zapi.
APIsPricingDocsMCP
GitHub
APIsPricingDocsMCPGitHubSign in

Privacy Policy

Last updated: 2026-08-10

Contents

  1. 01Introduction
  2. 02Personal Data Controller
  3. 03Data We Collect
  4. 04Data We Do NOT Store
  5. 05Data About People You Look Up
  6. 06Legal Basis for Processing
  7. 07Purposes of Processing
  8. 08Showcase and Public Submissions
  9. 09Data Retention
  10. 10Sharing Data with Third Parties
  11. 11Cross-Jurisdictional Data Transfers
  12. 12Cookies and Local Storage
  13. 13Data Subject Rights
  14. 14Connecting External AI Clients
  15. 15Data Security
  16. 16Data Breach Notification
  17. 17Data of Minors
  18. 18Policy Changes
  19. 19Contact
01

Introduction

This Privacy Policy explains how Zapi (operated by Zeative Labs) collects, uses, stores, and protects your personal data as a Platform user. This policy is prepared in accordance with Law No. 27 of 2022 on Personal Data Protection (the PDP Law) of the Republic of Indonesia.

02

Personal Data Controller

The personal data controller for the data you provide is Zeative Labs, domiciled in the Republic of Indonesia. For all matters relating to personal data protection, you can contact [email protected].

03

Data We Collect

When you sign up and use the Platform, we collect: • Identity: name, email, avatar, and provider ID when you sign in with Google, GitHub, or Discord. • Password: only if you sign up with email and password. It is stored as a hash, never in plaintext. • Credentials: API key, stored as a hash. • Account metadata: registration timestamp, last seen, subscription tier, plan expiry. • Billing data (for paid tiers): invoice recipient name, tax ID/NPWP (optional), payment history via a third-party payment gateway. • Activity logs: IP address, user agent, endpoint accessed, timestamp, status code, latency. • Bulk job results: when you submit a batch, the results are held so you can fetch them after the job finishes. • Webhook delivery records: the endpoint you registered, HTTP response code, and retry attempts.

04

Data We Do NOT Store

• Plaintext passwords. Email sign-ups are stored as a hash; if you use Google, GitHub, or Discord, no password reaches us at all. • Credit card numbers, processed directly by the payment gateway, never touching Zapi servers. • API request/response body content: we store only metadata (endpoint, status, latency), not the payload. • Cross-site tracking outside the Platform.

05

Data About People You Look Up

Zapi endpoints return public data from third-party platforms such as Instagram, TikTok, and YouTube. That data can include personal data of people who are not Zapi users: display name, username, profile photo, follower counts, bio links, and public post content. For this category we act as controller on the basis of legitimate interest in operating a public data catalogue, limited strictly to what the source already publishes without a login. We do not access private accounts, login-gated content, direct messages, or contact details, and we do not build standing profiles of individuals for our own use. Results are served on request and may be held briefly in a per-endpoint cache. If your personal data appears in a Zapi response and you want it removed, email [email protected] with the subject "DATA REMOVAL" and the profile URL. We respond within 7 business days. Data that stops being public at the source stops being served.

06

Legal Basis for Processing

In accordance with Article 20 of the PDP Law, we process your personal data based on: • Explicit consent when you agree to the Privacy Policy and Terms of Service. • Performance of the contract between you and Zapi (providing the API service). • Legal obligations (e.g. tax recordkeeping, audits). • The Controller's legitimate interest in preventing fraud and abuse and maintaining Platform security.

07

Purposes of Processing

Personal data is processed for the following purposes: • Authentication and authorization of Platform access. • Billing, invoicing, and financial administration. • Tracking quota and rate limits per account. • Detecting and preventing abuse, fraud, and AUP violations. • Transactional communications (billing notifications, service changes, security alerts). • Internal research and improving the Platform's quality (in aggregate, non-identifying form).

08

Showcase and Public Submissions

If you submit a project to Showcase, the title, description, URL, cover image, and any testimonial you attach (name, role, photo, notes) are reviewed by us and published on the Platform once approved. Only submit a testimonial photo, name, or role belonging to another person if you have their permission. You can ask us to unpublish your entry at any time via [email protected], and it is removed together with your account if you delete it.

