Apilift Privacy Policy
Effective date: 6 September 2026
This Privacy Policy explains how Egor Sergeev, trading under the product name Apilift (Apilift, we, us or our), handles personal data when you use the Apilift website, command-line software, Chrome extension and shared interface registry.
1. Controller and contact
The controller is Egor Sergeev, Kanika Center, Block B, Panayioti Simeou, Flat 206, 3105 Limassol, Cyprus. Contact: contact@apilift.dev.
The Service is intended only for people aged 18 or older. Paid features are available to eligible customers in the United Kingdom and other locations supported by Paddle and applicable law.
2. What stays on your device
During a task you initiate, the Chrome extension can observe the selected tab’s URLs, requests, responses, page activity and authentication material needed to capture or replay the requested operation. Depending on the product you select, this can include identifiers, communications, financial or health information, location, browsing activity and other website content.
Authentication values are held briefly in Chrome memory for the authorised operation and redaction. They are not placed in generated interfaces. Credential-redacted records can be retained temporarily in the extension’s bounded local write-ahead log until delivery to the Apilift program on the same computer succeeds. Other task content can remain in the local Apilift catalog until you delete it from your device.
Apilift keeps a local execution history containing a random event identifier, service and operation names, interface revision and source, operation effect, timestamps and duration, effective user policy, outcome category, diagnostic category, HTTP status, client version and agent runtime. The local history does not contain command arguments, URLs, headers, request or response bodies, credentials, session context, concrete account values or upstream error text. It is retained for 90 days by default, subject to a local retention setting, and remains available when server-side tracking is unavailable or not accepted.
Apilift automatically reads locally stored Codex and Claude sessions to measure productive Action usage and estimate savings. A background collector reads request token counters, model and producer versions, timestamps and tool-result correlation receipts. Native indexes and process sidecars locate those histories. Transcripts, prompts, tool arguments and results, screenshots, URLs and credentials remain local and are not copied into accounting records or uploaded. The private local accounting store retains numeric measurements, coverage and minimum pseudonymous linkage; native session and request identifiers are hashed locally. File locations and collection cursors remain on your device. Apilift does not change native history settings. Missing histories or incomplete records leave measurements unavailable. Discovery supplies repeatable-workflow baseline samples; discovery cost is never displayed or deducted from savings. API-equivalent cost estimates use recorded models and versioned prices and do not represent complete provider billing.
Raw browser captures, command arguments, URLs, headers, request and response bodies, browser credentials, session context, concrete account values and upstream error text are not sent with execution metadata to the public registry. Because local processing happens under your control, you are responsible for choosing authorised accounts and data and for deleting local task records you no longer need.
3. Data we receive
When you create an account, we receive the account identifier issued by Supabase Auth, your email address, authentication provider, account status, trial dates, onboarding preferences and progress, personal-workspace membership, installation links and legal acceptances. We use these records to authenticate you, resume setup, connect your local installation and provide the applicable product features. If you choose Google or GitHub sign-in, that provider supplies Supabase Auth with the identity data shown in its consent flow; Apilift does not receive your provider password.
When an installation first connects to the registry, we receive a random installation identifier, a one-way hash of its authentication token, a temporary hash derived from the connection IP address, creation and last-activity times, and the versions, hashes and time of your legal acceptance. We use the IP-derived hash only to limit abusive registration rates and erase it after 24 hours.
Before each execution or discovery session, the command-line software requests current account, subscription, trial, usage and policy state from Apilift. It can also send the execution metadata listed in section 2. We associate these records with your installation, account and workspace and use them to authorize the session, provide local and account history, calculate Cloud active-browser usage, enforce policies and plan limits, measure reliability, distinguish service availability from an outdated operation or client regression, and propose interface rediscovery. If the hosted control plane is unavailable, a new execution or discovery session does not start. An automated reliability signal can create a rediscovery candidate but does not start discovery or execute a product operation by itself.
The command-line software can send numeric usage observations and revisions, measurement coverage and repeatable-workflow baseline samples bound to compatible Action versions. We associate productive Action records with your account, installation and app to estimate time, token and API-equivalent model-cost savings. Productive failed attempts and retries contribute to the cost of that work but earn no alternative benefit. Shared repeatable app preparation is attributed once per pseudonymous native root session and app. Discovery, setup, publication and verification earn no productive usage or savings, and discovery cost is never deducted. Recorded model and cache categories determine pricing; a model preference cannot rewrite measured consumption. Only numeric baseline measurements follow an app's existing public or private visibility; contributor session identities are not shared.
