Legal

Privacy Policy

Effective date: May 18, 2026 · Last updated: May 18, 2026

Your privacy matters. This policy explains what data APIlot collects, why we collect it, how it is used, and the rights you have over it — including those granted under the GDPR (EU/EEA), UK GDPR, and the CCPA (California).

1. Who We Are

APIlot ("we", "us", "our") operates the platform available at useapilot.com. We are the data controller for personal data collected through the Service.

Contact: [email protected]

2. Data We Collect

We collect the following categories of personal data:

Account dataName, email address, profile picture (from OAuth provider)
Authentication dataOAuth tokens from Google or GitHub (never your password)
Usage dataPages visited, features used, integration prompts submitted, timestamps
Integration contentPrompts you enter, API names you connect, generated code (stored to enable re-run and history)
API credentialsThird-party API keys and secrets you provide (encrypted at rest using AES-256)
Billing dataSubscription tier, billing status (payment card details are processed by Polar — we never see raw card numbers)
Technical dataIP address, browser type, device type, referrer URL, error logs
CookiesSession cookie (required), preference cookies (optional — see Section 7)

3. How We Use Your Data

We use your data to:

  • Provide the Service — authenticate you, process prompts, generate and deploy integrations (legal basis: contract performance)
  • Process payments — manage subscriptions and billing via Polar (legal basis: contract performance)
  • Improve the Service — analyse aggregate usage patterns to improve features (legal basis: legitimate interests)
  • Security and fraud prevention — detect abuse, rate-limit, and protect infrastructure (legal basis: legitimate interests)
  • Communications — send transactional emails (password reset, billing receipts) and, with your consent, product updates (legal basis: consent / contract)
  • Legal compliance — comply with applicable laws and respond to lawful requests (legal basis: legal obligation)

We do not sell your personal data, use it for ad targeting, or share it with data brokers.

4. Third-Party Services We Use

PolarSubscription billing and payment processingpolar.sh/privacy
Google / GitHub OAuthAuthentication (optional sign-in method)Respective privacy policies apply
PostHogOptional analytics — only loaded with your consent (no ad tracking, no cross-site data)posthog.com/privacy
Fly.ioCloud infrastructure and hostingfly.io/legal/privacy-policy
Neon / PostgreSQLDatabase hosting (encrypted at rest)neon.tech/privacy
Vercel / Next.jsFrontend rendering and CDNvercel.com/legal/privacy-policy
Resend (or similar)Transactional email deliveryApplicable provider policy

We only share data with third parties to the extent necessary to deliver the Service. All processors are required to handle data in accordance with applicable law.

5. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

  • Account data: retained until account deletion + 30-day grace period
  • Integration history: retained for the life of your account; you can delete individual integrations at any time
  • API credentials: deleted immediately upon your request or account deletion
  • Billing records: retained for 7 years to comply with financial regulations
  • Server logs: retained for 90 days

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

AccessRequest a copy of the personal data we hold about you
RectificationAsk us to correct inaccurate or incomplete data
Erasure (“right to be forgotten”)Request deletion of your personal data (subject to legal retention obligations)
PortabilityReceive your data in a structured, machine-readable format
RestrictionAsk us to restrict processing of your data in certain circumstances
ObjectionObject to processing based on legitimate interests
Withdraw consentWithdraw marketing consent at any time without affecting other processing
CCPA opt-outCalifornia residents may opt out of any sale of personal information (we do not sell data)

To exercise any right, email [email protected]. We will respond within 30 days (GDPR) or 45 days (CCPA). If you are in the EU/EEA, you also have the right to lodge a complaint with your local supervisory authority.

7. Cookies

When you first visit APIlot, a cookie consent banner asks you to accept or decline optional cookies. Your choice is stored in your browser and respected on every subsequent visit.

Session cookieRequired — cannot be declinedKeeps you signed in during your session
CSRF tokenRequired — cannot be declinedProtects against cross-site request forgery
cookie_consentRequired — cannot be declinedStores your cookie preference so we don't ask again
PostHog analyticsOptional — only set if you click "Accept all cookies"Aggregate, anonymised usage data (pages visited, features used) — no ad tracking, no cross-site data

We do not use third-party advertising cookies, tracking pixels, or browser fingerprinting. Required cookies are necessary for the Service to function and cannot be declined. You can block all cookies in your browser settings, but this will prevent you from signing in.

Update your preferences: Click the button below to reset your cookie choice. The consent banner will reappear so you can change your selection.

8. Data Security

We implement industry-standard security measures:

  • All data in transit is encrypted with TLS 1.2+
  • API credentials and secrets are encrypted at rest with AES-256
  • Access to production systems is restricted to authorised personnel
  • We conduct regular security reviews of our infrastructure

No system is 100% secure. If you discover a security vulnerability, please report it responsibly to [email protected].

9. International Data Transfers

APIlot is hosted on infrastructure primarily in the United States. If you are located in the EU/EEA or UK, your data may be transferred to and processed in the US. Where required, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the transfer mechanism.

10. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a prominent notice on the Service at least 14 days before the changes take effect. Your continued use after the effective date constitutes acceptance of the updated policy.

12. Contact and Data Controller

For privacy questions, data requests, or complaints:

APIlot
Email: [email protected]
Website: useapilot.com