Privacy Policy
Last updated: 2026-09-16
This policy explains what Apiheron collects when you use apiheron, why, and what you can do about it. It covers both the marketing site and the application.
1. Who is responsible
Apiheron, [company address], is the controller for the data described here. For privacy questions, including a request for a signed data processing agreement, write to [email protected].
For the data your SDK sends us, you are the controller and we are your processor: it is your application's traffic, and you decide what is sent.
2. Account data
When you create an account we store your name, email address, a hash of your password, your interface language and the time you signed up. If you upload a profile photo we store the re-encoded image.
For each active session we store its creation and expiry time, the IP address and the browser's user agent, so you can see your devices and sign them out.
3. What the SDK sends
For each captured response: the HTTP method, the full request URL including its query string, a normalised route, the status code, when it started and how long it took, the response size in bytes, the number of items in a list, the names and types of the response's fields, which of those fields your code read, the array operations run on them, the cache key, the page path the request was made from, the call-site frames that started it and the release tag you set.
The SDK does not send the values inside a response body. It sends the shape. Request URLs, however, are stored as they arrive, so anything you put in a query string reaches us. Use the SDK's ignore list to skip URLs you do not want recorded.
Everything captured is stored under your organization and is visible only to its members.
4. Technical data and cookies
We record the IP address of administrative actions in the audit log, so an organization can see who changed what. Server logs hold the usual request metadata for a short period.
The cookies we set are functional: the session cookie that signs you in, and small preferences for your language, your time zone, the selected project and the light or dark theme. We use no advertising or third-party analytics cookies, so there is no consent banner to click.
5. Why we process it, and on what basis
To provide the service you signed up for, including analysis, findings and billing: performance of our contract with you.
To keep the service secure and to prevent abuse, including rate limits and the audit log: our legitimate interest in a safe service.
To send transactional email — sign-in links, password resets, invitations, quota notices and billing notices: performance of the contract. We do not send marketing email without asking you first.
6. Who else sees it
We do not sell data and we do not share it for advertising. We use a small number of processors to run the service: our hosting provider ([hosting provider and region]), Polar for payments and invoicing, and Resend for transactional email.
Two integrations are off by default and run only if you turn them on with your own credentials: an AI advisor, which sends a finding and the response's field names to the model provider whose key you entered, and Papyro, which sends a finding to the board you configure. Turning one on is your decision, and it is your account with that provider.
7. Where it is stored, and for how long
Data is stored on our hosting provider's servers ([hosting provider and region]). Captured responses are deleted automatically once they pass your project's retention, capped by your plan's maximum. Findings and their history stay while the project exists.
Account data is kept until you delete your account. The audit log and billing records are kept as long as we need them for security and for the periods tax and accounting law requires. Backups are rotated and overwritten.
8. Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to its processing, and receive it in a portable format. Two of these are self-service: the Account and Organization pages each have a download as JSON and a delete.
Write to [email protected] for anything else. If you think we have handled your data wrongly, you can complain to your local data protection authority.
9. Security
Traffic runs over HTTPS. Passwords are hashed, ingest keys are stored hashed and are write-only, and integration secrets are encrypted at rest. Access to an organization's data is checked on every request against the member's role, and administrative changes are recorded in the audit log.
No system is perfect. If a breach affects your data, we will tell you and the supervisory authority as the law requires.
10. Children
The service is for developers and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes
When this policy changes materially we email organization owners before the change applies. The date at the top always shows the current version.