Privacy, plainly.
Effective 4 August 2026
API Fleet is an independent software project. This notice explains the limited personal information collected through our early-access website and product.
Who is responsible
API Fleet is currently operated as an independent project by its founder. For privacy questions, access requests, corrections, objections, or deletion requests, email hello@apifleet.io. The operator's legal identity and postal contact details will be provided where legally required and on a verified request.
What we collect
- Early access: work email, company name, team size, selected product priorities, and an optional message.
- Product accounts: name, email, password hash, organization membership and role.
- Product content: API specifications, portal configuration, publishing history, custom domains, and GitHub connection and synchronization records.
- Necessary technical and security information, such as request and error information produced by our hosting providers.
Why we use it
We use this information to respond to early-access requests, provide and secure API Fleet, synchronize specifications when requested, publish portals, prevent misuse, troubleshoot problems, and meet legal obligations. We do not sell personal information or use early-access details for unrelated newsletters.
Legal grounds
Where GDPR applies, processing is based on steps you ask us to take before providing the service, performance of the service, our legitimate interests in operating and securing the product, and legal obligations. We will ask separately before using consent for optional marketing.
Services we rely on
Early-access submissions are processed by Formspree, whose infrastructure is hosted on AWS in the United States. Formspree states that it uses Standard Contractual Clauses for covered international transfers. We also use our email provider, website and application hosting providers, database/storage providers, Cloudflare for domain and delivery services where enabled, and GitHub only when a customer connects a GitHub installation.
Retention
Early-access leads are reviewed at least annually and removed when no longer useful; Formspree's own plan retention may be shorter. Account and workspace information is kept while the service is active and then deleted or anonymized when no longer needed, subject to backups, security records, legal obligations, and requests from other workspace owners. Expired invitations and operational synchronization records are periodically removed.
Your choices and rights
Depending on where you live, you may request access, correction, deletion, restriction, portability, or object to certain processing. You may also complain to your local data-protection authority. Email hello@apifleet.io; we may verify your identity before acting.
Cookies and browser storage
The product uses an essential signed session cookie for authentication. Preferences may be stored locally in your browser. API credentials entered in the portal request tester are held only in the current page's memory and clear when the page reloads. The public marketing website does not currently use advertising or non-essential analytics cookies.
Security and changes
We use access controls, tenant isolation, encryption in transit, hashed passwords and limited provider permissions. No online service can promise absolute security. We will update this notice when the product or its providers materially change.