Effective Aug 28, 2026
APIDir privacy policy
APIDir collects the minimum data needed to operate the directory, measure usefulness, and deliver requested email.
Who is responsible
APIDir operates this directory. Privacy, access, correction, deletion, and consent questions can be sent to contact@apidir.dev.
Data we process
APIDir processes request metadata needed to deliver and secure the site, aggregate page and conversion analytics on ordinary public pages, an email address when you request an email feature, and contact details when you submit a private editorial request or service inquiry. We do not ask for provider API keys, private prompts, billing credentials, or passwords.
Private stack submissions
A stack submission may include a product name and URL, founder or representative name, contact email, selected providers, public evidence URL, use-case description, consent version, and source declaration. APIDir uses these fields only for private editorial, permission, abuse-prevention, and correction review. A submission is never published automatically, and contact details are not added to a public profile.
Pending submissions remain private while reviewed. Rejected submissions are not published. Approved public evidence may be retained for source and correction history, while private contact fields remain restricted. When operational notifications are configured, only an opaque submission identifier is sent to the Feishu review channel; submitted fields remain in the restricted D1 record. You may request access, correction, or deletion of a private submission at any time.
Private provider submissions and payment records
A provider submission may include provider and contact names, contact email, public website, pricing, documentation and API URLs, model-route notes, consent version, payment amount and status, and opaque Yito Pay order and event identifiers. APIDir stores these fields for payment reconciliation, abuse prevention, source review, follow-up questions, refunds, and privacy requests. Payment details are entered with the payment provider; APIDir does not receive or store full card or bank credentials.
Payment purchases intake and source review only. It never guarantees publication, ranking, a badge, or a positive result. Submitted contact details and payment identifiers are not added to public provider profiles. Operational notifications contain an opaque submission identifier rather than the submitted contact fields.
Private provider-service inquiries
A provider-service inquiry may include company and contact details, requested service, project context, budget range, timeline, consent version, and submission metadata. APIDir stores it in restricted D1 records only for scoping, contact, abuse prevention, service delivery, and privacy requests. It does not create a public profile, editorial decision, checkout, or payment.
When operational notifications are configured, only an opaque inquiry identifier is sent to the Feishu review channel. Submitted fields are not copied into that notification. You may request access, correction, or deletion by using the privacy contact above.
Analytics on ordinary public pages
When configured, ordinary public pages load Google Analytics 4, the analytics script at click.pageview.click, and Cloudflare Web Analytics. Analytics may process the visited URL, referrer, approximate location derived from network information, browser or device information, and page or interaction events. APIDir sends bounded events such as calculator completion, sharing, and provider-link use; their event payloads omit email addresses, confirmation tokens, private prompts, and payment payloads. A shareable cost-result URL contains the bounded token quantities entered in its query string, so page-URL analytics may process those values; do not enter confidential business information.
A browser can automatically send Google the page URL and IP address when Google Analytics loads. Read how Google uses information from sites that use its services, use Google's Analytics opt-out browser add-on, and review Cloudflare's privacy policy. This privacy page and sensitive email-action pages do not load APIDir's analytics scripts.
Advertising and cookies
APIDir identifies its Google AdSense publisher account in public page metadata and ads.txt, but advertising scripts are currently disabled. Before ads are enabled, APIDir must configure consent controls that satisfy the applicable region and Google's certified consent-management requirements.
If advertising is enabled, third-party vendors including Google may use cookies or similar storage to serve ads based on a visitor's prior visits to APIDir or other websites. Google's advertising cookies allow Google and its partners to serve and measure ads; other disclosed ad vendors may also use their own cookies under their policies. Visitors can control personalized advertising in Google Ads Settings or use participating-vendor controls at YourAdChoices. Rejecting non-essential advertising storage will not block APIDir research.
Email consent
Email subscriptions use double opt-in. APIDir records pending, active, unsubscribed, bounced, and complained states, source path, consent version, and immutable request or confirmation events so it can prove and respect the choice. Each research email includes an unsubscribe path.
Service providers and external links
APIDir uses Cloudflare Workers and D1 for delivery and structured records, Yito Pay and Stripe for provider-submission checkout and payment processing, ZeptoMail for transactional and approved editorial email, and Feishu for bounded operational notifications when configured. Provider, source, payment, and partner links lead to independent services governed by their own privacy terms. APIDir does not send calculator token quantities or subscription email addresses in provider-link URLs.
Retention and security
Price evidence is retained for audit and correction history. Subscription consent and suppression records are retained as needed to honor delivery choices and prevent a later accidental resubscription. Private submissions, payment reconciliation identifiers, and operational records are retained only for review, evidence history, refunds, abuse prevention, security, and privacy-request handling. Logs are designed to omit email addresses, tokens, credentials, payment bodies, and webhook bodies. Access is restricted to operational purposes.
Your choices
You may block or clear browser storage, use the provider controls linked above, unsubscribe from research email, or request access, correction, or deletion by emailing contact@apidir.dev. Some suppression, security, payment reconciliation, or evidence records may need to remain when required to honor your choice, prevent abuse, resolve a charge or refund, or keep an auditable source history.