Skip to content

Privacy Policy

Last updated: September 1, 2026

This Privacy Policy explains how Shanghai Keshan Technology Co., Ltd. ("ApiSorcery", "we", "us") collects, uses, and shares your personal information when you use the ApiSorcery service at apisorcery.com (the "Service").

Read together with our Terms of Service and Data Processing Addendum (for business customers acting as data controllers).

1. Information We Collect

1.1 Information You Provide

  • Account information: email, username, password (stored as a salted hash)
  • Profile information you choose to provide
  • Billing information collected by our merchant of record, Paddle (name, billing address, VAT ID; card data is tokenized by Paddle and never received by us)
  • Communications: support tickets, emails you send us

1.2 Information Collected Automatically

  • Usage information: which endpoints you call, generation counts, plan usage
  • Device and client information: OS, CLI version, hostname, device fingerprint (used for seat enforcement)
  • Log data: IP address, timestamps, HTTP method and path, response status, user-agent
  • Cookies and similar technologies (see Section 7)

1.3 Information from Third Parties

  • Payment status, invoice metadata, and subscription lifecycle events from Paddle
  • Aggregated error and performance telemetry from our error monitoring provider

We do not knowingly collect sensitive personal data (health, biometrics, religion, political opinions, etc.) or data from children under 16. Do not submit such data to the Service.

2. How We Use Your Information

We use collected information to:

  • Provide, maintain, and secure the Service (authentication, generation, seat enforcement, rate limiting)
  • Process payments, subscriptions, invoices, and refunds via Paddle
  • Communicate with you about your account, service updates, security, and support
  • Improve service performance, reliability, and features
  • Detect, prevent, and address fraud, abuse, and violations of our Terms
  • Comply with legal obligations and enforce our agreements

For individuals in the EEA / UK / Switzerland, we rely on the following legal bases under GDPR Art. 6(1):

PurposeLegal basis
Providing and maintaining the ServicePerformance of a contract (Art. 6(1)(b))
Payment processing and invoicingPerformance of a contract; legal obligation (Art. 6(1)(b), (c))
Security, fraud prevention, abuse detectionLegitimate interests (Art. 6(1)(f))
Product analytics and improvementsLegitimate interests, or consent where required (Art. 6(1)(f), (a))
Marketing emails to prospectsConsent (Art. 6(1)(a)) — you can opt out at any time
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))

Our legitimate interests are the ability to run and improve a secure and reliable service. We balance these interests against your rights and freedoms.

4. Sharing and Sub-processors

We do not sell or rent your personal information. We share it only:

  • With service providers ("sub-processors") acting on our behalf under written contracts
  • With Paddle.com Market Limited, our merchant of record, to process payments — see Paddle's Privacy Notice
  • To comply with law or valid legal process, or to protect our rights and safety
  • In connection with a business transfer (merger, acquisition, asset sale) — you will be notified and offered choices where required

Current sub-processors (also listed in the DPA):

Sub-processorPurposeRegion
Paddle.com Market LimitedPayment processing, merchant of recordIreland / UK
Cloud hosting providerCompute, storage, networkingMultiple
Email delivery providerTransactional and account emailsEU / US
Error monitoring providerAggregated error / performance telemetryEU / US

5. International Data Transfers

Where personal data is transferred outside the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on Standard Contractual Clauses (Commission Decision 2021/914) and the UK IDTA, together with supplementary technical and organizational measures as needed.

6. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy:

DataRetention
Account dataWhile your account is active + up to 12 months after closure
Billing / invoice records7 years or as required by tax law
Generated code and specs submittedNot stored server-side beyond the request lifecycle for generation
Application logs (with IP)90 days
Security logs (auth, admin actions)12 months
BackupsOverwritten on a rolling basis; expire within 90 days
Support correspondence3 years

You may request deletion of your account at any time (see Section 8).

7. Cookies and Similar Technologies

We use:

  • Essential cookies — required for authentication, session, and language preference
  • Analytics cookies (only after consent, in regions where required) — help us understand usage patterns
  • Preference cookies — remember your UI choices

You can accept or reject non-essential cookies via our cookie banner. Essential cookies cannot be disabled without breaking core functionality.

Paddle sets its own cookies on the checkout overlay for security and fraud prevention. See Paddle's Cookie Policy.

8. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten")
  • Restrict or object to certain processing
  • Portability — receive your data in a structured, machine-readable format
  • Withdraw consent at any time where processing is based on consent
  • Lodge a complaint with a data protection authority (EU / UK)

To exercise any of these rights, email support@apisorcery.com from the address on your account. We respond within 30 days.

8.1 California Residents (CCPA / CPRA)

If you are a California resident, you additionally have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of personal information
  • Correct inaccurate personal information
  • Opt out of the "sale" or "sharing" of personal information

We do not sell your personal information and do not share it for cross-context behavioral advertising. If this ever changes, we will update this Policy and provide a "Do Not Sell or Share My Personal Information" mechanism.

To submit a CCPA request, email support@apisorcery.com with "CCPA Request" in the subject.

9. Security

We implement appropriate technical and organizational measures — encryption in transit (TLS 1.2+) and at rest, access controls with least privilege, MFA for admin systems, network isolation, monitoring, incident response, and regular patching. See DPA § 6 for detail.

No system is perfectly secure; we cannot guarantee absolute security.

10. Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe we have collected such information, contact support@apisorcery.com and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced by email or in-product notification and reflected in the "Last updated" date above.

12. Contact Us

  • Privacy inquiries / data subject requests: support@apisorcery.com
  • Legal entity: Shanghai Keshan Technology Co., Ltd.
  • Registered address: Room A-522, No.188 Yesheng Road, Lingang New Area of China (Shanghai) Pilot Free Trade Zone, P.R.China
  • Merchant of record (payments): Paddle.com Market Limited — Privacy Notice