Skip to content
All policies

Privacy Policy

privacy-2026-09-17.1

Effective: 2026-09-17.

1. Scope and contact

This Policy describes personal information processed by Aurevant LLC, a Wyoming (USA) limited liability company, through the DataXAPI website, account console, public-data APIs, support and complaints. Contact privacy@dataxapi.com without first registering or purchasing. Original platforms and other applications you connect have their own processing rules.

We are responsible for processing whose purposes and means we determine. Callers using results in their own businesses also have duties for subsequent collection, storage, sharing and use. Actual legal roles depend on the activity; describing a service as a technical intermediary does not eliminate responsibility.

2. Information and purposes

Category Information and purpose
Account and authentication Email, identity identifiers, workspace associations, sessions and necessary verification information for sign-in and access management
API credentials Key digests, names, prefixes, permissions and creation/revocation state for authorization; full keys are delivered only on creation and must be kept securely
Trial and security Grant history, a normalized-email duplicate-prevention identifier, necessary network/device signals and abnormal events for preventing repeat claims, attacks and unauthorized access; such identifiers are not necessarily anonymous
Requests and results Submitted queries, URLs, public object identifiers, required parameters and retrieved public content for execution and normalized results
Usage and accounting Request identifiers, endpoint/version, time, duration, result category, charge status, balances, orders and payment/refund/dispute references for settlement and reconciliation
Support and rights Contact information, object links, relationship to the request, explanations, necessary evidence and decisions for support, appeals, export and deletion

Do not submit unrelated sensitive information, platform passwords, cookies, private sessions or others’ secret credentials. Public content may contain personal information and remains protected. If private or sensitive information is returned unexpectedly, stop further distribution and contact rights@dataxapi.com.

Payment credentials go directly to the checkout provider. The DataXAPI application does not ask you to send support full card numbers or CVCs or store them as product-account fields. We receive order, amount, status and transaction references needed for payment services. The Stripe account is opened and used by Aurevant LLC’s authorized principal on its behalf.

3. Recipients and sharing

We provide necessary data for defined service purposes. We do not sell personal information to data brokers or trade advertising audiences, and do not use account, query or complaint content to train our own models. This does not grant training rights to underlying public content.

The system uses, or enables by feature configuration, the following infrastructure services. A service may act as a processor or independently for different activities; a brand does not establish a single legal role or country of processing.

Service Data and purpose
Supabase Account email, authentication and business database records for identity, storage and corresponding recovery functions
Vercel Website/API requests and runtime information for hosting, delivery and operational security
Cloudflare DNS information; verification signals when security checks are enabled; controlled backups and minimal rights journals in R2; addresses and content for email forwarding. Each function receives what it needs; DNS use does not mean every API transaction is proxied
Resend Recipient addresses, verification/service-message content and delivery status for service email
Stripe Checkout information and payment, refund and dispute data for payment processing and its applicable security/compliance duties
Google mail services Addresses, message content and attachments forwarded to the operational support inbox to handle support, privacy and rights requests; the private inbox address is not published
Sentry and PostHog, when configured Redacted error/call events such as request identifiers, versions, duration, result categories and charge status for troubleshooting, reliability and service-use analysis; not a destination for raw queries or full results

An execution sends necessary query parameters and public identifiers to the data supplier used by that endpoint, not your DataXAPI key, payment credentials or complaint evidence. Where specific-recipient notice, separate consent or other procedures are required, they must precede the applicable processing. This general Policy is not separate consent. Contact privacy@dataxapi.com about recipients involved in a particular call.

For legal demands, security and disputes, we verify the request and scope, disclose necessary information and notify people where permitted. A business transfer involving personal information requires notice of recipients and rights; changes of purpose or means require the applicable procedures.

4. Retention boundaries

Data Retention rule
Normalized results Normal online replay availability is at most 24 hours; expired results are not delivered as history. Rights restrictions can end availability sooner
Usage metadata 90 days by default; necessary financial records are separate and are not all promised to disappear on day 90
Account and credentials Kept to provide an active account; revocation stops subsequent key authorization and deletion cleans the specified account/credential data
Payments, refunds and disputes Minimal records for payment verification, refunds, disputes and applicable accounting/legal duties; not for restoring marketing or account spending
Trial, deletion and restriction identifiers Necessary digests and decisions kept separately to prevent repeat grants and resurrection of deleted accounts or restricted content after recovery; full results are not retained as a substitute for restriction records
Support and complaints Necessary content while handling a request; after closure, only records needed for review, disputes or applicable law, with unnecessary attachments and information deleted or de-identified

Financial, security, rights, support-mail and backup records follow their own purposes and applicable requirements, not a universal 24-hour or 90-day erasure promise. Isolated records have restricted access and no unrelated use. They must be deleted or anonymized when their purpose ends and no further retention ground remains. You may ask about categories, reasons and applicable periods for your information and object to unnecessary retention.

The 24-hour window concerns online results, not simultaneous physical erasure of every cloud or backup copy. Backups are restricted to recovery. Restoration must remove expired results and reapply deletion and restriction decisions before serving data again. Deleting the login identity alone is not represented as complete business-data deletion.

5. Browser storage, analytics and email

Authentication uses persistent browser storage. The playground stores submitted text and retry identifiers in the current tab; checkout stores selected quotes and retry identifiers. See the Browser Storage Notice. These are not all cookies or cleared after one HTTP request.

The current website has no advertising tracking or browser behavioral analytics. The server may send redacted call events, which are not necessarily anonymous and do not automatically stop when browser cookies are disabled. Future non-essential tracking that needs consent requires appropriate choices first. You may also contact privacy support to ask about or request restriction of analytics processing relating to you.

Verification codes, necessary security notices and requested support replies provide the service. Initial registration does not automatically subscribe you to marketing. Use the contact addresses above rather than replying to a verification-code sender for privacy requests.

6. Regions and international processing

Infrastructure and data suppliers may process data outside your location, including overseas hosting, authentication, email and payments. We do not promise exclusively mainland China storage or treat registration as a substitute for required separate consent, recipient disclosure or transfer procedures. Processing requiring such procedures must follow their completion; affected features or regions should not open before the necessary conditions are met.

7. Rights and security

Depending on applicable law, you may request information, access, copies, correction, deletion, restriction or objection, withdraw consent-based authorization and complain to an authority. Use account settings for export/deletion or contact privacy@dataxapi.com, including when the console or sign-in is unavailable. Withdrawal does not invalidate prior consent-based processing or automatically cancel other lawful grounds.

Verification is proportionate to the request; identity documents are not required by default. If we cannot act, we explain why and how to seek review, responding within applicable legal deadlines. Rejecting unnecessary processing or exercising rights does not justify unreasonable differential treatment. See the Data Rights Notice for export/deletion scope.

We use transport protection, key digests, access controls, redacted logs and traceable decisions. No system is perfectly secure. We take remedial action and provide legally required notices after security incidents. Contact privacy support if a minor may have supplied information without meeting service eligibility so we can investigate and act appropriately.

8. Changes

Material changes to data categories, purposes or recipients are notified appropriately. Where renewed consent is required, it precedes the relevant processing. The published page shows its effective date and version; replacing a page does not erase transactions or existing rights requests.