Privacy Policy

Last updated: October 7, 2026 · version 2026-10-07

This policy is for API providers (“producers”) and visitors to this website. If you sign in to an API or developer portal that a provider runs on APIblaze, read the Consumer Privacy Notice instead.

1. Who we are and what this covers

APIblaze LLC (“APIblaze”, “we”, “us”), Birmingham, Michigan, United States, operates apiblaze.com, the dashboard, the command-line tools, and the gateway, identity, MCP and AI services described in our Terms of Service. This policy explains what we collect about you as a producer or website visitor, why, who processes it, and for how long.

Two roles. For your own account data we are the controller. For personal data about your End Users that flows through the Service, you are the controller and we are your processor, except for the limited platform-security processing described in the Consumer Privacy Notice, where we are an independent controller. Section 6 of the Terms is our data-processing agreement.

2. What we collect

From your identity provider when you sign in (GitHub for the dashboard and CLI): your name, email address, avatar, provider account id and handle. We do not receive your password.

What you give us: team name, contact and support email, optional phone and company details, the terms and privacy links you set for your End Users, custom domains, API specifications, configuration, transformation rules and the secrets you store with us, portal branding, recipes, support reports, and the email addresses of people you invite. A support report can carry a screenshot you choose to attach: it is taken of the page you are on, in your browser, and fields we recognise as keys, tokens or personal data are blacked out before the picture is made, so those pixels never exist. You can black out anything else yourself before sending, and only that edited picture is uploaded.

From GitHub repositories you connect (Section 4): repository names, the file listing of a repository you open, candidate specification files we read to find your OpenAPI document, and the document you choose.

Payment: Stripe holds your card details and billing address; we store only your Stripe customer id, your credit balance and ledger, and the amounts and dates of your top-ups.

Automatically, when you use the dashboard, CLI or API: session records, device-authorization sessions for the CLI (handle, email, codes, kept one day), the actions you take (an audit log with your user id, the operation and the objects touched), and the network address and user agent of your requests in our infrastructure provider’s application logs for about seven days. Abuse detection at proxy creation stores a one-way hash of the network address for two days, never the address itself.

About your End Users, on your behalf: see the Consumer Privacy Notice and Section 5 below.

Website visitors: standard server logs at our hosting provider, and, only if you accept analytics cookies, Google Analytics usage data (Section 8).

3. How we use it

  • To provide the Service: run your proxies, portals, MCP servers and chat widgets; sign you and your End Users in; apply your access rules; bill usage against your credits.
  • To keep the Service secure and prevent abuse: rate limiting, abuse detection across the platform, alerts to our operators, and enforcement of the Terms.
  • To show you what your API is doing: request logs, analytics, traffic samples you enable, audit logs.
  • To support you and communicate about the Service: support replies, invitations and access-request emails you trigger, onboarding and product-update email (Section 9), notices required by the Terms.
  • To improve the Service using aggregated, de-identified usage patterns.
  • To comply with law and to establish, exercise or defend legal claims.

Where the GDPR or a similar law applies, our legal bases are performance of the contract with you, our legitimate interests in running and protecting the Service and in telling you about it, consent where we ask for it (analytics cookies), and legal obligation.

4. GitHub access

Producers sign in with GitHub through the APIblaze GitHub App. The App asks for your public profile and email. Repository import needs the App installed on the repositories you choose, with read access to repository metadata and contents. When you open a repository in the import flow we list its files and read a limited number of candidate files to find an OpenAPI document; we keep only the document you select. We do not read repositories you have not opened, and we do not write to your repositories. The token GitHub issues us is stored encrypted for at most 30 days after your last sign-in and is used only for these operations. You can revoke the App from your GitHub settings at any time.

5. Logs, analytics and traffic capture

Request logs. For every request through a proxy we record who called (a consumer id or key id and, if your application sends it, an end-user id), the route, method, status, timing, cost and environment. By default header values, query strings and bodies are not recorded, only header names and the shape of the body. You can turn on capture of headers, query parameters, bodies and selected token claims per proxy, in any environment, in which case those values are recorded for your review. Credentials, cookies, network addresses, user agents, email headers and secret-shaped values are always removed before storage. Logs are kept 91 days and are visible to your team, to operators, and, for their own tenant only and without your origin details, to your End-User organizations.

