Privacy policy

Last updated: August 2026

1. Controller

The controller for data processing on this website is:
[controller name and postal address]
Email: info@subtoapi.app

2. Hosting (Cloudflare Pages)

This website is served through Cloudflare Pages, operated by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, and Cloudflare Germany GmbH, Rosental 7, 80331 Munich. When you visit the site, Cloudflare processes technically necessary data (IP address, date and time, requested URL, referrer, browser and operating-system identifier) in server logs in order to deliver the page and protect it against attacks.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and performant operation). Cloudflare is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition. More information: cloudflare.com/privacypolicy.

3. Account data

To use the dashboard you create an account. In doing so we process your email address, optionally your name and team name, a password hash (PBKDF2-SHA256 with a random salt — the password itself is not stored), the time of registration and of the last sign-in, and your role within the team.

The purpose is performance of the usage contract; the legal basis is Art. 6(1)(b) GDPR. The data is stored in a Cloudflare D1 database within Cloudflare’s infrastructure.

4. Reach measurement

We count page views on our public pages ourselves — no third-party analytics service, no cookie and nothing stored on your device. Each view records the path, the host of the referring site (never the full URL, which could carry search terms), the country derived from your IP address, and a coarse device, browser and operating-system class.

Your IP address is not stored. To count a person once instead of many times, we form a hash of the IP address and the browser identifier together with a random value that we replace every day and delete afterwards. Once that value is gone the hash cannot be recomputed, so the records cannot be traced back to you or linked across days. Page views are deleted after 180 days.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in understanding which pages are useful). Because nothing is read from or written to your device, § 25 TDDDG does not apply and no consent banner is required. Requests that identify themselves as bots are discarded before anything is stored.

5. Session cookie

After you sign in we set a strictly necessary cookie (co_session) containing a random session identifier. Signing in is not possible without it. It expires after 30 days and is set as HttpOnly and SameSite=Lax. Legal basis: § 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(b) GDPR. We set no advertising cookies, and our reach measurement (section 4) uses no cookie at all.

6. Payment processing (Stripe)

Paid plans are processed through Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland). We transmit your email address, the team or company name, and the plan and seat count you selected. You enter payment details (card or bank account) directly with Stripe; we neither receive nor store them.

We store only the Stripe customer and subscription identifiers and the subscription status. The legal basis is Art. 6(1)(b) GDPR. Information from Stripe: stripe.com/privacy.

7. Transactional email

Where enabled in this installation, we send invitation and password-reset emails through Resend (Resend, Inc.). The recipient address and the content of the respective email are transmitted. The legal basis is Art. 6(1)(b) GDPR. If sending is not configured, invitation links are shown in the dashboard only and are passed on by you.

8. Fonts (Google Fonts)

The site loads the Inter and JetBrains Mono typefaces from Google Fonts (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Your IP address is transmitted to Google in the process. The legal basis is Art. 6(1)(f) GDPR (consistent presentation). If your browser blocks external fonts, a system font is used. Information: policies.google.com/privacy.

9. What we explicitly do not process

SubToAPI is a developer platform for a server-side Claude connection. Therefore:

  • Provider credentials, refresh tokens and internal provider headers are never shown in the browser and never emitted in public integration examples.
  • SubToAPI API keys are stored hashed only. The full key is shown once, at creation or rotation.
  • Prompt and response content is not stored by default. We record only technical usage metadata such as endpoint, model, token counts, latency, status and request ID.
  • Billing data is processed through Stripe; complete payment details are not stored on our side.

10. Retention

We store account data for the duration of the usage relationship. After termination and expiry of statutory retention periods (in particular up to ten years for invoice data under commercial and tax law) it is deleted. Sessions expire after 30 days at the latest, invitations after seven days, password-reset links after one hour. Server logs at Cloudflare are deleted after a short period.

11. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). To exercise them, contact info@subtoapi.app.

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the one at the controller’s registered seat: [competent supervisory authority].

12. Changes

We adapt this policy when services, features or the legal situation change. The version published here at any given time applies.

SubToAPI is an independent product and is not affiliated with Anthropic PBC. “Claude” is a trademark of Anthropic PBC.