Privacy Policy

Effective date: 2026-08-05 Last updated: 2026-08-05

DRAFT — PENDING COUNSEL REVIEW. This document is a working draft prepared for public Beta and for review by the operator's legal counsel. It is not legal advice and does not constitute a final, counsel-approved Privacy Policy. It will be replaced by a counsel-reviewed final Privacy Policy before general availability (GA). Nothing in this Beta draft creates additional obligations beyond those already imposed by applicable law, and nothing in it waives any right or defense of the operator or of any data subject.

AllAPI ("we", "us", "our") is operated by Legal Eye Yazılım A.Ş., a company established in the Republic of Türkiye (Trade Registry No. 1020744; VKN 6081733803), with registered office at Sultan Selim Mah. Yamaç Sk. No:6 İç Kapı No:3, Kağıthane / İstanbul, Türkiye, trading as "AllAPI". We operate the HTTP API at api.allapi.io, the developer dashboard at app.allapi.io, the documentation at docs.allapi.io, the Model Context Protocol (MCP) tools, and related subdomains (collectively, the "Service").

This Privacy Policy explains what personal data we collect, why we collect it, on what legal basis, how we use and share it, how long we keep it, how we protect it, how we handle personal data of third parties that may appear inside data the Service returns, and the rights you and other data subjects have.

This Policy applies together with our Terms of Service and our Acceptable Use Policy. By using the Service you confirm that you have read and understood this Policy. Capitalized terms not defined here have the meanings given in the Terms of Service.


0. Our role and the two data-protection regimes that apply

We are the data controller (KVKK: veri sorumlusu; GDPR: controller) for the personal data described in this Policy, meaning we determine the purposes and means of processing.

Two data-protection regimes apply at the same time, and where they differ we apply the stricter standard:

Data controller identity, VERBİS and representatives:


1. Scope — the two kinds of data we handle

This Policy covers two distinct categories of data, and it is important not to confuse them:

  1. Customer personal data (§§2–13). Personal data about you — the account holder, dashboard user, or person contacting support. Here we are the controller and the ordinary rules below apply.
  1. Third-party public data returned by the Service (§14). The Service is a unified gateway that retrieves only publicly available data, using anonymous, unauthenticated requests (no login, no acceptance of any upstream's account terms), and returns it in a normalized JSON envelope. Some of that returned data may itself contain personal data of third parties (for example, a public profile name that appears in a public search result). Our role, legal basis, and — importantly — the removal / objection mechanism for individuals whose public data appears in Service responses are addressed separately in §14.

2. Data we collect (customer personal data)

2.1 Account data (you provide)

2.2 Operational data (collected automatically)

For each API request we retain the following metadata:

For each account we retain aggregated per-tier counters used for quota enforcement, billing, and abuse detection.

2.3 Support and communications data

When you contact us (e.g. [email protected] or a support channel) we retain the content of your message, your email address, and any X-Request-Id or account identifier you include, so we can investigate and respond.

2.4 What we do not collect


3. Legal bases for processing

We process customer personal data only where we have a lawful basis. The bases below map to GDPR Article 6 and to KVKK Article 5 (and Article 6 for any special categories, which we do not routinely process).

PurposeGDPR Art. 6 basisKVKK Art. 5 basis
Create and operate your account; authenticate requests; apply rate limits and quotas; deliver responsesArt. 6(1)(b) performance of a contractArt. 5(2)(c) directly related to the conclusion/performance of a contract
Issue invoices; keep tax and accounting recordsArt. 6(1)(c) legal obligationArt. 5(2)(ç) compliance with a legal obligation
Security, abuse/fraud detection, rate-limit enforcement, short-term operational logging, product improvement (aggregated)Art. 6(1)(f) legitimate interestsArt. 5(2)(f) legitimate interest (meşru menfaat), balanced against your rights
Any processing that genuinely requires consent (currently none for tracking)Art. 6(1)(a) consentArt. 5(1) explicit consent (açık rıza)

Legitimate-interest balancing. Where we rely on legitimate interests (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)), we have assessed that our interest in operating a secure, abuse-resistant Service does not override your fundamental rights and freedoms, because the data involved is limited operational metadata, retained for short periods, and not used to build profiles of you. You may object to this processing (§9).

Consent. We currently do not use tracking cookies or advertising networks, so we do not rely on consent for those purposes. If we ever introduce processing that requires consent, we will ask for it separately and you may withdraw it at any time without affecting prior processing.


4. How we use your data (purposes)

We do not use your personal data to make solely automated decisions that produce legal or similarly significant effects on you (§12).


