Privacy Policy
Our privacy policy and how we use your data
Effective date: 1 July 2026
This Privacy Policy explains what personal data AI Search API (aisearchapi.dev) collects, how we use it, who we share it with, and the rights you have. The Service is operated by AI Search API (aisearchapi.dev), a service of Cancode (“we”, “us”, or “our”), which is the data controller for the personal data described here. For questions or to exercise your rights, contact legal@aisearchapi.dev.
1. Data we collect
Account and organization data
- Your email address, and, if you use a team workspace, your organization name and the membership relationships within it.
- Authentication data required to sign you in and secure your account (for example, session records and, if enabled, multi-factor settings). We do not store passwords in plain text.
- Billing metadata where you purchase a paid plan (for example, plan, invoices, and the customer reference held by our payment processor). Card details are handled by our payment processor and are not stored by us.
API usage and metering data
- API keys associated with your account, and metering records, the number of captures and API calls, timestamps, plan and quota counters, rate-limit state, and coarse request metadata (such as status codes and error types) used for billing, abuse prevention, and support.
Query and capture data
- The queries and parameters you submit, and the results we return to you as the Envelope.
- The raw artifact a capture produces, the verbatim surface response. It reflects content displayed by public AI surfaces and the pages they cite. It is not intended to contain your personal data beyond the query text you chose to submit; do not put sensitive personal data into query text.
Technical and support data
- Server logs and security telemetry (for example, IP address, user agent, and request identifiers) collected to operate and protect the Service.
- Correspondence you send us (for example, support or contact-form messages).
2. How we use data
- To provide, secure, and operate the Service and your account.
- To meter usage, enforce quotas and rate limits, and bill for paid plans.
- To prevent abuse, fraud, and security incidents, and to comply with legal obligations.
- To provide support and respond to your requests.
- To maintain durable, provable capture artifacts so that you can demonstrate what a surface displayed on a given day.
- To understand and improve how the Service is used, in aggregate.
Our legal bases (where the EU/UK GDPR applies) are: performance of a contract (providing the Service), our legitimate interests (security, abuse prevention, and improvement), consent (for any non-essential analytics, where applicable), and compliance with legal obligations.
3. Aggregated indexes and derived datasets
Response content produced by a capture, engine answers and their citations, may be used to build aggregated, anonymized indexes and derived datasets, including rankings that we make publicly available. We do not include your identity, account information, or anything else that could tie a specific capture back to you or your organization in these datasets. We may also process the prompt text you submit for topic classification, to determine what a capture is about. Captures tied to a logged-in persona, and captures whose content appears to contain personal data, are excluded from this use; we retain such captures only briefly rather than durably.
4. Retention
A core feature of the Service is that the raw capture artifact is durable: the verbatim upstream response is retained as a long-lived record in object storage (Cloudflare R2), rather than being expired shortly after capture, so that you retain a provable record. We keep account, metering, and billing data for as long as your account is active and thereafter as needed to meet legal, tax, and accounting obligations. You can request deletion of your account and its associated artifacts as described in Section 7; some records may be retained where required by law or for legitimate security purposes.
5. Subprocessors and sharing
We do not sell your personal data. We share data with the following categories of subprocessors, who process it on our behalf to run the Service:
| Subprocessor | Purpose |
|---|---|
| Cloudflare | Hosting, edge delivery, application database, and durable artifact storage (Workers, D1, R2, and related services). |
| Bright Data | Managed browser network used by our capture fleet to reach public AI surfaces. |
| OpenRouter | Routing to official model APIs for surfaces captured through a vendor model API lane (for example, Claude). |
| Stripe | Payment processing for paid plans (used when you purchase a plan). |
| PostHog | Product and usage analytics, where enabled, to understand and improve the Service. |
We may also disclose data where required by law, to enforce our terms, or to protect the rights, safety, and security of our users, the public, or us. If we undergo a merger, acquisition, or asset sale, data may be transferred subject to this Policy.
6. International transfers
Our subprocessors may process data in countries other than yours, including the United States. Where required, we rely on appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) for such transfers.
7. Your rights
Depending on where you live (including under the EU/UK GDPR and similar laws), you may have the right to access, correct, delete, or port your personal data; to object to or restrict certain processing; and to withdraw consent. To exercise any of these rights, email legal@aisearchapi.dev. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data-protection authority.
Note that capture artifacts describe content produced by third-party AI surfaces and the pages they cite. If you believe an artifact contains personal data about you that should be removed, contact us and we will assess the request against our legal obligations and the evidentiary purpose of the record.
8. Cookies
Our website uses only the cookies necessary to run it, see our Cookie Policy for details.
9. Security
We use technical and organizational measures to protect personal data, including encryption in transit, access controls, and secret handling for API keys and credentials. No system is perfectly secure; you are responsible for keeping your API keys and account credentials confidential.
10. Children
The Service is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal data from children.
11. Changes and contact
We may update this Policy. If we make material changes, we will take reasonable steps to notify you before they take effect. Questions or requests can be sent to legal@aisearchapi.dev.