Privacy Policy
Effective date: August 13, 2026.
What we collect
When you create an account we store your email address, a hashed password (or an OAuth identifier from a third-party login provider), and the API keys you generate. When you make API requests we log the endpoint path, the sport the request was for, response status, response time, how the request reached us (direct API or an integration), the timestamp, and the originating API key, used for rate limiting, quota enforcement, and abuse detection.
How we use it
Account data lets us authenticate you and enforce per-key rate limits. Request logs let us bill paid plans accurately and detect abuse patterns. Aggregate, de-identified usage data informs product decisions. We do not sell, rent, or share your data with advertisers.
Retention
Account data is kept while your account is open. The request metadata described above is retained for analytics, billing accuracy, and abuse detection. We do not store IP addresses or user-agent strings in request logs. Billing records are kept for the period required by tax law in our operating jurisdiction.
Sub-processors
We use a small set of third-party services to operate the platform: a cloud hosting provider (compute + database), a payments processor (billing), an email delivery provider (transactional email), and OAuth identity providers (when you sign in with a third-party account). A full sub-processor list is in our Data Processing Addendum.
Your rights
You can request access to your account data, a copy of your API request logs, or deletion of your account. To exercise any of these, email [email protected] and we will handle it. Self-serve export and deletion from the developer dashboard are not available yet.
Contact
Questions about this policy go to [email protected].