CLI commands. When a request comes from our command-line tool we also record which command made it, its version, and an identifier for that run, so we can tell a failing request from a broken release and help you debug it. The command is a fixed label from the tool’s own list, such as key create — never the command line you typed, so anything you pass as an argument, including a secret, is not sent and not stored. Commands that make no request to us are not recorded at all.

Analytics. Per request we keep counts, latency, status, cost, the consumer id and the country of the caller in an analytics dataset for about 90 days. No network addresses.

Traffic capture. In development environments only, and only while it is enabled for a project (it is on by default for the dev environment and can be turned off per project; it never runs in test or production environments), we store samples of full requests and responses, including bodies and query strings, so you can inspect and replay them and draft your specification from them. Credentials, cookies, network addresses and user agents are removed; other content is stored as sent, so personal data your End Users put in requests may be included. Samples are kept 31 days or until you delete them, and are sent to the AI model providers only if you run traffic review on them.

Identities observed from traffic. When an End User calls a proxy with a token or key we record their identity (subject, email if the token carries one), first and last seen and a count, per tenant, for 90 days after last activity, so that you can see who is calling and pre-approve or block them.

6. AI features

The chat widget, MCP tooling, specification drafting, model and template generation and traffic review send content to language-model providers through OpenRouter: End-User chat messages, the responses your API returns to the chat, the development traffic you submit for review, and your API structure. We request routing that excludes providers who retain or train on inputs, and we do not send End-User identities, network addresses or credentials in prompts. If you bring your own model key, requests go to that provider under your agreement with them, and we do not store the key.

7. Security

  • All traffic to and from the Service uses TLS. Data is encrypted at rest by our infrastructure providers.
  • API keys are stored as one-way hashes. A key you give an expiry date is additionally held in full, in encrypted storage, until it expires, so that it can be shown again in the dashboard or the portal; a key with no expiry is shown once and only its hash is kept, and revoking a key removes the stored copy. Identity-provider tokens, OAuth client secrets, provider secrets and the secrets in your transformation rules are additionally encrypted at the application level with keys we hold and rotate. Operators can decrypt secrets when operating the Service; the dashboard can reveal an OAuth client secret to your team members with the right role.
  • Each producer’s data is isolated by team and tenant identifiers enforced in every query, and each team has its own authorization store.
  • Access to production systems is limited to operators with a named account and is recorded in our audit log.
  • Report vulnerabilities to security@apiblaze.com. We notify affected producers without undue delay, and within 72 hours of confirming a breach that affects their End-User data.

No system is perfectly secure, and we do not claim otherwise.

8. Cookies and similar technologies

Dashboard (necessary). A session cookie (__Secure-next-auth.session-token, valid 30 days, renewed on use) keeps you signed in, and short-lived state cookies protect the sign-in flow. These are required for the dashboard to work and need no consent.

Website (analytics, with consent). apiblaze.com loads Google Analytics 4 and PostHog only if you accept in the cookie banner. Until you accept, neither script loads and neither sets a cookie. Your choice is stored in your browser (abz_consent) and can be changed at any time through “Cookie settings” in the footer. Google Analytics sets the _ga and _ga_* cookies (up to two years) and reports pseudonymous usage to Google. PostHog sets its own identifier cookie, records which pages and elements you interact with, and may record a replay of your visit to this website. Both providers may process the data in the United States.

Website (attribution). If you arrive from an advertisement or a campaign link, we store the campaign identifiers, the page you landed on and the referring site in a first-party cookie (abz_attr, 90 days) so that a later sign-up can be attributed to the campaign that brought you. It is not set if you decline analytics, it is never shared with an advertising network from your browser, and it holds no name or email address.

Dashboard (product analytics). Once you are signed in, the dashboard uses PostHog to record pages viewed, clicks and session replays, tied to your account identifier, so we can see where the product is confusing. Text and form inputs are masked in these recordings, so API keys and customer data are not captured. This is not used for advertising.

Portals and proxies we run for you set only the cookies needed for your End Users’ sign-in, as described in the Consumer Privacy Notice.

