1Overview
We collect only what we need to operate the Service: your account identity, the content you create, and a minimal amount of operational telemetry. We do not sell personal information, we do not run third-party advertising, and we do not log the bodies of requests you send through the proxy.
2What We Collect
Account information. When you sign in through Google, GitHub, or Discord, we receive your provider-issued user ID, email address, display name, and (where available) avatar URL. We use these to create and manage your account.
Content you create. Collections, requests, environments, schemas, processors, custom scripts, response snapshots you save, descriptions, comments, and publish settings — collectively, “Your Content.” Your Content is stored in our managed Supabase database and is gated by row-level security so other users cannot read it unless you have published it or shared it with them.
Operational metadata. Basic information about how the Service is used, such as creation timestamps, sort order, last-saved timestamps, and version snapshots.
Diagnostic data. Limited server- and edge-side logs containing IP addresses, user-agent strings, request paths, and error messages. These are kept short-term for security monitoring and abuse investigation.
3What We Do Not Collect
- Payment information. The Service is currently free; we do not request or process any payment-card data.
- Proxy request bodies. Bodies forwarded through our request proxy are not persisted in our database. They pass through the edge function and are returned to your browser; they may briefly appear in transient operational logs in the event of an error.
- Sensitive header values. Values you mark as secrets in environments and authorization headers are stripped from local-cache writes before persistence to disk.
- Cross-site tracking. We do not use third-party advertising trackers, fingerprinting scripts, or cross-site cookies.
4How We Use Information
We use the information described above to:
- provide, maintain, and improve the Service;
- authenticate you and synchronize Your Content across devices you sign in from;
- secure the Service — detect and respond to abuse, fraud, and security incidents;
- communicate operational notices (security alerts, material changes to these documents);
- comply with applicable law and respond to lawful requests from authorities.
5Proxy Traffic
When you send a request through our proxy, we (a) validate the target URL against an allow list of public hosts, (b) strip credentials and origin headers we add for our own infrastructure, (c) forward the request to your specified destination, and (d) return the response to your browser.
The destination server you choose receives whatever your request contains. We do not control how that destination handles your data. Treat the proxy as an outbound HTTP client: do not put data into a request that you would not be willing to put into curl.
6AI Features
When you or a reader interacts with the docs chat assistant on a Docs Site, we send the question along with relevant context from the published collection (endpoint names, descriptions, schemas, and sample data you have authored) to a third-party large-language-model provider. We strip values you have marked as secrets before sending.
We do not authorize the LLM provider to use your inputs to train their general models, but you should not include sensitive personal data in published docs you would not otherwise share publicly.
8Published Docs Visibility
When you publish a collection, the visibility you choose controls who can see it:
- Closed — visible only to you, the owner.
- Open · view — anyone with the subdomain link can read the docs. Search engines and AI crawlers may discover and index the page.
- Restricted · view — only email addresses you list can read the docs after signing in through a supported identity provider.
If you change visibility from open to restricted or closed, we make the page unreachable, but third-party caches and search engines may retain copies for some time. Likewise, changing your subdomain breaks any links readers previously bookmarked.
9Storage, Cookies & Local Cache
We use browser localStorage to (a) cache Your Content for instant load on revisit, with secret-flagged values redacted; (b) store the auth tokens issued by Supabase; and (c) persist UI preferences such as theme and panel sizes.
We do not use third-party tracking or advertising cookies. The Service may set first-party cookies necessary for authentication and session management.
10Retention & Deletion
We retain Your Content for as long as your account is active. Operational logs are retained for a short period appropriate to their purpose (typically 30–90 days).
You may delete individual collections, requests, environments, and published versions at any time from within the Service. To delete your entire account and all associated content, contact us at the address in Section 16. We will action verified deletion requests within a reasonable period, after which residual copies may persist only in time-limited backups.
11Your Rights
Depending on where you live, you may have the right to access, correct, port, or delete personal information we hold about you, and to object to or restrict certain processing. You can exercise most of these directly inside the Service (export, edit, delete your collections), or by contacting us. We will respond within the time required by applicable law.
You may also withdraw consent for a specific identity provider by revoking access from that provider’s account-settings page.
12Security
We protect Your Content with row-level security policies at the database layer, transport encryption (HTTPS) end-to-end, secret redaction in local caches, and server-side validation against known-bad targets at the proxy. No system is perfectly secure; you are responsible for the security of the third-party systems you choose to call from the Service.
If you discover a vulnerability, please report it responsibly to support@apikumo.com before disclosing it publicly.
13Children
The Service is not directed to children under 13 (or the minimum age of digital consent in your jurisdiction). We do not knowingly collect personal information from such children. If you believe a child has provided us with personal information, contact us and we will delete it.
14International Transfers
The Service is hosted on infrastructure that may transfer data across borders. By using the Service, you consent to your information being transferred to and processed in countries other than your own, subject to appropriate safeguards required by law.
15Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent change. If we make material changes, we will provide reasonable notice (for example, by email or by posting a banner in the Service) before the changes take effect.
16Contact
For privacy questions or data-rights requests, contact support@apikumo.com.