Appservices Captcha — Privacy Policy
Last updated: 7 October 2026 — what the service stores of your API key. Since 4 October 2026 the extension signs in with your Appservices API key (version 2.2.0 and later).
This policy covers the Appservices Captcha browser extension and the captcha service it uses at www.appservices.dev/captcha (together, "the service"), operated by Appservices.
What the extension does
It solves the number-grid captcha on supported BLS visa appointment pages for Appservices subscribers: it reads the visible captcha tiles and the requested number on those pages, has them recognized by the service, and selects the matching tiles. It signs in with your Appservices API key; earlier versions used your subscription email, a sign-in the service is retiring.
Data we process
| Data | Source | Purpose | Where it goes |
|---|---|---|---|
| Your Appservices API key | You paste it in the extension | Identify your account and count your daily credits | Stored on your device, in the extension's own storage (web pages cannot read it); sent to the service with each request. The popup shows only its first and last characters |
| Your account name, plan and today's credits | The service, after you sign in | Show them in the popup | Stored on your device only |
| Captcha tile images and the requested number | The captcha on a supported BLS page | Recognize the digits on each tile | Sent to the service |
| Extension settings | You, in the popup | Behave as you chose | Stored on your device only |
| Technical request data (IP address and approximate country, time, result) | Your connection | Security, abuse prevention (e.g. detecting a subscription shared across many networks), troubleshooting | The service's server logs |
The extension does not read or send any other page content, form data, passwords, cookies, browsing history or personal communications, and it does not run on any other website.
How the service handles it
- Captcha images are processed in memory to recognize the digits and are not stored.
- The recognition result (the numbers) is kept for up to 5 minutes so a client can fetch it again.
- The service keeps a keyed hash of your API key, which identifies your account, and an encrypted copy of it, so that you can show the key again in your Appservices account after confirming your password (a key created before this was available is shown once only).
- Daily credit counters per subscription are kept for up to 35 days.
- Server logs (your account's subscription identifier, IP address, approximate country and request result — never the images or the key) are kept for up to 30 days.
- Subscription records (plan, status, expiry) come from Appservices' subscription system.
Sharing
We do not sell or rent your data, do not use it for advertising, and do not share it with third parties except the infrastructure providers that host and protect the service (Hetzner for hosting, Cloudflare for network protection), which process it only on our behalf.
Your choices
- Log out in the extension popup to delete the stored key and account details from your device.
- Uninstalling the extension removes all of its local data.
- To ask for your usage records to be deleted, contact us below.
Security
All traffic to the service uses HTTPS. The key is sent from the extension's background process, never from the BLS page or the extension's own page script. If you think your key was exposed, ask Appservices for a new one: the old key then stops working.
Contact
Website: www.appservices.dev
We may update this policy; the date above changes when we do.