Apilift Privacy Policy
Effective date: 27 September 2026
This Privacy Policy explains how Egor Sergeev, trading under the product name Apilift (Apilift, we, us or our), handles personal data when you use the Apilift website, command-line software, Chrome extension and shared interface registry.
1. Controller and contact
The controller is Egor Sergeev, Kanika Center, Block B, Panayioti Simeou, Flat 206, 3105 Limassol, Cyprus. Contact: contact@apilift.dev.
The Service is intended only for people aged 18 or older. Paid features are available to eligible customers in the United Kingdom and other locations supported by Paddle and applicable law.
2. What stays on your device
During a task you initiate, the Chrome extension can observe the selected tab’s URLs, requests, responses, page activity and authentication material needed to capture or replay the requested operation. Depending on the product you select, this can include identifiers, communications, financial or health information, location, browsing activity and other website content.
Authentication values are held briefly in Chrome memory for the authorised operation and redaction. They are not placed in generated interfaces. Credential-redacted records can be retained temporarily in the extension’s bounded local write-ahead log until delivery to the Apilift program on the same computer succeeds. Other task content can remain in the local Apilift catalog until you delete it from your device.
Apilift stores local command and execution records to correlate agent activity and measure usage. These records can include command arguments and temporary copies of command output, alongside command identity, timing, outcome and execution identifiers. The usage collector processes this evidence on your device and uploads only the permitted execution metadata and numeric measurements described below. Command arguments, responses and agent transcripts are not uploaded with those measurements. Local invocation records are pruned after 90 days. You control removal of local task data from your device.
Apilift automatically reads locally stored Codex and Claude sessions to measure productive Action usage and estimate savings. A background collector reads request token counters, model and producer versions, timestamps and tool-result correlation receipts. Native indexes and process sidecars locate those histories. The collector reads transcripts locally to find those measurements and correlate tool activity. It does not upload transcripts, prompts, tool arguments or results, screenshots, URLs or credentials. Its private local records include measurements, coverage, native session and request identifiers, correlation data and the command evidence described above. Identifiers sent with usage measurements are pseudonymised; native history paths and collection cursors remain on your device. Apilift does not change native history settings. Missing histories or incomplete records leave measurements unavailable. Discovery supplies repeatable-workflow baseline samples; discovery cost is never displayed or deducted from savings. API-equivalent cost estimates use recorded models and versioned prices and do not represent complete provider billing.
Raw browser captures, command arguments, URLs, headers, request and response bodies, browser credentials, session context, concrete account values and upstream error text are not sent with execution metadata to the public registry. Because local processing happens under your control, you are responsible for choosing authorised accounts and data and for deleting local task records you no longer need.
3. Data we receive
When you create an account, we receive the account identifier issued by Supabase Auth, your email address, authentication provider, account status, trial dates, onboarding preferences and progress, personal-workspace membership, installation links and the Terms version and acceptance time recorded when your account is created. We use these records to authenticate you, resume setup, connect your local installation and provide the applicable product features. If you choose Google or GitHub sign-in, that provider supplies Supabase Auth with the identity data shown in its consent flow; Apilift does not receive your provider password.
For each linked installation, we store its random identifier, a one-way hash of its authentication token, machine label, operating system, architecture, CLI version, readiness and creation and activity times. Linking an installation does not create an acceptance record.
The command-line software requests current account, entitlement and app-access information from Apilift. It reports execution identifiers, app and action versions, the selected interface, purpose, client family and agent, timestamps, outcome categories, HTTP status and bounded diagnostic classifications. We associate these records with the account, workspace and installation to authorize access, enforce limits, evaluate interface reliability and calculate usage. Request bodies, responses, command arguments and credentials are not included in these reports. Reliability evaluation can change which verified interface version is offered; it does not autonomously perform discovery or execute an app operation.
