INDEX / PRIVACY POLICY
EFFECTIVE 12 SEPTEMBER 2026
LEGAL

Privacy Policy

APIDirectory is a registry of public APIs. Almost everything on it is about APIs, not people. This page covers the personal data we do handle: who gives it to us, why we keep it, who processes it for us, and how to get it removed.

What we collect, and why

DATAWHENWHY
Email addressYou submit an API, claim an entry, buy placement, subscribe to the newsletter, take a dataset key, or buy a gateway keyTo verify ownership, deliver what you bought (keys, manage links, receipts), and send the mail you asked for
Claim recordsYou claim an entryThe verified email and method (domain email or DNS record) are the owner identity — there are no passwords
Stripe customer and subscription idsYou buy through StripeTo match a payment to what it bought, bill metered usage, and detect lapsed subscriptions. Card numbers never reach us; Stripe holds them
Gateway usage countsYou call an API through the gatewayPer key, per day: request and unit counts, for metering and plan limits. Request bodies and responses are proxied, not stored
Sellers' credentialsYou run a storefront or sell on the gatewayA Stripe restricted key and, if needed, an upstream API credential — stored encrypted (AES-GCM), decrypted only inside the gateway and the billing task, removable from the console at any time
Page views and outbound clicksYou browseCounted per entry, not per visitor, so owners can see how their listing performs. No advertising trackers, no third-party analytics
Assistant conversationsYou use the setup assistant in the owner consoleSent to Anthropic to generate replies. Stripe keys are scrubbed before sending and never reach the model; we don't retain transcripts

Cookies

One signed session cookie, set only after you open a manage link, keeps you signed in to the owner console for 30 days. There are no advertising or analytics cookies.

Who processes data for us

Google Cloud (hosting, in the United States), Supabase (the database), Cloudflare (the gateway, storefront hosting and custom-domain certificates), Stripe (payments), thin.host (transactional email), and Anthropic (the setup assistant). Each receives only what its job needs. We don't sell personal data and don't share it with anyone else, except where the law requires.

Storefront buyers

When you buy from a storefront, the seller is the merchant: your payment and customer record are on the seller's Stripe account and covered by the seller's own privacy terms. We hold your email, your key's hash and usage counts to operate the key, and we email you about it in the seller's name.

Retention

Claim records and purchase records stay for as long as the entry or subscription exists and for our accounting obligations after that. Newsletter subscriptions end when you unsubscribe — the row is deleted. Gateway keys and their usage stay while the key is active and for the billing period after deactivation. Encrypted credentials are deleted when a seller removes them or the storefront is deleted.

Your rights

You can ask what we hold about you, have it corrected, or have it deleted, subject to records we must keep for tax and accounting. Email registry@apidirectory.com from the address in question. Index entries about an API are not personal data and are handled through the claim process instead.

Changes

The effective date above changes when this policy does. See also the terms of service.