Privacy Policy
Last updated July 29, 2026
ApiTab is a local-first API client. Building, sending, and inspecting API requests happens entirely on your own device — request history, saved collections, and environment variables are stored locally by default and are never sent to our servers unless you explicitly turn on an account and team-sync feature described below.
Information we collect
We only collect data if you create an account. Creating an account is optional and is only needed to sync collections across devices or share them with a team.
- Account details: name and email address, and a hashed password if you register with email/password.
- Google Sign-In: if you choose "Continue with Google" instead, we receive your name, email address, and profile picture from Google to create or match your account. We never see or store your Google password.
- Synced content: collections, requests, folders, and any environment variables you mark as shared — but only once you sign in and use team/sync features. Requests you never save into a synced collection stay on your device only.
- Basic usage analytics: anonymous or account-linked session start/heartbeat/end events (timestamp, app version, platform) used only to understand overall usage — never the content of the requests you build or send.
How we use it
- To authenticate you and keep your collections in sync across your devices and team.
- To send account-related email (email verification, password reset codes).
- To understand aggregate product usage so we can improve ApiTab.
We do not sell your data, and we do not use it for advertising.
Third parties
If you sign in with Google, authentication is brokered through Google's OAuth service under Google's own privacy policy. Transactional email (verification codes, password resets) is sent through a third-party mail provider solely to deliver that email.
Data retention & deletion
Account and synced data is kept for as long as your account exists. You can delete your account and all associated synced data at any time from within the app, or by emailing us at the address below.
Security
Passwords are hashed, never stored in plain text. API access tokens can be revoked at any time by changing your password or signing out.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with an updated date at the top of this page.
Contact
Questions about this policy or your data — email apon2041@gmail.com.
ApiTab