AltAPIs Blog

AltAPIs · Trust centre

Privacy policy

A source-specific explanation of information collected by AltAPIs, its uses, recipients, retention, and your choices.

Updated 2026-09-15 · Applies to altapis.com
Trust centre Cookie policy Terms of use Disclaimer Affiliate disclosure Content & moderation Contact & privacy requests

1. Scope and responsibility

AltAPIs is the service name. The operator has not yet supplied a legal name, country, or postal address for this notice. This disclosure gap is not a claim of compliance; you can still send a request through the contact centre.

Use the secure contact and privacy-request form to reach the site operator. A direct privacy email has not yet been provided; the request centre works without email delivery.

This notice covers altapis.com, its forms, editorial content, newsletter tools and sponsored-ranking workflows. Third-party API providers, linked websites, payment pages and image hosts have their own practices. A listing is not an agreement for us to process your application’s end-user data.

2. Information we collect

The information depends on the feature you choose. Please do not put passwords, API keys, private keys, government-ID documents, health data, or other sensitive information into public or private text fields.

  • Browsing and security: the server receives an IP address, requested URL, time, browser/user-agent and possibly a referring URL. Infrastructure logs and short-lived rate-limit state help deliver and protect the site. Avoid putting personal data or secrets into search URLs.
  • Submissions: name, contact email, provider/source URLs, and the context you submit, plus time, review status and review notes. Submissions are private pending owner review; contact details are not deliberately published as listing content.
  • Privacy/contact requests: request type, optional email and country/region, message, case dates, status, replies and a hashed access key. The original access key is shown once to you and is not stored in readable form by the request service.
  • Newsletters, when enabled: email, selected topics, consent/confirmation history, delivery status, subscription and unsubscribe tokens. Legacy consent records may include a hashed IP address; a hash is not necessarily anonymous. New signups record the notice version without storing an IP hash in the subscriber record.
  • Sponsored campaigns, when enabled: submitted campaign identity, URL, description, email, amount/currency, provider transaction identifiers, status, accepted policy version and a hashed campaign-access token. Sponsored redirects add an aggregate click count; this does not identify unique people.
  • Owner operations: authenticated sessions, audit events, source snapshots, article drafts/revisions, approvals, uploaded media and AI generation records. These are not public visitor accounts.

3. Information from public sources

Directory information can be imported from approved public GitHub repositories, including public-apis/public-apis. Records may contain a maintainer’s or provider’s public name and links. Public availability does not remove privacy or intellectual-property rights. Use the contact centre to request correction, removal or an explanation of the source. Source updates are automated; ambiguous removals and editorial publication have review steps.

4. Why information is used

We use browsing/security data to serve pages, prevent abuse and investigate incidents; submission/contact data to respond and assess changes; newsletter data to deliver requested updates and honour opt-outs; and campaign data to fulfil and account for an ordered placement.

Where the EU/UK GDPR applies, the intended grounds are legitimate interests for proportionate site security and archive maintenance, steps requested before a contract/contract performance for commercial orders, consent for optional external images and marketing subscriptions, and legal obligation where a specific applicable law requires processing. We assess objections and whether less intrusive means can meet the purpose. These grounds are not interchangeable across countries: where local law requires consent or another condition, that condition must be met.

Providing contact information or accepting terms is not consent to advertising. We do not use these forms to build advertising audiences or sell mailing lists.

5. Service providers and disclosures

The website and its local backups run on a Hostinger VPS. Authorised operators and infrastructure providers may access information as needed to maintain the service. Backups on the same VPS are not off-site disaster recovery.

Newsletter delivery is currently disabled or not ready. No marketing send is enabled merely by this notice. The existing email integration is Resend; a future self-hosted mail service must be documented before activation.

Sponsored checkout is currently disabled or not ready. No crypto wallet or cryptocurrency payment processor is active through this notice. A future payment method requires updated notices and purchase terms before activation.

AI draft generation is not currently configured. The existing integration supports OpenAI for owner-selected briefs and source extracts; this notice does not activate it.

If you allow an externally hosted article image, its host receives a network request that can reveal your IP address and browser information. Images use a no-referrer policy. We cannot control the host’s logging or subsequent processing. You can keep them blocked and still read the article.

We may disclose necessary records in response to a valid legal requirement, to address fraud or protect rights, or as part of a genuine service ownership change subject to applicable safeguards and notice. We do not promise confidentiality against legally binding disclosure requirements.

6. International processing

The VPS processing region has not yet been confirmed in the public configuration. Do not assume that information stays in your country.

