Privacy Policy
Effective 23 August 2026 · Operated by Clean APIs
This policy explains what personal data Clean APIs ("we", "us") collects when you use cleanapis.com and our API, why we collect it, how long we keep it, who we share it with, and the rights you have over it. We have tried to describe this in plain terms rather than legal boilerplate.
1. Data we collect
Information you give us
- Account details — your name, email address, and optionally a phone number.
- Password — stored only as a bcrypt hash. We never store or transmit it in readable form, and we cannot recover it for you.
- Support messages — the contents of any ticket you open, so we can answer it.
- Payment references — for Binance Pay and cryptocurrency deposits, we store the transaction ID or blockchain hash you submit to automatically match and verify the incoming payment with our gateway.
Information from signing in with Google or GitHub
If you choose to sign in with Google or GitHub, we receive your name, email address, and profile picture URL from that provider, plus the provider's own account identifier so we can recognise you next time. We request only basic profile and email access. We never receive your password for those services, and we do not gain access to your Google account contents or your GitHub repositories. You can disconnect the provider at any time from your account settings, provided you have set a password first so you are not locked out.
Information created by using the API
- Usage records — timestamp, model requested, token counts, response latency, HTTP status, and which API key was used. This is what your dashboard and billing are calculated from.
- IP address — recorded with API requests and sign-in attempts, used for security, abuse investigation, and rate limiting.
- Session data — a session cookie so you stay logged in, along with the browser user-agent string.
Prompt and response content
We do not store the content of your prompts or the models' replies. Request bodies pass through our servers to the upstream model provider and are not written to our database. We keep only the metadata listed above — counts and timings, not text. One exception: if a request fails, a truncated error message from the provider may be recorded in our logs to make the failure diagnosable, and that message can occasionally include a fragment of the request.
Note that your prompts are transmitted to the upstream provider serving the model you selected, and that provider's own retention policy then applies to them. Which provider serves a given model is shown on our models page.
Payment card data
Card and online payments are handled entirely by Paddle on their secure systems. Card numbers never reach our servers and we cannot see them. We store only a token or reference and the last four digits, so you can recognise a saved payment method.
2. Why we use it
- To operate the service — authenticating you, routing API calls, metering tokens, and enforcing plan limits.
- To bill accurately — usage records are the basis of every charge, and you can audit them in your dashboard.
- To prevent abuse and fraud — detecting credential stuffing, shared or leaked API keys, and payment fraud.
- To contact you — verification codes, password resets, payment receipts, and service notices. Product and marketing emails are opt-in and off by default; you can change every notification type in your settings.
- To support you — reading and replying to your tickets.
- To meet legal obligations — retaining transaction records where the law requires it.
3. Who we share it with
We do not sell your personal data, and we do not share it for advertising. We disclose data only to:
- Upstream AI providers — your request content is forwarded to the provider serving the model you chose, because that is the service you asked for.
- Payment processors — Paddle receives the details needed to take a payment.
- Email delivery — the SMTP provider configured for this installation delivers your verification and notification emails.
- Infrastructure providers — our hosting provider and Cloudflare, which sits in front of the site for TLS termination and DDoS protection and therefore processes request metadata.
- Authorities — where we are legally compelled, or where disclosure is necessary to investigate a credible threat to someone's safety or to our systems.
If we are ever involved in a merger or acquisition, we will give notice before your data becomes subject to a different policy.
4. How long we keep it
- Account data — while your account exists.
- Usage records — retained so you can audit historical billing; aggregated well beyond that for capacity planning.
- Payment and invoice records — kept as long as financial and tax rules require, even after account closure.
- Verification codes — expire within minutes and are deleted once used.
- Payment screenshots — deleted once the payment is verified or rejected.
- Server logs — rotated on a short cycle.
5. Security
What we actually do, not aspirations:
- All traffic is served over HTTPS.
- Passwords are bcrypt-hashed.
- API keys are stored as a hash for verification, plus a separately encrypted copy so you can view your own key again. A stolen database alone does not yield usable keys.
- Upstream provider credentials and SMTP passwords are encrypted at rest.
- Sign-in and password-reset attempts are rate limited per account and per IP address.
- Verification codes expire quickly and lock out after a small number of wrong guesses.
No system is immune. If a breach affects your personal data, we will notify affected users and, where required, the relevant authority.
6. Your rights
You can, at any time:
- See your data — your dashboard shows your profile, usage history, invoices, and API keys.
- Correct it — update your name, email, and phone in settings.
- Export it — request a machine-readable copy of your account and usage data.
- Delete it — delete your account from settings. This removes your profile, API keys, and sessions. Invoices and transaction records are retained where financial law requires, and anonymised usage aggregates may remain.
- Choose what we email you — every optional notification type can be switched off; we will still send security and billing notices that are part of the service.
- Withdraw provider access — disconnect Google or GitHub, or revoke our access from that provider's own security settings.
To exercise any of these, email [email protected]. We will respond within 30 days.
7. Cookies
We use a session cookie to keep you signed in, a CSRF token cookie to protect forms from cross-site request forgery, and an optional "remember me" cookie if you tick that box. These are strictly necessary for the site to work and cannot be disabled while using an account. We run no advertising or third-party analytics trackers. Cloudflare may set its own cookie for security purposes.
8. International transfers
Our servers, our payment processors, and the AI providers we route to may be located outside your country. By using the service, you understand that your data — including the prompts you send — will be processed in those jurisdictions.
9. Children
The service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
10. Changes to this policy
We will update the effective date at the top when this policy changes. For changes that materially affect your rights, we will notify account holders by email or an in-app notice before they take effect. Continuing to use the service after that means you accept the updated policy.
Questions about this document? Email [email protected].