Privacy Policy
Last updated: August 2, 2026
This policy describes what Try It collects, why, and how it is handled. The short version: we collect the minimum needed to run an API with accounts and billing, we don’t sell data, and payment details never touch our servers.
What we collect
- Account data — your email address and a securely hashed password (bcrypt). We never store passwords in plaintext.
- Usage data — per-request logs (endpoint, API key, cache status, response time) used for quota enforcement, your usage dashboard, and abuse prevention.
- Request data — the parameters you send to the API are processed to produce your results; a summary of each request is kept in your history.
- Billing data — handled entirely by Stripe. We store your Stripe customer reference and plan, never card numbers.
What we don’t do
- No selling or renting of personal data.
- No advertising trackers, and no third-party analytics services.
- No reading of your requests or results beyond what’s needed for operations, debugging, or abuse investigation.
Analytics & session recording
Both tools below run on our own servers. Your data is not sent to Google Analytics, Hotjar, or any other third-party service.
- Page analytics (Umami). Counts page views and referrers. It sets no cookies, does not track you across sites, and does not build a profile of you. Because it collects no personal data, it runs without asking.
- Session recording (OpenReplay) — off unless you allow it. If you agree, we record how pages are used (clicks, scrolling, navigation) to find confusing or broken parts of the product. Everything you type, along with email addresses and API keys, is masked in your browser before anything is sent, so we never receive it. We ask once; if you decline, or simply ignore the prompt, nothing is recorded. To change your mind later, clear this site’s data in your browser and answer the prompt again.
Cookies & local storage
Your sign-in session is held in a secure, httpOnly cookie that JavaScript can’t read; we also use a small cookie for your light/dark theme and local storage to remember which team you’re viewing and whether you allowed session recording. We set no advertising or cross-site tracking cookies anywhere on the site.
Subprocessors
We share data only with the providers required to operate the Service, each receiving only what it needs:
- Stripe — payment processing; card details are handled entirely by Stripe and never reach our servers.
- Cloudflare — DNS and network protection in front of the Service.
- Forward Email — transactional email (team invitations and quota notifications).
- Plexsicity Identity (auth.plexsicity.com) — authentication and sign-in.
- Our cloud hosting provider — application servers and the database.
Our analytics and session-recording tools are self-hosted on our own infrastructure and are therefore not subprocessors — that data is never handed to another company.
Retention & deletion
Account and usage records are kept while your account is active. Request history is kept for 90 days. Cached results expire within 24 hours. To delete your account and associated data, email [email protected] and we’ll process it promptly.
Your rights
You can request a copy of your data, correction, or deletion at any time via the email above. If you are in a jurisdiction with specific data-protection rights (e.g. GDPR or CCPA), we honor requests accordingly.
Changes
If this policy changes materially, we’ll post the update here with a new date.
Contact
Privacy questions: [email protected].