🔒 Privacy & Compliance

Privacy & Compliance

ProtectMyAPI is designed with privacy-first principles and complies with major data protection regulations worldwide.

🌍

We automatically detect your jurisdiction and apply the appropriate privacy rules.


Supported Regulations

Global Coverage

RegulationRegionKey Rights
GDPREuropean UnionAccess, erasure, portability, consent
UK GDPRUnited KingdomSame as GDPR (post-Brexit)
CCPA/CPRACalifornia, USAKnow, delete, opt-out of sale
LGPDBrazilAccess, correction, deletion, consent
PIPEDACanadaAccess, correction, complaint
POPIASouth AfricaAccess, correction, deletion
PDPASingaporeAccess, correction, withdrawal
APPsAustraliaAccess, correction, anonymity

Your Privacy Rights

Right to Access

Request a copy of all your personal data:

  1. Go to Settings → Privacy
  2. Click Request Data Export
  3. Receive download link via email (within 24 hours)

Export includes:

  • Account information
  • Organizations and memberships
  • Apps and configurations
  • Usage statistics
  • Audit logs

Right to Deletion

Request deletion

Go to Settings → Account → Delete Account

Grace period

Account enters deletion queue (varies by jurisdiction):

  • GDPR: 30 days
  • CCPA: 45 days
  • LGPD: 15 days

Cancel if needed

You can cancel deletion during the grace period

Permanent removal

After grace period, all data is permanently deleted

Right to Portability

Export your data in machine-readable JSON format at any time.

Right to Rectification

Update your personal information in Settings → Profile.


Data We Collect

Account Data

DataPurposeRetention
Email addressAuthentication, notificationsUntil deletion
NameDisplay in dashboardUntil deletion
Password hashAuthenticationUntil deletion
IP addressesSecurity, fraud prevention90 days

Usage Data

DataPurposeRetention
Request countsAnalytics, billingAggregated indefinitely
Error ratesDebugging, monitoring30 days
Feature usageProduct improvementAggregated indefinitely

What We Don’t Collect

  • ❌ Request/response bodies
  • ❌ Your users’ personal data
  • ❌ Location data (beyond IP country)
  • ❌ Device identifiers
  • ❌ Biometric data

Required Consents

When creating an account, you must consent to:

  • Terms of Service - Required for all users
  • Privacy Policy - Required for all users

Optional Consents

These are opt-in and can be changed anytime:

  • Marketing emails - Product updates, tips
  • Analytics - Help us improve the product
  • Third-party sharing - Integration partners

Managing Consents

Go to Settings → Privacy → Manage Consents to view and update your consent preferences.


California Privacy Rights (CCPA/CPRA)

Do Not Sell My Personal Information

ProtectMyAPI does not sell personal information. However, you can still exercise your CCPA rights:

  1. Go to Settings → Privacy
  2. Click Do Not Sell or Share
  3. Confirm your choice

Categories of Personal Information

CategoryExamplesCollected
IdentifiersEmail, name, IP
Commercial informationPurchase history
Internet activityUsage data
GeolocationCountry from IP
Professional informationCompany name
BiometricFingerprints, face
Sensitive dataSSN, health

GDPR Compliance

Processing ActivityLegal Basis
Account managementContract performance
BillingContract performance
Security monitoringLegitimate interest
Product analyticsLegitimate interest (opt-out available)
MarketingConsent (opt-in)

Data Processing Agreements

We have DPAs with all sub-processors. Request a copy at [email protected].

Sub-Processors

ProviderPurposeLocation
HetznerInfrastructureGermany 🇩🇪
CloudflareCDN, securityGlobal (EU processing)
StripePaymentsUSA (SCCs)
ResendEmailUSA (SCCs)
AxiomLogging & analyticsUSA (SCCs)

Data Transfers

For transfers outside the EU/EEA, we rely on:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions where applicable
  • Supplementary measures as required

Data Retention

Retention Periods

Data TypeActive AccountAfter Deletion
Account dataIndefinitePurged
Usage logs30 daysPurged
Audit logs1 yearPurged
Backups7 days rolling90 days max
AnalyticsAggregatedAnonymized

Automatic Cleanup

  • Request logs: Deleted after 30 days
  • Failed login attempts: Deleted after 7 days
  • IP verification tokens: Deleted after 24 hours

Children’s Privacy

ProtectMyAPI is a business-to-business service not intended for children under 16. We do not knowingly collect personal information from children.

If you believe a child has provided us personal information, contact [email protected] for immediate deletion.


Security Measures

We protect your data with:

  • Encryption at rest: AES-256-GCM
  • Encryption in transit: TLS 1.3
  • Access controls: Role-based with MFA
  • Audit logging: All actions tracked
  • Regular backups: Encrypted, tested monthly

See our Security page for full details.


Third-Party Services

Services That Access Your Data

ServiceData AccessedPurpose
StripeEmail, billing infoPayment processing
ResendEmail addressTransactional emails
AxiomError data, logsMonitoring & debugging

Services That Don’t Access Your Data

  • Your API keys are encrypted and never shared
  • Request/response bodies never logged
  • No advertising networks

Essential Cookies (Required)

CookiePurposeDuration
sessionAuthenticationSession
csrfSecuritySession
preferencesUI settings1 year
CookiePurposeDuration
analyticsProduct improvement1 year

We do not use:

  • Advertising cookies
  • Third-party tracking cookies
  • Cross-site tracking

Privacy by Design

Built-In Privacy Features

  • Data minimization: We only collect what’s necessary
  • Purpose limitation: Data used only for stated purposes
  • Storage limitation: Automatic deletion of old data
  • Integrity: Encryption and access controls
  • Confidentiality: Need-to-know access only

Privacy Impact Assessments

We conduct PIAs before:

  • Launching new features
  • Changing data processing
  • Adding new sub-processors

Your Responsibilities

As a ProtectMyAPI user, you are responsible for:

  1. Your end users’ privacy: If your app collects user data through our proxy, you must:

    • Have a privacy policy
    • Obtain necessary consents
    • Respond to user requests
  2. Team member access: Ensure only authorized team members have access to your organization

  3. Secure credentials: Keep your API keys and account credentials secure


Contact Us

Privacy Inquiries

Email: [email protected] Response time: Within 5 business days

Data Protection Officer

For EU/UK inquiries: Email: [email protected]

Supervisory Authority

EU users can lodge complaints with their local Data Protection Authority.


Policy Updates

We may update this policy periodically. Changes will be:

  • Posted on this page
  • Emailed to all users (for material changes)
  • Effective 30 days after posting

Last updated: January 2025