1. Overview
This Privacy Policy explains how Mock API Studio collects, uses, stores, shares, and protects information when you use the website, dashboard, account features, API token features, documentation, and related package sync functionality.
This draft is intended for review before launch. It should be updated with the final company name, contact details, subprocessors, analytics tools, payment provider, email provider, hosting provider, and applicable jurisdiction-specific disclosures.
2. Information We Collect
- Account information, such as email address, password hash, email verification status, account identifiers, and account timestamps.
- Project content, such as project names, descriptions, schemas, shared types, endpoint paths, mock resource settings, relationships, auth configuration, query parameter settings, seeds, and local runtime configuration synced from the cloud.
- Subscription and billing status, such as plan, subscription state, renewal or expiration information, and payment-provider references. We should not store full payment card numbers.
- Technical information, such as IP address, browser, device information, request metadata, logs, error reports, API token usage, and security events.
- Communications, such as support messages, feedback, and product inquiries.
3. Information We Should Not Receive
Mock API Studio is designed for mock API development. You should not submit real secrets, credentials, private keys, production access tokens, payment card data, health data, government identifiers, production customer records, or other sensitive regulated data as mock project content.
If you accidentally submit sensitive information, you are responsible for removing it and contacting us if you need help with deletion.
4. How We Use Information
- To create and secure accounts.
- To verify email addresses and send account-related messages.
- To provide the dashboard, project storage, package sync, API token features, generated mock data workflows, and documentation.
- To manage subscriptions, billing status, plan limits, and entitlement checks.
- To monitor reliability, debug errors, prevent abuse, investigate suspicious activity, and protect the service.
- To respond to support requests and product feedback.
- To improve the product, documentation, performance, and user experience.
5. Legal Bases Where Required
Where laws such as GDPR require a legal basis, we may process personal information based on contract necessity, legitimate interests, consent, and legal obligations, depending on the context.
Examples include providing the service you requested, securing the platform, preventing abuse, complying with tax or legal obligations, and sending optional communications where consent is required.
8. Data Retention
We keep information for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and maintain backups.
Account and project data may be deleted or anonymized after account deletion, subject to backup schedules, legal requirements, security logs, billing records, and abuse-prevention needs.
9. Security
We use reasonable technical and organizational measures designed to protect information, such as password hashing, token-based authentication, access controls, transport security, and operational monitoring.
No system is perfectly secure. You are responsible for protecting your account credentials, API tokens, local runtime environments, and any data you choose to enter into the service.
10. International Transfers
We and our service providers may process information in countries other than where you live. Where required, we will use appropriate safeguards for international transfers.
11. Your Rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. You may also have the right to withdraw consent where processing is based on consent.
To make a privacy request, contact us using the contact address published in the product or on our website. We may need to verify your identity before fulfilling requests.
12. California and Similar State Rights
If applicable law grants privacy rights such as access, deletion, correction, portability, or opt-out rights for sale, sharing, targeted advertising, or profiling, we will honor those rights as required.
This draft should be updated before launch if Mock API Studio meets the thresholds for California or other US state privacy laws.
13. Children's Privacy
Mock API Studio is not directed to children, and we do not knowingly collect personal information from children under the age required by applicable law. If you believe a child provided personal information, contact us so we can take appropriate action.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we may notify you through the product, email, or another reasonable method. The effective date will indicate when the latest version applies.
15. Contact
Privacy questions and requests can be sent to the contact address we publish in the product or on our website.