09

Data Retention

Retention is set per category, not by a single blanket window: • Account data: for as long as the account is active. On deletion, your profile, sessions, API keys, webhooks, and Showcase entries are removed immediately. • Request traces (method, path, query, headers with credentials redacted, IP, user agent): kept according to your tier. Free 7 days, Pro 30 days, Ultra 90 days, subject to an upper ceiling. A different window can be set on an account by arrangement. • Request counters (endpoint, status code, latency, timestamp): kept beyond the trace window, because they are the unit your monthly quota is counted in. • Bulk job results: 7 days from job creation, then deleted with the job. • Webhook delivery records: 30 days. • Billing records and invoices: Indonesian tax rules require invoice records to be retained for 10 years. Deleting your account currently also removes your transaction history from the dashboard, so save any invoices you need from the billing page before you delete. • Once a retention period ends, data is permanently deleted or reduced to aggregates without identifiers.

10

Sharing Data with Third Parties

We do NOT sell personal data. Data is only shared with: • Infrastructure providers (cloud hosting, CDN, database) bound by equivalent confidentiality agreements. • Pakasir, the payment gateway that processes paid-tier payments. • Analytics providers (Google Analytics, Microsoft Clarity) for website usage metrics, with IP anonymization enabled. • Competent legal authorities pursuant to a court order or valid regulatory obligation.

11

Cross-Jurisdictional Data Transfers

Some of our infrastructure may be located outside the territory of the Republic of Indonesia (e.g. the Singapore/Tokyo regions). Transfers are carried out with assurances of a level of protection equivalent to the PDP Law, through standard contractual clauses or recognized security certifications.

12

Cookies and Local Storage

We use a small set of cookies for sign-in, one interface preference, and website analytics. There are no advertising or retargeting cookies. Every cookie we set is listed by name, purpose, duration, and opt-out method in the Cookie Policy at /cookies. Some features also keep data in your browser's local storage rather than on our servers: your playground run history, your bulk job list, the API key last selected in the docs, and UTM builder drafts. That data stays on your device and is cleared when you clear site data.

13

Data Subject Rights

In accordance with Articles 5–13 of the PDP Law, you have the right to: • Obtain information about the personal data being processed. • Access and obtain a copy of your personal data. • Correct inaccurate personal data. • Erase personal data (right to erasure). • Withdraw your consent to processing. • Object to certain processing. Account deletion is self-service in Settings, under Danger zone. It removes your profile, API keys, sessions, webhooks, and Showcase entries straight away; request traces age out on the schedule above, and request counters are retained for platform-level usage accounting without being linked to a live account. Data export is not yet self-service. For a copy of your data, or for any other request above, email [email protected] with the subject "PDP REQUEST". We respond within 7 business days.

14

Connecting External AI Clients

Zapi offers an MCP server so you can connect an external AI client or automation tool to your account. When you do, that client authenticates with an API key you issue and can call endpoints on your behalf, consuming your quota. The operator of that client is a third party we have no control over. We see the same request metadata as any other call: the key used, IP, user agent, and the endpoint. Whatever the client does with the response is governed by that client's own privacy policy, not this one. Revoke the key in your dashboard to cut the connection.

15

Data Security

We apply reasonable technical and organizational measures: • TLS 1.2+ encryption for all communications. • At-rest encryption for the production database. • Hashing of API keys and passwords with a cryptographically strong algorithm. • Redaction of credential headers (Authorization, API keys) before any request metadata is written. • Role-based access control for internal team access. • Logging and audit trails for changes to sensitive data. • Periodic rotation of credentials and secrets. No system is completely secure, so users must also safeguard their own credentials.

16

Data Breach Notification

In accordance with Article 46 of the PDP Law, in the event of a personal data protection failure that poses a risk to data subjects' rights, we will: • Notify affected data subjects within 3x24 hours of becoming aware. • Report to the PDP Authority within the timeframe prescribed by regulation. • Explain the type of data affected, mitigation steps, and recommended actions.

17

Data of Minors

The Platform is not intended for children under the age of 18. We do not knowingly collect data from minors. If you become aware of any minor's data that has entered the Platform without valid guardian consent, please report it to [email protected] so it can be deleted promptly.

18

Policy Changes

This Privacy Policy may be updated from time to time to reflect changes in practices, law, or Platform features. Material changes will be notified via email at least 30 days before they take effect. The last update date is shown at the top of this document.

19

Contact

Questions, data access requests, or privacy-related complaints can be submitted to [email protected] with the subject "PDP REQUEST". Requests to remove personal data that appears in an API response go to [email protected] with the subject "DATA REMOVAL". If you believe your PDP rights have not been fulfilled, you also have the right to file a complaint with the Personal Data Protection Authority of the Republic of Indonesia.

Browse APIsPricingDocsMCP serverGet an API key
zapi.One key, one response shape.
TermsPrivacyCookiesAUPRefunds© 2026