Security & Privacy

Review how accounts and API access work, what information the service processes, and which documents are available for your evaluation.

Security and data handling

HTTPS (TLS)

Use HTTPS for encrypted transport to the API.

API Key Auth

API keys authenticate protected endpoints. The keyless demo is public.

Storage and providers

Our privacy policy describes storage and service providers. Request control details for your procurement requirements.

Data we process

Account, technical, usage, billing and support information are processed to provide the service. Optional analytics are described in our privacy policy.

Information processed by the service

Account and authentication
Name, email and account credentials; Google sign-in can also provide profile information.
Technical and usage
API request metadata, IP address, browser and device information. Optional analytics and session replay depend on your consent choice.
Billing and support
Subscription records handled with Stripe, support communications and operational logs.

The Privacy Policy covers purposes, providers, retention and your choices. For a data request, email [email protected].

Review the DPA request process or the Trust & Reliability center before procurement.

Data Protection

Storage controls

Review the privacy policy and request current storage-control documentation.

Encryption in Transit

Connect to API endpoints over HTTPS.

Backups and recovery

Request current backup scope and restoration evidence before relying on recovery targets.

Data Retention

Retention and deletion are described in the privacy policy. Confirm any contractual retention requirements before purchase.

Privacy Policy

Data we process

Account, billing, usage and support processing, plus optional analytics, are described in the privacy policy.

No Data Selling

Your data is never sold to third parties

Right to Deletion

Request account and data deletion at any time

Usage and operational records

API usage and operational records support quota management, security and troubleshooting.

Compliance

Your Data, On Request

Contact [email protected] to request access, export or deletion of personal data under the privacy policy.

Procurement documentation

Request documentation for the controls and recovery requirements your organization needs.

We are not currently SOC 2 or ISO 27001 certified, and we do not claim GDPR certification — no such certification exists, and we have not been independently audited for GDPR compliance. What we can tell you is exactly what we do: the data we collect, how it is encrypted, and how to have it deleted. If your procurement process requires a formal certification, contact us and we will share the security documentation we do have.

API Security Best Practices

Recommended Practices

  • • Store API keys securely (never in source code)
  • • Use environment variables for API keys
  • • Implement proper error handling
  • • Monitor API usage regularly
  • • Rotate API keys periodically
  • • Use HTTPS for all API calls

Security Warnings

  • • Never expose API keys in frontend code
  • • Don't commit API keys to version control
  • • Avoid logging API keys in application logs
  • • Don't share API keys via email or chat
  • • Revoke unused or compromised keys immediately
  • • Use server-side API calls when possible

Security Questions?

Have questions about our security practices? Our team is here to help.