APIDirectory is a registry of public APIs. Almost everything on it is about APIs, not people. This page covers the personal data we do handle: who gives it to us, why we keep it, who processes it for us, and how to get it removed.
What we collect, and why
| DATA | WHEN | WHY |
|---|---|---|
| Email address | You submit an API, claim an entry, buy placement, subscribe to the newsletter, take a dataset key, or buy a gateway key | To verify ownership, deliver what you bought (keys, manage links, receipts), and send the mail you asked for |
| Claim records | You claim an entry | The verified email and method (domain email or DNS record) are the owner identity — there are no passwords |
| Stripe customer and subscription ids | You buy through Stripe | To match a payment to what it bought, bill metered usage, and detect lapsed subscriptions. Card numbers never reach us; Stripe holds them |
| Gateway usage counts | You call an API through the gateway | Per key, per day: request and unit counts, for metering and plan limits. Request bodies and responses are proxied, not stored |
| Sellers' credentials | You run a storefront or sell on the gateway | A Stripe restricted key and, if needed, an upstream API credential — stored encrypted (AES-GCM), decrypted only inside the gateway and the billing task, removable from the console at any time |
| Page views and outbound clicks | You browse | Counted per entry, not per visitor, so owners can see how their listing performs. No advertising trackers, no third-party analytics |
| Assistant conversations | You use the setup assistant in the owner console | Sent to Anthropic to generate replies. Stripe keys are scrubbed before sending and never reach the model; we don't retain transcripts |
Cookies
One signed session cookie, set only after you open a manage link, keeps you signed in to the owner console for 30 days. There are no advertising or analytics cookies.
Who processes data for us
Google Cloud (hosting, in the United States), Supabase (the database), Cloudflare (the gateway, storefront hosting and custom-domain certificates), Stripe (payments), thin.host (transactional email), and Anthropic (the setup assistant). Each receives only what its job needs. We don't sell personal data and don't share it with anyone else, except where the law requires.
Storefront buyers
When you buy from a storefront, the seller is the merchant: your payment and customer record are on the seller's Stripe account and covered by the seller's own privacy terms. We hold your email, your key's hash and usage counts to operate the key, and we email you about it in the seller's name.
Retention
Claim records and purchase records stay for as long as the entry or subscription exists and for our accounting obligations after that. Newsletter subscriptions end when you unsubscribe — the row is deleted. Gateway keys and their usage stay while the key is active and for the billing period after deactivation. Encrypted credentials are deleted when a seller removes them or the storefront is deleted.
Your rights
You can ask what we hold about you, have it corrected, or have it deleted, subject to records we must keep for tax and accounting. Email registry@apidirectory.com from the address in question. Index entries about an API are not personal data and are handled through the claim process instead.
Changes
The effective date above changes when this policy does. See also the terms of service.