Appservices Captcha — Privacy Policy

Last updated: 7 October 2026 — what the service stores of your API key. Since 4 October 2026 the extension signs in with your Appservices API key (version 2.2.0 and later).

This policy covers the Appservices Captcha browser extension and the captcha service it uses at www.appservices.dev/captcha (together, "the service"), operated by Appservices.

What the extension does

It solves the number-grid captcha on supported BLS visa appointment pages for Appservices subscribers: it reads the visible captcha tiles and the requested number on those pages, has them recognized by the service, and selects the matching tiles. It signs in with your Appservices API key; earlier versions used your subscription email, a sign-in the service is retiring.

Data we process

DataSourcePurposeWhere it goes
Your Appservices API keyYou paste it in the extensionIdentify your account and count your daily creditsStored on your device, in the extension's own storage (web pages cannot read it); sent to the service with each request. The popup shows only its first and last characters
Your account name, plan and today's creditsThe service, after you sign inShow them in the popupStored on your device only
Captcha tile images and the requested numberThe captcha on a supported BLS pageRecognize the digits on each tileSent to the service
Extension settingsYou, in the popupBehave as you choseStored on your device only
Technical request data (IP address and approximate country, time, result)Your connectionSecurity, abuse prevention (e.g. detecting a subscription shared across many networks), troubleshootingThe service's server logs

The extension does not read or send any other page content, form data, passwords, cookies, browsing history or personal communications, and it does not run on any other website.

How the service handles it

Sharing

We do not sell or rent your data, do not use it for advertising, and do not share it with third parties except the infrastructure providers that host and protect the service (Hetzner for hosting, Cloudflare for network protection), which process it only on our behalf.

Your choices

Security

All traffic to the service uses HTTPS. The key is sent from the extension's background process, never from the BLS page or the extension's own page script. If you think your key was exposed, ask Appservices for a new one: the old key then stops working.

Contact

Website: www.appservices.dev

We may update this policy; the date above changes when we do.