Privacy Policy
Last updated: March 28, 2026
1. Controller
The controller responsible for processing your personal data (Art. 4 No. 7 GDPR) is:
Jannes Korn
Höhenweg 13
88709 Hagnau am Bodensee, Germany
E-mail: legal@foxapi.dev
2. Data We Collect and Why
a) Account data — Google Sign-In
We offer authentication via Google OAuth 2.0. When you sign in with Google, we receive your name, e-mail address, and Google profile picture (if provided). We use this data solely to create and manage your account and to identify you on return visits.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). We do not receive your Google password. Google's own privacy policy applies to the Google sign-in flow: policies.google.com/privacy.
b) API keys and request logs
We store the API keys you generate and request log data (endpoint, HTTP status, latency, IP address, user agent, timestamp). This data is used to enforce rate limits, display usage statistics, and detect abuse.
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention). Request logs are deleted after 90 days.
c) Payment data — Stripe
Paid plans are processed by Stripe, Inc. (354 Oyster Point Blvd, South San Francisco, CA 94080, USA). We never store full card numbers ourselves. We retain billing metadata (plan, amount, billing period, Stripe customer/subscription ID) for invoicing.
Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (legal retention obligation under §§ 147 AO, 14b UStG — 10 years). Stripe's privacy policy: stripe.com/privacy.
d) Server log files
Our hosting infrastructure automatically records: IP address, date/time of request, URL, HTTP status, and referring URL. These logs are used solely for security and stability and are deleted after 30 days.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
e) Contact e-mails
If you contact us, we store your message and e-mail address to process your inquiry and delete this data once the matter is resolved, unless statutory retention periods apply.
Legal basis: Art. 6(1)(f) GDPR.
3. Cookies and Session Storage
We use technically necessary cookies and browser session storage to maintain your login session and short-lived UI state (e.g. MFA verification). These are strictly essential for the Service to function and require no consent under Art. 5(3) ePrivacy Directive.
We do not use advertising or tracking cookies.
4. Third-Country Transfers
Some service providers are located outside the EU/EEA (e.g. Stripe in the USA). Data transfers are secured by EU Standard Contractual Clauses (SCCs) or an applicable adequacy decision pursuant to Art. 46 GDPR.
5. Retention Periods
We store personal data only as long as necessary. API request logs: 90 days. Account data: for the duration of your account, deleted within 30 days of closure (unless longer retention is required by law, e.g. invoices: 10 years).
6. Your Rights
Under the GDPR you have the right to:
- Access (Art. 15) – obtain a copy of your data.
- Rectification (Art. 16) – correct inaccurate data.
- Erasure (Art. 17) – request deletion, subject to legal retention obligations.
- Restriction (Art. 18) – limit processing in certain circumstances.
- Portability (Art. 20) – receive your data in a machine-readable format.
- Objection (Art. 21) – object to processing based on legitimate interests.
- Withdraw consent – where applicable, withdraw at any time without affecting prior processing.
To exercise these rights, contact us at legal@foxapi.dev. We will respond within 30 days.
You may also lodge a complaint with the supervisory authority in your EU member state. In Baden-Württemberg, Germany: Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg.
7. Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, disclosure, or loss. All connections use HTTPS encryption.
8. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after changes are posted constitutes acknowledgment of the updated policy.