Privacy Policy
Effective 2026-09-28.
This policy explains how Active Life Hub LLC, the operator of API Finder and the business responsible for the personal data processed through it (the “controller” where that concept applies), handles information when you use the website or API. API Finder has no user accounts and is designed to collect as little as possible.
1. What we process
- Research requests and results: the capability text and constraints you submit, the resulting shortlist, request status, timestamps and a one-way hash of your Idempotency-Key (never the key itself). Please do not include personal data or secrets in requests.
- Payment metadata: the paying wallet address, payment amount, network, authorization nonce and settlement transaction hash. Blockchain transactions are public by nature. We never receive or store private keys, recovery phrases or card details.
- Operational and cost data: per-request usage of our providers (search calls, model tokens), durations and cost accounting.
- Technical data: for rate limiting we use a one-way hash of your IP address, held in memory and, for paid requests, in our database as a short-lived counter. Our hosting provider processes standard request logs (such as IP address, user agent and timestamps) for security and operations. Our application logs are designed to exclude request text, payment signatures and credentials.
We do not use advertising or analytics trackers, and the website sets no tracking cookies. The website stores your access key and pending request in your browser’s session storage so you can reopen your result; it is cleared when the tab session ends.
2. Why we process it
To perform the research you request and deliver results (performance of our agreement with you); to verify and settle payments, reconcile uncertain settlements and keep accounting records (contract and legal obligations); and to secure the Service, prevent abuse and measure costs (legitimate interests).
3. Providers (subprocessors)
- Vercel — website and API hosting, request logs.
- Neon — managed PostgreSQL database for requests, results and payment records.
- Tavily — web search and page retrieval; receives search queries derived from your request.
- Anthropic — language-model processing; receives your request and retrieved public pages.
- Coinbase Developer Platform — x402 payment verification and settlement on the Base network.
These providers process data under their own terms and privacy policies. We do not sell personal information or share it for cross-context behavioural advertising.
4. International processing
API Finder serves users globally. Our providers may process data in the United States and other countries, which may have different data-protection laws than your own. Where required, we rely on our providers’ contractual and legal transfer mechanisms.
5. Retention
Requests, results and payment records are kept so that you can retrieve results, retry failed paid research, and so we can reconcile payments and meet accounting and legal obligations. We aim to delete or anonymize request text and results within 24 months of the request, and payment records when no longer required for accounting or legal purposes. Deletion is currently performed as a periodic manual operation. Rate-limit counters are short-lived. On-chain transaction records cannot be deleted by anyone.
6. Security
Results are private: retrieval requires your secret key, of which we store only a hash. Secrets are held server-side, traffic uses HTTPS, inputs are size-limited and validated, retrieved web content is treated as untrusted, and access to production systems is restricted. No system is perfectly secure; keep your key private.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing of your personal data, and to complain to a data-protection authority. Because we have no accounts, please include your request ID and prove control of the corresponding key (or payer wallet) so we can locate the data without collecting more.
8. Children
The Service is intended for businesses and developers, not for children.
9. Changes and contact
We may update this policy; the effective date above will change. A dedicated privacy contact address for Active Life Hub LLC will be published on this page. See also the Terms & Conditions.