The command-line software can send numeric usage observations and revisions, measurement coverage and repeatable-workflow baseline samples bound to compatible Action versions. We associate productive Action records with your account, installation and app to estimate time, token and API-equivalent model-cost savings. Productive failed attempts and retries contribute to the cost of that work but earn no alternative benefit. Shared repeatable app preparation is attributed once per pseudonymous native root session and app. Discovery, setup, publication and verification earn no productive usage or savings, and discovery cost is never deducted. Recorded model and cache categories determine pricing; a model preference cannot rewrite measured consumption. Only numeric baseline measurements follow an app's existing public or private visibility; contributor session identities are not shared.
When you publish an interface, we receive its validated app, entity, action, transport and browser-context definitions as applicable; app name and origin; integrity identifiers; visibility; workspace association; revision history; validation metadata; and timestamps. Private interfaces are hosted on Apilift servers and available to authorised members of the owning workspace. They are excluded from public search and public app pages. Private does not mean local-only storage or end-to-end encryption. App credentials, captured traffic, command inputs and responses, saved parameter defaults and agent transcripts are not included in published definitions.
When an interface is saved to Community, its accepted resources, synthetic examples and validation metadata become public and can remain in public revision history. Creating a private copy does not withdraw an existing Community interface. If an owner explicitly makes a private interface public, only its confirmed current head and future public updates enter Community; earlier private revision history remains private. Trial expiry, subscription loss or downgrade does not publish, delete or change the visibility of private data.
When you use our website or registry, Fly.io and our application infrastructure can process IP address, request path, timestamp, user agent, request identifier and operational logs needed to deliver and protect the Service. We use PostHog in its EU region for website and product analytics, onboarding session replay, production exception diagnostics and revenue reporting. Website analytics use pseudonymous browser and session identifiers stored in cookies and local storage, landing paths without query strings, referrer domains, campaign parameters, the presence and type of recognised advertising click identifiers, browser/device information and coarse geography. We retain original acquisition and the latest non-direct acquisition touch, and associate them with your Apilift account after sign-in. The latest touch expires after 90 days; the first touch remains in PostHog under its configured retention, including after account erasure. A direct return does not replace an earlier campaign. These records help us understand conversion, app adoption, retention, reliability and revenue sources. We do not send advertising click identifier values to PostHog or share this data with advertising networks. A browser also stores a functional theme preference.
During signed-in onboarding, we record masked interactions on eligible Apilift dashboard pages, including return visits until a successful productive app operation. Setup, discovery and verification do not count as activation. Inputs, page text and element attributes are masked; credential, account-settings and billing screens and code or terminal areas are excluded. Third-party pages, captured requests and responses, authorization material, command arguments and agent transcripts are not recorded. Recording stops on logout or activation. A later correction of an operation’s purpose can change activation status.
The CLI, native program and extension send bounded diagnostic events containing pseudonymous installation/account links, versions, stage and outcome codes, durations, and sanitized error types and stack locations. The extension can queue installation and connection failures before receiving an account identity from the native program, without inspecting ordinary browsing. It sends queued events only after receiving an eligible identity, and drops them if analytics is disabled or no identity arrives within seven days. Eligible CLI, native-host and extension events go directly to PostHog; server and worker events use a backend delivery queue. Commands do not wait for analytics delivery. Financial analytics come from committed Paddle billing records and include pseudonymous transaction/subscription identifiers, status, currency, payment amount, tax, refunds and fixed recurring value. Analytics are collected by default in production; this does not make a Terms agreement, privacy acknowledgement or continued use a grant of consent. Where applicable law requires consent for nonessential tracking or replay, that processing must wait for a separate valid consent.
If you contact us, we receive your email address and the information you include. Do not send credentials or unnecessary personal data in a report.
4. Authentication email and payments
Supabase Auth processes account authentication for Apilift. Resend delivers one-time authentication codes from login@notifications.apilift.dev and processes the destination email address, message content and delivery metadata for that purpose. A code expires after ten minutes. We do not use authentication messages for marketing.
