Legal
Privacy Policy
Last updated: 13 July 2026
1. Introduction
Apicary ("Apicary", "we", "us", or "our") operates a cloud-based API mocking platform at apicary.dev and related subdomains (including the dashboard and mock API endpoints). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have regarding your data.
Apicary is the data controller for personal data processed through your account and use of our website and services. If you have questions about this policy or your data, contact us at privacy@apicary.dev.
This policy applies to visitors to our marketing site, registered users of the dashboard, and anyone whose HTTP requests are handled by our mock API runtime when directed at a workspace URL.
2. Information we collect
We collect information in the following categories, depending on how you interact with Apicary.
Account and profile data: when you create an account, we store your email address, display name, profile avatar URL, subscription plan tier, account creation date, and a unique user identifier. If you subscribe to a paid plan, we may also store a Lemon Squeezy customer identifier to link your account to billing records.
Authentication data: we support sign-in via Google OAuth, GitHub OAuth, and email magic links. We do not store your OAuth passwords. Authentication sessions are managed by our auth provider using secure HTTP-only cookies.
Workspace and configuration data: when you use the dashboard, we store workspace names, URL slugs, plan assignments, usage counters (such as requests used in the current billing period), and any settings you configure. We also store the mock endpoint definitions you create, including HTTP method, path, status code, JSON response body, response headers, delay settings, descriptions, and enabled/disabled state.
Request logs: when HTTP traffic hits your public mock URLs, our mock runtime records observability data so you can inspect traffic in the dashboard. Each log entry may include the HTTP method, request path, request headers, request body (truncated to a maximum of 64 KB per request), response status code, response duration in milliseconds, the matched endpoint (if any), workspace identifier, and timestamp. Sensitive request headers - such as Authorization, Cookie, API keys, tokens, secrets, and password-related headers - are automatically replaced with "[redacted]" before storage. We do not store client IP addresses in request logs.
Rate-limiting and abuse-prevention data: to protect the platform, we temporarily process your IP address and workspace slug in a Redis-backed sliding-window rate limiter (up to 300 requests per minute per IP and 60 requests per minute per workspace). This data is used only to enforce burst limits and is not written to your request log history. Requests blocked solely for rate limiting are not logged.
Technical and diagnostic data: our hosting providers and error-monitoring tools may collect standard technical information such as IP address, browser type, device type, operating system, referring URL, pages visited, timestamps, and error stack traces. In production, we use Sentry for error reporting with a 10% performance trace sample rate.
Communications: if you contact us by email (for example at support@apicary.com or privacy@apicary.dev), we process the content of your message and your email address to respond to your inquiry.
3. How we collect information
Directly from you: when you sign up, create workspaces and endpoints, manage your account, or contact support.
Automatically when you use the service: when you sign in (session cookies), load dashboard pages, or when HTTP clients send requests to your mock API URLs.
From third-party authentication providers: when you choose "Continue with Google" or "Continue with GitHub", we receive basic profile information (such as email, name, and avatar) that those providers share with us according to your settings and their policies.
From payment processors: when paid billing is enabled, Lemon Squeezy may provide us with subscription status, customer identifiers, and transaction metadata needed to manage your plan.
4. How we use your information
We use personal data for the following purposes:
Providing the service: authenticating you, hosting your workspaces and endpoint configurations, routing mock API traffic, returning configured responses, displaying real-time and historical request logs, and enforcing plan limits (endpoints, workspaces, and monthly request quotas).
Operating and securing the platform: detecting and preventing abuse, enforcing rate limits, monitoring errors and performance, maintaining infrastructure, and protecting against unauthorized access.
Account and billing management: displaying your plan and usage, processing upgrades and downgrades when billing is available, and communicating about subscription changes.
Support and communication: responding to your requests, sending authentication emails (magic links), and notifying you of important service changes.
Legal compliance: complying with applicable laws, responding to lawful requests, and enforcing our Terms of Service.
We do not sell your personal data. We do not use your data for third-party advertising or cross-context behavioral advertising.
5. Legal bases for processing (EEA, UK, and Switzerland)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
Contract: processing necessary to provide the Apicary service you signed up for, including account management, mock API routing, request logging, and plan enforcement.
Legitimate interests: operating, securing, and improving the platform; preventing fraud and abuse; and handling support inquiries - balanced against your rights and expectations.
Consent: where required for optional activities (for example, if we introduce non-essential cookies or marketing communications in the future). Essential authentication cookies do not require consent.
Legal obligation: where we must retain or disclose data to comply with law.
6. Mock API traffic and your responsibilities
Apicary mock URLs are publicly reachable by anyone who knows or discovers the workspace slug and path. Traffic sent to those URLs is processed and may be logged in your workspace, visible to you and anyone with access to your Apicary account.
Do not send real personal data, production credentials, payment card numbers, health information, or other sensitive data to mock endpoints unless you have a lawful basis to do so and accept that such data may be stored in request logs subject to the retention periods described below.
You are responsible for the endpoint definitions and sample data you configure, and for controlling who you share mock URLs with.
If third parties (such as your application users or testers) send personal data to your mock URLs, you act as an independent controller for that data. You should inform those individuals and ensure you have an appropriate legal basis for such processing.
