Effective September 2, 2026

EnrichAPI.com Privacy Policy

This policy explains the current privacy posture of the static EnrichAPI.com website and the principles intended to govern any future Enrich API account or processing service.

Data minimizationRetentionUser rightsSecurity
EnrichAPI.com privacy and data controls for API requests, logs, retention and user rights

Current service status

EnrichAPI.com is currently a static product and documentation website. This policy will be updated before account, analytics, billing or API-processing systems collect additional data.

1. Scope

This Privacy Policy explains how EnrichAPI.com may collect, use, store and share information through the public website, developer accounts and a future Enrich API service. The currently delivered website is static and does not itself provide a working account or API backend.

2. Information we may process

Website information

A production deployment may receive standard server logs such as IP address, requested URL, browser information, time and response status. If analytics are added, this policy and the site interface should identify the provider and available controls.

Account information

When account services are implemented, information may include name, work email, organization, authentication records, plan, billing contact and team roles. Passwords should be handled by a qualified identity provider and stored only as secure hashes or provider-managed credentials.

API customer content

API requests may contain text, records, URLs, document content or other data selected by the customer. Customers should send only information needed for the chosen enrichment. The service should not use customer content to train generalized models unless the customer has explicitly agreed to that use.

Usage and diagnostic information

The service may process request identifiers, schema versions, selected routes, timing, error codes, billable units and validation results. Logs should avoid raw sensitive content by default.

3. How information may be used

Information may be used to provide and secure the service, authenticate users, process enrichment requests, deliver results, operate billing, prevent abuse, diagnose errors, communicate service changes and comply with legal obligations. Product analytics should use the minimum information needed and should be separated from customer content where practical.

4. Model providers and subprocessors

A production Enrich API may route requests to third-party infrastructure or AI model providers according to the customer’s selected policy. Before launch, publish an accurate subprocessor list and explain available provider, region and retention controls. Third-party services operate under their own agreements and privacy terms.

OpenAI, xAI, Anthropic, OpenRouter, Microsoft and Cursor names used elsewhere on this site are third-party trademarks and do not imply affiliation.

5. Cookies and local storage

The static website package does not require advertising cookies. A production account system may use essential cookies for secure sessions, fraud prevention and user preferences. Non-essential analytics or marketing cookies should be added only with appropriate notice and consent controls where required.

6. Retention and deletion

Set specific retention periods for account records, billing records, request metadata, customer content, batch outputs and backups. Keep customer content only as long as needed to provide the service or meet documented obligations. Provide controls for deletion and define how long deletion takes to propagate through active systems and backups.

7. Privacy rights and choices

Depending on location and applicable law, individuals may have rights to access, correct, delete or restrict certain personal information, object to processing, receive a portable copy or withdraw consent. Verify identity before fulfilling a request and document any lawful exception.

Customers remain responsible for having a lawful basis to submit personal information to the Enrich API and for responding to requests related to data they control.

8. Security

Use encryption in transit, scoped access, secret management, logging controls, vulnerability management and incident response appropriate to the service. No security measure eliminates all risk. Publish only security claims that the deployed systems can support.

9. International processing

Infrastructure and providers may process information in more than one country. Before launch, document actual processing locations and put appropriate transfer mechanisms in place where required.

10. Children

The service is intended for business and developer use and is not directed to children. Do not knowingly collect personal information from children through account or API workflows.

11. Changes to this policy

Update the effective date when this policy changes. For material changes, provide notice through the website, account console or email as appropriate.

12. Contact

Privacy questions may be sent to [email protected] with “Privacy inquiry” in the subject line. This policy will be revised as production data flows and jurisdiction-specific obligations are finalized.