CleanedWeb
On this page

Trust

Security at CleanedWeb

Keep your account, API credentials, and the data you collect under your control. This page explains the integration safeguards and reporting process for CleanedWeb.

Accounts and credentials#

The web application uses a same-origin session when talking to its builder. Its session cookie is HttpOnly, so page scripts cannot read it. Server integrations use the authentication instructions supplied with their generated API. Keep API credentials on your server, in your deployment’s secret storage, rather than in browser code or source control.

Where key management is enabled in your workspace, the API detail page lets you create and revoke credentials. Save a newly issued secret securely; the API detail page clears its displayed copy when you leave. This does not erase a secret you copied or revoke the credential. Check the key’s scopes and expiry before integrating it. To rotate a key, validate the replacement with a bounded request before revoking the old credential.

Inputs and collected data#

Submit public source URLs that you are authorized to process. Do not put passwords, access tokens, private session links, or sensitive personal information into source URLs or support messages. Public accessibility does not remove privacy obligations or third-party rights.

Source previews, saved definitions, example records, and execution output can contain information from the source. Treat these as data: restrict who receives them and review them before sharing. A generated API can change how easily information is accessed; use only the fields you need.

Version and output checks#

Generated APIs expose a definition version and source-specific limits. Pin requests to the expected version and review the output schema before using a changed definition. Inspect the response summary for partial results; a successful HTTP response alone does not establish complete collection.

The integration guide explains the request and verification steps.

Retention and deletion#

Our Privacy Policy explains the purposes for which information is retained. To request deletion or ask about a particular workspace, email info@cleanedweb.com. Include the relevant account or record identifier, without sending live credentials. Legal, billing, and security records may need to be retained.

If your organization needs specific processing terms, a retention schedule, data-location commitments, or a security review, contact us before sending data subject to those requirements.

Report a vulnerability#

Email info@cleanedweb.com with the affected URL, a description, and the smallest reproduction you can provide. Redact secrets and personal information. If a credential has been exposed, revoke it through your workspace where available and tell us its non-secret identifier.

Use your own account and data for a reproduction. Do not access another customer’s data, disrupt service, or publish sensitive details in a public issue.