Consumer Privacy Notice
For people who sign in to APIs and developer portals powered by APIblaze.
Last updated: July 3, 2026
Who this is for
This notice is for end users — the people who sign in to an API, developer portal, or application that is operated by an API provider and powered by APIblaze ("APIblaze", "we", "us"). It describes what happens to your information when you sign in and use that service. The API provider's own privacy policy also applies to how they use your information.
The parties and their roles
- The API provider — the business or developer whose API or portal you sign in to. They are the primary controller of your information; their privacy policy governs how they use it.
- APIblaze — we operate the sign-in and identity infrastructure for the provider. For most of what we do we act on the provider's behalf (a processor). We also use a limited amount of this information for our own purposes — chiefly keeping the platform secure and preventing abuse across the service — and for those purposes we are a controller. This notice covers that processing.
- Your login provider — the identity provider you choose (for example GitHub or Google) verifies who you are and shares basic profile information based on the permission you grant it.
What we collect
When you sign in and use a provider's service through APIblaze, we may process:
- Profile information from your login provider — typically your name, email address, and a provider account identifier. We do not receive your password, and we request only the basic permission needed to sign you in.
- Sign-in and account records — a stable internal identifier we create for you, which API and provider you signed in to, and timestamps of your sign-ins, so the provider can recognize you across sessions.
- Technical information — when you make requests, we process the identifiers in them (for example an API key, which we store only as an irreversible hash, or a token, which we store encrypted), and we record limited request metadata including an approximate location (country) derived from your network address.
- Request content (only in specific cases) — see "Request content" below.
How we use it
- To operate sign-in and create and manage your access to the provider's service.
- To apply the provider's access rules — group memberships, permissions, and usage limits.
- To keep the platform secure and prevent abuse and fraud. This includes analysis across the service to detect misuse and automated enforcement of the provider's access rules — see "Automated access decisions" below. We keep the details of our abuse-detection methods confidential so they cannot be evaded.
- To keep basic, aggregated analytics (such as request counts and country) needed to run the service.
- To keep security and audit records.
Automated access decisions
Access to a provider's API may be granted or denied automatically based on that provider's rules — for example whether your email or domain is on their allowlist, whether you belong to a required group, or whether your account has been suspended. A denied request is refused in real time. If you believe access was denied in error, contact the API provider, who controls those rules; you can also contact us at the address below.
Request content
An API provider can enable a traffic-capture feature in a non-production (development) environment to help them debug their API. When enabled, the contents of requests and responses on that environment — which may include information you send — are stored so the provider can review them. We remove credentials such as tokens and API keys from stored samples, but we do not remove other content by field name, so any personal data inside a request or response body may be retained. This is controlled by the API provider and is off unless they turn it on.
Who we share it with
- The API provider — so they can identify and manage you as their user. They can see your identity (such as name and email), your group memberships, and your access status.
- The provider's own systems — when you call their API, we pass your identifier and group memberships to their backend so it can serve your request.
- Our service providers (subprocessors) — we use Cloudflare (hosting, storage, and network), Upstash (rate-limit counters), an OpenFGA authorization service, and AWS SES (to send operational email to providers and our team). These process data on our instructions.
- We do not sell your personal information, and we do not send you marketing email.
How long we keep it
- Your identity and account records: while the API provider maintains your access.
- Identities observed from traffic: pruned after about 90 days without activity.
- Stored provider tokens: no longer than about 30 days.
- Security and audit records: retained for a period appropriate to security and legal needs, and some security-audit entries are kept even after other data is deleted.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. Because the API provider is the primary controller, requests about how they use your data are best directed to them. For the processing APIblaze carries out (operating sign-in and platform security), contact us at privacy@apiblaze.com. You can also revoke the permission you granted your login provider at any time from that provider's settings.
Security
We protect your information with encryption in transit, encryption at rest for stored tokens and secrets, irreversible hashing of API keys, isolation of each provider's data, and access controls. No system is perfectly secure, but we work to protect your information appropriately.
If you sign in with APIblaze's shared login
Some providers use a shared APIblaze sign-in option. If you use it, your login provider's consent screen names APIblaze rather than the API provider — but your profile information is still used to give you access to the API provider whose service you are signing in to, as described here. Providers can instead use their own login, in which case their own name appears at that step.
Children and sensitive data
Our sign-in is not directed at children under 16 and is not intended for the collection of special categories of data (such as health, biometric, or similar sensitive information). Please do not submit such information through sign-in.
Changes and contact
We may update this notice; material changes will be reflected by the date above. Questions can be sent to privacy@apiblaze.com (APIblaze LLC, Birmingham, Michigan, United States). For how a specific API provider uses your data, please see that provider's privacy policy.