5. Data retention

We keep personal data only as long as necessary for the purpose for which it was collected, or for a legally mandated period.

DataRetention
Account data (email, password hash, key hash, profile)Life of account + 30 days after deletion, then purged
Operational logs (request metadata, IP address, user-agent)30 days, then aggregated and purged
X-Request-Id + per-request metadata30 days
Aggregated per-tier usage counters24 months (billing and product analytics)
Invoices and payment records7 years — Turkish Tax Procedure Law (VUK) and accounting obligations; comparable EU tax-law periods
Support conversations24 months from last activity
Backups30 days (rolling), encrypted
Data-subject removal / rights-request records (§14, §9)Kept as needed to evidence that we honored the request and to prevent re-appearance, then purged

Where local law imposes a longer or shorter mandatory retention, that law prevails.


6. Data sharing and sub-processors

We do not sell your personal data. We share personal data only:

6.1 Sub-processors

CategoryPurposePersonal data involvedLocation
Merchant of Record — Creem (Armitage Labs OÜ)Payment processing, invoicing, and VAT/sales-tax collection & remittance for paid tiersbilling details, email, name, country, tax IDEstonia (EU)

The Merchant of Record (Creem / Armitage Labs OÜ) is named because it is the seller for paid orders. For the other categories, a current list of the specific named sub-processors is available to customers on request at [email protected]. We keep this list current; material changes are announced per §15, and you may object to a new sub-processor as described there.

Merchant of Record note. For paid tiers, Creem (Armitage Labs OÜ, Estonia) acts as the seller / Merchant of Record. Creem collects your payment details directly, issues the invoice, and collects and remits VAT / sales tax. Your purchase is therefore also subject to Creem's own checkout terms and privacy notice. We receive from Creem only the invoice and billing-record data described in §2.1.

Third-party public data returned by the Service is not our personal data to share; the original publisher's own policies apply, and your onward use of it is governed by the Terms and the Acceptable Use Policy — see §14.


7. International transfers

Our infrastructure (servers and database) is hosted in the European Union / EEA. Because the data controller, Legal Eye Yazılım A.Ş., is established in Türkiye, your account and billing data may also be accessed from and processed in Türkiye, which has its own data-protection law (KVKK). Personal data may additionally be processed by the sub-processors listed in §6.1, in the locations shown there.

GDPR / UK-GDPR transfers. Where personal data of EU / UK residents is transferred outside the EEA / UK (including to Türkiye or to a sub-processor outside the EEA), we rely on an appropriate transfer mechanism — an adequacy decision where one exists, or Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum where applicable), together with any supplementary measures required. A copy of the relevant transfer safeguards is available on request at [email protected].

KVKK cross-border transfers. Transfers of personal data abroad under KVKK (as amended in 2024) are made on one of the permitted bases — an adequacy decision by the Personal Data Protection Board, an appropriate safeguard such as a standard contract (standart sözleşme) or binding corporate rules / undertaking, or, where none applies, one of the exceptional grounds (including explicit consent).


8. Your rights as a data subject

Depending on where you live, you have some or all of the following rights. To exercise any of them, see §10.

8.1 Türkiye residents (KVKK Article 11)

You have the right to:

8.2 EU / UK residents (GDPR / UK-GDPR)

You have the right to:

8.3 California residents (CCPA / CPRA)

You have the right to:

8.4 Other jurisdictions

If your local law grants you additional rights, we will honor them to the extent legally required.


9. Objection and withdrawal

Where we process your data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation; we will stop unless we demonstrate compelling legitimate grounds that override your interests or the processing is needed to establish, exercise, or defend legal claims. Where we process on the basis of consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal. Where we introduce a new sub-processor (§6.1) you may object as described in §15.


10. How to exercise a right — and how to file a removal request

10.1 Customer rights requests

Email [email protected] with the subject line "Privacy request" and describe the right you want to exercise. We respond within 30 days (or the local statutory deadline, if shorter — including the KVKK 30-day period). We may ask you to verify your identity before releasing or acting on data, to protect your account.

10.2 Removal of your personal data that appears inside Service responses

If you are an individual (not necessarily a customer) whose personal data appears in data the Service returns, you may request suppression/removal at [email protected] with the subject line "Removal request". See §14 for how this works, what we can and cannot do, and what information to include. You may also use [email protected] to report misuse.

10.3 Complaints to a supervisory authority


11. Cookies and similar technologies

You can block or delete cookies in your browser, but doing so may prevent you from staying logged in to the dashboard.


