Privacy Policy
Effective Date: 24 July 2026
APIPoints ("we", "us", or "our") operates the APIPoints platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, API, and services.
1. Information We Collect
We collect information you provide directly to us:
- Account Information: Name, email address, and password (stored as a salted hash — we cannot read your password).
- Payment Information: Processed by Stripe. We do not store credit card numbers. Stripe's privacy policy applies to payment processing.
- API Usage Data: We log API endpoints accessed, timestamps, and credit consumption for billing and rate limiting. We do not log request payloads or response content.
- Agent Data: If you create agents via our platform, we store agent configurations (name, system prompt, model selection) that you provide.
2. How We Use Your Information
- To provide, maintain, and improve our services
- To process payments and manage subscriptions
- To authenticate API requests and enforce rate limits
- To track credit usage and billing
- To send service-related communications (account alerts, billing notices)
- To detect and prevent abuse or unauthorized access
3. Information We Do NOT Collect
- We do not read, store, or process the content of your API requests or responses.
- We do not track your use of third-party LLM providers.
- We do not sell your personal information to third parties.
- We do not use your data for advertising or marketing profiling.
4. Data Storage & Security
Your data is stored on Cloudflare's infrastructure (D1 database, Workers). Cloudflare operates data centers globally with enterprise-grade security. We use industry-standard encryption for data in transit (TLS) and at rest.
Passwords are hashed using PBKDF2 with SHA-256 and a unique per-user salt (100,000 iterations). We never store or have access to plaintext passwords.
5. Third-Party Services
6. Data Retention
We retain your account information for as long as your account is active. API usage logs are retained for 90 days for billing and debugging purposes, then purged. If you delete your account, your personal data is removed within 30 days.
7. Your Rights
Depending on your jurisdiction, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Export your data in a portable format
- Object to processing of your data
To exercise these rights, email us at privacy@apipoints.dev.
8. Cookies
We do not use tracking cookies. The only local storage used is on your device (browser) to store your authentication token and preferences. This data never leaves your device unless you make an API request.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on our website. Continued use of the service after changes constitutes acceptance.
10. Contact
For privacy-related inquiries: privacy@apipoints.dev
APIPoints is operated by Loadcircle Ltd, registered in England and Wales.