Privacy Policy

Last updated: July 2026

1. Introduction

API Direct ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and API services (collectively, the "Service").

We are based in the United Kingdom and operate in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using our Service, you agree to the collection and use of information in accordance with this policy.

Our Service is not intended for identifying or targeting individuals on the basis of special categories of personal data (such as health, political opinions, religious beliefs, sexual orientation, or biometric data), and such use is prohibited by our Terms of Service.

2. Data Controller

API Direct is the data controller responsible for your personal data. If you have any questions about this Privacy Policy or our data practices, please contact us at support@apidirect.io. If you need our full registered details or a postal address, ask us by email and we will provide them.

3. Information We Collect

3.1 Account Information

When you create an account, we collect:

  • Email address - Required for account creation and communication
  • Password - Stored in hashed form; we never store plaintext passwords
  • Name - If you sign up via Google OAuth, we may receive your name from Google

3.2 Payment Information

When you add a payment method, we store:

  • Card details - Only the last 4 digits, card brand, and expiry date (full card details are stored by Stripe)
  • Billing identifiers - Stripe customer ID and subscription ID for payment processing

3.3 Usage Data

When you use our API, we collect:

  • API request logs - Endpoint called, timestamp, response latency, and whether the request succeeded or failed
  • Cost data - Amount charged per request for billing purposes
  • API key usage - Which API key was used for each request

We do not log the data returned in API responses.

We do not log the parameters of your API queries when a request succeeds. When a request fails, we retain a truncated snapshot of that request's parameters (its query string and, where applicable, its JSON body) so that we can diagnose the error, alert you to it, and prevent it recurring. These snapshots are stored with the usage record for the failed request and are deleted when you delete your account.

3.4 Technical Data (IP Addresses)

Your IP address is processed automatically whenever you use our website or API. We use it to:

  • Rate limiting - Enforcing the per-IP request limits described in our Terms of Service
  • Security and abuse prevention - Detecting and blocking abusive or fraudulent traffic

IP addresses are used transiently for these purposes and also appear in the application and infrastructure logs generated by our hosting provider. We do not use your IP address to build a profile of you, and we do not use it for advertising or cross-site tracking.

3.5 Analytics and Advertising Measurement

We use a small number of analytics and measurement tools:

  • Account milestone events - Our servers record events such as sign-up, first API request, and adding a payment method, linked to your account, so that we can understand how the Service is used and improve it (Mixpanel)
  • Website analytics - Aggregate page-view and performance measurement for our website (Vercel Web Analytics)
  • Advertising measurement - A third-party advertising pixel that measures the effectiveness of our advertising campaigns and may set cookies in your browser (Reddit Ads)
  • Referral attribution - We store, in your browser, how you first arrived at our site (campaign parameters in the link you followed, the referring website, and the page you landed on). If you go on to create an account, this is saved against it so we can tell which campaigns bring people to us

3.6 Information We Do Not Collect

We do not collect:

  • Precise location data
  • Device fingerprints
  • Special category data about you (such as health, political opinions, or religious beliefs)

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process payments and manage your account
  • Send transactional emails (e.g., welcome emails, payment confirmations)
  • Respond to your enquiries and provide customer support
  • Monitor and analyse usage patterns to improve the Service
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

5. Legal Basis for Processing

Under UK GDPR, we process your personal data based on the following legal grounds:

  • Contract performance - Processing necessary to provide our Service to you
  • Legitimate interests - Processing necessary for our legitimate business interests, such as improving our Service and preventing fraud
  • Legal compliance - Processing necessary to comply with our legal obligations
  • Consent - Where you have given consent for specific processing activities

6. Data Sharing and Third-Party Services

We share your information with the following categories of third-party service providers who assist us in operating the Service:

Provider Purpose Data Shared
Supabase Database and authentication Account data, usage records
Stripe Payment processing Payment and billing information
Amazon Web Services (SES) Email delivery Email address, name
Upstash Caching and rate limiting Temporary usage counters
Vercel Hosting infrastructure Request metadata
Mixpanel Product analytics Email address, account milestone and usage events
OpenRouter AI sentiment analysis (only when requested) The text of the public content you submit for analysis with get_sentiment=true
Google Sign-in; web font delivery Email, name (only if using Google sign-in); IP address and browser details of all visitors, via fonts loaded on each page
Reddit Advertising measurement IP address, browser details, pages visited
jsDelivr (Volentio JSD) Content delivery for website scripts IP address, browser details

We do not sell your personal data to third parties. We may disclose your information if required by law or in response to valid legal requests from public authorities.

A current list of the providers we use is maintained on our sub-processors page.

7. International Data Transfers

Some of our third-party service providers are located outside the United Kingdom. When we transfer your personal data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO), or transfers to countries with adequate data protection laws.

8. Data Retention

We retain your personal data for as long as necessary to:

  • Provide the Service to you
  • Comply with our legal and regulatory obligations
  • Resolve disputes and enforce our agreements

When you delete your account, we will delete your personal data immediately, including your profile, API keys, and usage records. Some data may be retained in backups for a limited period as required by law or for legitimate business purposes.

9. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access - Request a copy of your personal data
  • Right to rectification - Request correction of inaccurate data
  • Right to erasure - Request deletion of your personal data
  • Right to restriction - Request limitation of processing
  • Right to data portability - Request transfer of your data in a machine-readable format
  • Right to object - Object to processing based on legitimate interests
  • Right to withdraw consent - Withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us at support@apidirect.io. We will respond to your request within one month.

You can delete your account and all associated data at any time through your dashboard settings.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of data in transit using TLS/HTTPS
  • Hashing of passwords and API keys (we never store them in plaintext)
  • Access controls and authentication for our systems
  • Regular security reviews and updates

While we strive to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

11. Cookies and Similar Technologies

We use:

  • Essential cookies - Necessary for the operation of the Service, such as authentication session cookies
  • Advertising and measurement technologies - Our website includes a third-party advertising pixel (Reddit Ads) which measures the effectiveness of our advertising and may set cookies in your browser
  • Referral attribution - A first-party cookie (_apidirect_attr), stored for 90 days, recording how you first reached our site: any campaign parameters in the link you followed, the referring website, and the page you landed on. If you create an account, this is linked to it

If you are in the UK or the European Economic Area, we ask for your consent before setting the optional cookies above, and we do not set them unless you accept. Essential cookies are always set, as the Service cannot run without them. Elsewhere, the optional cookies are set by default.

To change your choice, delete the _cc cookie through your browser settings and reload the page: we will ask again. You can also block or delete any of these cookies through your browser settings without affecting your ability to use the Service. We do not sell the data collected by these technologies.

12. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on our website prior to the changes becoming effective. We encourage you to review this policy periodically.

14. Complaints

If you have concerns about how we handle your personal data, please contact us first at support@apidirect.io. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

15. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Email: support@apidirect.io