Terms of Service
Last updated: 2026-09-16
These terms are the agreement between Apiheron ("we") and you when you use apiheron.com and app.apiheron.com ("the service"). By creating an account you accept them. If you do not accept them, do not use the service.
1. What the service does
Apiheron is a developer tool. An SDK you install in your own frontend records what your application does with the API responses it receives — which fields it reads, how long requests take, how large responses are — and sends that record to our collector, which turns it into findings you read in the app.
The SDK records the shape of a response: field names, types, array lengths, timings and the request URL. It does not send the values inside the response body.
2. Your account
You need an account to use the service, and you must give a real email address you control. You are responsible for everything done under your account and for keeping your password and ingest keys secret. Tell us at once if you believe someone else has access.
You must be at least 16 years old, or the age of digital consent in your country, whichever is higher. An account for an organization may only be created by someone allowed to accept these terms for it.
3. Acceptable use
Send us data only from applications you own or are authorised to profile. Do not use the service to break the law, to infringe anyone's rights, to send malicious content, or to attack, overload or reverse engineer the service.
Ingest keys are write-only and bound to the origins you list, but they ship inside your pages. Treat them accordingly and revoke any key you no longer need.
4. Your data
The data you send stays yours. You grant us the permission we need to store and process it in order to run the service for you: to analyse it, to show you findings and to keep backups.
You are responsible for what you send. Request URLs are stored as they are, so a URL that carries personal data in its query string will be stored too. The SDK has an ignore list and a sample rate for exactly this reason, and every project has a field ignore list.
You can download everything stored about your organization as JSON, at any time, from the Organization page.
5. Plans, quotas and payment
The free plan and the paid plans differ in how many responses may be captured a month and how long data is kept. When a month's quota is used up, capture pauses until the next month starts or the plan is raised; data already stored is not affected.
Paid plans are billed through Polar, which acts as merchant of record and issues your invoices. Subscriptions renew automatically until cancelled, and you cancel or change them yourself in the billing portal. Cancelling stops the next renewal; it does not refund the period already paid for, except where the law gives you a refund right.
We may change prices. A change reaches an existing subscription no earlier than its next renewal, and we tell you at least 30 days before.
6. Retention and deletion
Captured responses are deleted automatically once they pass the retention set on the project, capped by the plan's maximum. Findings derived from them are kept while the project exists.
You may delete your account or your organization yourself at any time. Deleting an organization deletes its projects, captured data, findings, members and invitations immediately, and it cannot be undone. Backups are kept for a short period after that and then overwritten.
7. Availability
We do everything reasonable to keep the service available, but it is provided as it is, without an uptime guarantee. Maintenance, failures and dependencies outside our control can interrupt it.
The service is a development tool. It must not be relied on as a monitoring or alerting system for a production incident.
8. Suspension and termination
We may suspend or close an account that breaks these terms, that puts the service or other customers at risk, or whose payment stays unpaid. Where it is reasonable, we warn first and give you a chance to fix it.
You may stop using the service at any time by deleting your account.
9. Liability
To the extent the law allows, the service is provided without warranties of any kind, and we are not liable for indirect or consequential loss, lost profits, or lost or corrupted data.
Where we are liable, our total liability is limited to the amount you paid us in the twelve months before the event. Nothing here excludes liability that cannot be excluded by law, including for death, personal injury, fraud or gross negligence.
10. Changes to these terms
We may change these terms. A material change is announced by email to organization owners at least 30 days before it applies. Continuing to use the service after that means you accept the new terms.
11. Law and contact
These terms are governed by [governing law and courts].
Apiheron, [company address]. Questions about these terms: [email protected].