Apiguru

Privacy policy

Last updated 5 September 2026

Apiguru operates the Amazon data API at apiguru.app, the dashboard at dash.apiguru.app and the agent endpoints at agent.apiguru.app and mcp.apiguru.app. This policy says what those services collect, why, who else sees it, and how to get it removed. Questions or requests: [email protected].

What we collect

If you create an account: your email address, a hashed password (never the password itself), a normalised form of your email used to stop one person opening many free trials, your API key, and — if you sign in with Google — your Google account identifier. We record the IP address you registered from, the country derived from it, and where you arrived from (referrer or campaign), to tell real signups from automated ones.

When you call the API: we log the endpoint, the query parameters you sent, the time, the response status, how long it took, and the calling IP address. We need this to bill correctly, to show you your own usage, and to investigate abuse and outages. The parameters are part of the request, so an ASIN or a search term you query is stored in that log.

If you pay: Stripe processes the payment and holds the card details. Card numbers never reach our servers. We keep the Stripe customer and subscription identifiers, your balance, your plan and your usage counts.

If you pay as an agent (x402): the keyless path needs no account and we hold no personal data for it. We record the paying wallet address, the amount and the settlement reference, because the payment happens on a public blockchain (Base). Free probe budgets are counted per IP address; IPv6 addresses are grouped by their /64 block.

If you email us or use the feedback wall: what you write. Feedback wall entries are public by design — the message, the category, the tool it is about, the agent name and any contact you add are shown to everyone. The IP address behind a submission is stored for rate limiting and is never published.

If you receive our email: whether you opened it and whether you clicked, through a tracking pixel and redirect links. Every message carries an unsubscribe link, and account and billing email is sent regardless.

Analytics and cookies on the dashboard

The dashboard and marketing pages load, in addition to the session cookie that keeps you signed in:

  • Google Analytics 4 and Google Ads — page views and conversions, so we know which ads bring people who actually use the API.
  • Microsoft Clarity — heatmaps and session recordings of how pages are used. Recordings can capture what you type into a page, so do not paste secrets into fields that are not meant for them.
  • PostHog — product analytics, served through our own domain. Once you are signed in, events are associated with your account id.
  • Cloudflare Turnstile on the registration form, to keep bots out.

Blocking these in your browser does not affect API access. The API itself sets no cookies and runs no analytics scripts.

Who else sees your data

We share only what each of these needs to do its job, and we do not sell personal data to anyone:

  • Stripe — payments and invoices.
  • Google — analytics, ads measurement and, if you use it, sign-in.
  • Microsoft — Clarity analytics.
  • PostHog — product analytics.
  • Cloudflare — DNS, bot protection and the marketing site.
  • ZeroBounce — a one-off deliverability check of the email address at signup.
  • Our mail provider — sending account and product email.

We will disclose data if the law requires it. We do not sell or rent it, and we do not build advertising profiles out of what you query.

Where the data lives, and for how long

Our servers are in Germany (Hetzner). Some processors above operate in the United States, so data reaches them there.

  • Account records: until you ask us to delete the account.
  • API request logs: kept while they are useful for billing disputes, usage reporting and abuse investigation, then removed.
  • Feedback wall entries: kept until you ask us to remove them.
  • Email tracking: kept with the campaign record.
Your rights

Write to [email protected] from the address on the account and you can get a copy of what we hold, have it corrected, have the account and its data deleted, or object to the analytics above. If you are in the EEA or the UK you also have the right to complain to your data protection authority. Deleting an account does not erase blockchain payment records, which we cannot alter.

Security

Everything is served over HTTPS. Passwords are stored hashed. API keys are secrets: treat one like a password, and rotate it from the dashboard if it leaks. Tell us at [email protected] if you believe an account has been compromised.

Children

Apiguru is a developer tool and is not directed at children. Do not create an account if you are under 16.

Changes

If this policy changes materially we will update the date at the top and, for account holders, say so by email.