Privacy policy
Two hats: for your account we are the controller; for the traffic you proxy through us we are your processor, and the DPA governs. Last updated 8 August 2026.
What we collect, as controller
-
Account data
Email address, password hash (PBKDF2; we never see the password), account and member names and roles, and the timestamps of the above. Used to run your account and to email you the things you asked for - verification, resets, invites, alerts.
-
Billing data
Handled by Stripe. We store your Stripe customer id, subscription id, plan and usage counts. Card numbers never touch our infrastructure.
-
Operational logs
Web server logs for the control plane (this site): IP address, user agent, path, time - kept 30 days for security and debugging, then deleted.
-
Cookies
One signed session cookie, plus a CSRF token cookie. No tracking cookies, no analytics beacons, no third-party scripts - the pages you are reading load nothing from anyone else.
Proxied traffic, as processor
Traffic through your proxies is processed on your instructions under the data processing addendum. What our systems retain from it: violation fingerprints and one redacted example per fingerprint per window - never a full request or response body, and credential headers are stripped before a violation record is even assembled. Conforming traffic is forwarded and forgotten. Retention follows your plan (7 days to 1 year) and your deletion instructions.
Where it lives, who touches it
Service data is hosted in the UK/EU. The third parties we use are listed, with what they see and where they run, on the sub-processor list; today that is Stripe (billing) and Resend (transactional email), plus our hosting provider. We do not sell data, and nobody gets it for advertising - there is no advertising.
Your rights
Under UK and EU data protection law you can ask for access to, correction of, export of, or deletion of your personal data - mail admin@openapi-proxy.com and we answer within a month. Deleting your account from the account page does the same without the email. If you think we have handled your data badly you can complain to the ICO (UK) or your local supervisory authority - though we would appreciate the chance to fix it first.