Privacy Policy
Last updated: July 27, 2026
This Privacy Policy explains how Hi-Api (“we”, “us”) collects, uses, and protects personal data when you use the Hi-Api service (the “Service”). We act as the data controller for the account and usage data described below. It is written to meet our obligations under the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. Personal data we collect
- Account data — your name, email address, and a securely hashed password when you register.
- Team & organization data — organization membership, roles, and email addresses of people you invite.
- Billing data — subscription plan and billing status. Card details are collected and stored by our payment processor, Stripe, not by us.
- Content you create — the schemas, entries, endpoints, and request tokens you store in the Service, which may themselves contain personal data you choose to store.
- Technical & usage data — IP address, request logs, rate-limit counters, and language preference, used to operate and secure the Service.
3. Legal bases for processing
Under the GDPR / UK GDPR, we process your personal data on the following bases:
- Performance of a contract — to create your account, provide the Service, and manage your subscription.
- Legitimate interests — to secure the Service, prevent abuse, enforce rate limits, and maintain operational logs.
- Legal obligation — to keep records required by law, including for tax and accounting.
- Consent — where we ask for it explicitly; you may withdraw consent at any time.
4. Service providers (processors)
We share personal data only with providers that process it on our behalf:
- Stripe — payment processing and subscription billing.
- Resend — transactional email (verification, invitations, password resets).
- Our hosting and database providers — to store account data and your content (MongoDB and Redis).
Where data is transferred outside the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
5. Data retention
We keep your personal data for as long as your account is active. If your account is locked for non-payment, your data is retained for a short grace period so you can re-subscribe, and is then permanently deleted. Billing records are kept for as long as required by applicable law.
When an owner deletes their organization from the dashboard, we delete the organization, every member account, and all schemas, endpoints, request tokens and stored entries from our live systems immediately. Copies may persist in our encrypted operational backups for up to 30 days after deletion, after which those backups are rotated out and overwritten. Backups are only ever used for disaster recovery; if a backup is restored within that window, we re-apply outstanding deletions to the restored data.
6. Your rights
If you are in the EU or UK, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. You also have the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, contact us at privacy@hi-api.example. You can also exercise two of these rights yourself, without contacting us: under Account → Data in the dashboard you can download a machine-readable JSON export of your organization's data (portability), and an owner can permanently delete the organization and everything in it (erasure).
7. Security
We protect your data with industry-standard measures, including encryption of request tokens at rest, password hashing, httpOnly session cookies, and access controls. No method of transmission or storage is completely secure, but we work to protect your data and to notify you of breaches where the law requires it.
8. Contact us
For any question about this Privacy Policy or your personal data, contact Hi-Api at privacy@hi-api.example.