apisloth / legal
Privacy Policy
This policy explains what information apisloth processes, why it is used, and the choices available to account holders.
1. Information we collect
We may collect the following categories of information:
- Account information: your name, email address, authentication records, and account preferences.
- Connected-service information: API source URLs, repository identifiers, encrypted access credentials, and settings you choose to provide.
- Workflow content: API specifications, structured diffs, repository context, generated changes, verification reports, pull-request details, and capped run logs.
- Usage and technical information: request times, IP address, browser or device information, feature usage, diagnostics, and security events produced when you use the service.
- Communications: messages and support requests you send to us.
2. How we use information
We use information to:
- provide API monitoring, repository analysis, code generation, verification, and pull-request workflows;
- authenticate users, enforce account limits, prevent abuse, and protect the service;
- diagnose failures, maintain reliability, provide support, and understand how features perform;
- communicate about the service, including material operational or policy changes; and
- comply with law and enforce our agreements.
3. How information is shared
We do not sell personal information. We may disclose information in the following limited circumstances:
- to infrastructure, database, authentication, code-hosting, and AI model providers that process information to operate the service;
- to your connected services when a workflow reads a repository, pushes a branch, or opens a pull request at your direction;
- when required by law or reasonably necessary to protect rights, safety, service integrity, or users; and
- as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate protections.
4. Credentials and security
Credentials submitted for connected services are intended to be encrypted at rest and used only for authorized workflows. We use administrative, technical, and organizational measures designed to protect information. No system is completely secure, and we cannot guarantee that unauthorized access or loss will never occur.
5. Data retention
We retain information for as long as reasonably necessary to provide the service, maintain security and audit history, comply with legal obligations, resolve disputes, and enforce agreements. Retention may vary by data type. Backup copies and records required for legitimate legal or security purposes may remain for a limited period after account deletion.
6. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of certain personal information, or to object to particular processing. You may also disconnect sources and repositories or stop using the service. To make a request, contact privacy@apisloth.dev. We may need to verify your identity before completing a request.
7. International processing
apisloth and its service providers may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we use appropriate safeguards for international transfers.
8. Children
The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, please contact us.
9. Changes to this policy
We may update this policy as the service or legal requirements change. We will post the revised policy with an updated effective date and provide additional notice when required by law.
10. Contact
Privacy questions or requests may be sent to privacy@apisloth.dev.