Privacy Policy
Last updated: August 25, 2026 · Effective from: August 25, 2026
1. Overview
APIShare ("we", "us", "our") operates the API marketplace and tunneling service at https://apishare.cc. This Privacy Policy explains what data we collect, how we use it, and the choices you have.
2. Information We Collect
2.1 Account Information
- Email address — account identification, password recovery, email verification
- Hashed password — bcrypt-hashed, never stored in plaintext
- API keys and agent tokens — opaque credentials used to authenticate API calls
- Wallet balance and transaction history — for recharge and earnings tracking
2.2 Google OAuth Data (If Google Login Is Enabled)
If you choose to sign in with Google (when enabled), Google shares with us:
- Google User ID — stable identifier; we do not receive your Google password
- Email address (as verified by Google)
- Display name and profile picture URL
We use this information solely for authentication. We do not request access to your Google Contacts, Drive, Gmail, or any other Google service.
2.3 Provider and Tunnel Metadata
- API call counts, timestamps, and latency (for billing and SLA)
- Upstream provider routing decisions (which provider served which call)
- Tunnel connection metadata (IP, user-agent, duration)
- Error rates and HTTP status codes (aggregated, for monitoring)
2.4 What We Do NOT Collect
- We do not log, inspect, or store the request body or response body of your API calls (they pass through our gateway in streaming fashion)
- We do not sell, rent, or share your personal data with third parties for marketing
- We do not run cross-site tracking or behavioral analytics
3. How We Use Your Information
- Service operation — API routing, billing, wallet management, marketplace listings
- Security — rate limiting, abuse prevention, fraud detection
- Provider payouts — calculating and disbursing earnings to API providers
- Legal compliance — responding to legitimate law enforcement requests
4. Data Retention
- Account data — retained while account is active; deleted within 30 days of deletion request
- API call metadata — 90 days for billing/audit, then permanently deleted
- Transaction history — 7 years (tax compliance requirement in Singapore)
- Connection logs — 30 days
- API request/response content — never stored (passthrough only)
5. Your Rights
Depending on your jurisdiction (GDPR/CCPD/LGPD), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data
- Export your transaction history
- Revoke Google OAuth access via Google Account Permissions
- Object to certain processing activities
To exercise these rights, email privacy@samai.cc.
6. Google OAuth Compliance
APIShare's Google OAuth integration follows Google's OAuth 2.0 Policies:
- Restricted scope: Only
openid email profile— minimum required for authentication - No silent refresh: We never request offline access tokens
- Transparent disclosure: This Privacy Policy is linked from the OAuth consent screen
- Revocation: Revoke access anytime via Google Account Permissions; we delete your Google ID within 30 days
7. Data Security
- TLS 1.3 for all transport connections
- bcrypt password hashing (cost factor 12)
- API keys stored as SHA-256 hashes (lookup-only)
- PostgreSQL with disk-level encryption at rest
- PayPal/Metamask payment integration with PCI-DSS-compliant tokenization
- Regular security audits and prompt patching
8. International Transfers
Your data may be processed on servers located in Singapore and Hong Kong. We comply with GDPR Chapter V for data transfers outside the EU/EEA.
9. Children's Privacy
APIShare is not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact privacy@samai.cc and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via in-app notification and update the "Last updated" date above. Continued use after the effective date constitutes acceptance.
11. Contact
For privacy questions or requests:
- Email: privacy@samai.cc
- Operator: SamAI Group, Singapore
- Website: https://samai.cc
© 2026 SamAI Group. All rights reserved.