Privacy Policy

Last updated July 29, 2026

ApiTab is a local-first API client. Building, sending, and inspecting API requests happens entirely on your own device — request history, saved collections, and environment variables are stored locally by default and are never sent to our servers unless you explicitly turn on an account and team-sync feature described below.

Information we collect

We only collect data if you create an account. Creating an account is optional and is only needed to sync collections across devices or share them with a team.

How we use it

We do not sell your data, and we do not use it for advertising.

Third parties

If you sign in with Google, authentication is brokered through Google's OAuth service under Google's own privacy policy. Transactional email (verification codes, password resets) is sent through a third-party mail provider solely to deliver that email.

Data retention & deletion

Account and synced data is kept for as long as your account exists. You can delete your account and all associated synced data at any time from within the app, or by emailing us at the address below.

Security

Passwords are hashed, never stored in plain text. API access tokens can be revoked at any time by changing your password or signing out.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected here with an updated date at the top of this page.

Contact

Questions about this policy or your data — email apon2041@gmail.com.