Last updated: 2026-08-10
This Privacy Policy explains how Zapi (operated by Zeative Labs) collects, uses, stores, and protects your personal data as a Platform user. This policy is prepared in accordance with Law No. 27 of 2022 on Personal Data Protection (the PDP Law) of the Republic of Indonesia.
The personal data controller for the data you provide is Zeative Labs, domiciled in the Republic of Indonesia. For all matters relating to personal data protection, you can contact [email protected].
When you sign up and use the Platform, we collect: • Identity: name, email, avatar, and provider ID when you sign in with Google, GitHub, or Discord. • Password: only if you sign up with email and password. It is stored as a hash, never in plaintext. • Credentials: API key, stored as a hash. • Account metadata: registration timestamp, last seen, subscription tier, plan expiry. • Billing data (for paid tiers): invoice recipient name, tax ID/NPWP (optional), payment history via a third-party payment gateway. • Activity logs: IP address, user agent, endpoint accessed, timestamp, status code, latency. • Bulk job results: when you submit a batch, the results are held so you can fetch them after the job finishes. • Webhook delivery records: the endpoint you registered, HTTP response code, and retry attempts.
• Plaintext passwords. Email sign-ups are stored as a hash; if you use Google, GitHub, or Discord, no password reaches us at all. • Credit card numbers, processed directly by the payment gateway, never touching Zapi servers. • API request/response body content: we store only metadata (endpoint, status, latency), not the payload. • Cross-site tracking outside the Platform.
Zapi endpoints return public data from third-party platforms such as Instagram, TikTok, and YouTube. That data can include personal data of people who are not Zapi users: display name, username, profile photo, follower counts, bio links, and public post content. For this category we act as controller on the basis of legitimate interest in operating a public data catalogue, limited strictly to what the source already publishes without a login. We do not access private accounts, login-gated content, direct messages, or contact details, and we do not build standing profiles of individuals for our own use. Results are served on request and may be held briefly in a per-endpoint cache. If your personal data appears in a Zapi response and you want it removed, email [email protected] with the subject "DATA REMOVAL" and the profile URL. We respond within 7 business days. Data that stops being public at the source stops being served.
In accordance with Article 20 of the PDP Law, we process your personal data based on: • Explicit consent when you agree to the Privacy Policy and Terms of Service. • Performance of the contract between you and Zapi (providing the API service). • Legal obligations (e.g. tax recordkeeping, audits). • The Controller's legitimate interest in preventing fraud and abuse and maintaining Platform security.
Personal data is processed for the following purposes: • Authentication and authorization of Platform access. • Billing, invoicing, and financial administration. • Tracking quota and rate limits per account. • Detecting and preventing abuse, fraud, and AUP violations. • Transactional communications (billing notifications, service changes, security alerts). • Internal research and improving the Platform's quality (in aggregate, non-identifying form).
If you submit a project to Showcase, the title, description, URL, cover image, and any testimonial you attach (name, role, photo, notes) are reviewed by us and published on the Platform once approved. Only submit a testimonial photo, name, or role belonging to another person if you have their permission. You can ask us to unpublish your entry at any time via [email protected], and it is removed together with your account if you delete it.
Retention is set per category, not by a single blanket window: • Account data: for as long as the account is active. On deletion, your profile, sessions, API keys, webhooks, and Showcase entries are removed immediately. • Request traces (method, path, query, headers with credentials redacted, IP, user agent): kept according to your tier. Free 7 days, Pro 30 days, Ultra 90 days, subject to an upper ceiling. A different window can be set on an account by arrangement. • Request counters (endpoint, status code, latency, timestamp): kept beyond the trace window, because they are the unit your monthly quota is counted in. • Bulk job results: 7 days from job creation, then deleted with the job. • Webhook delivery records: 30 days. • Billing records and invoices: Indonesian tax rules require invoice records to be retained for 10 years. Deleting your account currently also removes your transaction history from the dashboard, so save any invoices you need from the billing page before you delete. • Once a retention period ends, data is permanently deleted or reduced to aggregates without identifiers.
Some of our infrastructure may be located outside the territory of the Republic of Indonesia (e.g. the Singapore/Tokyo regions). Transfers are carried out with assurances of a level of protection equivalent to the PDP Law, through standard contractual clauses or recognized security certifications.
In accordance with Articles 5–13 of the PDP Law, you have the right to: • Obtain information about the personal data being processed. • Access and obtain a copy of your personal data. • Correct inaccurate personal data. • Erase personal data (right to erasure). • Withdraw your consent to processing. • Object to certain processing. Account deletion is self-service in Settings, under Danger zone. It removes your profile, API keys, sessions, webhooks, and Showcase entries straight away; request traces age out on the schedule above, and request counters are retained for platform-level usage accounting without being linked to a live account. Data export is not yet self-service. For a copy of your data, or for any other request above, email [email protected] with the subject "PDP REQUEST". We respond within 7 business days.
Zapi offers an MCP server so you can connect an external AI client or automation tool to your account. When you do, that client authenticates with an API key you issue and can call endpoints on your behalf, consuming your quota. The operator of that client is a third party we have no control over. We see the same request metadata as any other call: the key used, IP, user agent, and the endpoint. Whatever the client does with the response is governed by that client's own privacy policy, not this one. Revoke the key in your dashboard to cut the connection.
We apply reasonable technical and organizational measures: • TLS 1.2+ encryption for all communications. • At-rest encryption for the production database. • Hashing of API keys and passwords with a cryptographically strong algorithm. • Redaction of credential headers (Authorization, API keys) before any request metadata is written. • Role-based access control for internal team access. • Logging and audit trails for changes to sensitive data. • Periodic rotation of credentials and secrets. No system is completely secure, so users must also safeguard their own credentials.
In accordance with Article 46 of the PDP Law, in the event of a personal data protection failure that poses a risk to data subjects' rights, we will: • Notify affected data subjects within 3x24 hours of becoming aware. • Report to the PDP Authority within the timeframe prescribed by regulation. • Explain the type of data affected, mitigation steps, and recommended actions.
The Platform is not intended for children under the age of 18. We do not knowingly collect data from minors. If you become aware of any minor's data that has entered the Platform without valid guardian consent, please report it to [email protected] so it can be deleted promptly.
This Privacy Policy may be updated from time to time to reflect changes in practices, law, or Platform features. Material changes will be notified via email at least 30 days before they take effect. The last update date is shown at the top of this document.
Questions, data access requests, or privacy-related complaints can be submitted to [email protected] with the subject "PDP REQUEST". Requests to remove personal data that appears in an API response go to [email protected] with the subject "DATA REMOVAL". If you believe your PDP rights have not been fulfilled, you also have the right to file a complaint with the Personal Data Protection Authority of the Republic of Indonesia.