Privacy Policy

What we hold, what we deliberately do not, and what you can ask us to do about it. Last updated 8 September 2026.

The short version

We are a licensing gateway, not a proxy. Your API traffic does not pass through us. We authorise a key and record that it was used — we never see what it was used for, because your request bodies never reach us.

We hold what is needed to run an account: who you are, what you pay, which keys you have, and a log of gateway calls so your usage page works and so you can debug a refusal.

What we collect

Account information

Your name, email address, phone number, country, and the company details you enter at signup. A hashed password — never the password itself. If you enable two-factor authentication, the secret needed to verify your codes.

Billing information

Your plan, subscription state, invoices and their amounts. Where you pay by card, an authorisation reference from the payment processor that lets us charge the renewal. We never see or store your card number — that is held by the processor, and we could not produce it if asked.

Where you pay in cryptocurrency, the payment reference, the amount quoted, and the transaction hash once one is known. A public blockchain address is public by nature; we do not link it to anything beyond the payment.

Keys and domains

The keys issued to you, the domain each is locked to, the verification records proving control of that domain, and the settings on each key — scopes, IP allowlists, environments, rate limits.

Gateway usage

For each call to the gateway: which key, the endpoint name you supplied, the outcome, the refusal reason if there was one, the calling IP address, and the time.

Security scans

Where you run a security scan on one of your verified domains, we record the results — which DNS, email and web-security checks passed or failed, and the evidence behind each. This is information about your own domain’s public configuration, gathered by reading public DNS and making ordinary requests to your own site. We store the latest scan per domain so you can see it again without re-running it.

Support and community

Messages you send us, and anything you post publicly in the community. Community posts are public by design and are shown under a display name rather than your email address.

What we do not collect

  • Your API request or response bodies. We are not in that path. The verify call tells us a key was used; it does not carry your payload.
  • Your end users’ personal data. We have no relationship with the people using your application and no record of them.
  • Card numbers. Handled entirely by the payment processor.
  • Cross-site tracking. We do not run advertising trackers, we do not sell data, and we do not build profiles across other websites.

The first of these is worth restating because it is the one that matters most: it is a property of how the system is built, not a policy we have adopted. We could not disclose your API payloads under any circumstance, because we have never held them.

Data we handle for you

Two features process data on your behalf rather than for our own purposes, and the distinction matters in law: for these, you are the controller and we are your processor. You decide what is collected and why; we act on your instructions to provide the feature.

  • Visitor insights. Where you enable it and place the snippet on your own site, we record page views and coarse, non-identifying signals about your visitors so your dashboard can show you your own traffic. We do not use it for our own purposes and do not combine it across customers.
  • Security scans. The results of scanning your own verified domains, described above.

Because these run in your name, you are responsible for having a lawful basis to collect what you collect and for telling your own users where the law requires. If you need a data processing agreement to use these features, contact us and we will put one in place.

Why we hold it

Account and billing data: to provide the service you have bought and to meet accounting obligations.

Keys, domains and verification records: because they are the service — without them there is nothing to authorise.

Usage logs: so your dashboard can show what your keys are doing, so you can diagnose a refusal, so we can enforce plan limits, and so abuse can be identified.

IP addresses in usage logs: to make IP allowlisting work, to identify abuse, and so that a refusal can be traced to a caller when you are debugging.

Our legal bases

Where data-protection law (such as the UK/EU GDPR) asks us to name a lawful basis for processing, these are the ones we rely on:

  • Performing our contract with you — running your account, issuing and authorising keys, taking payment, and showing you your usage. Without this data there is no service to provide.
  • Our legitimate interests — keeping the service secure, preventing abuse and fraud, and diagnosing faults — weighed so as not to override your rights.
  • Complying with a legal obligation — keeping billing and tax records for as long as the law requires.
  • Your consent — where we ever ask for it for something optional. You can withdraw it at any time, and we do not rely on it for anything the service needs to function.

Cookies and storage

We set a session cookie when you sign in. It identifies your session and nothing else, it is HttpOnly, and it is marked Secure in production. We also use a cookie to hold the cross-site request forgery token that protects forms you submit. Both are strictly necessary to run the site, which is why they need no consent banner.

Your browser also keeps a few small preferences in local storage — such as which billing period you last looked at — so the interface remembers them between visits. These never leave your browser and are never sent to us.

We set no advertising or analytics cookies and run no third-party trackers, so there is genuinely nothing to consent to. Our Cookie & Storage Notice lists everything in full.

Bot protection

Where you enable bot protection on a key, the check looks at the request headers of visitors to your site and asks the browser to run a small script and return an answer. What it produces is one bit of information: this looked like a browser, or it did not.

It does not fingerprint visitors across sites, does not persist anything on the visitor’s device beyond the life of a single check, and does not build a profile. The record we keep is the same usage row any gateway call produces.

Because the check runs on your visitors, you should mention it in your own privacy notice.

Who else sees it

We use a small number of providers to run the service:

  • Payment processing — to take card payments. They receive your name, email and card details directly; we receive a reference.
  • Email delivery — to send verification codes, receipts and renewal notices. They receive your email address and the message.
  • Hosting — the infrastructure the application and database run on.
  • Blockchain explorers — where you pay in crypto, we query public block explorers to see whether a transfer has arrived. Only the public address and amount are involved.

We do not sell your data and we do not share it for advertising. We disclose it where we are legally required to, and where we can lawfully tell you that we have, we will.

Where it is processed

BuildAPI runs on infrastructure in the region its operator has chosen, and the providers named above may process data in the countries where they operate. If you are in a country with data-transfer rules — such as the UK or the EU — that can mean your data is processed outside it.

Where that happens, we rely on the appropriate safeguards for the provider in question, such as the standard contractual clauses. You can ask us which providers are involved and where.

How long we keep it

Account and billing records are kept while your account is open and afterwards for as long as accounting and tax rules require.

Gateway usage logs are kept on a retention period the operator of this installation configures. Older rows are deleted automatically once that period passes.

When you close your account, keys are revoked and your personal data is deleted on the schedule above. Community posts are anonymised rather than deleted — the answer you gave two years ago stays useful to the next person, without your name on it.

Your rights

Depending on where you live you may have the right to:

  • ask what we hold about you and get a copy;
  • have inaccurate details corrected — most are editable in your dashboard;
  • ask us to delete your data, subject to records we must keep;
  • object to processing, or ask us to restrict it;
  • take your data elsewhere;
  • complain to your data protection authority.

Your dashboard exports your own data without asking us. For anything else, write to us at the address below and we will answer within a month. Exercising any of these rights costs you nothing and we will not treat you differently for it.

If you are in California, the CCPA/CPRA gives you the right to know what personal information we collect and why, to get a copy, to have it corrected or deleted, and to opt out of its “sale” or “sharing”. There is nothing to opt out of: we do not sell or share your personal information, and we have not in the preceding twelve months. The categories we collect, and why, are the ones listed at the top of this page.

How it is protected

Passwords are hashed, never stored in a form we could read. API keys are stored hashed as well as issued, so a database copy does not hand over working credentials.

Traffic is served over TLS. Administrative access is limited to people who need it. Sensitive actions are written to an audit log.

No system is perfectly secure and anybody who tells you otherwise is selling something. If we discover a breach affecting your data we will tell you, and we will tell you what we know rather than waiting until we know everything.

Children

This is a developer tool and is not intended for children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, tell us and we will remove it.

Changes

If we change this policy materially we will email account holders before it takes effect. The date at the top is when it last changed.

Contact

BuildApi
2999 Brown Street
Pleasanton, CA 94566
support@buildapi.app

See also our Terms of Service.