Privacy Policy
Last updated: August 4, 2026
This Privacy Policy explains what data API Espresso collects and how it's used.
1. What We Collect
- Account/billing data: your email and payment details, collected and processed by Paddle (our merchant of record) — we do not see or store your full card details.
- API usage data: for each API request, we log the endpoint called, status code, response time, and (for the image comparison API specifically) the hostname only of any image URLs submitted — never the full URL, since URLs can contain sensitive query parameters. We do not store the images themselves.
- API key: stored only as a one-way cryptographic hash. We cannot see or recover your actual key.
2. How We Use It
- To operate the Service (authenticate requests, enforce quotas/rate limits, bill correctly)
- To troubleshoot issues and monitor abuse
- To communicate service-related notices (e.g. planned downtime, policy changes) to your billing email
3. Third Parties
- Paddle — payment processing, billing, tax handling
- Cloudflare — hosting infrastructure (Workers, KV, D1) and DNS-over-HTTPS resolution used for security checks on submitted URLs
We do not sell your data to third parties.
4. Data Retention
Usage logs are retained for 90 days for troubleshooting and abuse monitoring, then deleted. Billing records are retained as required by Paddle/applicable tax law.
5. Your Rights
You may request a copy of the data we hold about you, or request deletion of your account data, by contacting support@apiespresso.com.
6. Contact
Questions about this policy: support@apiespresso.com