API Privacy Agreement
Draft — pending counsel review · not yet in force1Scope, plainly
This policy covers the Scan API: your API account, your usage, and the query data you send us. It is deliberately short, because we collect deliberately little. The consumer app’s privacy policy is separate.
2What we hold about you, the customer
- Account: a business email, an organisation name, and the API key we issued. No profile, no enrichment.
- Billing: handled by the channel you chose — Stripe, AWS, or Microsoft. We never see or store card numbers. We hold the invoice ledger: calls made, rates applied, amounts billed.
- Usage and metering logs: per call — timestamp, endpoint, domain queried, result status, latency. Kept because the meter is the contract; used for billing, rate limiting, abuse prevention and honest benchmarks.
3The people you scan
Answers derive from publicly indexed pages only — no private databases, no logins, no purchased data about your subjects. Where the subject’s page is not publicly indexed, the honest answer is “indeterminate,” and that is what you get.
4What we never do
- Sell or share your queries, your subjects’ data, or your results — to anyone, including advertisers, data brokers, or “partners.” Not as “sale,” not as “sharing” as California defines those words.
- Use your query patterns to compete with you or to inform anyone else’s product.
- Enrich, append, or resell the identities you submit.
5Retention
- Query identities and evidence payloads: retained 90 days for invoice disputes and abuse investigation, then deleted. You can request earlier deletion of specific queries at any time.
- Metering ledger (counts, amounts, statuses — no subject identities): retained as long as tax and accounting law requires.
- Account data: deleted within 30 days of account closure, minus what the law makes us keep.
6Security and subprocessors
Keys are hashed at rest, transport is TLS, access is least-privilege and logged. We use a small set of subprocessors — cloud infrastructure, the search providers that serve public-index queries, and the billing channels — each bound to use your data only to provide their service to us. The current list is available on request at [email protected].
7Your rights, and your subjects’ rights
You can get a copy of what we hold about your account, correct it, or delete it — email [email protected], answered within 30 days, no fee. Where a person you scanned exercises privacy rights against us directly, we honour them for the data we hold (Section 5) and refer them to you for the data you hold — as your service provider we don’t decide what you keep.
8Changes and contact
Material changes come with 30 days’ notice to your account email. The promises in Sections 3 and 4 are floors, not snapshots — a change will never weaken them for data already collected. Questions: [email protected]. Disputes follow the same remedy-petition-then-arbitration path as the API Terms, Section 10.
This document is written in plain English on purpose. Where plain English and legal effect could diverge, counsel review resolves it before this takes force.