Privacy Policy
Last updated: October 7, 2026 · version 2026-10-07
This policy is for API providers (“producers”) and visitors to this website. If you sign in to an API or developer portal that a provider runs on APIblaze, read the Consumer Privacy Notice instead.
1. Who we are and what this covers
APIblaze LLC (“APIblaze”, “we”, “us”), Birmingham, Michigan, United States, operates apiblaze.com, the dashboard, the command-line tools, and the gateway, identity, MCP and AI services described in our Terms of Service. This policy explains what we collect about you as a producer or website visitor, why, who processes it, and for how long.
Two roles. For your own account data we are the controller. For personal data about your End Users that flows through the Service, you are the controller and we are your processor, except for the limited platform-security processing described in the Consumer Privacy Notice, where we are an independent controller. Section 6 of the Terms is our data-processing agreement.
2. What we collect
From your identity provider when you sign in (GitHub for the dashboard and CLI): your name, email address, avatar, provider account id and handle. We do not receive your password.
What you give us: team name, contact and support email, optional phone and company details, the terms and privacy links you set for your End Users, custom domains, API specifications, configuration, transformation rules and the secrets you store with us, portal branding, recipes, support reports, and the email addresses of people you invite. A support report can carry a screenshot you choose to attach: it is taken of the page you are on, in your browser, and fields we recognise as keys, tokens or personal data are blacked out before the picture is made, so those pixels never exist. You can black out anything else yourself before sending, and only that edited picture is uploaded.
From GitHub repositories you connect (Section 4): repository names, the file listing of a repository you open, candidate specification files we read to find your OpenAPI document, and the document you choose.
Payment: Stripe holds your card details and billing address; we store only your Stripe customer id, your credit balance and ledger, and the amounts and dates of your top-ups.
Automatically, when you use the dashboard, CLI or API: session records, device-authorization sessions for the CLI (handle, email, codes, kept one day), the actions you take (an audit log with your user id, the operation and the objects touched), and the network address and user agent of your requests in our infrastructure provider’s application logs for about seven days. Abuse detection at proxy creation stores a one-way hash of the network address for two days, never the address itself.
About your End Users, on your behalf: see the Consumer Privacy Notice and Section 5 below.
Website visitors: standard server logs at our hosting provider, and, only if you accept analytics cookies, Google Analytics usage data (Section 8).
3. How we use it
- To provide the Service: run your proxies, portals, MCP servers and chat widgets; sign you and your End Users in; apply your access rules; bill usage against your credits.
- To keep the Service secure and prevent abuse: rate limiting, abuse detection across the platform, alerts to our operators, and enforcement of the Terms.
- To show you what your API is doing: request logs, analytics, traffic samples you enable, audit logs.
- To support you and communicate about the Service: support replies, invitations and access-request emails you trigger, onboarding and product-update email (Section 9), notices required by the Terms.
- To improve the Service using aggregated, de-identified usage patterns.
- To comply with law and to establish, exercise or defend legal claims.
Where the GDPR or a similar law applies, our legal bases are performance of the contract with you, our legitimate interests in running and protecting the Service and in telling you about it, consent where we ask for it (analytics cookies), and legal obligation.
4. GitHub access
Producers sign in with GitHub through the APIblaze GitHub App. The App asks for your public profile and email. Repository import needs the App installed on the repositories you choose, with read access to repository metadata and contents. When you open a repository in the import flow we list its files and read a limited number of candidate files to find an OpenAPI document; we keep only the document you select. We do not read repositories you have not opened, and we do not write to your repositories. The token GitHub issues us is stored encrypted for at most 30 days after your last sign-in and is used only for these operations. You can revoke the App from your GitHub settings at any time.
5. Logs, analytics and traffic capture
Request logs. For every request through a proxy we record who called (a consumer id or key id and, if your application sends it, an end-user id), the route, method, status, timing, cost and environment. By default header values, query strings and bodies are not recorded, only header names and the shape of the body. You can turn on capture of headers, query parameters, bodies and selected token claims per proxy, in any environment, in which case those values are recorded for your review. Credentials, cookies, network addresses, user agents, email headers and secret-shaped values are always removed before storage. Logs are kept 91 days and are visible to your team, to operators, and, for their own tenant only and without your origin details, to your End-User organizations.
CLI commands. When a request comes from our command-line tool we also record which command made it, its version, and an identifier for that run, so we can tell a failing request from a broken release and help you debug it. The command is a fixed label from the tool’s own list, such as key create — never the command line you typed, so anything you pass as an argument, including a secret, is not sent and not stored. Commands that make no request to us are not recorded at all.
Analytics. Per request we keep counts, latency, status, cost, the consumer id and the country of the caller in an analytics dataset for about 90 days. No network addresses.
Traffic capture. In development environments only, and only while it is enabled for a project (it is on by default for the dev environment and can be turned off per project; it never runs in test or production environments), we store samples of full requests and responses, including bodies and query strings, so you can inspect and replay them and draft your specification from them. Credentials, cookies, network addresses and user agents are removed; other content is stored as sent, so personal data your End Users put in requests may be included. Samples are kept 31 days or until you delete them, and are sent to the AI model providers only if you run traffic review on them.
Identities observed from traffic. When an End User calls a proxy with a token or key we record their identity (subject, email if the token carries one), first and last seen and a count, per tenant, for 90 days after last activity, so that you can see who is calling and pre-approve or block them.
