterFetch API and the MCP connector at mcp.jupiterfetch.com. Reach us at [email protected].

The brand data we cache, and whose it is

We hold the cache, so this is the section that says what that means.

When someone asks us for a domain’s brand profile we fetch that domain’s public pages and cache the result. That cache is ours: we run it and we can purge it. We do not need the site owner’s account or cooperation to fetch a public page, and we do not seek personal data from the sites we fetch.

What the service stores

Everything JupiterFetch keeps, and for how long.

DataWhat it isHow long it is kept
Brand profilesPublic information about a fetched domain: name, logos, colors, fonts, links, page metadata.Served for 7 days, then fetched again the next time the domain is requested, replacing the stored copy. A profile nobody asks for again stays cached until we delete it.
Fetch recordsOne row per attempt: domain, status, which path was used, duration, error code, timestamps. No account details.Kept as an operational log, with no automatic deletion.
Hosted imagesLogos and other images from a brand profile: JupiterFetch fetches them, converts what needs converting, and stores them on its CDN.Deleted 44 days after they were stored.
AccountsYour name and email address, a password hash if you set a password, and a link to your Google account if you sign in with Google. Each sign-in session records the IP address and browser it came from.Kept while your account is open and deleted when the account is deleted.
API keysEach key’s name, a hash of the key, an encrypted copy so you can reveal it again, and when it was created, last used and revoked.Kept while your account is open, revoked keys included, and deleted when the account is deleted.
Usage recordsOne row per API or MCP request: domain, status, error code, whether a credit was spent, time taken, and which key or connected app made it.Kept while your account is open and deleted when the account is deleted.
BillingYour credit balance, each purchase’s amount and credits, your auto top-up settings, and your Stripe customer reference. Card details are entered on Stripe’s pages and never reach us.Kept while your account is open and deleted when the account is deleted. Stripe keeps its own payment records.
Product eventsMilestones such as signing up, buying credits and connecting an AI app, tied to your account ID. They hold the domain of your email address, never the address itself, plus your country and the campaign or site that referred you, when known.Read by our internal analytics. Kept after an account is deleted, tied only to an account ID that no longer exists.

Images JupiterFetch fetches are stored on its CDN and deleted 44 days after they were stored.

Brand profiles describe organizations, not people. The personal data in the list is your account and what hangs off it, plus whatever incidentally appears on a fetched public page.

Cookies and browser storage

Two cookies, one saved setting, and no advertising trackers.

A session cookie keeps you signed in. When you first arrive on the site we may set jf_attribution, a cookie that remembers for 30 days which campaign or site referred you (campaign tags, an ad click ID, the referring domain and, when known, your country), so a sign-up can be credited to it. The light and dark theme switch saves your choice in your browser’s local storage. Our public pages load one analytics script from another company, Ahrefs, which counts visits without setting cookies. The sign-in pages and your account pages do not load it, and we load no advertising scripts.

If you connect an AI app through the MCP connector

What connecting Claude, ChatGPT or another MCP client to your account stores, and how to remove it.

An AI app registers itself with us before you connect it. We keep the details it sends, such as its name and the web addresses it sends you back to after sign-in. When you approve the connection we record your consent and a connection record: the app’s name as we display it, whether we could verify that name, when you connected it and when it last looked up a brand.

The app then holds an access token, which lasts 1 hour, and a refresh token, which lasts 30 days and is replaced each time the app uses it. We store both hashed, the same way as an API key: we keep enough to check a token when the app presents it, not the token itself. Once a token has been expired or revoked for 30 days, its record is deleted the next time we clear out old tokens.

Each brand lookup the app makes leaves the same usage record as an API request: the domain, the status, whether a credit was spent, and the app’s name. Our product events note that an app was connected and which tool each call used and how it ended, with no domain in them.

The app receives the brand profiles and the credit balance you ask it for. It does not receive your email address or your password from us. What the app does with the data it receives is governed by that app’s own privacy policy, not this one.

To disconnect an app, use Disconnect under Connect to Claude & more on the API & MCP page, which deletes its tokens, your consent and the connection record at once. You can also remove the connector inside the AI app; tokens the app still holds then stop working when they expire, so use Disconnect to end access at once. Deleting your account deletes your tokens, consents, connection records and usage records. An app’s registration belongs to the app rather than to your account, so it is not deleted with your account.

Services that handle data for us

The companies JupiterFetch relies on, and what each one sees.

ServiceWhat it does for us
RailwayRuns the JupiterFetch application servers.
NeonHosts the database that holds everything in the table above except images.
CloudflareSits in front of the site, stores and serves hosted images, and runs the Turnstile bot check on sign-in forms and the demo.
StripeTakes card payments and stores the cards you save for auto top-up.
PostmarkSends account email: sign-in codes, verification, password resets and balance notices.
SentryReceives error reports. Credentials, cookies and request bodies are stripped before they are sent.
AhrefsCounts visits to our public pages: the page, the referring site, links clicked and forms sent, your browser, device and language, and your country and city. It sets no cookies and does not store your IP address.
GoogleSigns you in, only if you choose Sign in with Google.
SlackCarries internal alerts to our team about sign-ups and purchases, which can include the account’s email address.

If we fetched your site

What we request from it, and what we keep.

We request public pages, execute their assets, and cache the brand profile we build from them. We do not submit forms, sign in, or request anything behind authentication, so we do not collect your users’ data.

Data retention

How long each kind of data is kept, in one place.

Your choices

What you can do yourself, and what to ask us for.

Your usage, API keys, connected apps and billing are on your account pages, where you can revoke keys, disconnect apps and turn off auto top-up. To get a copy of what we hold about you, or to delete your account, email [email protected] from the address on the account. Deleting an account deletes everything above that is kept while your account is open. We send only account email: sign-in codes, verification, password resets, and notices when your balance runs low, runs out or an auto top-up fails. We send no marketing email.

Children’s data

JupiterFetch is a developer service and is not intended for anyone under 16. We do not knowingly collect data from children.

Changes to this policy

When we change this policy we post the new version on this page and update the date at the top.

Contact us

Privacy questions and requests about your data go to [email protected]. If your question is about a domain we have cached, we can answer it directly: we operate the service and hold the data.

For anything else, see the contact page.