Legal

Privacy Policy

Published · Version v2026.10.03

Which version applies to you. This version v2026.10.03 applies from to accounts created on or after that date, to visitors of our websites and to people who are not Apiway account holders. For accounts created before 3 October 2026 it takes effect on ; until then the previous version (v2026.09.27) continues to govern those accounts. Where this version gives you more protection or more choices than the previous one (for example cookie consent, the retention limits in §7 and the rights in §9), we already apply it to everyone today.

Counterparts: Terms of Use · Data Processing Addendum · Subprocessors · Previous version. Privacy questions and requests: info@apiway.ai. Your Privacy Choices.

This Privacy Policy (the “Policy”) explains how ApiWay, Inc., a corporation incorporated in Delaware, USA (“ApiWay”, “Apiway”, “we”), processes personal data when you visit our websites, use the Apiway service (the “Service”), or interact with something an Apiway customer built or sent with the Service. We provide the Service to users worldwide, including in the EEA, the UK and California.

ApiWay is the controller of the personal data of its account holders and of visitors to its websites (§2.4). When a customer uses the Service to process other people’s data, ApiWay is that customer’s processor (§2.5).

In short

  • We do not sell your personal data. Advertising and analytics tags (Google Analytics 4, Meta Pixel and Meta Conversions API) run only if you allow them in the cookie banner, and never on pages our customers hand to their own visitors (§16).
  • Data we receive from Google (Gmail, Google Calendar, Google Drive, Google Sheets) is used only to provide the features you use, is never used for advertising, is never sold and is never used to train generalized AI models (Google user data section below).
  • The Service is not “transit-only”: depending on the products you use, it stores things such as an index of your mailbox, tasks, files, Telegram room messages and email-marketing contacts. §17 says what each product keeps, and §7 says for how long.
  • AI features send your inputs to AI providers (Google Gemini, Anthropic, and image and video models reached through PiAPI) only to produce the result you asked for, under terms that do not allow those providers to train their models on it (“Use of AI Services”).
  • When you use Apiway to handle other people’s data — your newsletter contacts, booking invitees, leads, Instagram commenters, the users of an app you host — you decide what happens to it and we act on your instructions as a processor (§2.5).
  • You can access, correct, export or delete your data and object to or opt out of certain processing wherever you live (§9).

Google user data (Gmail, Google Calendar, Google Drive, Google Sheets)

Limited Use. Apiway’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You choose which Google products to connect, each with its own consent screen, and you can disconnect each one in Apiway at any time or revoke Apiway’s access in your Google Account permissions. This is what each connection accesses, why, and what Apiway keeps:

Product and Google permissionWhat we access and whyWhat Apiway stores
Gmail (Mail app, the mail assistant, and email delivery you set up in Lead transfer). Permissions: read and modify mail and labels (gmail.modify), create drafts and send (gmail.compose), your address and profile picture (userinfo.email, userinfo.profile).Messages, threads, labels and attachments, to show your mailbox inside Apiway; to move, label, archive, pin, snooze or sort mail when you do; to draft, schedule and send the emails you write or approve; to sort mail into the feeds and folders you set up; and, when you use an AI feature (summaries, Rooms, extracted tasks and agreements, reply drafts, the Company Library, account notes, finding conversations that went quiet), to produce that feature’s result.An index of your threads (subject, a short snippet, senders and recipients, dates, labels, unread and replied flags); the facts, tasks, agreements, summaries and notes our AI features extract from threads you work with; contact-card fields and hashed fingerprints of email signatures; copies of attachments in threads you open as a Room, so they can be shown, organised, shared and downloaded; drafts you write in Apiway; read receipts for emails you send with tracking switched on; and dated copies of publicly shared Google Docs, Sheets and Slides linked in threads you open as a Room, so you can later show what a document said when it was shared. Apiway does not keep a copy of your message bodies; it reads them from Gmail when you open them. Your OAuth tokens are stored so the connection keeps working.
Google Calendar (Calendar app, booking pages, meeting reminders). Permission: see and edit events (calendar) and your address.Events and free/busy information, to show your calendar, to compute the free slots on your booking pages from the calendars you select, to create, update and cancel the events you or your booking pages request (including adding the invitee as an attendee), and to send a reminder about an upcoming meeting to a chat you chose.Your connection, your availability and booking-page settings, and the record of each booking made through Apiway. Google Calendar remains the source of truth for your events; Apiway reads them live and does not keep a copy of your calendar.
Google Drive. Permission: only the files and folders you pick or that Apiway creates for you (drive.file), and your address.The files and folders you select with Google’s picker or that Apiway creates or uploads at your request — for example a folder you show through an Apiway share link, files guests upload into that folder through your link, and the version history of a document you keep there. Apiway cannot see the rest of your Drive.Your connection and references to the files and folders you selected. Public Drive folders that someone shared as an “anyone with the link” URL are read with a public key, without any Google account, and are not Google user data.
Google Sheets (Lead transfer). Permissions: edit spreadsheets (spreadsheets), see the names of your Drive files (drive.metadata.readonly), and your address.The list of your spreadsheet names, so you can choose a destination, and the spreadsheet you chose, so new leads can be added to it as rows.Your connection, the spreadsheet you chose and a delivery log (see §17.5 and §7).

