Cookie Policy
Effective date: 2026-08-05 · Last updated: 2026-08-05
DRAFT — PENDING COUNSEL REVIEW. Working draft for public Beta; not legal advice.
This Cookie Policy explains the very limited use of cookies and similar technologies across AllAPI, operated by Legal Eye Yazılım A.Ş. It expands on Privacy Policy §11.
1. Summary
AllAPI uses no advertising cookies, no third-party analytics cookies, and no cross-site trackers. The only cookie we set is a single first-party session cookie on the dashboard, which is strictly necessary to keep you logged in.
2. Cookies by domain
| Domain | Cookies | Purpose | Type |
|---|---|---|---|
api.allapi.io (the API) | None | Authentication is via the X-AllAPI-Key header, not cookies | — |
app.allapi.io (dashboard) | 1 session cookie (HMAC-signed, Secure, HttpOnly, SameSite=Lax) | Keep you logged in after sign-in | Strictly necessary |
docs.allapi.io (docs) | None | Fully static documentation | — |
The signup form at app.allapi.io runs a bot-challenge (CAPTCHA) to protect against automated abuse; the challenge may set a short-lived token. It is a security control, not advertising or analytics.
3. Why no consent banner (currently)
Under the EU ePrivacy Directive / Türkiye practice, strictly necessary cookies (like a session cookie required for a service you requested) do not require prior consent. Because we set no non-essential cookies, we do not display a cookie-consent banner.
4. Managing cookies
You can block or delete cookies in your browser settings. Blocking the dashboard session cookie will prevent you from staying signed in. Blocking cookies has no effect on API usage, which is header-authenticated.
5. Changes
If we ever introduce analytics or other non-essential technologies, we will update this policy, add a consent mechanism where required, and announce material changes per Privacy §15.
Contact
[email protected] · Operator: Legal Eye Yazılım A.Ş., Kağıthane / İstanbul, Türkiye.
Draft — pending counsel review. Not legal advice.