9. Email

We send transactional email through Amazon SES and Resend: invitations and access requests you trigger, verification codes, security and billing notices, and support replies. Through Loops we send a short onboarding sequence when you create an account and occasional product updates; every such email has an unsubscribe link, and unsubscribing does not affect transactional email. We do not sell or rent your address and do not run advertising campaigns to it.

10. Who we share it with

We do not sell personal data. We share it with:

  • Your team members, according to their roles, and your End Users’ organizations, for their own tenant only.
  • Your End Users: the team name and the terms and privacy links you set are shown on the sign-in screen.
  • Service providers (subprocessors) listed below, who process data on our instructions.
  • Authorities and others when the law requires it, to enforce the Terms, or to protect the rights, safety or property of APIblaze, our customers or the public.
  • A successor in a merger, acquisition or sale of the Service, who will be bound by this policy.

Subprocessors as of the date above. We update this table at least 30 days before adding one, except where a change is urgently needed for security or to keep the Service running, in which case we update it as soon as we can; you can object under Section 6 of the Terms.

ProviderPurposeData involved
Cloudflare, Inc. (US, global network)Runs the Service: compute, key-value and object storage, durable objects, queues, analytics datasets, rate limiting, bot challenges, custom hostnames, DNS and TLSAll Service data, including request logs, traffic samples, wallet and usage state, and queued log and ledger rows
Neon, Inc. (US)Primary database for accounts, teams, projects, configuration, End-User identities and audit logsAccount data, End-User Records, audit logs
OpenFGA (self-hosted on Neon)Authorization engine for permissions and group rulesUser identifiers, group and permission relations
Stripe, Inc. (US)Payments, invoices, tax calculation where enabledName, email, billing address, payment details (held by Stripe), Stripe customer id
Vercel, Inc. (US)Hosting of the dashboard and this websiteDashboard session data in transit; website visits
GitHub, Inc. (US)Sign-in for producers, repository import, our managed sign-in application for End UsersGitHub profile, repository listing and files you import
OpenRouter, Inc. (US) and the model providers it routes to (Anthropic, OpenAI, Google, DeepSeek and others)AI chat, MCP tooling, specification drafting, traffic review. We request routing that excludes providers who retain or train on inputsChat content, API responses returned to the chat, captured development traffic you submit for review, API structure
Amazon Web Services, Inc. (SES, US)Transactional email: team invitations, alerts, support repliesRecipient email address and message content
Resend, Inc. (US)Transactional email: access requests, mailbox verification codes, registration approvalsRecipient email address and message content
Loops, Inc. (US)Onboarding and product-update email to producersEmail address, first name, account identifier
Google LLC (Web Risk API)Checks proxy target URLs against threat lists at creationTarget URL only
Google LLC (Google Analytics)Website usage statistics, only with your consent (see Cookies)Pseudonymous visitor identifier, pages viewed
PostHog, Inc. (US)Product analytics for this website (only with your consent) and for the dashboard: pages viewed, clicks, session replay, and which campaign brought an accountPseudonymous visitor identifier, pages and elements interacted with, masked session recordings; in the dashboard, your account identifier
Identity providers you connect (Google, Microsoft, Facebook, Auth0, other OpenID Connect issuers)Sign-in for your End Users, at your configurationEnd-User profile as the provider returns it
GitHub, Inc. (Issues)Each support report is filed as an issue in our private tracker so we can work it, and replies there are relayed to youReport text, the surface and frequency, your console errors and recent failing calls, and a one-way fingerprint of your address — never the address itself, and never an attached screenshot
Linear, Inc. (US)The contact form on this website creates a ticketName, email, company and the message you write
Google LLC (Forms)The appeal form linked from a suspended accountWhatever you write in the appeal
jsDelivr and the Tailwind CDNServe two scripts used by the hosted sign-in pages and the developer portalYour End User's network address and browser, as with any script a browser fetches

Alerts and operational notices to our operators go to an internal Slack or Discord channel. They carry identifiers and counts: team, billing-account, project and user identifiers, target hostnames, request and error counts, money figures, support-report identifiers and links, and, while we are in beta, a note when a new account is created. They also carry the text an operator types when declaring an incident. They never carry email addresses, display names, network addresses, request or response content, end-user identities, or an attached screenshot. Separately, you can give us a webhook of your own in Team settings, and we will post your billing and money events to it; that address is stored as a secret and used for nothing else.

