Privacy posture
CrawlerToll is built so that as little data as possible reaches us. The full, binding statement is the privacy notice; this page is the technical summary.
The crawler decision (WordPress plugin)
The decision runs on your own server: HTTP request in, verdict out (allow, 402 or 403). It reads the method, path and headers of the request, logs nothing and sends nothing anywhere. In the WordPress plugin, Pro can keep bot-request logs in your own database, under a retention window you set.
Sealed posts and the unlock service
The paid part of a premium post is encrypted on your server. The unlock service (registry.crawlertoll.com, operated by Charthouse Ltd) holds the content key, the price and the pricing rules, and records a receipt for each unlock: content id, payment rail, transaction reference, amount and time. It never receives the article text, card numbers or wallet keys. See the unlock service.
Payments
Card payments run on your own Stripe account; the card form is Stripe's, so card data goes to Stripe only. USDC payments are settled by a third-party x402 facilitator into your own wallet; the transaction is public on-chain by design. CrawlerToll holds no payment credentials and takes no cut.
Readers' browsers
To keep a reader's access after an unlock, the paywall stores the content key and access pass in the reader's own browser. Metered free reads (Pro) keep a random identifier in the browser. None of this is sent to anyone except the unlock service when the reader renews access.
There is no telemetry and no usage tracking of your site by CrawlerToll.