7. Cookies and similar technologies
We use cookies and similar technologies that are strictly necessary to operate the service:
Authentication cookies: Supabase sets session cookies (prefixed with "sb-") to keep you signed in to the dashboard. These are essential cookies required for the service to function.
We do not currently use analytics, advertising, or social-media tracking cookies on the dashboard or marketing site.
Our website loads fonts from Google Fonts (Inter and JetBrains Mono). Google may collect usage data according to its own privacy policy when fonts are requested by your browser.
You can control cookies through your browser settings. Disabling essential authentication cookies will prevent you from staying signed in to the dashboard.
8. Third-party service providers
We use trusted third-party processors to run Apicary. They process data only on our instructions and for the purposes described in this policy:
Supabase - database hosting, authentication, row-level security, and real-time subscriptions. Stores account, workspace, endpoint, and request log data.
Vercel - hosts the Next.js dashboard and the Hono-based mock API runtime (including Vercel Edge functions). Processes HTTP requests and standard access logs.
Upstash - Redis-backed rate limiting for burst protection. Temporarily stores workspace slug and IP address counters.
Sentry - error monitoring and performance tracing for the web application. May receive error reports, stack traces, browser metadata, and limited session context when errors occur.
Google and GitHub - OAuth identity providers when you choose those sign-in methods. Each provider processes authentication data under its own privacy policy.
Lemon Squeezy - payment processing and subscription management for paid plans (when enabled). Processes billing details, payment method information, and transaction records.
We select providers with appropriate security practices. Their processing is governed by data processing agreements or equivalent contractual safeguards where required.
9. International data transfers
Apicary and our subprocessors may process and store data in the European Union and other countries, including the United States, where our infrastructure providers operate.
When personal data is transferred outside the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, or equivalent mechanisms, unless an adequacy decision applies.
You may contact us for more information about the safeguards we use for international transfers.
10. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy:
Account and profile data: retained while your account is active. If you request account deletion, we delete or anonymize this data within a reasonable period, subject to any legal retention obligations.
Workspace and endpoint configuration: retained while the workspace exists. Deleting a workspace from the dashboard permanently removes the workspace, its endpoints, and associated request logs.
Soft-deleted endpoints: when you delete an endpoint, we set a deletion timestamp rather than immediately purging the row. Soft-deleted endpoint records are excluded from active use and may be retained briefly for operational integrity.
Request logs: retained so you can inspect traffic in the dashboard. Our target retention periods are 30 days on the Free plan and 90 days on paid plans (Solo and Team), after which logs will be automatically deleted. Until automated retention is fully deployed, logs may persist until you delete the workspace, delete your account, or we otherwise purge them.
Rate-limiting counters: stored in Redis for the duration of the active sliding window (approximately one minute) and then expire automatically.
Server and error logs: retained by our hosting and monitoring providers according to their default retention schedules, typically from a few days to several months.
Billing records: retained as required by tax, accounting, and payment regulations, which may be longer than your account lifetime.
Backup copies: our infrastructure providers may retain encrypted backups for a limited period after deletion. Data in backups is overwritten on a rolling basis.
11. Security
We implement technical and organizational measures designed to protect your data, including encrypted connections (HTTPS/TLS), authenticated access to the dashboard, row-level security in our database so users can only access their own workspaces, automatic redaction of sensitive HTTP headers in request logs, and secret-key isolation so privileged database credentials are never exposed to the browser.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately and sign out of all sessions.
12. Your privacy rights
Depending on where you live, you may have the following rights regarding your personal data:
Access - request a copy of the personal data we hold about you.
Rectification - request correction of inaccurate or incomplete data.
Erasure - request deletion of your personal data, subject to legal exceptions.
Restriction - request that we limit how we use your data in certain circumstances.
Portability - receive your data in a structured, commonly used, machine-readable format where technically feasible.
Objection - object to processing based on legitimate interests.
Withdraw consent - where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
Complaint - lodge a complaint with your local data protection authority. If you are in the EU, you can find your authority at edpb.europa.eu. UK residents may contact the ICO at ico.org.uk.
California residents (CCPA/CPRA): you have the right to know what personal information we collect, request deletion, and opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. You may exercise these rights by contacting us at the address below.
To exercise any of these rights, email us at privacy@apicary.dev. We may need to verify your identity before fulfilling your request. We will respond within the timeframes required by applicable law.
You can delete individual workspaces (including their logs and endpoints) from the dashboard at any time. For full account deletion, contact us at privacy@apicary.dev and we will process your request.
13. Children's privacy
Apicary is not directed at children under 16, and we do not knowingly collect personal data from anyone under 16 (or the minimum age required in your jurisdiction). If you believe a child has provided us with personal data, contact us and we will take steps to delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the service. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or through a notice in the dashboard.
Your continued use of Apicary after the effective date of an updated policy constitutes acceptance of the changes, except where further consent is required by law.
15. Contact us
For privacy-related questions, data subject requests, or concerns about this policy, contact:
Apicary
Email: privacy@apicary.dev
For general product support, you may also reach us at support@apicary.com.