1. Who we are
APIRecap is operated by MOLEBYTES LTD, trading as APIRecap (“we”, “us” and “our”).
- Company number: 17406550.
- Registered in England and Wales as a private limited company.
- Privacy enquiries: hello@apirecap.com.
- Support and legal notices: hello@apirecap.com.
This notice explains how we handle personal information when you visit our website, join the waitlist, use an account, read shared documentation, subscribe to release alerts or contact us. It should be read alongside our terms and conditions.
2. Our role in handling information
We act as a data controller for information we use to run our business, manage accounts and subscriptions, answer enquiries and protect the service. This means we decide why and how that information is used.
When a customer uploads documentation containing personal information, or uses APIRecap to manage readers and release subscriptions, we generally process that information on the customer’s instructions. The customer is normally the controller, or a processor acting for its own client. The customer is responsible for the content it provides and for giving its readers the appropriate privacy information.
For requests about information in a customer’s documentation, contact that customer first. We will help the responsible customer respond where required. Our own handling of account and security information remains covered by this notice.
Our data processing agreement sets out the terms for customer data, subprocessors, security, assistance with rights, breach notification, international transfers and return or deletion of data. It applies when agreed with the responsible customer.
3. Information we handle and where it comes from
- Account and team information: your name, email address, password hash, workspace membership, role, project permissions, invitations and account settings. A workspace administrator may provide your email address when inviting you.
- Social sign-in: if you choose Google or GitHub, we receive your provider identifier, name and email address to create or recognise your account. We do not receive your password for that provider.
- Customer content: OpenAPI and Markdown documents, previous versions, project and API names, logos, change facts and draft or approved release notes. These may contain personal information if a customer includes it.
- Publishing and activity records: publishing-key names, key hashes and usage records, actions taken by team members, timestamps and the projects or versions affected.
- Agreement records: the accepted version, time, account and workspace, and whether the acceptance was for personal user obligations or made by an authorised Owner for the customer.
- Release subscriptions: email address, the selected project or API, confirmation and unsubscribe records, the share link used and delivery records.
- Reader activity: which shared project, API or comparison page was opened, when it was opened and which share link was used. These application records do not store a reader’s IP address or browser user agent. A named client link identifies the link used, not necessarily the person who opened it.
- Website and technical information: page visits and browser information from analytics, and connection, session, error and security records. Hosting infrastructure and session records may include IP addresses and user agents; these are separate from the reader activity records described above.
- Enquiries and waitlist: your name, email address, message and our correspondence.
- Billing information: when paid billing is enabled, the customer and subscription identifiers, contact and invoice details, payment status and transaction records needed for a paid subscription. Stripe will process payments and handle card details under its own privacy notice.
Please use example data in your API documentation. Avoid uploading passwords, live access tokens, payment card details or personal information that is unnecessary for describing your API.
4. Why we use information
Where we act as a controller, we use the following lawful bases under UK data protection law:
- Providing accounts and paid services
- To perform our contract with you, or take steps you request before entering it. Where your organisation is the customer, our legitimate interest is administering its account and providing the service to its authorised users.
- Supporting and protecting the service
- Our legitimate interests in answering enquiries, investigating faults, preventing abuse, securing accounts and maintaining reliable service. We consider the effect on individuals and limit the information used for these purposes.
- Waitlist messages and optional marketing
- Your consent where required. We use a waitlist request to send the updates you requested. You can withdraw consent by contacting us or using an unsubscribe option provided in a message.
- Release alerts
- We send the alerts a reader requested after they confirm their address, on the customer’s instructions. Readers can unsubscribe using the link in each alert. The responsible customer must establish the appropriate lawful basis for its use of subscriber information.
- Optional analytics
- Your consent. You can reject analytics or withdraw consent through the cookie preferences control.
- Legal, accounting and dispute records
- Compliance with legal obligations, and our legitimate interest in establishing, exercising or defending legal claims where applicable.
If you do not provide information required for an account or a requested service, we may be unable to provide that part of the service. Optional messages and marketing preferences do not affect your ability to use core account features.
6. Service providers and other disclosures
We use providers to deliver specific parts of APIRecap. Access is limited to the relevant service and must be governed by appropriate contracts. Our providers are:
- Amazon Web Services (AWS)
- Application hosting and data storage in Europe (London), region
eu-west-2. Amazon Bedrock processes change facts to draft release notes; see sections 7 and 8. - Better Stack
- Receives application logs and exception reports to diagnose failures and maintain the service. Remote reports exclude request bodies, cookies, authentication headers and user profiles, with redaction of credentials, email addresses and access-link tokens. Our Better Stack log and error storage is in US West (Oregon), United States, separate from our AWS application storage in London. Application logs sent to Better Stack are retained for 2 days; exception reports are retained for 90 days. Its data processing agreement describes its processing and international transfer terms.
