Privacy Policy

Last Updated: April 21, 2026

Effective Date: April 14, 2026

Designed to support your GDPR & CCPA obligations

MyApi is a product of Agentic Integration LLC, 5900 Balcones Drive, STE 100, Austin, TX 78731, USA ("we", "us", or "our"). We are committed to protecting your privacy. This policy is designed to support our and our customers' obligations under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.

1. What Data We Collect

1.1 Information You Provide

1.2 Information Automatically Collected

1.3 Cookies and Local Storage

We use a minimal set of cookies essential for the Service to function:

Cookie Name Purpose Type Duration
myapi.sid Session authentication Essential (HttpOnly, Secure) 7 days
myapi_master_token Persistent API authentication Functional 7 days
myapi_user User display information Functional 7 days

You can configure cookie preferences (essential only, all, or none) through the cookie consent banner or Settings page. We also use browser localStorage to store your authentication token and workspace selection for a seamless experience.

Master Token Security Notice

The myapi_master_token cookie grants complete API access to your account. Unlike the session cookie (myapi.sid), this cookie is accessible to JavaScript on the page to enable programmatic API access. If you access the Service on a shared or untrusted device, clear this cookie after use or revoke the master token from Settings → Token Vault. You can revoke any master token at any time.

No Third-Party Tracking or Analytics

We do not embed any third-party analytics, tracking pixels, advertising scripts, or social media trackers. Your browsing behavior within the Service is not shared with any advertising or analytics company.

2. How We Use Your Data

We DO NOT sell your personal data.

Your data is never sold to third parties, data brokers, or marketing companies. We do not use your data for targeted advertising. We do not share your data with third parties for their own marketing purposes.

3. Data Sharing and Third-Party Processors

We share your data only in the following limited circumstances:

3.1 Service Providers (Data Processors)

Provider Purpose Data Shared
Stripe Payment processing Billing email, subscription plan, payment method (handled directly by Stripe)
SMTP / SendGrid Email delivery Recipient email address, email subject and body content
Anthropic Claude model inference (direct API and via OpenClaw proxy) Conversation prompts, system prompts, persona context, knowledge base excerpts. Anthropic Privacy Policy
OpenAI (via OpenClaw proxy) GPT model inference Conversation prompts, system prompts, persona context. OpenAI Privacy Policy
Google (Gemini) Gemini model inference (direct API and via proxy) Conversation prompts, system prompts, persona context. Google Privacy Policy
xAI (via OpenClaw proxy) Grok model inference Conversation prompts routed through OpenClaw proxy. xAI Privacy Policy
GitHub (Copilot) Code generation Code context and prompts you authorize. GitHub Privacy Statement
OpenRouter (fallback) Fallback AI routing Conversation prompts routed to underlying providers. OpenRouter Privacy Policy
OpenClaw Proxy AI routing and orchestration intermediary All prompts and responses to cloud AI providers pass through this layer. OpenClaw is operated by Agentic Integration LLC (the same legal entity as MyApi) and is subject to this Privacy Policy. Request metadata (model, token counts, latency) may be logged for operational monitoring. Prompt content is not retained beyond request processing.
Local / Self-Hosted Models (Ollama: Gemma, Qwen, StarCoder, Llama, etc.) Local AI inference (privacy-preserving) No data transmitted externally. All inference occurs on the server where the Service is installed.
OAuth Providers (Google, GitHub, Slack, etc.) Third-party service integration OAuth authorization codes and tokens (to maintain your connected accounts)

3.2 Other Circumstances

3.3 Workspace and Team Data

When you participate in a workspace, other workspace members with appropriate roles may access shared resources including personas, skills, knowledge base documents, and activity logs within that workspace. Workspace administrators can manage members, view audit logs, and configure workspace settings. Data you create within a workspace is accessible according to the workspace's role-based access control settings.

4. Data Security

We implement multiple layers of security to protect your data:

4.1 Encryption

4.2 Access Controls

4.3 Infrastructure

5. Data Retention

Data Type Default Retention Period Notes
Account Information Until account deletion Deleted immediately and permanently upon request
OAuth Tokens Until disconnected or account deleted Encrypted at rest; revoked upon disconnection
Session Data 7 days Cleaned up automatically every 15 minutes
Conversations & Messages Until account deletion Deleted when account is deleted; can be individually deleted
Notifications 60 days Automatically expired after 60 days
Audit Logs Up to 365 days Audit logs are append-only (tamper-evident) and retained for up to 365 days, then permanently purged. On account deletion, your name and email are removed immediately, so any audit rows remaining within the retention window reference only an internal identifier — no direct personal identifiers — and are purged as they age out.
Compliance Audit Logs Append-only (immutable) Append-only for tamper-evidence and security. After account deletion these reference only an internal id whose associated personal data (name, email) has been removed — no direct personal identifiers remain.
Backups 30 days Configurable; maximum 50 backups retained
OAuth State Tokens Cleaned hourly Temporary tokens expired and removed automatically
Rate Limit Records 24 hours Cleaned up automatically every hour
Pending Device Approvals 7 days Expired approvals are automatically removed

Workspace administrators can configure custom retention policies for notifications, audit logs, and activity logs through the Settings page. Custom policies may shorten (but are subject to minimum compliance requirements) or extend default retention periods.