If you purchase paid features through Paddle, Paddle processes payment-card, billing, tax, transaction, fraud-prevention and invoice information as merchant of record or authorised reseller under its own privacy notice. Apilift receives Paddle customer, product, price, transaction, subscription, invoice, refund, adjustment and chargeback identifiers and status; billing contact and currency details; subscription periods and scheduled changes; and the minimum metadata needed to associate the purchase with your workspace. We do not receive or store full card details.
Paddle sends signed billing webhook events to Apilift. We store the provider event identifier, event type, occurrence time, body hash, processing state and error information needed for idempotent processing, reconciliation and audit. The raw event body is retained only for bounded retry processing and is removed after successful processing. We use Paddle identifiers and custom metadata to recover a checkout whose outcome was unknown after a network interruption without sending a blind duplicate purchase request.
For Cloud, we receive or calculate immutable active-browser usage segments, monthly subscription-anchored usage windows, included and overage duration, six-minute billing units, applicable price version and billing-run status. These records support the 100-hour monthly allowance, overage charges, corrections, customer billing views, refunds and reconciliation. We do not use a general-purpose credit balance.
5. Why we process data
We process account, installation, acceptance, contribution, operation policy, execution, subscription, transaction and Cloud usage data as necessary to provide the Service, administer payments and perform our agreement with you; reliability analysis, security, rate limiting, diagnostics, abuse prevention, reconciliation and defence of legal claims for our legitimate interests in operating a reliable and lawful service; billing, tax, accounting, reports, rights requests and required records to comply with legal obligations; and optional processing on consent where we specifically ask for it. We do not treat acceptance of the Terms as consent to unrelated data processing.
Where we rely on legitimate interests, we limit the data, use pseudonymous identifiers where practical, apply short retention to network-derived data and provide the rights described below.
6. Who receives data
Fly.io provides application hosting and network infrastructure. Supabase provides hosted authentication, database and storage infrastructure. Resend provides transactional email delivery. PostHog processes the analytics, masked recordings, exception diagnostics described above in its EU region. Those providers process data for us under their contractual terms and security measures. Google or GitHub also processes authentication data under its own privacy terms if you choose that provider. Public interface revisions are available to anyone.
Authorised members of your workspace receive access to its private interfaces. We do not disclose a private interface to another workspace merely because it covers the same product, origin or name. We can also disclose data to professional advisers, authorities or other recipients when reasonably necessary to comply with law, protect rights and security, investigate abuse, or establish and defend legal claims. If the Service or its operation is transferred, relevant records can transfer subject to this policy and applicable law. Paddle receives payment information when you enter its checkout and receives subscription, plan-change, renewal, Cloud overage, cancellation, refund and dispute instructions or records while it administers the resulting payment relationship.
7. International transfers
Our providers can process data in the European Economic Area and other countries. Where personal data is transferred outside the EEA to a country without an adequacy decision, we rely on an available lawful safeguard such as the European Commission’s standard contractual clauses and supplementary measures where required. Contact us to request information about the safeguard relevant to your data.
8. Retention
We retain server execution reports and their attached measurements for 90 days after execution. Invalid baseline samples are removed after 90 days; valid samples and baseline profiles remain. Expired link codes are removed after one day, agent-session records after 30 days without activity, and publication-attempt records after seven days. We delete installation records after 24 months without authenticated activity, removing their machine identity while retaining valid numeric baseline measurements. Revoking an installation prevents further use of its credentials. Account erasure removes its activity records, measurements, usage totals, preferences and private app data; accepted public revisions and required accounting records are subject to the exceptions below.
CLI and native-host diagnostic queues hold up to 1,000 events, and extension queues up to 200 events, for at most seven days. Delivered backend analytics queue records are removed after 30 days. Successfully processed Paddle event payloads are cleared; processed or abandoned event records are removed after one year. Failed deliveries have bounded retries and may require operator recovery. PostHog retains data according to its configured retention, which can differ by data type and plan; contact us for the applicable retention. Deleting an Apilift account does not automatically remove previously collected product analytics, including the account-deletion event, or associated PostHog person and recordings. We assess verified privacy-rights requests for provider-held data under applicable law. Revoking an installation does not automatically erase the account’s other analytics.
