Effective 6 October 2026 · Last updated 6 October 2026
In plain English: we keep your email, your keys (as hashes we cannot reverse), a log of the calls you make and your credit top-ups. Card details stay with Stripe. What you ask for is passed to the data provider that answers it, and a page you turn into an API is read by an AI model. We do not sell your data or use it for advertising.
This policy covers FetchAPI, the website at fetchapi.co, its HTTP API, its MCP server and the account pages (together, "the service"). "We" means the people who run FetchAPI. Questions go to support@fetchapi.co.
Your account. You sign in with your email address and a one-time code; there is no password. Sign-in runs on Supabase Auth, which stores your email address and a user id. Your browser keeps the sign-in session in its local storage until you sign out.
Your API keys. When you create a key we store its owner email, the name and the "what will you use it for" text you give it, its limits and the first few characters (so you can tell keys apart). The key itself is stored only as a SHA-256 hash: we cannot read it back, and it is shown to you once.
Your calls. Each call made with your key is logged with: the key, which provider and path you called, what you asked
for (the query string, or the start of the request body, cut to 300 characters), the HTTP status, the upstream cost, what we
charged you, and how long it took. Parameters whose names look like credentials (tokens, passwords, cookies, session ids,
proxy settings, API keys) are replaced with [redacted] before anything is written. We do not store the data the
provider sends back to you. You can see this log on your account page.
Payments. Credit is bought through Stripe Checkout. Stripe collects and holds your card details; we never see or store a card number. From Stripe we record the payment: your email, your user id, the amount of credit, and the Stripe session and payment ids, in a credit ledger.
APIs you make. When you use "Make an API" we store the page URL and the task you typed, the progress of the run, and the resulting API description (the endpoints, parameters and how to read the page). These APIs are private to your account and are never published in our public catalogue. The AI cost of each run is logged as a call, as above, with the URL.
Page views. The site uses Vercel Web Analytics to count page views. It does not use cookies, and it records the page, the referrer, and coarse device, browser and country information, not who you are. We do not use advertising pixels or third-party tracking cookies.
Server logs. Our host (Vercel) keeps short-lived request logs, which include IP addresses, to run and protect the service. We also use your IP address, in memory only, to limit how many keys can be created from one place.
We use these companies to run the service. Each sees only what it needs:
We may disclose data when the law requires it, or to protect the service and its users from fraud or abuse. If FetchAPI is ever transferred to someone else, this policy goes with the data.
These companies may process data outside your country, including in the United States.
No system is perfectly secure. If we learn of a breach that affects your data, we will tell you without undue delay.
Account data, keys (including revoked ones), the call log and the APIs you make are kept while your account exists, so your usage and billing history stay complete. You can delete an API you made on your account page at any time. Payment records are kept as long as tax and accounting law requires, even after an account is deleted. Vercel's request logs expire on their own after a short period.
You can ask us to show you, correct, export or delete the personal data we hold about you, or object to how we use it. Email support@fetchapi.co from the address on your account. Depending on where you live (for example under the GDPR in the EU and UK, or the CCPA in California) you may have further rights, including the right to complain to your data protection authority. We do not sell personal information as the CCPA defines it.
Deleting your account revokes your keys and deletes your APIs; we keep payment records as section 7 says.
The service is for developers and businesses, not for anyone under 16. If you believe a child has given us data, tell us and we will delete it.
If we change this policy we update the date at the top. If a change is material, we will tell account holders by email before it takes effect.
Privacy questions and requests: support@fetchapi.co. See also our Terms of Service.