Privacy Policy
Last updated: 29 May 2026
1. Introduction and Scope
Welcome to Theresa API ("we", "our", or "Theresa"). This Privacy Policy is designed to help you transparently understand how we collect, use, store, and protect your personal information when you access our website, register an account, and interact with our Application Programming Interface (API) services.
This document applies to all users of the Theresa API platform without exception, including free tier users, paid subscribers, and third parties integrating our services into their applications. By accessing or using our platform in any form, you provide explicit consent to the data management practices described in this document.
If you do not agree with the terms in this Privacy Policy, please discontinue using the services. Questions or objections can be submitted to our team for clarification.
2. Data Controller Identity
Theresa API is an API service platform independently managed by the development team under the creator pseudonym Blackrosé. As the data controller, we are fully responsible for decisions regarding the purpose and means of processing your personal data. For privacy-related correspondence, you can contact us at:
- Email: [email protected]
- Platform: api.theresav.eu
- Ticket System: Available in your user dashboard
3. Information We Collect
To provide an optimal and secure service experience, we divide data collection into several categories:
- Account Registration Information: When you create an account, we collect your unique username, an active email address, and a password that is immediately hashed using cryptographic algorithms before storage. We never store plaintext passwords.
- Third-Party Authentication Information (OAuth): If you choose to log in using Google or GitHub, we only receive your public profile name, email address, and unique identifier from the provider. We do not request or receive access to your contacts, private repositories, or other sensitive resources.
- Telemetry Data and API Request Logs: Every call to our API endpoints automatically generates a log record that includes the requester's IP address, device User-Agent, request timestamp (in GMT), requested endpoint path, HTTP method, response status code, and processing duration in milliseconds.
- Transaction and Financial Data: When you upgrade or top up your balance, we record the transaction reference, amount, payment status, and timestamp. We do not directly store credit card or bank credentials; payments are processed securely through payment gateways.
- Service Usage Data: We track aggregate API usage statistics per user, such as total daily requests, most frequently accessed endpoints, and response status code distribution for quota management and service improvement.
4. Information We Do NOT Collect
Transparency is our core value. The following is data that we explicitly do not collect or store:
- The content or payload of your API requests — including target URLs sent, search queries, AI prompts, or documents supplied as query parameters.
- Biometric data in any form.
- Government-issued identification numbers (national IDs, driver's licences, passports).
- Health or medical records.
- Data from devices not directly connected to our platform (we do not use cross-site tracking pixels).
5. No-Log Policy for Payload Content
We value your operational confidentiality. We strictly implement a no-log policy for the content and payload of every API query you execute:
- URLs you send to downloading or scraping endpoints are immediately removed from volatile memory once the response is sent.
- Search parameters and keywords are never persisted in any permanent log storage.
- Prompt instructions sent to AI endpoints are never recorded or utilised to train models.
- Temporary files uploaded for processing are permanently purged shortly after processing completes.
This guarantee is a structural commitment of our system architecture, ensuring payload data is never written to persistent disk storage.
6. How We Use Your Information
The minimal data we collect is used strictly for platform operational requirements:
- Authentication & Authorisation: Validating your identity and ensuring only requests with valid API Keys access the services.
- Quota Management (Rate Limiting): Calculating daily API calls per your subscription plan and automatically resetting quotas every midnight GMT.
- System Security: Detecting abnormal request patterns that indicate malicious intrusion attempts, DDoS attacks, or service abuse.
- Service Communication: Dispatching essential transactional notices such as account verification, password reset tokens, and payment receipts.
- Quality & Performance Optimisation: Analysing aggregate performance metrics to resolve bottlenecks and enhance response speeds.
7. Legal Basis for Data Processing
All processing of personal data is conducted pursuant to recognised legal bases:
- Contractual Performance: Processing necessary to provide the API services you subscribe to.
- Legitimate Interests: Processing necessary to maintain platform infrastructure integrity, prevent fraud, and secure user data.
- Legal Obligations: Compliance with statutory legal and regulatory requirements.
8. Cookies and Storage Technologies
We use client-side storage technologies in a purposeful and minimal manner:
- Session Cookies (Essential): Used to maintain your authenticated login state while navigating the dashboard.
- Preference Storage: Storing local UI preferences (such as theme choice) within your browser's localStorage without transmission to servers.
We do not employ third-party advertising cookies, behavioural trackers, or advertising network monitors.
9. Sharing Data with Third Parties
We never sell, monetise, or distribute personal data to third parties for marketing purposes. Limited data sharing occurs solely with:
- Infrastructure Providers: Cloud computing and hosting infrastructure partners bound by rigorous Data Processing Agreements (DPA).
- Payment Processors: Necessary payment verification metadata transmitted to authorized payment gateways.
- Legal Compliance: Disclosure mandated by valid court orders or statutory legal processes.
10. Data Security Practices
We employ multi-layered security measures (defence-in-depth) to protect user information:
- Transit Encryption (TLS/SSL): All client-server communications are encrypted with TLS 1.2+ and enforced via HTTP Strict Transport Security (HSTS).
- Robust Password Hashing: Passwords are protected using bcrypt cryptographic algorithms with salted iterations.
- API Key Safeguards: API keys are hashed and encrypted; original raw keys are viewable only upon generation.
- Access Controls: Production system access is strictly governed by least-privilege principles and multi-factor authentication.
11. Data Retention and Deletion
We adhere to strict data retention policies based on minimal necessity:
- Active Account Data: Maintained throughout the active lifespan of your user account.
- Technical API Logs: Request metadata logs are automatically pruned after 30 days.
- Account Deletion: Upon account deletion requests, all associated account data is permanently erased within 7 working days.
12. Your Data Subject Rights
You possess enforceable rights regarding your personal information:
- Right of Access & Portability: Request an export copy of personal records held in standard structured formats.
- Right of Rectification: Amend or update inaccurate personal details directly via the profile interface.
- Right to Erasure: Request full permanent deletion of your profile and data records.
- Right to Object & Restrict: Request restrictions on specific processing activities where applicable.
To exercise your rights, please reach out to [email protected]. Requests will be acknowledged and handled within statutory timeframes.
13. Contact Information
For questions, privacy enquiries, or data requests, our team is reachable through:
- Email: [email protected]
- Helpdesk: Available in the user dashboard
- Working Hours: Monday–Friday, 09:00–17:00 GMT