Security & Privacy
Review how accounts and API access work, what information the service processes, and which documents are available for your evaluation.
Security and data handling
HTTPS (TLS)
Use HTTPS for encrypted transport to the API.
API Key Auth
API keys authenticate protected endpoints. The keyless demo is public.
Storage and providers
Our privacy policy describes storage and service providers. Request control details for your procurement requirements.
Data we process
Account, technical, usage, billing and support information are processed to provide the service. Optional analytics are described in our privacy policy.
Information processed by the service
- Account and authentication
- Name, email and account credentials; Google sign-in can also provide profile information.
- Technical and usage
- API request metadata, IP address, browser and device information. Optional analytics and session replay depend on your consent choice.
- Billing and support
- Subscription records handled with Stripe, support communications and operational logs.
The Privacy Policy covers purposes, providers, retention and your choices. For a data request, email [email protected].
Review the DPA request process or the Trust & Reliability center before procurement.
Data Protection
Storage controls
Review the privacy policy and request current storage-control documentation.
Encryption in Transit
Connect to API endpoints over HTTPS.
Backups and recovery
Request current backup scope and restoration evidence before relying on recovery targets.
Data Retention
Retention and deletion are described in the privacy policy. Confirm any contractual retention requirements before purchase.
Privacy Policy
Data we process
Account, billing, usage and support processing, plus optional analytics, are described in the privacy policy.
No Data Selling
Your data is never sold to third parties
Right to Deletion
Request account and data deletion at any time
Usage and operational records
API usage and operational records support quota management, security and troubleshooting.
Compliance
Your Data, On Request
Contact [email protected] to request access, export or deletion of personal data under the privacy policy.
Procurement documentation
Request documentation for the controls and recovery requirements your organization needs.
We are not currently SOC 2 or ISO 27001 certified, and we do not claim GDPR certification — no such certification exists, and we have not been independently audited for GDPR compliance. What we can tell you is exactly what we do: the data we collect, how it is encrypted, and how to have it deleted. If your procurement process requires a formal certification, contact us and we will share the security documentation we do have.
API Security Best Practices
Recommended Practices
- • Store API keys securely (never in source code)
- • Use environment variables for API keys
- • Implement proper error handling
- • Monitor API usage regularly
- • Rotate API keys periodically
- • Use HTTPS for all API calls
Security Warnings
- • Never expose API keys in frontend code
- • Don't commit API keys to version control
- • Avoid logging API keys in application logs
- • Don't share API keys via email or chat
- • Revoke unused or compromised keys immediately
- • Use server-side API calls when possible
Security Questions?
Have questions about our security practices? Our team is here to help.