Where available, you can also connect YouTube to publish videos you select to your own channel; that connection uses YouTube API Services, is governed by the YouTube Terms of Service and the Google Privacy Policy, and is used only to upload what you chose. Google Analytics 4 and Search Console reports that you connect for the assistant are read through a service account you grant read-only access to (§17.8), not through your Google sign-in.

What we never do with Google user data.

  • We do not use it to serve advertisements, including retargeting, personalised or interest-based advertising, and we never add it to our own email-marketing lists or advertising audiences.
  • We do not sell it, and we do not transfer it to data brokers or other information resellers.
  • We do not use it to determine creditworthiness or for lending purposes.
  • We do not use it to develop, improve or train generalized artificial intelligence or machine learning models. Google Workspace API data is never used for that purpose.
  • We transfer it to others only as needed to provide or improve the features you use (for example to the hosting and AI providers below, or to a chat you asked us to post a meeting reminder to), to comply with law, for security, or as part of a merger or acquisition after notice to you.

AI processing of Google user data. When you use an AI feature on your mail, calendar or files, the content needed for that request is sent to an AI provider (Google Gemini or Anthropic Claude) only to produce the result you asked for. Those providers process it under their commercial API terms, which do not permit them to use it to train their models, and they act as our subprocessors.

Human access. No Apiway employee or contractor reads your Google user data unless (a) you explicitly ask us to for specific messages or files (for example by sharing them with support); (b) it is necessary for security purposes, such as investigating abuse or a security incident; (c) it is necessary to comply with applicable law; or (d) the data has been aggregated and anonymised and is used for our internal operations. Our administrators have no tool that opens another person’s mailbox.

Disconnecting. When you disconnect a Gmail mailbox in Apiway, its tokens and the index of its threads are deleted. Tasks, notes, files and other items you created or kept in Apiway stay in your account until you delete them or your account (§7). Deleting your account deletes all of it.

Use of AI Services

Many features of the Service use artificial-intelligence models: image and video generation, virtual try-on, text generation, the Apiway assistant (in the app, in Telegram, in ChatGPT and through MCP), summaries and extraction in Mail, Telegram rooms and Instagram automations, voice transcription, moderation, and the AI coding agent in App Factory. When you submit prompts, images, references, files, voice messages or other content (“AI Inputs”), we send the part of them the feature needs to an AI provider and return the result (“AI Output”). The providers we use today are:

  • Google (Gemini models, including image generation, Veo and Omni video, and voice transcription);
  • Anthropic (Claude models, used by the assistant and by the App Factory coding agent);
  • PiAPI, an aggregator through which we reach image and video models made by Kuaishou (Kling video) and ByteDance (Seedream images and Seedance video). If Google declines to generate an image for content-policy reasons, the Service may automatically send the same request to Seedream through PiAPI so that you still receive a result; this is described in the product and you are charged for the model that produced the image.

We choose providers whose terms do not allow them to use our customers’ inputs and outputs to train their models, and we contractually limit them to processing that data to provide the service to us. Providers may keep inputs for a short period for abuse monitoring under their own terms. AI processing takes place outside the European Economic Area, in the United States and, for models reached through PiAPI, possibly in other countries including China and Singapore. See §8 for transfer safeguards and the Subprocessors page for the current list.

Do not include special categories of personal data or other sensitive information in AI Inputs unless it is strictly necessary and lawful. Do not submit content unless you have the rights and lawful basis to do so. AI Output may be inaccurate, incomplete or similar to existing third-party content; you are responsible for checking it before you rely on or publish it (§12).

