Privacy policy

Two hats: for your account we are the controller; for the traffic you proxy through us we are your processor, and the DPA governs. Last updated 8 August 2026.

What we collect, as controller

Proxied traffic, as processor

Traffic through your proxies is processed on your instructions under the data processing addendum. What our systems retain from it: violation fingerprints and one redacted example per fingerprint per window - never a full request or response body, and credential headers are stripped before a violation record is even assembled. Conforming traffic is forwarded and forgotten. Retention follows your plan (7 days to 1 year) and your deletion instructions.

Where it lives, who touches it

Service data is hosted in the UK/EU. The third parties we use are listed, with what they see and where they run, on the sub-processor list; today that is Stripe (billing) and Resend (transactional email), plus our hosting provider. We do not sell data, and nobody gets it for advertising - there is no advertising.

Your rights

Under UK and EU data protection law you can ask for access to, correction of, export of, or deletion of your personal data - mail admin@openapi-proxy.com and we answer within a month. Deleting your account from the account page does the same without the email. If you think we have handled your data badly you can complain to the ICO (UK) or your local supervisory authority - though we would appreciate the chance to fix it first.