Privacy Policy
Last updated: 2026-09-18. This is a working draft pending legal review before public launch.
The short version
We process your files to do the job you asked for, then delete them. Default retention is 60 minutes, or immediately when you confirm the download. We do not train models on your files, we do not sell data, and we do not look at your content.
What we collect
Account data. Email, name, company and country. Needed to run your account and issue invoices.
Payment data. Handled entirely by Stripe. Card numbers never touch our servers — we store only a Stripe customer reference and the last four digits shown to you in your dashboard.
Usage data. Which endpoint, when, file size, duration, cost and outcome. Needed for billing, capacity planning and support. We keep it for 13 months.
Your files. Stored only for as long as it takes to process them and for you to collect the result, then deleted.
Technical data. IP address and user agent on API requests, retained for 7 days for abuse prevention and debugging.
File retention in detail
| Stage | Retention |
|---|---|
| Uploaded input | Deleted as soon as processing completes |
| Result | 60 minutes by default, configurable from 1 minute to 24 hours |
On your ack call |
Deleted immediately |
| Backstop | Storage lifecycle rule deletes anything left after 24 hours |
Three independent mechanisms, because one is not enough to be confident.
What we never do
We never train machine learning models on your files. We never sell or share your data with advertisers. We never read your file contents except when you explicitly ask us to investigate a specific failed job, and then only that job.
Subprocessors
We use Cloudflare, Amazon Web Services, Google Cloud, Supabase, Stripe and SendGrid. The current list with each one's role is at subprocessors. We give 30 days' notice before adding a new one.
Your rights
You can access, export, correct or delete your data at any time. Email hello@justapi.tech and we will respond within 30 days. Closing your account anonymizes your personal data within 60 days; we keep transaction records where accounting law requires it.
Security
TLS in transit and encryption at rest. API keys are stored hashed and never in plain text. Access to production systems requires multi-factor authentication. We will notify affected users within 72 hours of confirming a breach that puts personal data at risk.