Legal
Privacy Policy
Last updated July 13, 2026
This Privacy Policy explains how AnyAPI Labs, Inc. ("AnyAPI," "we," "us") handles personal information when you use our website (getanyapi.com), the API gateway at api.getanyapi.com, our documentation, and related services (together, the "Service").
1. Scope: controller vs. processor
This policy covers personal information we handle as a controller: your account, billing, support communications, and how you use our websites and gateway.
Data retrieved through the Service on your instructions (request parameters and API responses) is handled by us as your processor. You are the controller of any personal data it contains, you are responsible for having a legal basis to collect it, and that processing is governed by our Terms of Service and, where executed, a data processing addendum, not by this policy.
2. Information we collect
- Account information. Name, email address, and sign-in identifiers, collected through our authentication provider when you create an account or sign in.
- Billing information. Wallet top-ups are processed by our payment processors. We receive transaction records and limited card metadata (such as brand and last four digits); we never receive or store full card numbers.
- Phone verification information. If you choose to verify your phone for a promotional credit, we process your phone number, IP address, user agent, and browser and device signals to complete verification and prevent fraud. We do not store the verification code.
- Request and usage data. When you call the gateway we log the API key used, the endpoint called, request parameters, response status, latency, amount charged, timestamps, IP address, and user agent. We use these logs to operate, bill, debug, and secure the Service.
- Site analytics. We use product analytics (PostHog) on our websites to collect usage events, device and browser information, and pages visited. Analytics traffic is proxied through our own domain. Sessions may be recorded to help us improve the product.
- Communications. Messages you send us, such as support requests.
3. How we use information
- Providing and operating the Service, including authenticating you and metering and billing your usage.
- Securing the Service: preventing fraud, abuse, and multi-account misuse of promotions.
- Debugging, support, and improving the product.
- Sending transactional messages (receipts, balance and security notices) and, with an opt-out, product updates.
- Complying with legal obligations, including tax and accounting requirements.
4. How we share information
We do not sell personal information. We share it with service providers who process it on our behalf:
- Clerk: authentication and account management.
- Autumn: billing and payments (via Stripe as payment sub-processor).
- PostHog: product analytics and session replay.
- Prelude: optional phone verification and fraud prevention.
- Cloudflare and Microsoft Azure: hosting, content delivery, and infrastructure.
When you make an API request, the request parameters needed to fulfill it are shared with the third-party services we use to retrieve the data. We may also disclose information if required by law or legal process, to protect our rights or the safety of others, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to it).
5. Cookies and similar technologies
We use strictly necessary cookies for authentication and session management, browser storage for preferences (such as your theme choice), and analytics cookies and storage for the product analytics described above. You can control cookies through your browser settings; disabling necessary cookies may prevent sign-in from working.
6. Data retention
We keep account and billing information for as long as your account is active and afterwards as needed for legal, tax, and accounting purposes. A phone number pending verification is encrypted and deleted when the verification ends or within 24 hours. After a successful claim, we keep a one-way HMAC digest of the number, its country, and claim timestamps to enforce the one-phone limit without retaining the raw number. Request and response payloads are retained only for a limited period for operation, debugging, abuse prevention, and billing-dispute resolution, after which they are deleted or anonymized. Aggregated usage statistics that no longer identify you may be retained indefinitely.
7. Security
We protect personal information with technical and organizational measures, including encryption in transit, hashed credentials and API keys, and access controls. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you as required by applicable law.
8. International transfers
We are based in the United States and process information there. Where we transfer personal information from regions with data-transfer restrictions (such as the EEA, UK, or Switzerland), we rely on appropriate safeguards, including standard contractual clauses.
9. Your rights and choices
Depending on where you live (including under the GDPR, UK GDPR, and US state privacy laws such as the CCPA), you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. We do not sell personal information or share it for cross-context behavioral advertising. To exercise any right, email support@getanyapi.com; we will verify your request and respond within the time required by law. You may also lodge a complaint with your local supervisory authority.
10. Children
The Service is for business and professional use and is not directed to children. We do not knowingly collect personal information from anyone under 16; if you believe we have, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a revised "Last updated" date and, for material changes, notify you by email or through the Service.
12. Contact
Privacy questions and requests: support@getanyapi.com.