12. Automated decision-making and profiling

We do not use your personal data for solely automated decisions that produce legal or similarly significant effects on you (GDPR Art. 22; KVKK Art. 11). Rate limiting and abuse detection are technical safeguards, applied to protect the Service, and are not profiling of you as an individual.


13. Security

No system is perfectly secure. If you discover a vulnerability, please report it to [email protected] — we appreciate responsible disclosure.


14. Third-party personal data returned by the Service (removal & objection)

This is the section that addresses individuals whose personal data appears inside data the Service returns, rather than our own customers. It is the core of our data-subject-protection posture.

14.1 What the Service does

The Service is a unified read-only gateway. For each request, it retrieves only publicly available data from an Upstream Source using an anonymous, unauthenticated request — we do not log in, do not accept any upstream's account-holder terms, do not resell authenticated-API or credential access, and do not bypass authentication, DRM, paywalls, or captchas. The retrieved data is returned to the customer in a normalized JSON envelope. We do not store the response payloads (see §2.4).

Some of that publicly available data may itself contain personal data of third parties — for example, a name, a public handle, or other identifiers that the individual or a publisher has already made public on the open web.

14.2 Our role and legal basis for this data

For personal data that transits the Service inside upstream responses, we act as a conduit / controller for the limited act of retrieval and normalized delivery. We rely on:

Important limits on what "public" means. Public availability defeats claims based purely on breach of a platform's account terms or unauthorized-access theories (because we operate logged-out and accept no account terms). It does not by itself extinguish copyright, database, trademark, or personal-data rights. Accordingly:

14.3 Removal / suppression right for affected individuals

If your personal data appears in data returned by the Service and you want it suppressed, you may ask us to act. This right is available to any affected individual, whether or not you are a customer.

How to request removal. Email [email protected] with the subject line "Removal request", and include:

  1. Your identity and enough detail to verify you are the individual concerned (we will request only what is necessary to verify, and use it only to process the request);
  2. The specific personal data at issue and, where possible, the Upstream Source, endpoint/platform slug, or query through which it appears (an example X-Request-Id helps greatly);
  3. Confirmation that you are the data subject or an authorized representative.

What we can do. On a valid request, we will suppress the identified personal data at our layer — for example by blocking the relevant query path or filtering the identified data from responses our Service returns — and confirm back to you. We keep a minimal record of the request so the data does not re-appear (§5).

What we cannot do. We cannot delete data at the Upstream Source — that data lives on a third-party site we do not control. To have it removed at source, you must contact the original publisher. Suppression at our layer stops the Service from returning it, but does not remove it from the open web.

Objection. Independently of removal, you may object to our processing of your personal data through the Service on grounds relating to your particular situation, using the same channel; we will assess the objection under §9.

Timing. We handle removal and objection requests within 30 days (or the shorter statutory deadline that applies), and may extend for complex requests with notice to you.

14.4 Abuse reporting and cooperation

Suspected misuse of the Service involving personal data (e.g. scraping-for-doxxing, re-identification, or building surveillance tooling — all prohibited by the Acceptable Use Policy) can be reported to [email protected]. We investigate, may suspend or terminate offending accounts, preserve evidence, and cooperate with law-enforcement and supervisory authorities where lawfully required.


15. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes — those that materially expand our use of your personal data, add a new sub-processor, or reduce your rights — will be announced at least 14 days in advance via email to the address on your account and on the dashboard, giving you the opportunity to object to a new sub-processor or to close your account before the change takes effect. Non-material clarifications may be published without advance notice; the "Last updated" date at the top always reflects the latest revision.


16. Children

The Service is not directed to individuals under the age of 18 and we do not knowingly collect personal data from children as customers. If you believe a child has provided us data, contact [email protected] and we will delete it promptly.


17. Contact

Data controller: Legal Eye Yazılım A.Ş. (Türkiye; Trade Registry No. 1020744, VKN 6081733803), registered office Sultan Selim Mah. Yamaç Sk. No:6 İç Kapı No:3, Kağıthane / İstanbul, Türkiye, trading as "AllAPI".

If your inquiry concerns a specific request or a removal, include the X-Request-Id from any Service response — it lets us locate the operational record in seconds.


Draft — pending counsel review. Not legal advice. Prepared for Legal Eye Yazılım A.Ş. / AllAPI, tailored to AllAPI's anonymous public-data model under Türkiye (KVKK) and EU/UK (GDPR), with Creem as Merchant of Record. Counsel to finalize VERBİS registration, EU Art. 27 representative, DPO determination, and the specific KVKK/GDPR cross-border transfer mechanisms before GA.