11. How long we keep it

DataRetention
Account, team, project and configuration dataUntil you delete it, then the cascade below
Provisioned End-User identities, groups, API keys (hashes)Until you or your End User deletes them, or you delete the tenant or team
Identities observed from traffic but not provisioned90 days after last activity
Request logs91 days
Traffic samples (development environments, when enabled)31 days, or until you delete them
Analytics datasets (request counts, latency, country, request path, consumer id)About 90 days
Producer and End-User audit logs90 days
Abuse alerts, delivery failures90 days
Credit ledger and top-up recordsKept as accounting records; not pruned on a schedule
Export bundles72 hours; 1 hour when they contain secrets
Support reports, including any screenshot you attach365 days
Wallet and usage state held in durable objectsWhile the wallet is in use; a closed wallet is swept 90 days later
Log and ledger rows waiting in a queueUp to 14 days
Long-running MCP task records (who ran a tool, and its result)24 hours
Identity-provider tokens (encrypted)At most 30 days after your last sign-in or token refresh
Sign-in session records7 days (30 days for dynamically registered clients)
Authorization codes, verification codes, MCP sessions10 minutes, 10 minutes, 1 hour
Hashed network addresses used for abuse detection at proxy creation2 days
Database backups35 days
Application logs (console output at our infrastructure provider)About 7 days
Unclaimed anonymous proxiesDeleted after 72 hours without traffic or 30 days of silence

When you delete your account or team, the deletion runs as a cascade: proxies, tenants, End-User Records, keys, configuration, request logs, analytics for the team, the team’s authorization store and credit counters are deleted, and your identity, team memberships and CLI sessions are removed. Keys are revoked and their stored copies removed, though the key record and its hash stay until the team itself is deleted. We keep, after deletion: your Stripe customer record (payment history, for tax and accounting law, seven years); the credit ledger and top-up records, which are accounting records; a deletion record in our audit log with your user id; your own end-user record on the consumer side, marked deleted rather than removed, because it has its own lifecycle; the wallet’s durable-object storage, which is closed at once and swept 90 days later; End-User identities you may hold in other producers’ tenants; analytics rows already written, until they expire; and time-limited counters until they expire. Your Loops contact is deleted with your account. Deletion runs as a resumable background job, and its bookkeeping row is kept 30 days after it finishes.

12. Your rights and choices

  • Access and correction: your profile and team settings are editable in the dashboard; identity details come from your identity provider and change when you change them there.
  • Deletion: delete proxies, tenants and teams from the dashboard, and your account from Account settings (you must be the only member of the teams you own). Deletion is described in Section 11.
  • Portability: export your configuration and End-User Records at any time from the dashboard or CLI, in OpenAPI, SCIM 2.0 and documented JSON, free of charge, as described in Section 10 of the Terms. Request logs and analytics are viewable in the dashboard but are not part of the export.
  • Email: unsubscribe from onboarding and product email with the link in any such message.
  • Cookies: change your analytics choice under “Cookie settings”.
  • Objection and restriction, where the law provides them, and the right to complain to your data-protection authority.

For anything you cannot do yourself, email privacy@apiblaze.com. We answer within 30 days and may ask you to verify your identity. We do not discriminate against you for exercising a right.

13. International transfers

We are based in the United States and our subprocessors process data there and, for Cloudflare’s network, in the country closest to the request. If you are in the European Economic Area, the United Kingdom or Switzerland, transfers rely on the providers’ standard contractual clauses or an adequacy decision, and we can provide our data-processing terms on request.

14. Children

The Service is for businesses and adults. We do not knowingly collect data from anyone under 18 as a producer, or under 16 as an End User, and we delete it if we learn we have.

15. Changes and contact

We may update this policy; material changes are announced by email or in the dashboard at least 30 days before they take effect, and the version at the top changes. Questions and requests: privacy@apiblaze.com, APIblaze LLC, Birmingham, Michigan, United States.