Public APIs

Privacy Policy

Last updated 22 September 2026

This policy explains what personal data Public APIs (publicapis.dev) collects, why, and what you can do about it. Public APIs and its sister site Dev Resources (devresourc.es) are run by the same person, share the same infrastructure and newsletter, and follow this same policy.

The short version:

  • You can browse both sites without an account, and nothing about you is sold.
  • There are no advertising or cross-site tracking cookies. Our analytics is self-hosted and cookieless.
  • If you sign in, we keep what we need to run your account: your email, name and profile picture.
  • Anything you submit for listing is public. Your email address and account stay private.

1. Who is responsible for your data

The data controller is Marcel Cruz, an individual based in Spain, who operates Public APIs and Dev Resources (“we”, “us”). For any question or request about your data, write to us through the contact form (choose “Something else”). We answer within one month, as the GDPR requires.

2. What we collect, why, and our legal basis

Browsing the site

Like any website, our hosting provider receives your IP address, browser details and the pages you request, so it can deliver the site and protect it from abuse. Legal basis: our legitimate interest in running a secure, working website.

We measure traffic with Rybbit, an open-source analytics tool that we host ourselves. It sets no cookies and stores nothing on your device. It records the pages you view, the referring site, campaign parameters in the URL (such as utm_source), links you follow to other sites, and a few named actions (such as adding a bookmark or sending the contact form). Your IP address and browser details are used only to work out your approximate country and an anonymous session identifier that changes daily. We don’t use analytics to identify you, and we don’t combine it with your account. Legal basis: our legitimate interest in understanding which parts of the site are useful. You can object by blocking the script (any content blocker does it) or by writing to us.

Your account

Accounts are optional. You need one to submit a listing, save bookmarks, or manage advertising you bought. Sign-in is handled by Clerk, which stores your email address, your name and profile picture if you provide them, and your sign-in method. We use this to sign you in, to show your name and picture in the account menu, and to tie your bookmarks, submissions and purchases to you. Legal basis: performing our agreement with you (the Terms of Service).

Signing in with Google

If you choose “Continue with Google”, Google shares with us only your name, email address and profile picture (the basic “openid”, “email” and “profile” permissions). We ask for nothing else: we have no access to your Gmail, Drive, contacts or any other Google data. About this Google user data:

  • How we use it: only to create your account, sign you in, show your name and picture in the account menu, and link your submissions, bookmarks and purchases to your account.
  • Where it’s stored: your profile is held by Clerk, our sign-in provider. Our database keeps your account ID, and your email address where a submission or purchase needs it.
  • Who it’s shared with: no one, apart from the service providers listed in section 4 that process it on our behalf. We never sell it, never use it for advertising, and never use it to develop or train AI models.
  • Deletion: ask us to delete your account and we remove this data as described in section 6. You can also remove our access at any time from your Google Account’s third-party connections page.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy. Google handles your Google account under its own privacy policy.

Bookmarks

We store which APIs you bookmarked against your account ID, so your list follows you between devices. Legal basis: performing our agreement with you.

Submitting a listing

When you submit a listing, we store what you enter (name, URL, description, keywords and category) together with your account ID and email address. The listing details become public once published, and may be publicly previewable while in review. Published listings are also added to our public, MIT-licensed GitHub repositories, where the history is permanent. Your email address and account ID are never published: we use them to recognise you as the owner and to contact you about the listing. Legal basis: performing our agreement with you.

To build the listing page, we visit the submitted website, take screenshots of it, and use automated tools, including AI models from Anthropic, to help review it and draft a summary. This processes the website’s public content, not personal data about you.

Newsletter

If you join from the form in the footer, we store your email address to send you new APIs every two weeks. Legal basis: your consent, which you can withdraw at any time.

When you create an account, we also add your email address to the newsletter. Legal basis: our legitimate interest in keeping members up to date with the directory. You can object at any time: every issue has a one-click unsubscribe link. After you unsubscribe we keep your address marked as unsubscribed, so we don’t email you again.

Contact form

Messages sent through the contact form (your name, email address and message) are emailed to us and are not stored in our database. We use them only to reply to you. Legal basis: our legitimate interest in answering you, or taking steps you asked for before an agreement.

Reporting a listing

The “Report” button on a listing opens a public issue in our GitHub repository containing the issue type and your optional message. Please don’t put personal information in it. No account is needed and we don’t record who sent the report.

