Effective Aug 21, 2026

APIDir privacy policy

APIDir collects the minimum data needed to operate the directory, measure usefulness, and deliver requested email.

Data we process

APIDir processes request metadata needed for security, aggregate page and conversion analytics, and an email address when you request APIDir Delta. We do not ask for provider API keys.

Analytics

Public pages load Google Analytics 4 when configured, the analytics script at click.pageview.click, and Cloudflare Web Analytics. Sensitive email-action pages disable analytics and edge transformations. Analytics must not receive email addresses, confirmation tokens, private prompts, or payment payloads.

Email consent

Email subscriptions use double opt-in. Pending, active, unsubscribed, bounced, and complained states are recorded so APIDir can respect delivery choices.

Infrastructure

APIDir uses Cloudflare Workers and D1 for application delivery and structured records, plus ZeptoMail for transactional confirmation and operational email when configured.

Retention and security

Price evidence is retained for audit. Subscription and consent records are retained as needed to honor consent and suppression. Logs omit email, tokens, credentials, and webhook bodies.

Your choices

Every research email includes an unsubscribe path. For access, correction, or deletion requests, email contact@apidir.dev.