Privacy Policy
Last updated: 25 August 2026
This Privacy Policy explains what personal data API Stock ("we", "us") collects when you use the API Stock website, dashboard and API, why we collect it, who we share it with, and what you can ask us to do with it. It forms part of our Terms of Service.
1. Controller
API Stock is the controller of the personal data described here. For privacy questions, and to exercise any of the rights in section 8, contact [email protected].
2. Data we collect
We collect only what the Service needs to run and to bill correctly.
- Account data — your email address, and the name and avatar your sign-in provider gives us if you sign in with Google or GitHub. If you register with a password, we store only a hash of it.
- Session data — the session token, its expiry, and the IP address and user agent of the device that created it.
- API keys — the keys issued to your account, their settings, and when each was last used.
- Generation data — for each request: the model, the parameters you sent (including your prompt and any media URLs you referenced), the status, timings, the price charged, and any error message returned.
- Generated media — the files a model produced for you, stored on our own storage and served to you from there.
- Chat usage — for LLM requests we record the model, the provider, and token counts and cost. We do not store the message content of chat requests.
- Payment data — the amount, currency, method, status and the acquirer's transaction reference. We never receive your card number or wallet credentials; those go to the acquirer directly.
- Technical data — IP address and derived country, used for security, abuse prevention and routing.
- Device data — when you visit the website we ask our identity service for a device identifier derived from your browser and device. We store it together with the signup trial it was granted for, so that the free trial can be given once per device rather than once per email address. It is not used for advertising or profiling.
- Analytics data — page URLs, traffic sources, campaign parameters, referrers, device and browser information, Google Analytics client and session identifiers, and selected product-funnel events. We briefly retain a server-side delivery record for confirmed events such as sign-up, first successful request and payment. When you are signed in, analytics events may be associated with your internal user ID; we do not send your email address to Google Analytics.
3. Why we process it, and on what basis
- To provide the Service — running generations, delivering results, and firing the webhooks you configure. Basis: performance of our contract with you.
- To price, charge and refund correctly, and to keep the usage history you see in the dashboard. Basis: performance of our contract, and our legal obligation to keep accounting records.
- To authenticate you and keep accounts secure. Basis: performance of our contract, and our legitimate interest in securing the Service.
- To detect, investigate and prevent fraud, abuse and breaches of our acceptable-use rules. Basis: our legitimate interest, and compliance with legal obligations.
- To operate and improve reliability — monitoring, error diagnosis, capacity planning. Basis: our legitimate interest.
- To contact you about the Service, including changes to these policies. Basis: performance of our contract.
- To measure campaign, page and signup performance using Google Analytics. Basis: the consent you give by accessing or continuing to use the website, your agreement to these Terms, and our legitimate interest in measuring and improving the Service.
- We do not use your prompts, media or outputs to train models, and we do not sell personal data.
4. Who we share it with
We share data only with the parties needed to deliver the Service:
- Upstream model providers — when you make a request, its parameters, including your prompt and any media you reference, are sent to the provider serving that model. Which provider serves a request depends on the model, the parameters and provider availability. Each provider processes that data under its own privacy policy.
- Payment providers — our crypto and card acquirers receive the amount, the order reference and whatever they need to take the payment. They are independent controllers of the payment data they collect from you.
- Infrastructure providers — hosting, object storage, database and cache providers acting as our processors.
- Google Analytics — Google receives website analytics data described in this Policy to provide traffic and product-funnel reports. We do not enable Google Ads or remarketing through this integration.
- Authorities — where we are legally required to disclose, or where disclosure is necessary to establish or defend legal claims.
- A successor — if we are involved in a merger, acquisition or sale of assets, subject to this Policy continuing to apply.
5. International transfers
Our providers and infrastructure may be located outside your country, including outside the European Economic Area. Where personal data is transferred from the EEA or the UK, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses with appropriate additional safeguards.
6. How long we keep it
- Generated media is kept for the retention period shown in your usage log and is then deleted from our storage. Download anything you need to keep.
- Generation records — the model, parameters, status and price — are kept while your account exists, so that your usage history and billing remain auditable.
- Payment and accounting records are kept for as long as tax and accounting law requires, typically several years, even after an account is closed.
- Account and session data is deleted when you delete your account, except for what we must retain by law or to defend a legal claim.
- Security and abuse logs are kept for a limited period proportionate to the risk.
- Google Analytics identity links are kept for up to 400 days after the browser was last seen, and successfully delivered server-event records are normally removed after 30 days.
- Google Analytics event data is configured for 14-month retention.
- The device identifier attached to a signup trial is kept after the account is deleted, and is detached from it — otherwise deleting an account would release the device for another free trial. The matching browser cookie expires after 24 hours.
7. Security
We protect data in transit with TLS, store passwords only as hashes, isolate the database and cache from the public internet, and restrict internal access to those who need it. API keys are secrets you control: you can deactivate, regenerate or delete any key from the dashboard, and doing so takes effect immediately. No system is perfectly secure, and we cannot guarantee absolute security.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and receive a copy of it in a portable format;
- have inaccurate data corrected;
- have your data deleted, subject to the retention we are legally required to apply;
- restrict or object to processing we carry out on the basis of legitimate interests;
- withdraw consent where processing is based on consent, without affecting processing already carried out;
- lodge a complaint with your local data protection authority.
- To exercise any of these, write to [email protected]. We will respond within the period the applicable law requires, normally one month.
9. Cookies and similar technologies
We use strictly necessary session technologies, browser preferences and Google Analytics for page usage and product-funnel measurement. Google Analytics loads when you use the website. By accessing or continuing to use the website, you consent to this analytics collection. Google Ads and remarketing remain disabled. See our Cookie Policy for the identifiers, retention periods and browser controls available to you.
10. Children
The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy. We will publish the updated version with a new effective date and, where the change materially affects how we handle your data, notify you by email or in the dashboard before it takes effect.
12. Contact
Privacy questions and requests: [email protected].