- Web3Forms
- Receives the name, email address and message submitted through the waitlist form, together with technical information needed to process the submission. It is operated by Web3Creative in India and uses servers in the United States, with subprocessors in Europe and other locations. Its data processing agreement describes its subprocessors and incorporates Standard Contractual Clauses and the UK Addendum where applicable.
- Google Analytics
- Measures public website page use after you accept analytics, including after product launch. Signed-in customer pages, shared API documentation, invitations and password-reset pages do not load this integration. The separate administration area also uses consent-controlled analytics in production. Google may process analytics information in the United States and other countries where it or its subprocessors operate, under its data processing terms. Shared documentation pages use APIRecap’s own reader activity records instead of this third-party analytics integration.
- Google and GitHub
- Provide optional sign-in and handle information as independent providers. Their processing may take place in the United States and other countries where they operate. Their privacy notices describe their locations and transfer safeguards: Google and GitHub.
- Stripe
- Our planned payment provider when paid billing is enabled. It will process subscription payments and handle payment card details. APIRecap will use customer and subscription identifiers, billing details, payment status and transaction records to manage subscriptions and accounting. Stripe may process information in the United States, India and other countries. Its privacy policy describes its transfer safeguards, including Standard Contractual Clauses, the UK Addendum and the Data Privacy Framework where applicable.
- Amazon Simple Email Service (SES)
- Sends transactional emails, including team invitations, password resets, subscription confirmations and release alerts, through AWS Europe (London), region
eu-west-2. It processes recipient addresses, message content and delivery information. Messages are delivered to recipients’ email providers, which may process them outside the UK. - Google Workspace email
- Hosts our hello@apirecap.com mailbox for support, privacy enquiries and legal notices. Google processes sender and recipient addresses, message content, attachments and related mailbox information. We use Google Workspace’s default data-region settings and have not selected a UK or Europe-only storage restriction. Google may store or process mailbox information outside the UK, including in the United States and other countries where Google or its subprocessors operate. This mailbox is separate from our AWS application storage.
We may also disclose information to professional advisers, where required by law, or where necessary and proportionate to protect rights and investigate abuse. If the business is transferred, relevant information may pass to the new operator subject to applicable law and appropriate confidentiality protections.
We do not sell personal information or make customer documentation available to advertisers.
7. UK hosting and international transfers
APIRecap is hosted on Amazon EC2 in AWS Europe (London), region eu-west-2. Our Amazon RDS databases, uploaded documents, snapshots, application-managed backups and local application logs are stored in the same region. Remote diagnostic reports are also sent to Better Stack as described in section 6. We use London for our AWS application infrastructure.
That storage location is distinct from processing by external providers, optional sign-in services and the email systems used by recipients. It is also distinct from access by customers or readers outside the UK. The location and transfer arrangements for each provider must be assessed separately.
Where we make a restricted international transfer, we must use an applicable UK adequacy regulation or appropriate safeguards, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any required assessment and additional measures. Contact us for information about the safeguards relevant to your data.
8. AI-assisted release notes
APIRecap sends a limited list of detected change facts and version numbers to Claude Haiku 4.5 through Amazon Bedrock to suggest release-note wording. Facts can include endpoint paths, parameter names and schema or field names from your documents. This request does not send the full uploaded document.
We use Bedrock’s EU cross-region inference profile through its London endpoint. AI requests may be processed in the United Kingdom, Germany, Sweden, Italy, Spain, Ireland or France. This processing can take place outside eu-west-2; our application storage remains in London.
Suggested notes remain private until an Owner or Editor approves them. APIRecap stores the suggestion and approved note with the relevant version. We use this processing to provide release notes, not to make decisions about individuals that have legal or similarly significant effects.
Bedrock model invocation logging is disabled, so we do not use that feature to save AI inputs or outputs to CloudWatch or S3. For Claude Haiku 4.5 under the default configuration we use, AWS describes model inputs and outputs as not routinely retained by Bedrock. AWS and third-party model providers do not use Bedrock inputs or outputs to train their models. APIRecap still stores the generated note with its document version.
AWS may process information for abuse detection and retains rights to handle flagged content under its security and legal terms. See its abuse detection documentation and Bedrock privacy information. These disclosures apply to our current model and configuration; we will review them before changing either.
