Privacy Policy
This policy explains what apipreflight.com (operated by Phillip Wilson, a sole trader in Australia) collects about you, why, and what you can do about it.
Not ready to publish. The contact address on this page is still the placeholder TODO-support@apipreflight.com. Set CONTACT_EMAIL in lib/legal.ts to a working mailbox before accepting payments.
The short version
- You can use the basic Service without an account and without giving us your name.
- We do not sell your data, and we do not run advertising trackers.
- We collect the minimum needed to run the Service: an email if you sign up, the mocks you create, and limited technical logs.
- You can ask us for a copy of your data, or ask us to delete it, at any time.
What we collect
If you create a mock without an account
We store the mock definition itself (method, path, status, headers, response body, delay) and the time it was created. We do not ask for your name or email. These mocks are deleted automatically after the period stated on the site.
If you create an account
We store your email address and authentication details (handled by Supabase — we never see your password), plus the mocks, collections and settings you create. If you subscribe to a paid plan, Stripe stores your billing details and sends us your subscription status, customer identifier and the last four digits and brand of your card. We never receive or store your full card number.
Requests made to your mock endpoints
This is the part specific to a service like ours, so it deserves plain language. When an application calls one of your mock URLs on apipreflight.io, we process that request in order to answer it, and we may record details of it — method, path, query string, headers, body, the response we returned and how long it took — so that you can inspect it in your dashboard.
Whatever your application sends to a mock endpoint is stored in those logs. If your app sends real customer data, tokens or credentials to a mock, that data lands in our logs. Please point mocks at test data only. Request logging is limited or disabled on the free tiers, retained for a limited period on paid plans, and can be cleared by you.
Technical logs and analytics
Our hosting provider records standard server logs (IP address, timestamp, requested URL, user agent) which we use to keep the Service running, apply rate limits and investigate abuse. We use privacy-friendly, aggregate traffic measurement and do not use third-party advertising or cross-site tracking cookies.
Cookies
We use cookies only where they are needed to make the site work: keeping you signed in, and security. There is no advertising or profiling cookie to opt out of. The mock-serving domain apipreflight.io is deliberately session-free and does not set authentication cookies at all.
Why we are allowed to use it
Where privacy law requires a legal basis, ours is: performing our contract with you (running the Service and billing you), our legitimate interests (keeping the Service secure, preventing abuse), and consent where you have given it. In Australia we handle personal information in line with the Australian Privacy Principles.
Who we share it with
We do not sell personal information. We share it only with the providers needed to run the Service:
| Provider | Purpose | Primary location |
|---|---|---|
| Vercel | Website and API hosting | United States |
| Supabase | Database and user authentication | United States |
| Stripe | Payment processing (paid plans) | United States |
We may also disclose information where required by law. These providers are located overseas, mainly in the United States, so your information may be stored or processed outside Australia.
How long we keep it
- Mocks without an account: deleted automatically after the stated expiry period.
- Account data and saved mocks: until you delete them or close your account.
- Request logs: a limited retention window depending on your plan, then deleted.
- Billing records: kept as long as tax and accounting law requires (generally five years in Australia).
Security
Traffic is encrypted in transit with HTTPS. Data is stored with row-level access rules so one account cannot read another's. Administrative keys are held server-side only. No system is perfectly secure, and as set out in our terms, mock endpoints are public by design — please keep real secrets out of them.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or restrict how we use it. Email TODO-support@apipreflight.com and we will respond within a reasonable period, normally 30 days. If you are unhappy with our response you may complain to the Office of the Australian Information Commissioner (oaic.gov.au), or to your local data protection authority.
Children
The Service is not directed at children and accounts require you to be at least 16.
Changes
We may update this policy. If a change materially affects you, we will give notice on the site before it takes effect.
Contact
Privacy questions or requests: TODO-support@apipreflight.com.