Privacy Policy
Last updated: July 31, 2026
This Privacy Policy explains how Endpointry (“Endpointry”, “we”) processes personal data when you use our websites and APIs (the “Services”). We act as the data controller for the account and billing data described below.
1. Data we collect
- Account data. When you sign in with Google, GitHub or LinkedIn we receive your name, email address and avatar from that provider. We never receive or store passwords.
- Usage metadata. For each API request we record operational metadata: endpoint, response status, latency, request ID and aggregate counts used for quotas and billing. We do not log response payloads.
- Billing data. Payments are processed by Stripe. We store your subscription state and Stripe customer reference; full card details never touch our systems.
- Communications. Messages you send us (contact form, email) including the contact details you provide.
2. Purposes and legal bases
- Providing and securing the Services (performance of a contract).
- Billing, accounting and fraud prevention (contract; legal obligation; legitimate interest).
- Service communications such as quota alerts and incident notices (legitimate interest).
- Product improvement using aggregated, de-identified usage statistics (legitimate interest).
We do not sell personal data and we do not use it for third-party advertising.
3. Subprocessors
We rely on a small set of infrastructure and service providers, currently: Cloudflare (hosting and edge network), Neon (database hosting), Stripe (payments) and Plausible (cookieless, privacy-first website analytics). Sign-in is delegated to Google, GitHub and LinkedIn. A current list with processing locations is available on request at legal@endpointry.com.
4. International transfers
Our providers may process data outside your country. Where GDPR applies, transfers rely on adequacy decisions or Standard Contractual Clauses put in place by the relevant provider.
5. Retention
- Account data: for the life of the account and up to 90 days after deletion.
- Usage metadata: raw request metadata up to 90 days; aggregated statistics up to 24 months.
- Billing records: as required by tax and accounting law.
6. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, restrict or delete your personal data, and to object to certain processing. Contact legal@endpointry.com and we will respond within 30 days. If you are in the EEA/UK you may also lodge a complaint with your supervisory authority.
7. Security
Security practices — including credential hashing, encryption in transit and data minimization — are described on our Security page.
8. Cookies
We use only essential cookies. See the Cookie Policy.
9. Enterprise customers (DPA)
A Data Processing Agreement incorporating Standard Contractual Clauses is available for Enterprise customers on request.
10. Changes and contact
We will announce material changes to this policy by email or in-product notice. Privacy questions: legal@endpointry.com.