6. AI Data Processing

Important: AI Processing Disclosure

When you use AI conversation features, your prompts, persona configurations, and relevant knowledge base content are sent to third-party AI providers for processing.

6.1 Data Flow Architecture

When you use AI features, your data flows through the following layers (in order):

  1. Your Client (browser, API client, or agent) sends a request to the Service API
  2. MyApi Service processes the request, retrieves relevant persona context and knowledge base excerpts, and constructs an AI prompt
  3. OpenClaw Proxy (if applicable): The constructed prompt is routed through an AI routing proxy, which may add system-level context, apply routing logic, and log request metadata before forwarding to the external AI provider
  4. External AI Provider (Anthropic, OpenAI, Google, etc.) receives and processes the prompt, returning a response
  5. The response travels back through the same layers, and MyApi stores the conversation in your account

For local models (Ollama), steps 3 and 4 occur on the same server as the Service — your prompt data does not leave the server.

6.2 Agent and Third-Party Platform Access

When you access the Service via a third-party AI agent or platform (such as a ChatGPT GPT, an MCP client, an OpenAPI-based automation, or the Hermes platform), the following applies:

6.3 AI Provider Training Practices

AI Provider Training Disclosure

We do not train AI models on your private content or conversations. However, when your data is transmitted to third-party AI providers, those providers may use that data for purposes including model safety improvements or fine-tuning, subject to their own terms and your API tier with them:

We recommend reviewing each provider's current privacy policy for the most up-to-date information on their training practices.

7. Google API Services — Limited Use Disclosure

Google API Services User Data Policy Compliance

MyApi's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, with respect to data obtained through Google APIs:

7a. Gmail API Data Use

In addition to the general Google API Limited Use commitments above, the following applies specifically to Gmail data:

8. GDPR — Lawful Basis for Processing

Under Article 6 of the GDPR, we process your personal data on the following lawful bases:

Processing Activity Lawful Basis Details
Account creation and authentication Contract performance (Art. 6(1)(b)) Necessary to provide the Service you signed up for
OAuth token storage and integration Contract performance (Art. 6(1)(b)) Required to connect and operate your third-party service integrations
AI conversation processing Contract performance (Art. 6(1)(b)) Necessary to deliver AI features you explicitly use
Billing and payment processing Contract performance (Art. 6(1)(b)) Required to manage your subscription and invoicing
Security monitoring, audit logs, rate limiting Legitimate interests (Art. 6(1)(f)) Protecting the integrity and security of the Service and all users
Device fingerprinting and approval Legitimate interests (Art. 6(1)(f)) Preventing unauthorized account access; less intrusive than alternatives
Aggregate usage analytics Legitimate interests (Art. 6(1)(f)) Improving Service reliability and features; data used only in aggregate
Email notifications (security alerts, device approvals) Legitimate interests (Art. 6(1)(f)) Necessary to keep you informed of security-relevant events on your account
Marketing or non-essential notifications Consent (Art. 6(1)(a)) Only sent where you have opted in; withdrawable at any time via Settings
Compliance audit log retention Legal obligation (Art. 6(1)(c)) Retained to comply with applicable legal and regulatory requirements
Responding to legal requests Legal obligation (Art. 6(1)(c)) Required by law, regulation, or lawful governmental request

Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing before withdrawal. Where processing is based on legitimate interests, you have the right to object (see Section 11).

9. Device Fingerprinting

To protect your account security, we generate a SHA-256 hash of your device characteristics (such as browser type, screen attributes, and IP address) to create a unique device fingerprint. This fingerprint is used to:

Device fingerprints are stored as irreversible hashes and cannot be used to reconstruct your device information. You can view and revoke approved devices at any time through your account settings.

The device fingerprint hash incorporates your IP address as one input factor. Because IP addresses can indicate approximate geographic location, the device approval system implicitly processes location data as part of this security function. We do not use this data for tracking, profiling, or any purpose beyond device approval authentication.

10. Privacy Controls

You have control over your privacy settings through the Service dashboard:

11. Your Rights

GDPR Rights (EU/EEA Users)

CCPA Rights (California Residents)

12. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at [email protected]. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly.

13. International Data Transfers

MyApi is a self-hosted platform. Your data is stored on the server where the Service is deployed. If you access the Service from outside the jurisdiction where the server is located, your data may be transferred across borders. We implement appropriate safeguards (including encryption in transit and at rest) to protect your data during any such transfer in accordance with applicable data protection laws.

When AI features are used, your data is additionally subject to international transfer to the extent that the AI provider receiving your request is located in a different jurisdiction. Requests routed to Anthropic, OpenAI, or Google are processed on servers in the United States. Requests to xAI and other providers are processed per those providers' infrastructure policies.

For EU/EEA users, we rely on the following transfer mechanisms for personal data transferred to AI providers:

We recommend reviewing each AI provider's data transfer mechanisms, which are disclosed in their respective privacy policies linked in Section 3.1.

14. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms:

15. Exercise Your Rights

To exercise any of your privacy rights:

Response Times:

We may verify your identity before processing a request to protect against fraudulent requests.

16. Contact Us

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes:

Your continued use of the Service after changes take effect constitutes acceptance of the revised policy. We encourage you to review this policy periodically.