6. AI features
The chat widget, MCP tooling, specification drafting, model and template generation and traffic review send content to language-model providers through OpenRouter: End-User chat messages, the responses your API returns to the chat, the development traffic you submit for review, and your API structure. We request routing that excludes providers who retain or train on inputs, and we do not send End-User identities, network addresses or credentials in prompts. If you bring your own model key, requests go to that provider under your agreement with them, and we do not store the key.
7. Security
- All traffic to and from the Service uses TLS. Data is encrypted at rest by our infrastructure providers.
- API keys are stored as one-way hashes. A key you give an expiry date is additionally held in full, in encrypted storage, until it expires, so that it can be shown again in the dashboard or the portal; a key with no expiry is shown once and only its hash is kept, and revoking a key removes the stored copy. Identity-provider tokens, OAuth client secrets, provider secrets and the secrets in your transformation rules are additionally encrypted at the application level with keys we hold and rotate. Operators can decrypt secrets when operating the Service; the dashboard can reveal an OAuth client secret to your team members with the right role.
- Each producer’s data is isolated by team and tenant identifiers enforced in every query, and each team has its own authorization store.
- Access to production systems is limited to operators with a named account and is recorded in our audit log.
- Report vulnerabilities to security@apiblaze.com. We notify affected producers without undue delay, and within 72 hours of confirming a breach that affects their End-User data.
No system is perfectly secure, and we do not claim otherwise.
9. Email
We send transactional email through Amazon SES and Resend: invitations and access requests you trigger, verification codes, security and billing notices, and support replies. Through Loops we send a short onboarding sequence when you create an account and occasional product updates; every such email has an unsubscribe link, and unsubscribing does not affect transactional email. We do not sell or rent your address and do not run advertising campaigns to it.
11. How long we keep it
| Data | Retention |
|---|---|
| Account, team, project and configuration data | Until you delete it, then the cascade below |
| Provisioned End-User identities, groups, API keys (hashes) | Until you or your End User deletes them, or you delete the tenant or team |
| Identities observed from traffic but not provisioned | 90 days after last activity |
| Request logs | 91 days |
| Traffic samples (development environments, when enabled) | 31 days, or until you delete them |
| Analytics datasets (request counts, latency, country, request path, consumer id) | About 90 days |
| Producer and End-User audit logs | 90 days |
| Abuse alerts, delivery failures | 90 days |
| Credit ledger and top-up records | Kept as accounting records; not pruned on a schedule |
| Export bundles | 72 hours; 1 hour when they contain secrets |
| Support reports, including any screenshot you attach | 365 days |
| Wallet and usage state held in durable objects | While the wallet is in use; a closed wallet is swept 90 days later |
| Log and ledger rows waiting in a queue | Up to 14 days |
| Long-running MCP task records (who ran a tool, and its result) | 24 hours |
| Identity-provider tokens (encrypted) | At most 30 days after your last sign-in or token refresh |
| Sign-in session records | 7 days (30 days for dynamically registered clients) |
| Authorization codes, verification codes, MCP sessions | 10 minutes, 10 minutes, 1 hour |
| Hashed network addresses used for abuse detection at proxy creation | 2 days |
| Database backups | 35 days |
| Application logs (console output at our infrastructure provider) | About 7 days |
| Unclaimed anonymous proxies | Deleted after 72 hours without traffic or 30 days of silence |
When you delete your account or team, the deletion runs as a cascade: proxies, tenants, End-User Records, keys, configuration, request logs, analytics for the team, the team’s authorization store and credit counters are deleted, and your identity, team memberships and CLI sessions are removed. Keys are revoked and their stored copies removed, though the key record and its hash stay until the team itself is deleted. We keep, after deletion: your Stripe customer record (payment history, for tax and accounting law, seven years); the credit ledger and top-up records, which are accounting records; a deletion record in our audit log with your user id; your own end-user record on the consumer side, marked deleted rather than removed, because it has its own lifecycle; the wallet’s durable-object storage, which is closed at once and swept 90 days later; End-User identities you may hold in other producers’ tenants; analytics rows already written, until they expire; and time-limited counters until they expire. Your Loops contact is deleted with your account. Deletion runs as a resumable background job, and its bookkeeping row is kept 30 days after it finishes.
12. Your rights and choices
- Access and correction: your profile and team settings are editable in the dashboard; identity details come from your identity provider and change when you change them there.
- Deletion: delete proxies, tenants and teams from the dashboard, and your account from Account settings (you must be the only member of the teams you own). Deletion is described in Section 11.
- Portability: export your configuration and End-User Records at any time from the dashboard or CLI, in OpenAPI, SCIM 2.0 and documented JSON, free of charge, as described in Section 10 of the Terms. Request logs and analytics are viewable in the dashboard but are not part of the export.
- Email: unsubscribe from onboarding and product email with the link in any such message.
- Cookies: change your analytics choice under “Cookie settings”.
- Objection and restriction, where the law provides them, and the right to complain to your data-protection authority.
For anything you cannot do yourself, email privacy@apiblaze.com. We answer within 30 days and may ask you to verify your identity. We do not discriminate against you for exercising a right.
13. International transfers
We are based in the United States and our subprocessors process data there and, for Cloudflare’s network, in the country closest to the request. If you are in the European Economic Area, the United Kingdom or Switzerland, transfers rely on the providers’ standard contractual clauses or an adequacy decision, and we can provide our data-processing terms on request.
14. Children
The Service is for businesses and adults. We do not knowingly collect data from anyone under 18 as a producer, or under 16 as an End User, and we delete it if we learn we have.
15. Changes and contact
We may update this policy; material changes are announced by email or in the dashboard at least 30 days before they take effect, and the version at the top changes. Questions and requests: privacy@apiblaze.com, APIblaze LLC, Birmingham, Michigan, United States.