Privacy Policy

Effective

This policy explains what personal information Apinoa collects when you use our API and website, what we do with it, how long we keep it and the choices you have. It is part of our Terms of Service.

1. Who we are

Apinoa (“we”, “us”) provides the Apinoa API and the website at apinoa.com. The controller responsible for your personal information is Thebase (더베이스), a sole proprietorship registered in the Republic of Korea, business registration number 126-39-01733.

Our chief privacy officer handles privacy questions, requests and complaints and is reachable at privacy@apinoa.com.

2. Information we collect

Account. Your name (optional), email address and password, which we store only as a bcrypt hash. If you sign in with Google we receive your Google account’s email address, name, profile picture and account identifier. If you sign in with GitHub we receive your GitHub account identifier, username, display name, profile picture and verified primary email address; we use the access GitHub grants only to read these once and do not keep it. We record when you accepted our Terms of Service, this Privacy Policy and the Credit Terms, and which version you accepted.

API keys. Keys are stored as salted hashes; we cannot recover a key after it has been shown to you once.

API usage. For each API call: the endpoint, method, request parameters, response status, duration, the amount charged, any error message, the API key used and the time. From these we keep daily totals per account and provider (number of calls, billable requests and units, and spend).

Error logs. When a request to the API, gateway or website fails, we record the path, method, status, error details, your account and API key identifiers if known, your IP address, your browser’s user agent and the query parameters, with any parameter that looks like a credential (key, token, password, signature and the like) redacted.

Content you send to the API. Images you submit for translation are processed to extract and translate their text. Text extracted from images and its translation is kept in a translation cache that is not linked to your account. Product data requests are made on your behalf to the marketplaces you query.

Files you upload. Fonts and images you upload to your account are stored in object storage.

Payments. Purchases are processed by Paddle, our merchant of record. Paddle collects your payment details, billing address and tax information; we never see or store your card number. We receive and keep your Paddle customer identifier and, for each purchase, the transaction identifier, amount, currency, status and invoice link, together with the ledger of credit added to and spent from your balance.

Free credit requests. If you request free credit through our Discord server, you enter the email address you signed up to apinoa with; we use it to find your account. We keep that email address, the account it matches, what you enter in the request form (company or project, intended use, expected volume and marketplaces of interest), your Discord user identifier and username, and our decision, including who made it and, if credit we granted is later withdrawn, the amount taken back. An eligible account is granted credit automatically. When credit is granted, we email the account and tell its owner the Discord username that asked, so the owner learns if someone else requested it. Our staff can see the Discord user and the account a request is for. No one-time codes are used to link your Discord user to your account.

Support tickets in Discord. If you open a private ticket in our Discord server, we keep your Discord user identifier and username, the topic and subject you choose, the email address you give us in the ticket (we use it to find your account) and the account it matches, the ticket’s status and who closed it and when. Which account the email matches is shown only to our staff, not in the ticket. The details you enter and the conversation that follows are held by Discord in a private thread that only you, our staff, and anyone you or our staff add to the ticket can see; we do not store them. Anyone added to a ticket can read all of it, including what was written before they joined and the email address shown in it. Other members of #tickets can see that you opened a ticket, but not what it says.

3. How we use it

We use personal information to:

  • create and secure your account, authenticate you and your API keys;
  • provide the Service, meter usage and charge your prepaid balance;
  • process purchases and refunds with Paddle and keep financial records;
  • send transactional emails: email verification, password reset, credit expiry and balance notices, and replies to your messages;
  • diagnose failures, answer support requests about a specific request, and protect the Service against abuse.

We do not sell your personal information, and we do not use it for advertising.

4. Marketplace data the Service retrieves

The Service caches and stores the product information it retrieves from public marketplace pages, to serve requests faster, to enforce our Terms, and to build aggregated datasets and data products that we may license or sell to others. It can include information about third parties, such as seller names or the display names of reviewers. We keep retrieved data apart from your account and do not use it to profile individuals. Before we use it in aggregated datasets or data products we offer to others, we remove or de-identify personal information in it, and we strip everything that could identify the customer whose request retrieved it — account, API key, request identifiers, timestamps, IP addresses and query parameters. We never share which data a customer requested. If you believe we hold personal information about you from a public source, contact us and we will act on your request as the law requires.

5. How long we keep it

  • Per-call API logs: 24 hours. They are then deleted automatically and only the daily totals described above remain.
  • Error logs: 30 days, then deleted automatically.
  • Sign-in sessions: 7 days; expired sessions are removed automatically every hour.
  • Email verification and password reset links: expire after 24 hours and 4 hours respectively.
  • Account, daily usage totals and uploaded files: for as long as your account exists.
  • Payment and balance records: not deleted automatically; we keep them for as long as we need them to meet accounting, tax and legal obligations and to handle disputes.
  • Email you send us: in our email inbox for as long as needed to handle your enquiry.