When you save an interface, we receive its validated service, entity, operation and optional authentication-recipe resources; service name and origin; technical integrity identifiers; visibility; workspace association where private; revision history; validation metadata; and timestamps. Private interfaces are hosted on Apilift servers and are available to authorised members of the owning workspace, but are not published in Community, public search, autocomplete, SEO or public explorer surfaces. Private does not mean local-only storage or end-to-end encryption.
When an interface is saved to Community, its accepted resources, synthetic examples and validation metadata become public and can remain in public revision history. Creating a private copy does not withdraw an existing Community interface. If an owner explicitly makes a private interface public, only its confirmed current head and future public updates enter Community; earlier private revision history remains private. Trial expiry, subscription loss or downgrade does not publish, delete or change the visibility of private data.
When you use our website or registry, Fly.io and our application infrastructure can process IP address, request path, timestamp, user agent, request identifier and operational logs needed to deliver and protect the Service. We use the functional execution and usage measurements described above but do not use them for advertising or cross-service behavioural profiling. We do not currently use advertising, tracking pixels or advertising cookies. A browser can store a functional theme preference on your device.
If you contact us, we receive your email address and the information you include. Do not send credentials or unnecessary personal data in a report.
4. Authentication email and payments
Supabase Auth processes account authentication for Apilift. Resend delivers one-time authentication codes from no-reply@auth.apilift.dev and processes the destination email address, message content and delivery metadata for that purpose. A code expires after ten minutes. We do not use authentication messages for marketing.
If you purchase paid features through Paddle, Paddle processes payment-card, billing, tax, transaction, fraud-prevention and invoice information as merchant of record or authorised reseller under its own privacy notice. Apilift receives Paddle customer, product, price, transaction, subscription, invoice, refund, adjustment and chargeback identifiers and status; billing contact and currency details; subscription periods and scheduled changes; and the minimum metadata needed to associate the purchase with your workspace. We do not receive or store full card details.
Paddle sends signed billing webhook events to Apilift. We store the provider event identifier, event type, occurrence time, body hash, processing state and error information needed for idempotent processing, reconciliation and audit. The raw event body is retained only for bounded retry processing and is removed after successful processing. We use Paddle identifiers and custom metadata to recover a checkout whose outcome was unknown after a network interruption without sending a blind duplicate purchase request.
For Cloud, we receive or calculate immutable active-browser usage segments, monthly subscription-anchored usage windows, included and overage duration, six-minute billing units, applicable price version and billing-run status. These records support the 100-hour monthly allowance, overage charges, corrections, customer billing views, refunds and reconciliation. We do not use a general-purpose credit balance.
5. Why we process data
We process account, installation, acceptance, contribution, operation policy, execution, subscription, transaction and Cloud usage data as necessary to provide the Service, administer payments and perform our agreement with you; reliability analysis, security, rate limiting, diagnostics, abuse prevention, reconciliation and defence of legal claims for our legitimate interests in operating a reliable and lawful service; billing, tax, accounting, reports, rights requests and required records to comply with legal obligations; and optional processing on consent where we specifically ask for it. We do not treat acceptance of the Terms as consent to unrelated data processing.
Where we rely on legitimate interests, we limit the data, use pseudonymous identifiers where practical, apply short retention to network-derived data and provide the rights described below.
6. Who receives data
Fly.io provides application hosting and network infrastructure. Supabase provides hosted authentication, database and storage infrastructure. Resend provides transactional email delivery. Those providers process data for us under their contractual terms and security measures. Google or GitHub also processes authentication data under its own privacy terms if you choose that provider. Public interface revisions are available to anyone.
Authorised members of your workspace receive access to its private interfaces. We do not disclose a private interface to another workspace merely because it covers the same product, origin or name. We can also disclose data to professional advisers, authorities or other recipients when reasonably necessary to comply with law, protect rights and security, investigate abuse, or establish and defend legal claims. If the Service or its operation is transferred, relevant records can transfer subject to this policy and applicable law. Paddle receives payment information when you enter its checkout and receives subscription, plan-change, renewal, Cloud overage, cancellation, refund and dispute instructions or records while it administers the resulting payment relationship.