A provider may process information in other countries. Where applicable, the operator must verify processor terms, the locations/subprocessors involved and a lawful transfer mechanism, such as an adequacy decision or appropriate contractual safeguards. We do not claim that transfer agreements or certifications exist when they have not been verified. You may request more information through the contact centre.

7. Retention and deletion

Retention depends on the purpose, unresolved requests/disputes, security needs and actual legal recordkeeping obligations. We do not retain information merely because it might someday be useful. Current technical limits and gaps are set out below; these are not guarantees that an entire category disappears on a fixed day.

  • Owner authentication cookies expire after eight hours. The cookie-preference record expires after 90 days. A requested campaign-access key uses tab-scoped session storage; an older persistent campaign key can be cleared from Cookie preferences.
  • Rate-limit counters are in server memory, age out of their active window and disappear on service restart. Access/security logs rotate by size and may contain older requests until rotation. They do not currently have a universal day-based deletion schedule.
  • Unconfirmed newsletter links expire after 24 hours; this does not automatically erase the subscriber record. Unsubscribing stops future marketing selection. A minimal suppression record may need to remain to avoid resubscribing you.
  • Submissions, privacy cases, campaign records and newsletter evidence currently require owner review for deletion. Privacy-case content can be redacted by the owner once the case is closed; redaction does not erase information from unrelated stores or existing backups.
  • Local operational backups currently have no automatic expiry policy. They are access-restricted, not a publicly accessible archive. A deletion request must include backup handling and any restore safeguards; live deletion alone is not described as complete erasure. A documented retention schedule remains an operator action.

8. Choices and requests

You can ask for access, correction, deletion, a portable copy, restriction, objection, consent withdrawal, or information about recipients and sources. Use the secure request form and keep its access key to read replies without relying on email. You may ask a representative to act for you; proportionate identity and authority checks can be necessary before we disclose or change someone’s records.

We aim to review a request within 21 days. That is an operational target, not an extension of a shorter legal deadline or a guarantee of automated resolution. Applicable statutory timelines, lawful exceptions and extension notices take precedence. A denial should explain the reason and any available appeal route. Submit an appeal using the same contact centre. You can complain to your relevant regulator without first accepting our decision.

No advertising/analytics trackers or sale/sharing for cross-context behavioural advertising are implemented. Global Privacy Control keeps optional external images blocked in this browser. A Do Not Track signal also keeps them blocked. These controls do not stop essential delivery, security logs or information you choose to submit.

9. Regional rights

This service accepts privacy requests from people worldwide. The legal rights that apply depend on your location, the operator’s activities, statutory thresholds and commencement dates—not merely on visiting an international website.

  • EEA/UK: where the GDPR or UK GDPR applies, rights can include access, rectification, erasure, restriction, portability, objection and withdrawing consent, plus a complaint to a supervisory authority. Not every right applies to every record or processing basis.
  • California and other US states: where applicable, rights can include knowing/accessing, correcting, deleting or obtaining a copy, and opting out of sale, sharing, targeted advertising or certain profiling. We do not offer a financial incentive for personal information and do not penalise a privacy request. Applicable state appeal rights remain available.
  • India: where the DPDP Act and relevant rules apply and are in force, requests may concern access information, correction/completion/updating, erasure, consent withdrawal, grievances and nomination. The 2025 rules have phased commencement; this notice is not a representation that every provision is already in force or that AltAPIs has completed compliance. Moderating content does not exempt its personal-data processing.
  • Other jurisdictions, including Brazil, Canada, Australia and Switzerland: use the same request route for locally available access, correction, deletion, objection or complaint rights. Mandatory local protections are not waived by these policies.

10. Children and sensitive information

AltAPIs is intended for adult developers and businesses, not directed at children. Do not submit forms, subscribe or purchase if you are under 18. We do not implement parental-consent or child-verification workflows. If a child’s information has been submitted, ask us to investigate and remove it as required; an age statement is not a substitute for applicable safeguards.

11. Security and automated processing

Controls include HTTPS, restricted owner access, request limits and protected local data files. No website or VPS can be guaranteed immune from compromise. If a personal-data incident occurs, the operator must assess it and meet applicable notification duties; this policy does not promise that a notification system is fully automated.

Source sync, ordering and AI draft tools automate parts of the archive. Paid positions reflect disclosed commercial rules, not a decision about your credit, employment or legal eligibility. Private request cases are handled by the owner, not decided by an AI system.

12. Changes to this notice

The version and update date appear on this page. Material changes to collection or optional features require an updated explanation and, where required, a new choice before those features operate. Earlier consent is not permission for an unrelated new purpose.

Trust centre · Privacy policy · Cookie policy · Terms of use · Disclaimer · Affiliate disclosure · Content & moderation · Contact & privacy requests

Sponsored placement is not independent rank.