Accepted public revisions are retained while useful for the shared library, security, integrity and provenance. Private interfaces and their private revision history remain while the owning workspace is active, including while paid access is paused after trial or subscription loss, and are deleted with the workspace subject to security, backup and legal retention. Making an interface public does not expose its earlier private revision history. Local records remain on your device until you remove them. Account and workspace records remain while the account is active. Erasure can retain inaccessible anonymized account and workspace records to anchor required accounting. A hashed trial identity remains to prevent repeated introductory trials; the hash derives from the normalized email address, or account identifier if no email is available. Paddle customer, transaction, invoice, adjustment, refund, chargeback and reconciliation records can remain afterward only as long as needed for legal, fraud-prevention, accounting, tax and dispute obligations. Successfully processed raw billing webhook bodies are removed; failed bodies are kept only for the bounded retry period. Expired device codes are retained only as short-lived setup records. Authentication email delivery metadata is retained according to Resend's configured service retention. Support, rights-request and legal records are kept only as long as needed for the request and applicable legal requirements.
9. Security
We use random installation credentials, one-way token hashing, workspace-scoped access controls, encrypted network transport, privacy preparation before saving, private-aware cache and job scope, restricted infrastructure access and operational logging designed not to include private service metadata. The Chrome extension accepts work only from an installed local native host and active Apilift task scopes. Private interfaces are not end-to-end encrypted, and no system is completely secure, so you should use appropriate test accounts, device security and backups.
10. Your choices and rights
You can revoke linked installations in the dashboard and request access to, export of or deletion of your account or installation data by emailing contact@apilift.dev. We may need information to verify that a request concerns you. Before completing account deletion, we cancel any Paddle subscription, remove private workspace/app data and associated activity, anonymize the retained account, and delete the authentication user. Previously collected analytics and the account-deletion event remain subject to PostHog retention in the ordinary account-deletion flow. If your request also seeks erasure of personal data held by our providers, we assess that as part of the same request under applicable law. If cancellation or a required owned-data deletion step fails, account deletion requires recovery before it is complete. Accepted public revisions remain attributed to a deleted author. Accounting and payment records subject to legal, fraud, refund, chargeback or dispute retention can remain. Removing the Chrome extension and removing local Apilift task records are separate actions under your control.
Subject to applicable law, you can ask to access, correct, erase, restrict or receive your personal data, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. We can ask for information needed to verify that the request concerns you. Some rights are limited where retention or processing is required by law or another person’s rights.
Send requests to contact@apilift.dev. You may complain to the Office of the Commissioner for Personal Data Protection in Cyprus at dataprotection.gov.cy or to another competent supervisory authority.
11. Automated decisions
We do not currently make decisions producing legal or similarly significant effects about you solely through automated processing. Automated integrity and abuse checks can reject or restrict a technical contribution; you can request review under the Acceptable Use Policy.
12. Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. The extension uses browser information only to provide and improve the user-facing task you requested. We do not sell it, use it for advertising, use it to determine creditworthiness or lend it to humans for unrelated review except where required for security, abuse prevention, legal compliance or support with your affirmative agreement.
13. Changes
We publish revisions here with an effective date. Corrections and clarifications do not require an acknowledgement. For material changes to how we handle personal data, we explain what changes and when through a dedicated email or another effective direct notice, in advance of the changed processing. A privacy notice update does not require you to accept the policy or interrupt existing access. Where processing requires your consent, we ask separately for that specific processing before it starts and provide a way to withdraw consent. Continuing to use Apilift or dismissing a notice is not consent to optional processing. We retain versioned policy copies in Git history and the Terms version and acceptance time recorded when your account was created. Apilift does not use policy-update notice cards or retain notice-dismissal records.