10. How long we keep information
We keep information for the purposes described here, taking account of the service requested, customer instructions, security needs, legal obligations and the time needed to resolve disputes. We then delete it or make it no longer identifiable. Different records have different lifetimes:
- Accounts and customer content: while needed to provide the workspace and retain its chosen versions. The Owner can download retained workspace data and close the workspace in Account settings. Ordinary access, shared documentation, publishing and release alerts stop on closure. The Owner has 30 days to reopen it or download retained data from the closure page; after that, the hourly deletion process permanently removes its current member accounts, projects, documents and versions, release notes, logos, subscribers, access keys, invitations, activity and reader records from the live application. Removing a teammate or deleting a project is a separate action.
- Agreement records: the signer's name and email, accepted version, authority scope and time are kept to evidence the agreement while the customer workspace remains. Removing the signer's login does not erase that minimal evidence for an active customer's agreement. Workspace deletion removes its application acceptance records; personal user acknowledgements are removed with the account. Necessary evidence for an active claim or a legally required business record may be retained separately under the safeguards described here.
- Release subscriptions: confirmed subscriptions are kept while alerts are requested. Unconfirmed requests are deleted by the hourly cleanup after seven days from the latest confirmation request. Unsubscribing stops alerts immediately; after 30 days, the hourly cleanup deletes the unsubscribed address and its associated confirmation, delivery and unsubscribe records. A new signup requires a new confirmation. Workspace or project deletion also removes the associated subscriptions.
- Waitlist messages: we keep our copies while needed for the requested launch updates or enquiries. You can withdraw your request by contacting us. Web3Forms’ published processing terms describe a three-year storage lifetime for submissions, separate from dashboard visibility. They provide for deletion within 90 days of ending its service, with residual backup copies overwritten on its backup cycle. Requests to erase information must also address relevant provider copies.
- Support correspondence: normally 12 months after the last reply. Valid instructions to erase customer data held on a customer’s behalf also apply to relevant support and provider copies. Minimal records necessary for our separate lawful controller purposes, such as an active dispute or security incident, may be kept separately until it is resolved; once resolved, expired records are removed. We explain any exception when responding to a deletion request.
- Team activity and reader events: 90 days, with hourly cleanup of older records. Usage reporting therefore reflects retained activity rather than lifetime totals.
- Local application logs: daily rotation retains the current and previous calendar day; hourly cleanup removes older daily files. Better Stack’s separate log and error periods are stated in section 6. Web-server and other infrastructure logs require their own rotation controls.
- Billing records: where needed to meet tax and accounting obligations, we retain only the necessary billing information for the applicable legal period, rather than keeping the closed workspace or its documents for that purpose. Billing is not yet enabled.
- Backups: our application backups consist of RDS database snapshots, retained for 30 days in AWS Europe (London), region
eu-west-2. Information deleted from the live database may remain in earlier snapshots until they expire, for up to a further 30 days after live deletion. Restricted backup copies are not used for ordinary service delivery.
The provider diagnostic and analytics periods describe routine retention; they do not prevent earlier erasure where required. Customer instructions to delete data we process on their behalf must also be applied to relevant provider copies, subject to lawful exceptions and restricted backup expiry. Analytics and minimal records used for our separate controller purposes are assessed under their own lawful basis. If a backup is restored, closure and deletion instructions must be reapplied before customer access is restored.
11. How we protect information
Application controls include workspace and project permissions, password hashing, hashed publishing-key secrets, encryption of stored share-link and subscriber tokens, revocable share links and redaction of remote diagnostic reports. Token encryption does not mean that all documents or database fields are encrypted by the application. APIRecap does not currently provide multi-factor authentication.
Authorised staff and service providers may need access for support, security, maintenance or legal obligations. Access must be limited to its purpose and protected by appropriate technical and organisational measures.
No online service can eliminate every security risk. Keep account credentials and share links secure, remove secrets from uploaded examples and contact us promptly if you suspect unauthorised access.
12. Your choices and rights
Depending on the circumstances, you can ask to access or correct your personal information, have it erased, restrict its use or receive it in a portable form. You can withdraw consent at any time without affecting processing that was lawful before withdrawal.
You can object to processing based on legitimate interests. You can always object to the use of your personal information for direct marketing.
Contact the privacy email in section 1. We may need proportionate information to verify your identity. We normally respond within one month, subject to any extension or other rule permitted by law, and explain any lawful reason we cannot fulfil a request.
Use the unsubscribe link in a release email to stop those alerts. Contact the customer responsible for a document if your request concerns information it has published or instructed us to process.
You can complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, or to another supervisory authority where you have that right. You do not have to contact us before exercising that right.
13. Children and changes to this notice
APIRecap is intended for professional use by adults and is not directed at children. Contact us if you believe a child has provided personal information so that we can investigate and take appropriate action.
We may update this notice as the service or our legal obligations change. We will show the effective date and bring material changes to your attention where appropriate. A change to this notice does not by itself provide consent for a new use of personal information.