Legal
Privacy Policy
Last updated: April 11, 2026
1. Information We Collect
When you create a YepAPI account, we collect your email address and name (provided via Google or GitHub OAuth). We also collect:
- API usage data (endpoints called, timestamps, response codes)
- Billing information processed by our payment provider (Stripe)
- IP addresses and basic device information from server logs
2. How We Use Your Information
We use your information to:
- Provide and maintain the YepAPI service
- Process billing and track API usage
- Send transactional emails (billing receipts, account alerts)
- Improve service reliability and detect abuse
- Respond to support requests
We do not sell, rent, or share your personal information with third parties for marketing purposes.
3. API Request Data
YepAPI acts as a proxy — your API requests pass through our infrastructure to reach third-party providers. We do not store the contents of your API request payloads or response bodies beyond what is necessary for real-time routing, billing, and short-term debugging logs (retained for up to 30 days).
Third-party API providers may have their own data handling and retention policies. We recommend reviewing their privacy policies for details on how they process data.
4. Cookies & Analytics
We use essential cookies to maintain your session and authentication state. We may use privacy-friendly analytics to understand how our site is used. We do not use third-party advertising trackers.
5. Data Security
We implement industry-standard security measures to protect your data, including:
- HTTPS encryption for all data in transit
- API keys hashed at rest
- Access controls and audit logging on internal systems
While we take reasonable precautions, no system is 100% secure. We cannot guarantee absolute security of your data.
6. Third-Party Services
We use the following third-party services to operate YepAPI:
- Stripe — payment processing
- Google & GitHub OAuth — authentication
- Third-party API providers — to fulfill API requests made through our service
Each of these services has their own privacy policies governing how they handle your data.
7. Data Retention
We retain your account information for as long as your account is active. If you delete your account, we will remove your personal data within 30 days. Billing records may be retained longer as required by law.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Export your usage data
To exercise any of these rights, email us at [email protected].
9. Changes to This Policy
We may update this privacy policy from time to time. We will notify registered users of material changes via email. Continued use of the service after changes constitutes acceptance.
10. Contact
Questions about privacy? Email us at [email protected].