Privacy Policy
Effective
This policy explains what personal information Apinoa collects when you use our API and website, what we do with it, how long we keep it and the choices you have. It is part of our Terms of Service.
1. Who we are
Apinoa (“we”, “us”) provides the Apinoa API and the website at apinoa.com. The controller responsible for your personal information is Thebase (더베이스), a sole proprietorship registered in the Republic of Korea, business registration number 126-39-01733.
Our chief privacy officer handles privacy questions, requests and complaints and is reachable at privacy@apinoa.com.
2. Information we collect
Account. Your name (optional), email address and password, which we store only as a bcrypt hash. If you sign in with Google we receive your Google account’s email address, name, profile picture and account identifier. If you sign in with GitHub we receive your GitHub account identifier, username, display name, profile picture and verified primary email address; we use the access GitHub grants only to read these once and do not keep it. We record when you accepted our Terms of Service, this Privacy Policy and the Credit Terms, and which version you accepted.
API keys. Keys are stored as salted hashes; we cannot recover a key after it has been shown to you once.
API usage. For each API call: the endpoint, method, request parameters, response status, duration, the amount charged, any error message, the API key used and the time. From these we keep daily totals per account and provider (number of calls, billable requests and units, and spend).
Error logs. When a request to the API, gateway or website fails, we record the path, method, status, error details, your account and API key identifiers if known, your IP address, your browser’s user agent and the query parameters, with any parameter that looks like a credential (key, token, password, signature and the like) redacted.
Content you send to the API. Images you submit for translation are processed to extract and translate their text. Text extracted from images and its translation is kept in a translation cache that is not linked to your account. Product data requests are made on your behalf to the marketplaces you query.
Files you upload. Fonts and images you upload to your account are stored in object storage.
Payments. Purchases are processed by Paddle, our merchant of record. Paddle collects your payment details, billing address and tax information; we never see or store your card number. We receive and keep your Paddle customer identifier and, for each purchase, the transaction identifier, amount, currency, status and invoice link, together with the ledger of credit added to and spent from your balance.
Free credit requests. If you request free credit through our Discord server, you enter the email address you signed up to apinoa with; we use it to find your account. We keep that email address, the account it matches, what you enter in the request form (company or project, intended use, expected volume and marketplaces of interest), your Discord user identifier and username, and our decision, including who made it and, if credit we granted is later withdrawn, the amount taken back. An eligible account is granted credit automatically. When credit is granted, we email the account and tell its owner the Discord username that asked, so the owner learns if someone else requested it. Our staff can see the Discord user and the account a request is for. No one-time codes are used to link your Discord user to your account.
Support tickets in Discord. If you open a private ticket in our Discord server, we keep your Discord user identifier and username, the topic and subject you choose, the email address you give us in the ticket (we use it to find your account) and the account it matches, the ticket’s status and who closed it and when. Which account the email matches is shown only to our staff, not in the ticket. The details you enter and the conversation that follows are held by Discord in a private thread that only you, our staff, and anyone you or our staff add to the ticket can see; we do not store them. Anyone added to a ticket can read all of it, including what was written before they joined and the email address shown in it. Other members of #tickets can see that you opened a ticket, but not what it says.
3. How we use it
We use personal information to:
- create and secure your account, authenticate you and your API keys;
- provide the Service, meter usage and charge your prepaid balance;
- process purchases and refunds with Paddle and keep financial records;
- send transactional emails: email verification, password reset, credit expiry and balance notices, and replies to your messages;
- diagnose failures, answer support requests about a specific request, and protect the Service against abuse.
We do not sell your personal information, and we do not use it for advertising.
4. Marketplace data the Service retrieves
The Service caches and stores the product information it retrieves from public marketplace pages, to serve requests faster, to enforce our Terms, and to build aggregated datasets and data products that we may license or sell to others. It can include information about third parties, such as seller names or the display names of reviewers. We keep retrieved data apart from your account and do not use it to profile individuals. Before we use it in aggregated datasets or data products we offer to others, we remove or de-identify personal information in it, and we strip everything that could identify the customer whose request retrieved it — account, API key, request identifiers, timestamps, IP addresses and query parameters. We never share which data a customer requested. If you believe we hold personal information about you from a public source, contact us and we will act on your request as the law requires.
5. How long we keep it
- Per-call API logs: 24 hours. They are then deleted automatically and only the daily totals described above remain.
- Error logs: 30 days, then deleted automatically.
- Sign-in sessions: 7 days; expired sessions are removed automatically every hour.
- Email verification and password reset links: expire after 24 hours and 4 hours respectively.
- Account, daily usage totals and uploaded files: for as long as your account exists.
- Payment and balance records: not deleted automatically; we keep them for as long as we need them to meet accounting, tax and legal obligations and to handle disputes.
- Email you send us: in our email inbox for as long as needed to handle your enquiry.
7. International transfers
The providers listed above process data outside the Republic of Korea, in the countries shown next to each. The information transferred is the information each provider needs, as described in that section; it is transferred over encrypted connections when you use the Service, and kept for the periods in “How long we keep it”.
These transfers are necessary to perform our contract with you and are disclosed here in accordance with the Personal Information Protection Act. For personal information subject to the GDPR or UK GDPR, transfers rely on an adequacy decision or on the standard contractual clauses in each provider’s data processing terms. You may object to a transfer by contacting us, but because the Service cannot run without these providers, we would then be unable to provide it to you.
9. Security
Passwords and API keys are stored only as hashes. Traffic to the Service is encrypted in transit. No system is perfectly secure; if a breach affects your personal information we will notify you and the authorities as the law requires.
10. Your rights
You can ask us to give you access to, correct, delete or export the personal information we hold about you, and to restrict or object to how we use it. You can change your name in your account settings. For anything else, including deleting your account, email privacy@apinoa.com from the address on your account. We will answer within the time the law that applies to you requires.
Deleting your account removes your account and the data linked to it, except records we must keep, such as payment and balance records, for the purposes described in “How long we keep it”.
11. If you are in the EEA or the UK (GDPR)
We process your personal information on these legal bases: to perform our contract with you (your account, the Service, billing); to comply with legal obligations (tax and accounting records); and our legitimate interests in securing, diagnosing and improving the Service and preventing abuse (error logs, rate limiting). Where we rely on consent, you may withdraw it at any time.
In addition to the rights above, you have the right to data portability and the right to lodge a complaint with your local data protection supervisory authority.
12. If you are in Korea (PIPA)
In accordance with the Personal Information Protection Act, the items we collect, the purposes we use them for, how long we keep them and the providers we entrust processing to are set out in the sections above. We do not provide your personal information to third parties beyond those providers except as required by law.
When a retention period ends, or the purpose of processing is achieved, we destroy the information without delay: database records are deleted, automatically for the logs described above, and electronic files are deleted so they cannot be restored.
You may exercise your rights to access, correct, delete or suspend the processing of your personal information by contacting our chief privacy officer at privacy@apinoa.com. You may also seek help from the Personal Information Protection Commission or the Korea Internet & Security Agency privacy center.
13. Children
The Service is offered for business use by people aged 18 or over, and we do not knowingly collect personal information from children.
14. Changes to this policy
We may update this policy by posting a revised version with a new effective date and, for material changes, emailing registered users beforehand.
15. Contact
Privacy questions and requests: privacy@apinoa.com.
See also the Terms of Service.