legal

Privacy Policy

Last updated: 2026-07-18

1. Who We Are

NukeAPI provides a global data-deletion API service. Contact: hello@nukeapi.dev

2. Data We Collect

Account data: Email address and an encrypted password when you register.

API usage data: Deletion-request logs, timestamps, integration names, and job statuses. We log outcomes, not the personal data being deleted.

Integration credentials: API keys you provide for third-party services are stored AES-256-GCM encrypted. We never log them in plaintext.

API keys: We store only a bcrypt hash (plus a deterministic lookup hash) — never the raw key.

Billing data: Managed entirely by Dodo Payments, our merchant of record. We do not store payment-card information.

3. Data We Do Not Collect

4. How We Use Your Data

5. Sub-processors

We use the following sub-processors to deliver NukeAPI:

Sub-processorPurposeLocation
SupabasePrimary database, auth and encrypted credential storageUnited States
UpstashRedis-backed rate limiting and abuse protectionUnited States
ResendTransactional email deliveryUnited States
Dodo PaymentsMerchant of record for billing (card/PayPal)United States
VercelHosting and serverless computeUnited States

6. Data Retention

Deletion-request logs and PDF audit trails are retained for 90 days, then permanently deleted. Account data is retained until you delete your account; credentials are encrypted and deleted when you disconnect an integration or delete your account. You may request immediate deletion by emailing hello@nukeapi.dev.

7. Your Privacy Rights

Regardless of where you are located, you have the right to access, correct, export, or delete your personal data held by NukeAPI. This includes rights under GDPR, CCPA/CPRA, LGPD, and equivalent laws worldwide. Contact us at hello@nukeapi.dev. We will respond within 30 days and will never sell your data to third parties.

8. International Data Transfers

Data may be transferred to and processed in countries outside your home jurisdiction. NukeAPI ensures all such transfers are protected by appropriate safeguards including Standard Contractual Clauses or equivalent internationally recognised transfer mechanisms.

9. Cookies

We use only essential session cookies required for authentication. We do not use tracking or advertising cookies.

10. Security

All data is transmitted over HTTPS/TLS 1.2+. Credentials are encrypted at rest with AES-256-GCM. API keys are never stored in plaintext. We conduct regular security reviews and follow industry best practices.

11. Changes to This Policy

We may update this policy periodically. We will notify you of material changes via email or dashboard notice.