7. International transfers
Our providers can process data in the European Economic Area and other countries. Where personal data is transferred outside the EEA to a country without an adequacy decision, we rely on an available lawful safeguard such as the European Commission’s standard contractual clauses and supplementary measures where required. Contact us to request information about the safeguard relevant to your data.
8. Retention
We erase the IP-derived registration hash after 24 hours. We retain server execution and raw value facts for 90 days, daily value rollups for 13 months, and monthly and lifetime service value rollups until account deletion. Value baseline profiles remain while the corresponding Action version exists. We retain Cloud usage windows and billing-run summaries for 13 months unless a longer period is needed for accounting, tax, refund, fraud, chargeback or dispute obligations. Policy settings and their audit fields remain while the workspace is active or until they are deleted with the account, subject to records required for security or legal claims. We delete rejected contribution packages and their associated records after 30 days. We delete an installation record after 24 months without authenticated activity. Deleting your installation removes its pseudonymous association and non-public contribution, execution and raw value records earlier, but does not remove accepted public revisions, account-level value rollups or their history. Deleting the account removes its value events, rollups, preferences and one-time session attribution.
Accepted public revisions are retained while useful for the shared library, security, integrity and provenance. Private interfaces and their private revision history remain while the owning workspace is active, including while paid access is paused after trial or subscription loss, and are deleted with the workspace subject to security, backup and legal retention. Making an interface public does not expose its earlier private revision history. Local records remain on your device until you remove them. Account, workspace, trial and subscription projections are retained while the account is active. Paddle customer, transaction, invoice, adjustment, refund, chargeback and reconciliation records can remain afterward only as long as needed for legal, fraud-prevention, accounting, tax and dispute obligations. Successfully processed raw billing webhook bodies are removed; failed bodies are kept only for the bounded retry period. Expired device codes are retained only as short-lived setup records. Authentication email delivery metadata is retained according to Resend's configured service retention. Support, rights-request and legal records are kept only as long as needed for the request and applicable legal requirements.
9. Security
We use random installation credentials, one-way token hashing, workspace-scoped access controls, encrypted network transport, privacy preparation before saving, private-aware cache and job scope, restricted infrastructure access and operational logging designed not to include private service metadata. The Chrome extension accepts work only from an installed local native host and active Apilift task scopes. Private interfaces are not end-to-end encrypted, and no system is completely secure, so you should use appropriate test accounts, device security and backups.
10. Your choices and rights
You can inspect local execution records using apilift history, export the data associated with the current pseudonymous installation using apilift privacy export, and delete that installation association using apilift privacy delete --yes. Installation and account exports include retained numeric value events and account exports include retained value rollups. You can revoke linked installations from the dashboard and ask us to export or delete account data, including server execution facts, value data, subscription projection and policy settings. Deleting an account with an active subscription first requests immediate Paddle cancellation; if Paddle is unavailable, the request remains pending until cancellation can be confirmed. Financial records subject to accounting, tax, fraud, refund, chargeback or dispute retention are not erased merely because account access ends. Removing the Chrome extension clears storage controlled by Chrome; deleting the local Apilift catalog, including its execution history and pending value queue, is a separate action under your control.
Subject to applicable law, you can ask to access, correct, erase, restrict or receive your personal data, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. We can ask for information needed to verify that the request concerns you. Some rights are limited where retention or processing is required by law or another person’s rights.
Send requests to contact@apilift.dev. You may complain to the Office of the Commissioner for Personal Data Protection in Cyprus at dataprotection.gov.cy or to another competent supervisory authority.
11. Automated decisions
We do not currently make decisions producing legal or similarly significant effects about you solely through automated processing. Automated integrity and abuse checks can reject or restrict a technical contribution; you can request review under the Acceptable Use Policy.
12. Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. The extension uses browser information only to provide and improve the user-facing task you requested. We do not sell it, use it for advertising, use it to determine creditworthiness or lend it to humans for unrelated review except where required for security, abuse prevention, legal compliance or support with your affirmative agreement.
13. Changes
We will publish changes here with a new effective date. We will request renewed acceptance before a material change that affects the agreement or your reasonable expectations. Archived accepted versions remain available for verification.