Introduction
APIFreaks is operated and maintained by its legal entity, JFreaks Software Solutions LLC ("we", "us"). This policy explains what we collect on apifreaks.com, why we collect it, how long we keep it, and what choices you have. It covers the APIs, tools, MCP server and agent integrations, site, documentation, and account dashboard.
For your account, payment, and site data we act as the controller. For the input you send to our APIs and tools we act as your processor, handling it on your instructions and for no other purpose. Enterprise customers can request a Data Processing Agreement as described in our Terms & Conditions.
If anything here needs clarifying, Contact Us.
What we collect
Your account. When you sign up we collect your name, email address, and password. We also hold any details you later add to your profile from your dashboard. If you use an organization account, we also hold the team structure and member details needed to manage seats and shared access.
Payment. Checkout payments are handled by Paddle as the merchant of record. Payment instrument details are collected by Paddle and never touch our infrastructure. Paddle shares only the transaction details we need to fulfill your purchase and maintain our records.
API usage. Calls to APIFreaks endpoints are logged so we can keep the platform secure, stop abuse, and bill accurately. Those logs cover the key used, the endpoint called, the time, the originating IP address, and the outcome, and we keep them for 30 days. They do not include a full copy of your request content. Calls that arrive through our MCP server or an agent integration are authenticated and logged in the same way as direct calls.
Tools. Tools that require you to be signed in draw on your credit balance, so a request to one is recorded against your account in the same way an API call is, and for the same 30 days.
Messages you send us. When you use the contact form or the support chat, we keep your message and the details you used to reach us for as long as it takes to resolve the issue and handle anything that follows from it.
Cookies and browser storage
We use cookies and similar browser storage on the site. You can manage what is allowed through the cookie preference control on the site, and reopen it at any time to change your choice.
Essential cookies and browser storage are set by us and cannot be switched off, because the site does not function without them. They keep you signed in, protect your session, and remember your preferences. Your consent choice is itself stored in local storage so that we do not have to ask you again on every visit.
With your consent, we use third-party analytics services to understand how the site is used. They collect limited usage information, such as the pages visited, how you interact with them, and general device and browser characteristics; depending on the service and your choice, this may or may not involve cookies or similar browser storage. We review this information in aggregate to improve the site's performance and usability. If you decline or later withdraw consent, these services stop tracking your visits from that point: no analytics identifiers are set or read, and your activity is no longer recorded against you. Only essential cookies and browser storage are needed for the site to work.
How we use it
Everything above exists to run the Service: creating and securing accounts, delivering the API results you request, metering usage and processing payments, answering your questions, and sending the service messages you need to receive, such as receipts, quota alerts, and notice of changes to our terms or this policy. We also use it to protect the platform, through authentication, rate limiting, and fraud and abuse prevention, and to meet our tax and legal obligations. Where you have allowed optional third-party analytics and performance cookies, we use visitor data in aggregate to understand site usage and improve performance.
The content of your requests, and the results they return, is yours. We process it to return your result and do not use it for purposes of our own.
Newsletter
Our newsletter is optional. You can turn it on when you sign up or later from your dashboard, and turn it off the same way. Opting out stops the newsletter only, not the service messages tied to your account.
How long we keep things
Your account details stay with us for as long as your account is open. Access logs are kept for 30 days.
Where a request involves uploading a file or generating one, we hold it only as long as needed to complete the request and make the result available to you.
You can delete your account yourself, from your dashboard, without contacting us. Access ends immediately and your keys stop working. Your account data then stays on our infrastructure for 90 days, so the account can be restored if the deletion was a mistake and so we can still act on any fraud or abuse that involved it. If you want it restored, Contact Us within those 90 days. After that, it is wiped from our systems permanently and cannot be restored.
Payment and invoice records are the exception. We are required to keep proof of transactions for tax and accounting purposes, so those survive the deletion of your account, held both by us and by our payment provider under its own retention rules.
Who else handles your data
We do not sell your personal data, and we do not share it with advertisers or data brokers.
A small number of service providers process data on our behalf so the platform can operate. They fall into these categories: payment processing, optional third-party sign-in, security and bot protection, support and communication, hosting and infrastructure, service email delivery, and optional analytics. Each provider receives only the data needed for its role, is required to protect it to the standard set out in this policy, and may use it only for the purpose we engaged it for. Unless you have consented to analytics, nothing analytics providers receive is linked to you or recorded against you.
These providers, and we, may process data in countries other than the one you are in. Where those transfers require a specific legal mechanism, we rely on Standard Contractual Clauses or other lawful transfer tools.
We may also disclose information where the law requires it, or where it is necessary to protect the platform, our users, or our rights.
EEA and UK (GDPR)
If you are in the EEA or the UK, GDPR lets you ask us for a copy of the personal data we hold about you, ask us to correct it, ask for erasure where we no longer have a lawful reason to keep the data, receive a portable copy of data you gave us, restrict or object to certain processing, and withdraw consent you have given for optional cookies or the newsletter. You can also delete your account yourself from your dashboard. To make a request, Contact Us; we may need to confirm it comes from the account holder before acting on it. We do not make automated decisions about you that produce legal or similarly significant effects. Our grounds for processing are the contract with you (running your account and the APIs), legitimate interests (a secure platform), consent (optional cookies and the newsletter), and legal obligation (tax and accounting records). If you are not satisfied with how we handle a request, you can lodge a complaint with your local data protection authority.
California (CCPA / CPRA)
If you are in California, CCPA and CPRA let you ask what personal information we have collected and why, ask us to delete or correct it, and opt out of the sale or sharing of personal information. We do not sell or share personal information as those laws define it, so there is nothing to opt out of. Using these rights will not cost you anything or change the service you receive.
How we protect your data
All traffic to APIFreaks is encrypted in transit over HTTPS. Passwords are stored hashed rather than in readable form. Access to production systems is limited to the people who need it, and payment instrument details never touch our infrastructure at all.
Children
APIFreaks is built for developers and businesses, and our Terms require you to be 13 or older to use it. We do not knowingly collect personal data from anyone under 13. If you believe a child has created an account, Contact Us and we will remove it.
Changes to this policy
If we make a change that materially affects you, we will update the date at the top and let account holders know by email or in the dashboard before it takes effect. Minor clarifications may be made without notice.
Contact
For privacy questions about APIFreaks, data requests, or security reports, Contact Us.
Company
APIFreaks is operated and maintained by its legal entity, JFreaks Software Solutions LLC, and built in Lahore, Pakistan. The company is registered at:
JFreaks Software Solutions LLC
7345 W Sand Lake Rd, Ste 210, Office 5169
Orlando, FL 32819
United States
Phone: +1 (917) 724-2931