Template document. These pages are a starting point written for a developer API business, not legal advice. Have a qualified lawyer review and adapt them for your jurisdiction before you rely on them.

Privacy Policy

Last updated 22 September 2026

1. What we collect

  • Account data — name, email, optional company and description of your use case.
  • Authentication data — a hashed password and SHA-256 digests of your API keys. We never store either in a recoverable form.
  • Usage data — for each API request: the endpoint, query parameters, status code, duration, credit cost, originating IP and user agent.
  • Billing data — plan, interval, invoice history. Full payment card numbers are never stored on our systems.
  • Support data — messages you send us through the contact form.

2. Why we collect it

To operate your account, meter and bill usage accurately, show you your own analytics, enforce rate limits, detect abuse, and answer your support requests. We do not sell personal data and we do not use it for third-party advertising.

3. Retention

Per-request logs are retained for the period attached to your plan (3 to 365 days) and then deleted. Aggregated daily counters are kept for as long as your account is open so your historical charts remain meaningful. Account and invoice records are retained as long as legally required after closure.

4. Sharing

We share data only with infrastructure providers strictly necessary to run the Service (hosting, email delivery, payment processing), each bound by a data processing agreement. We disclose data to authorities only where legally compelled.

5. Your rights

You can access, correct, export or delete your data. Profile fields are editable in account settings, request logs are exportable as CSV from the dashboard, and account deletion can be requested through support. If you are in the EEA or UK, you also have the right to lodge a complaint with your supervisory authority.

6. Cookies

We set a session cookie to keep you signed in and a CSRF cookie to protect form submissions. Both are strictly necessary — there are no advertising or cross-site tracking cookies, which is why this site has no cookie banner. Your theme preference is stored in localStorage and never leaves your browser.

7. Security

Traffic is encrypted in transit. Passwords are hashed with PBKDF2 and API keys stored only as SHA-256 digests. Access to production data is limited to staff who need it. If you believe you have found a vulnerability, tell us before disclosing it publicly and we will work with you.

8. Contact

Privacy questions or requests: contact us.