6. Service providers we share it with

We share personal information only with the providers that run parts of the Service for us, and only what each needs:

  • Paddle (United Kingdom, United States) — merchant of record for purchases: checkout, payment processing, tax, invoicing and refunds.
  • Resend (United States) — delivery of transactional email.
  • Discord (Discord Inc., United States) — free credit requests and private support tickets in our Discord server. When you request free credit, your account email address, company or project and intended use are posted to a private staff channel. An eligible request is granted automatically; we tell you privately in Discord (a reply only you can see and a direct message) and email the account’s owner. When you open a support ticket, your Discord username and identifier, the topic, subject, email address and details you enter and the conversation that follows are held by Discord in a private thread only you, our staff and anyone added to the ticket can see; we store only the topic, subject, status, the email address you give us in the ticket (we use it to find your account) and the account it matches. Which account it matches is posted to a private staff channel. Other members of #tickets can see that you opened a ticket, but not what it says.
  • Google (United States) — “Sign in with Google” on the login and registration pages.
  • GitHub (GitHub, Inc., United States) — “Sign in with GitHub” on the login and registration pages.
  • Cloudflare (United States) — delivers and protects the website and the account API: requests to apinoa.com and api.apinoa.com pass through it, including your IP address. Its R2 service stores uploaded files and website media.
  • Vast.ai (United States) — GPU servers that process images sent to the image translation API.
  • Google (Gemini), OpenRouter and DeepInfra (United States) — language models that translate text extracted from images. They receive the extracted text, not your account details.
  • OVHcloud (United States) — the servers where our website, API, database and cache run.

We may also disclose information where the law requires it, or to protect our rights, users or the public.

7. International transfers

The providers listed above process data outside the Republic of Korea, in the countries shown next to each. The information transferred is the information each provider needs, as described in that section; it is transferred over encrypted connections when you use the Service, and kept for the periods in “How long we keep it”.

These transfers are necessary to perform our contract with you and are disclosed here in accordance with the Personal Information Protection Act. For personal information subject to the GDPR or UK GDPR, transfers rely on an adequacy decision or on the standard contractual clauses in each provider’s data processing terms. You may object to a transfer by contacting us, but because the Service cannot run without these providers, we would then be unable to provide it to you.

8. Cookies and local storage

We set only the cookies the Service needs:

  • access_token and refresh_token — keep you signed in (HTTP-only; 7 and 30 days).
  • access_token_expires_at — lets the dashboard know when to refresh your sign-in (7 days).
  • gh_oauth_state — protects a sign-in with GitHub while it is in progress (HTTP-only; 10 minutes, removed when the sign-in finishes).
  • NEXT_LOCALE — the language you chose (1 year).

Your light or dark theme preference is kept in your browser’s local storage. We do not use analytics, tracking or advertising cookies. Paddle’s checkout and Google’s and GitHub’s sign-in, when you use them, are governed by their own privacy policies.

9. Security

Passwords and API keys are stored only as hashes. Traffic to the Service is encrypted in transit. No system is perfectly secure; if a breach affects your personal information we will notify you and the authorities as the law requires.

10. Your rights

You can ask us to give you access to, correct, delete or export the personal information we hold about you, and to restrict or object to how we use it. You can change your name in your account settings. For anything else, including deleting your account, email privacy@apinoa.com from the address on your account. We will answer within the time the law that applies to you requires.

Deleting your account removes your account and the data linked to it, except records we must keep, such as payment and balance records, for the purposes described in “How long we keep it”.

11. If you are in the EEA or the UK (GDPR)

We process your personal information on these legal bases: to perform our contract with you (your account, the Service, billing); to comply with legal obligations (tax and accounting records); and our legitimate interests in securing, diagnosing and improving the Service and preventing abuse (error logs, rate limiting). Where we rely on consent, you may withdraw it at any time.

In addition to the rights above, you have the right to data portability and the right to lodge a complaint with your local data protection supervisory authority.

12. If you are in Korea (PIPA)

In accordance with the Personal Information Protection Act, the items we collect, the purposes we use them for, how long we keep them and the providers we entrust processing to are set out in the sections above. We do not provide your personal information to third parties beyond those providers except as required by law.

When a retention period ends, or the purpose of processing is achieved, we destroy the information without delay: database records are deleted, automatically for the logs described above, and electronic files are deleted so they cannot be restored.

You may exercise your rights to access, correct, delete or suspend the processing of your personal information by contacting our chief privacy officer at privacy@apinoa.com. You may also seek help from the Personal Information Protection Commission or the Korea Internet & Security Agency privacy center.

13. Children

The Service is offered for business use by people aged 18 or over, and we do not knowingly collect personal information from children.

14. Changes to this policy

We may update this policy by posting a revised version with a new effective date and, for material changes, emailing registered users beforehand.

15. Contact

Privacy questions and requests: privacy@apinoa.com.

See also the Terms of Service.