Privacy policy
bigapi.dev, api.bigapi.dev, console.bigapi.dev · Controller: Artoption GmbH, Hamburg, Germany · support@bigapi.dev
1. What we process and why
- API keys and accounts. A key is created without personal data. We store a hash of the key, its name, creation and last-use time, balance and usage counters. Legal basis: contract (Art. 6(1)(b) GDPR).
- Files you send. Files are processed in memory or in a temporary directory and deleted immediately after the response is delivered, at the latest within 10 minutes. We do not read, index or keep them.
- Usage records. Per operation: type, timestamp, duration, page count, size, cost, HTTP status, key id. Kept for billing and abuse prevention, 24 months. No file content.
- Key issuance limits. A salted hash of the IP address with a daily counter, kept 7 days, to limit free keys per IP (legitimate interest, Art. 6(1)(f)).
- Payments. Handled by Stripe as merchant of record (Stripe Payments Europe Ltd.). We receive your email, the amount and a payment reference; we never see card data. Stripe’s privacy notice: stripe.com/privacy.
- Server logs. IP address, request path, status, timestamp, user agent – 14 days, for security and fault diagnosis.
- Unknown paths. Requests to non-existent API paths are counted per path and day (no key, no IP) to decide which operations to build next.
2. Where
Processing servers: Hetzner Online GmbH, Germany. Account database: Supabase (EU region). Website and console hosting: Hostinger (EU). Fonts are loaded from Google Fonts (Google Ireland Ltd.) – this transmits your IP address to Google; we will self-host fonts in a future release.
3. Cookies and tracking
None. The console stores your API key in your browser only if you tick “remember on this device”. No analytics, no ads.
4. Your rights
Access, rectification, erasure, restriction, portability and objection under Art. 15–21 GDPR, and the right to complain to a supervisory authority (for us: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit). To exercise them, email support@bigapi.dev from the address linked to your account, or quote your key prefix.
5. Deletion
Revoke keys any time in the console. To delete the account and its records, email us; balance refunds follow the terms.
Last updated: 22 August 2026.