Effective Aug 21, 2026
APIDir privacy policy
APIDir collects the minimum data needed to operate the directory, measure usefulness, and deliver requested email.
Data we process
APIDir processes request metadata needed for security, aggregate page and conversion analytics, and an email address when you request APIDir Delta. We do not ask for provider API keys.
Analytics
Public pages load Google Analytics 4 when configured, the analytics script at click.pageview.click, and Cloudflare Web Analytics. Sensitive email-action pages disable analytics and edge transformations. Analytics must not receive email addresses, confirmation tokens, private prompts, or payment payloads.
Email consent
Email subscriptions use double opt-in. Pending, active, unsubscribed, bounced, and complained states are recorded so APIDir can respect delivery choices.
Infrastructure
APIDir uses Cloudflare Workers and D1 for application delivery and structured records, plus ZeptoMail for transactional confirmation and operational email when configured.
Retention and security
Price evidence is retained for audit. Subscription and consent records are retained as needed to honor consent and suppression. Logs omit email, tokens, credentials, and webhook bodies.
Your choices
Every research email includes an unsubscribe path. For access, correction, or deletion requests, email contact@apidir.dev.