Advertising and paid services

Payments are handled by Stripe on its own checkout pages: we never see or store your card details. From Stripe we receive your email address, your customer and subscription identifiers, the plan you bought and its status. We also store what you give us to set up your ad, such as logos, banner text and notes to us; logos and banner text are shown publicly as part of your ad. Legal basis: performing our agreement with you, and our legal obligation to keep tax and accounting records.

Contributions on GitHub

If you open a pull request or issue on our GitHub repositories, we copy its details (your GitHub username, the title, content and comments) into our own tools to review it. Automated tools, including AI models, help us sort and assess it. This data comes from GitHub, where it is already public. Legal basis: our legitimate interest in maintaining the directory.

Automated decisions

The automated tools described above help us review submissions and contributions. They don’t make decisions that have legal or similarly significant effects on you.

3. Cookies and local storage

We only store what the site needs to work, so there is no cookie banner:

  • Sign-in cookies set by Clerk, which keep you signed in and protect your account. These are strictly necessary for a service you ask for.
  • Theme preference (light, dark or system), saved in your browser’s local storage so the site remembers your choice. It never leaves your device.

Stripe sets its own cookies on its checkout pages, mainly to prevent fraud. Logos and screenshots are served from Cloudinary’s image network, so your browser connects to Cloudinary to load them. We use no advertising, social media or cross-site tracking cookies.

4. Who we share data with

We don’t sell or rent your personal data. We share it only with the service providers we need to run the sites, and each gets only what it needs to do its job:

  • Vercel: website hosting and delivery.
  • Supabase: our database (account IDs, bookmarks, submissions, advertising records).
  • Clerk: sign-in and account management.
  • Stripe: payments and billing. Stripe also acts as an independent controller for fraud prevention and its own legal obligations.
  • Amazon Web Services (Ireland region): sending emails, including the newsletter (the newsletter software itself runs on our own server) and contact-form messages to us.
  • Cloudinary: storing and serving screenshots and advertiser logos.
  • Anthropic: AI processing of submitted websites and GitHub contributions, as described above.
  • GitHub: hosting our public repositories and the issues created by the Report button.

Our analytics (Rybbit) and newsletter software run on servers we control. We may also disclose data if the law requires it, or to protect our rights or the safety of others.

5. International transfers

Some of these providers are based in, or process data in, the United States or other countries outside the European Economic Area. Where they do, the transfer is protected by the EU-U.S. Data Privacy Framework where the provider is certified, or by the European Commission’s Standard Contractual Clauses. You can ask us for details of these safeguards through the contact form (choose “Something else”).

6. How long we keep data

  • Account and bookmarks: until you ask us to delete your account.
  • Submissions: the listing stays public for as long as it is in the directory, and in the history of our GitHub repositories. We keep your email address and account ID with it while you own the listing, and remove them on request.
  • Newsletter: until you unsubscribe. We then keep your address only as “unsubscribed”, so we never email you again.
  • Contact messages: for as long as needed to deal with your message and any follow-up.
  • Payment records: for as long as Spanish tax and accounting law requires, currently up to six years.
  • Server logs: a short time, usually days to weeks, as set by our hosting provider.
  • Analytics: kept as statistics that don’t identify you.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • have inaccurate data corrected;
  • have your data deleted, including your whole account;
  • restrict how we use your data;
  • receive your data in a portable format;
  • withdraw your consent at any time, without affecting what we did before.

You also have the right to object, at any time, to our use of your data based on legitimate interests, including the newsletter and analytics.

To use any of these rights, write to us through the contact form (choose “Something else”), from the email address the request relates to if you can. We may ask you to confirm your identity before acting on it. If you think we have mishandled your data, you can complain to the Agencia Española de Protección de Datos (AEPD) or to the data protection authority where you live.

You don’t have to give us any personal data to browse the sites. An email address is required to create an account, join the newsletter or buy advertising, because we can’t provide those without it.

8. Security

All traffic is encrypted over HTTPS. Access to our database and admin tools is limited to us and protected by authentication, and card payments never touch our servers. No system is perfectly secure, but we take reasonable steps to protect your data and will tell you if a breach affects you, as the law requires.

9. Children

The sites are for developers and aren’t directed at children. We don’t knowingly collect data from anyone under 14, the age of digital consent in Spain. If you think a child has given us personal data, tell us and we will delete it.

10. Changes to this policy

We update this policy when our practices change; the date at the top shows the latest version. If a change significantly affects how we use data you have already given us, we will tell you by email or on the site before it takes effect.