Data processing addendum
You are the controller of the traffic you proxy; we are your processor. This page is the addendum incorporated into the terms of service for every account. Last updated 8 August 2026.
1. Subject matter and instructions
We process API traffic you route through your proxies, for the purposes you configure and no other: forwarding it to your upstream, validating it against the OpenAPI documents you supply, and producing violation and drift reports. Your configuration - modes, sampling, retention, deletion - is your documented instruction set. We process nothing for our own purposes beyond the aggregate statistics described in the terms, which contain no personal data.
2. What we retain
Violation fingerprints and one redacted example per fingerprint per window. Never a full request or response body.
A fingerprint is the shape of a violation - operation, schema
pointer, error class - not its content. The single example kept per
window has field values redacted before storage; field names survive,
contents do not. Authorization, Cookie and
similar credential headers are stripped before a violation record is
assembled. Conforming traffic is forwarded and not stored. Because
request bodies may contain personal data of your users, the categories
of data subjects and personal data are defined by what you choose to
send through your proxies; the mechanism above bounds what of it we
can hold.
3. Retention and deletion
Drift data is retained for your plan's window (7 days to 1 year) and then deleted. On account deletion or written instruction we delete your proxies promptly and purge stored data within 30 days, and confirm. After a downgrade, data is retained 30 days and then treated the same way. Backups age out on the same schedule.
4. Security measures
TLS in transit at the edge and to your upstream; tenant isolation by compiled per-tenant configuration; secrets held as references resolved at boot and redacted from output; card data never on our systems (Stripe); the fail-open design and its chaos evidence as described on the security page. Access to production is limited to people who operate it, on named accounts.
5. Sub-processors
The current list, with what each sees, is at /subprocessors. We add to it only with 30 days' notice to account owners, during which you may object; continuing to use the service after the notice period is acceptance. Each sub-processor is bound by terms no weaker than these.
6. Where processing happens
Service data is processed in the UK/EU. Where a sub-processor involves a transfer outside the UK/EEA (for example Stripe's or Resend's US operations), it is covered by the UK Addendum / EU Standard Contractual Clauses in that provider's terms.
7. Breach notification and audit
If we become aware of a personal data breach affecting your data we notify the account owner without undue delay and within 72 hours of awareness, with what we know and what we are doing. We assist with your data-subject requests and impact assessments to the extent the data we hold makes that meaningful. Once a year, on reasonable notice, you may audit our compliance with this addendum - in the first instance through our documentation and the security page's published evidence, and where that genuinely does not answer the question, by a review call.
8. The self-hosted alternative
Where even fingerprints must not leave your network, the Business tier's self-hosted data plane runs inside it, and this addendum then covers only your control-plane account data and whatever fingerprint stream you choose to enable.