upAPIupAPI
MarketplaceDocsPricing
Sign inGet API key
LEGAL

Privacy Policy

Last updated: September 2, 2026

upAPI is an API marketplace and gateway operated by 14930398 Canada Inc. (“upAPI”, “we”, “us”). This policy explains how we handle personal data when you visit upapi.io, browse the marketplace, or sign in to the platform at app.upapi.io. Because upAPI sits between you and the upstream APIs you call, it also draws the line between the data we control and the data you simply route through us.

On this page

  1. When this policy applies
  2. Personal data we collect
  3. Data you route through the gateway
  4. Upstream and third-party APIs
  5. How we use personal data
  6. Analytics and error monitoring — what is actually recorded
  7. How we disclose personal data
  8. International data transfers
  9. Data retention
  10. Security
  11. Your rights and choices
  12. Deleting your account and your data
  13. Cookies and similar technologies
  14. Children
  15. Changes to this policy
  16. Contact us

1.When this policy applies

This policy applies where upAPI acts as a controller of personal data — where we decide why and how it is processed. That covers visitors to upapi.io, people who contact us, and developers who create and use an upAPI account and the gateway at app.upapi.io (together, you).

It does not govern the personal data you route through the gateway to build your own products. For that data you are the controller and upAPI is your processor — see “Data you route through the gateway” below. This policy also does not apply to upAPI's own staff or contractors.

2.Personal data we collect

When you use our website and platform, we collect:

  • Account and profile data — your name and email when you sign up. If you register through a third-party sign-in provider such as GitHub or Google, we receive basic profile information from them, such as your email, username, and avatar.
  • API credentials — we issue API keys for your organization. A key is shown to you once and stored only in hashed or truncated form so we can identify, meter, and revoke it.
  • Billing data — paid plans run through our subscription and payment providers. We receive limited billing details such as your plan, status, and the last four digits of a card — never full card numbers.
  • Usage and log data — to run and meter the gateway we record technical data about each request, such as the endpoint called, timestamps, response status, latency, request volume, rate-limit counters, your IP address, and device and browser information.
  • Support communications — records of your correspondence with us.
  • Guest accounts — you can try the marketplace without signing up. A guest session still creates a real account and organization on our side, addressed on an internal domain, so keys and usage can be metered. It carries no name or email of yours unless you convert it into a full account.

3.Data you route through the gateway

When you send a request through upAPI, we transmit the parameters you supply to the API that fulfills it and return the response to you. Those parameters and responses may, depending on what you choose to send, contain personal data about your own users.

For that data we act as your processor: we handle it on your instructions, only to deliver the Services, and never for our own purposes. You are responsible for having a lawful basis to send it and for honoring the rights of the people it concerns. If you are an end user of a product built on upAPI and want to exercise your rights, contact the developer who operates that product, since they control the data.

4.Upstream and third-party APIs

upAPI is a gateway in front of many third-party and community-published APIs. When you call a marketplace endpoint, your request is forwarded to the upstream provider that fulfills it, and whatever you include in that request is shared with that provider so it can return a result. Each provider handles data under its own terms and privacy practices, which we don't control — review them before sending sensitive data through an endpoint.

5.How we use personal data

  • Provide, operate, secure, and maintain the gateway and your account.
  • Authenticate you and authorize your API keys.
  • Meter usage, enforce rate limits and plan quotas, and bill paid plans.
  • Respond to your requests and provide support.
  • Monitor and improve performance, investigate errors, and develop new features, including through aggregate analytics.
  • Detect, prevent, and address fraud, abuse, and security incidents.
  • Send you service and administrative messages, which are part of the Services and aren't marketing.
  • With your consent or as otherwise permitted, send you product updates.
  • Comply with legal obligations and enforce our agreements.

Where the GDPR or similar laws apply, we rely on one or more of these legal bases: your consent, performance of a contract with you, our legitimate interests in running and improving the Services, and compliance with a legal obligation.

6.Analytics and error monitoring — what is actually recorded

Rather than describe this in the abstract, here is the configuration that runs on upapi.io and app.upapi.io today. If it changes, this section changes with it.

  • Product analytics — PostHog, self-hosted on our own servers. It runs in memory-only mode: it writes no cookie and no other identifier to your device, so closing the tab ends the session. It records page views and page leaves, automatically captured interactions on the page (clicks and form submissions), and the technical context any web request carries — browser, operating system, screen size and referring page. Your IP address reaches our own infrastructure as part of that request; it is not handed to a third-party analytics vendor.
  • Who those events belong to. Signed out, they are anonymous. Signed in, we attach your internal account identifier — a random database id, never your email address — together with your organization id, the app and its version, and the environment; on billing screens we add your plan, subscription status and entitlement. That is the complete list of what identifies you.
  • Session replay is switched off. We do not record your screen, your keystrokes, or the contents of your forms, in PostHog or anywhere else.
  • Error monitoring — Sentry, self-hosted. When something breaks we capture the error and its stack trace, the route you were on, and the same account and organization identifiers, plus a sampled trace of the request for performance work. Sentry’s “send default personal information” option is off, and replay is not enabled.
  • Subscriptions — RevenueCat. Checkout and subscription state run through RevenueCat, keyed on your organization id. Only coarse context goes with it: subscription status, entitlement, product id and store. No card numbers, receipts or prices are fed back into analytics.
  • Google Analytics — optional, and off until you say yes. It is the only thing on our sites that writes analytics cookies, so it is the only thing behind the cookie banner. Decline and the Google script is never loaded at all — not loaded-and-muted.

