Privacy Policy
Last updated: September 2, 2026
1.When this policy applies
This policy applies where upAPI acts as a controller of personal data — where we decide why and how it is processed. That covers visitors to upapi.io, people who contact us, and developers who create and use an upAPI account and the gateway at app.upapi.io (together, you).
It does not govern the personal data you route through the gateway to build your own products. For that data you are the controller and upAPI is your processor — see “Data you route through the gateway” below. This policy also does not apply to upAPI's own staff or contractors.
2.Personal data we collect
When you use our website and platform, we collect:
- Account and profile data — your name and email when you sign up. If you register through a third-party sign-in provider such as GitHub or Google, we receive basic profile information from them, such as your email, username, and avatar.
- API credentials — we issue API keys for your organization. A key is shown to you once and stored only in hashed or truncated form so we can identify, meter, and revoke it.
- Billing data — paid plans run through our subscription and payment providers. We receive limited billing details such as your plan, status, and the last four digits of a card — never full card numbers.
- Usage and log data — to run and meter the gateway we record technical data about each request, such as the endpoint called, timestamps, response status, latency, request volume, rate-limit counters, your IP address, and device and browser information.
- Support communications — records of your correspondence with us.
- Guest accounts — you can try the marketplace without signing up. A guest session still creates a real account and organization on our side, addressed on an internal domain, so keys and usage can be metered. It carries no name or email of yours unless you convert it into a full account.
3.Data you route through the gateway
When you send a request through upAPI, we transmit the parameters you supply to the API that fulfills it and return the response to you. Those parameters and responses may, depending on what you choose to send, contain personal data about your own users.
For that data we act as your processor: we handle it on your instructions, only to deliver the Services, and never for our own purposes. You are responsible for having a lawful basis to send it and for honoring the rights of the people it concerns. If you are an end user of a product built on upAPI and want to exercise your rights, contact the developer who operates that product, since they control the data.
4.Upstream and third-party APIs
upAPI is a gateway in front of many third-party and community-published APIs. When you call a marketplace endpoint, your request is forwarded to the upstream provider that fulfills it, and whatever you include in that request is shared with that provider so it can return a result. Each provider handles data under its own terms and privacy practices, which we don't control — review them before sending sensitive data through an endpoint.
5.How we use personal data
- Provide, operate, secure, and maintain the gateway and your account.
- Authenticate you and authorize your API keys.
- Meter usage, enforce rate limits and plan quotas, and bill paid plans.
- Respond to your requests and provide support.
- Monitor and improve performance, investigate errors, and develop new features, including through aggregate analytics.
- Detect, prevent, and address fraud, abuse, and security incidents.
- Send you service and administrative messages, which are part of the Services and aren't marketing.
- With your consent or as otherwise permitted, send you product updates.
- Comply with legal obligations and enforce our agreements.
Where the GDPR or similar laws apply, we rely on one or more of these legal bases: your consent, performance of a contract with you, our legitimate interests in running and improving the Services, and compliance with a legal obligation.
6.Analytics and error monitoring — what is actually recorded
Rather than describe this in the abstract, here is the configuration that runs on upapi.io and app.upapi.io today. If it changes, this section changes with it.
- Product analytics — PostHog, self-hosted on our own servers. It runs in memory-only mode: it writes no cookie and no other identifier to your device, so closing the tab ends the session. It records page views and page leaves, automatically captured interactions on the page (clicks and form submissions), and the technical context any web request carries — browser, operating system, screen size and referring page. Your IP address reaches our own infrastructure as part of that request; it is not handed to a third-party analytics vendor.
- Who those events belong to. Signed out, they are anonymous. Signed in, we attach your internal account identifier — a random database id, never your email address — together with your organization id, the app and its version, and the environment; on billing screens we add your plan, subscription status and entitlement. That is the complete list of what identifies you.
- Session replay is switched off. We do not record your screen, your keystrokes, or the contents of your forms, in PostHog or anywhere else.
- Error monitoring — Sentry, self-hosted. When something breaks we capture the error and its stack trace, the route you were on, and the same account and organization identifiers, plus a sampled trace of the request for performance work. Sentry’s “send default personal information” option is off, and replay is not enabled.
- Subscriptions — RevenueCat. Checkout and subscription state run through RevenueCat, keyed on your organization id. Only coarse context goes with it: subscription status, entitlement, product id and store. No card numbers, receipts or prices are fed back into analytics.
- Google Analytics — optional, and off until you say yes. It is the only thing on our sites that writes analytics cookies, so it is the only thing behind the cookie banner. Decline and the Google script is never loaded at all — not loaded-and-muted.
Ask us for a copy of your analytics record and we will give you the events tied to your account identifier — that identifier is the only key that links any of it to you.
8.International data transfers
We and our providers may process personal data in countries other than yours. Where we transfer it across borders — for example out of the EEA or the UK — we put appropriate safeguards in place, such as the European Commission's Standard Contractual Clauses or reliance on an adequacy decision, so your data keeps an equivalent level of protection. Contact us for details.
9.Data retention
We keep personal data only as long as needed for the purposes in this policy, then delete or anonymize it. How long depends on the type of data, why we hold it, and our legal obligations — broadly, account data for the life of your account and request logs for a limited operational window. Email support@upapi.io for specifics.
10.Security
We use technical and organizational measures — including encryption in transit, access controls, hashed API keys, and monitoring — to protect personal data against unauthorized access, loss, or misuse. No system is perfectly secure, and you play a part too: keep your API keys secret and server-side. As our documentation notes, a key should never be exposed in client-side code. If you think a key is compromised, rotate it from the dashboard and tell us.
11.Your rights and choices
Depending on where you live, you may have some or all of the rights below. We may need to verify your identity before acting on a request.
- Access — ask what personal data we hold about you.
- Correction — ask us to fix inaccurate or incomplete data.
- Deletion — erase your account and its data yourself, in one action, from the dashboard. See Deleting your account and your data for exactly what goes and what is legally retained.
- Restriction and objection — ask us to limit or stop certain processing.
- Portability — receive a copy of the data you provided in a portable format.
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting prior processing.
- Complain — lodge a complaint with your local data-protection authority, though we'd appreciate the chance to help first.
To exercise any of these, email support@upapi.io. If it's data we hold on behalf of a customer, contact that customer directly.
12.Deleting your account and your data
Deletion is self-serve and immediate — you do not have to email anyone and wait. In the dashboard, open your settings, scroll to the Danger zone, choose Delete organization, and type the organization name to confirm. Only the organization owner can do it.
That one action removes, in a single database transaction: the organization and your user account; every membership and pending invitation; every API key; your products, operations and hosted functions; your billing subscription record; and your sessions and sign-in credentials. Files you uploaded are swept from object storage immediately afterwards.
Two things deliberately survive, and we would rather say so than let you discover it. Metered call records — the per-request rows we bill and rate-limit from — are kept as financial records, no longer linked to a live account. And payment records held by our payment provider are retained under their own legal obligations. Everything else is gone.
A guest account and its organization are ordinary records and are deleted by the same path. If you would rather we did it for you, or you want a copy of your data first, email support@upapi.io and we will handle it.
14.Children
upAPI is a developer tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we'll remove it.
15.Changes to this policy
We may update this policy to reflect changes in law or how we operate. We'll post the new version here and update the date above; where a change is significant we'll make reasonable efforts to highlight it.
16.Contact us
Questions or requests about this policy or your personal data? Email support@upapi.io and we'll be glad to help.