Privacy Policy
Last updated: 13 September 2026
We collect as little data as possible. This policy explains exactly what we process and why.
1. What we collect
- Account data (paid users): email address and subscription records needed to provide billing and support.
- Request metadata: IP address, user agent, request timestamps and query parameters of image requests, used for rate limiting, abuse prevention and aggregate usage statistics.
- Payments: processed by our payment provider (Paddle). We never see or store full card numbers.
2. What we do NOT do
- We do not sell your data or share it with advertisers.
- We do not train AI models on your requests.
- We do not store generated images longer than CDN caching (≤ 10 minutes) unless you embed them publicly yourself.
3. Legal bases & retention
Processing is based on contract performance (providing the Service), legitimate interest (security, rate limiting) and consent where required. Account data is kept while your subscription is active and up to 24 months afterwards for tax/legal obligations; request logs are kept for up to 90 days.
4. Sub-processors
- Cloudflare, Inc. — hosting, CDN and D1 database (EU data processed in the US under the EU-US Data Privacy Framework).
- Paddle — payment processing (merchant of record).
5. Your rights
You may request access, rectification, deletion or a copy of your personal data at any time by emailing hello@opengraphapi.com. EU/UK residents may lodge complaints with their supervisory authority.
6. International transfers
The Service is hosted on Cloudflare's global network. Personal data may be transferred to the United States under safeguards referenced in section 4.
7. Changes
Material changes will be announced on this page with the new effective date.