Ask us for a copy of your analytics record and we will give you the events tied to your account identifier — that identifier is the only key that links any of it to you.

7.How we disclose personal data

We do not sell your personal data. We disclose it only as described here:

  • Within your organization — if you use upAPI as part of a team, other members and administrators can see account and usage activity associated with it.
  • Service providers (subprocessors) — vendors that process data on our behalf under confidentiality and data-protection terms, including cloud hosting and database providers, transactional email, our subscription and payment providers, error monitoring, product analytics, and any proxy providers you enable.
  • Upstream API providers — the third-party endpoints your requests are routed to, as described above.
  • Business transfers — if we're involved in a merger, acquisition, financing, or sale of assets, personal data may transfer as part of that deal and stays subject to this policy.
  • Legal and safety — where we believe it necessary to comply with law or legal process, enforce our terms, or protect the rights, property, or safety of upAPI, our users, or the public.

8.International data transfers

We and our providers may process personal data in countries other than yours. Where we transfer it across borders — for example out of the EEA or the UK — we put appropriate safeguards in place, such as the European Commission's Standard Contractual Clauses or reliance on an adequacy decision, so your data keeps an equivalent level of protection. Contact us for details.

9.Data retention

We keep personal data only as long as needed for the purposes in this policy, then delete or anonymize it. How long depends on the type of data, why we hold it, and our legal obligations — broadly, account data for the life of your account and request logs for a limited operational window. Email support@upapi.io for specifics.

10.Security

We use technical and organizational measures — including encryption in transit, access controls, hashed API keys, and monitoring — to protect personal data against unauthorized access, loss, or misuse. No system is perfectly secure, and you play a part too: keep your API keys secret and server-side. As our documentation notes, a key should never be exposed in client-side code. If you think a key is compromised, rotate it from the dashboard and tell us.

11.Your rights and choices

Depending on where you live, you may have some or all of the rights below. We may need to verify your identity before acting on a request.

  • Access — ask what personal data we hold about you.
  • Correction — ask us to fix inaccurate or incomplete data.
  • Deletion — erase your account and its data yourself, in one action, from the dashboard. See Deleting your account and your data for exactly what goes and what is legally retained.
  • Restriction and objection — ask us to limit or stop certain processing.
  • Portability — receive a copy of the data you provided in a portable format.
  • Withdraw consent — where we rely on consent, withdraw it at any time without affecting prior processing.
  • Complain — lodge a complaint with your local data-protection authority, though we'd appreciate the chance to help first.

To exercise any of these, email support@upapi.io. If it's data we hold on behalf of a customer, contact that customer directly.

12.Deleting your account and your data

Deletion is self-serve and immediate — you do not have to email anyone and wait. In the dashboard, open your settings, scroll to the Danger zone, choose Delete organization, and type the organization name to confirm. Only the organization owner can do it.

That one action removes, in a single database transaction: the organization and your user account; every membership and pending invitation; every API key; your products, operations and hosted functions; your billing subscription record; and your sessions and sign-in credentials. Files you uploaded are swept from object storage immediately afterwards.

Two things deliberately survive, and we would rather say so than let you discover it. Metered call records — the per-request rows we bill and rate-limit from — are kept as financial records, no longer linked to a live account. And payment records held by our payment provider are retained under their own legal obligations. Everything else is gone.

A guest account and its organization are ordinary records and are deleted by the same path. If you would rather we did it for you, or you want a copy of your data first, email support@upapi.io and we will handle it.

13.Cookies and similar technologies

There is less here than most policies of this kind describe:

  • Strictly necessary — the session and sign-in cookies on app.upapi.io that keep you logged in and protect the forms you submit, and one small cookie that remembers your answer to the banner. These are required for the site to work and are not optional.
  • Product analytics — none. PostHog runs cookieless, in memory only, as described above.
  • Google Analytics — the only non-essential cookies we would ever set (`_ga` and its companions). They appear only if you press Accept on the cookie banner, and never before it.

You can change your mind whenever you like: reopen your cookie choices, or use the Cookie choices link in the footer of every page. Declining leaves the rest of the site working exactly as it did. Most browsers also let you refuse or delete cookies outright.

14.Children

upAPI is a developer tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we'll remove it.

15.Changes to this policy

We may update this policy to reflect changes in law or how we operate. We'll post the new version here and update the date above; where a change is significant we'll make reasonable efforts to highlight it.

16.Contact us

Questions or requests about this policy or your personal data? Email support@upapi.io and we'll be glad to help.

upAPIupAPI

One API key for every API in the catalog. One gateway, one pooled monthly quota, and an MCP server your agents can call.

Product

MarketplaceAll APIsGet the appPricingCompare alternativesDashboard

Developers

DocumentationAPI ReferenceOpenAPI Spec

Company

AboutSecurityPrivacyTermsCookie choicesSupportRefer & EarnPartner Terms

Open source

SDK on npmMCP server on npmSDK on GitHubMCP on GitHub
© 2026 upAPI — one key, every API.one key · one pooled quota · every API