Privacy Policy
Last updated 22 September 2026
1. What we collect
- Account data — name, email, optional company and description of your use case.
- Authentication data — a hashed password and SHA-256 digests of your API keys. We never store either in a recoverable form.
- Usage data — for each API request: the endpoint, query parameters, status code, duration, credit cost, originating IP and user agent.
- Billing data — plan, interval, invoice history. Full payment card numbers are never stored on our systems.
- Support data — messages you send us through the contact form.
2. Why we collect it
To operate your account, meter and bill usage accurately, show you your own analytics, enforce rate limits, detect abuse, and answer your support requests. We do not sell personal data and we do not use it for third-party advertising.
3. Retention
Per-request logs are retained for the period attached to your plan (3 to 365 days) and then deleted. Aggregated daily counters are kept for as long as your account is open so your historical charts remain meaningful. Account and invoice records are retained as long as legally required after closure.
4. Sharing
We share data only with infrastructure providers strictly necessary to run the Service (hosting, email delivery, payment processing), each bound by a data processing agreement. We disclose data to authorities only where legally compelled.
5. Your rights
You can access, correct, export or delete your data. Profile fields are editable in account settings, request logs are exportable as CSV from the dashboard, and account deletion can be requested through support. If you are in the EEA or UK, you also have the right to lodge a complaint with your supervisory authority.
6. Cookies
We set a session cookie to keep you signed in and a CSRF cookie to protect form submissions.
Both are strictly necessary — there are no advertising or cross-site tracking cookies, which
is why this site has no cookie banner. Your theme preference is stored in
localStorage and never leaves your browser.
7. Security
Traffic is encrypted in transit. Passwords are hashed with PBKDF2 and API keys stored only as SHA-256 digests. Access to production data is limited to staff who need it. If you believe you have found a vulnerability, tell us before disclosing it publicly and we will work with you.
8. Contact
Privacy questions or requests: contact us.