Privacy

Last updated 2026-07-27. This site is readable without an account and sets no tracking cookies. If you create a free account to use the API, this is everything we store.

What we store, and why

What Why How long
Your e-mail address It is your account. Sign-in is a link we e-mail you, so we cannot have an account without it. Until you delete your account.
Your organization and its members API keys, quota and usage belong to an organization, not to a person. Until the organization is deleted.
API keys To authenticate your calls. We store a hash of the secret, never the secret itself. Until you revoke the key or delete the organization.
Usage events Which endpoint or tool was called, when, with which key, the status and the duration — so we can run the service, prevent abuse and plan capacity. 90 days, then deleted. Daily totals per organization are kept for 24 months.
Last sign-in time To see whether an account is still in use. Until you delete your account.

What we deliberately do not store

  • The arguments you send to our API or MCP tools
  • The responses we send back
  • Your IP address (we do not store it in our usage log)
  • Tracking cookies, advertising pixels or third-party analytics

This matters most for the API: your queries can reveal which models your systems depend on. We record that an endpoint was called, never what you asked it.

Legal basis (GDPR)

Your e-mail address and organization are processed to perform the agreement you enter into by creating an account. Usage events are processed on the basis of legitimate interest — operating the service, preventing abuse and planning capacity — and are minimised and deleted on the schedule above.

Who else sees it

  • Resend delivers our sign-in links and invitation e-mails, and therefore processes your e-mail address.
  • Hetzner hosts the servers and the database, in Germany.

We do not sell data, and no provider pays to be listed or described a particular way — see the methodology.

Your rights

You can see everything we record about your usage on the usage page in your dashboard. You can delete your account yourself from the account page: that removes your account and every organization where you are the only member, including its API keys, which stop working immediately. Usage events are detached from your account rather than deleted, because aggregate call volume is no longer personal data once it is not linked to a person.

For access, correction, export or any other request, or to complain, contact us via the about page. You also have the right to lodge a complaint with your national data protection authority.

Changes

If this statement changes in a way that affects what we collect, we will say so on this page and update the date at the top.

Create a free account