1. Terms and definitions

1.1. Account — the User’s account identified by the data specified during registration. Account data may include name, email, billing details, and service settings.

1.2. Account registration — the User’s action signaling the intention to conclude a License Agreement (Terms of Use), expressed by clicking “Register” or using other authentication methods.

1.3. Personal data subject — an individual to whom Personal data relates.

1.4. Website (Site) — a set of integrated software and hardware as well as information published on the Internet and displayed in text, graphic or sound form.

1.5. License — a non-exclusive right to use the Program to the extent established by the ApiWay service.

1.6. Personal Account — the User account identified by the User’s email address.

1.7. Control Panel — the User interface that allows the User to change settings and perform available actions in the Program.

1.8. Software extensions — additional functionality offered to the User at ApiWay’s discretion.

1.9. ApiWay Server (Server) — a hardware and cloud infrastructure providing sufficient performance for the Program.

1.10. Email — for ApiWay: info@apiway.ai; for the User: the address provided when registering the Account.

1.11. Integration Content — data that reaches the Service from, or is sent by the Service to, an account or system the User connects (for example Gmail, Google Calendar, Telegram, Instagram, a CRM, an advertising lead form or a messenger). Depending on the product, Integration Content is either relayed and logged, or stored so the product can work; §17 describes which, and §7 how long it is kept.

1.12. AI Inputs / AI Output — content you submit to or receive from AI features as defined above.

1.13. Customer Personal Data — personal data of people other than the User that the User processes with the Service, such as email-marketing contacts, booking invitees, leads, Instagram commenters and senders of direct messages, participants of rooms and work chats, and the users of an app the User hosts. ApiWay processes Customer Personal Data as a processor (§2.5).

2. General Terms

2.1. This Policy defines the procedure for working with Users’ Personal Data and other data used through the Service (including Integration Content).

2.2. Measures to ensure the security of Personal Data are an integral part of ApiWay’s activities.

2.3. Contractual relations between ApiWay and the User are governed by the License Agreement/Terms of Use.

2.4. ApiWay as controller. ApiWay is the controller of the personal data of its account holders and workspace members (account, billing, usage and support data), of visitors to its own websites, and of the data it uses for its own purposes as described in this Policy (security, product analytics, its own marketing, legal compliance). Earlier versions of this Policy described the Service as processing integration data on a “transit-only” basis; that is not accurate for the current Service, and §17 describes what each product stores.

2.5. ApiWay as processor. For Customer Personal Data (§1.13) — including Email Marketing contacts, booking invitees on a User’s booking page (§14), leads moved by Lead transfer, Instagram commenters and senders of direct messages handled by a User’s automations, participants of a User’s rooms and work chats, visitors of a User’s Apiway Pages and hosted forms, and the users of an app the User hosts (§15) — the User is the controller and ApiWay processes the data on the User’s documented instructions under the Data Processing Addendum, which forms part of the Terms of Use. If you are one of those people, please send requests about your data to the business that collected it; if you write to us, we will forward your request to that business and help it respond (§9.6).

3. Personal Data Processing Principles

3.1.1. Lawfulness, fairness, and transparency. ApiWay processes Personal Data only where permitted by applicable law.

3.1.2. Data minimization. We collect only the minimum data necessary to provide and secure the Service.

3.1.3. Purpose limitation. We process Personal Data for the purposes listed in §4.4: to perform our contract with the User, and to operate, secure and improve the Service, and otherwise only where the law allows.

3.1.4. Accuracy. We take reasonable steps to keep Personal Data accurate and up to date.

3.1.5. Storage limitation. We keep Personal Data no longer than the periods in §7, unless a longer period is required by law.

3.1.6. Integrity and confidentiality. We use appropriate technical and organizational measures to protect Personal Data.

4. Personal Data Processing Terms

4.1.1. With the User’s consent where required.

4.1.2. As necessary to perform a contract with the User (provide the Service).

4.1.3. To comply with legal obligations.

4.1.4. For ApiWay’s legitimate interests (e.g., security, fraud prevention, service analytics) provided such interests are not overridden by Users’ rights.

4.2. ApiWay does not sell Personal Data and does not disclose Personal Data or Integration Content to third parties except as described in this Policy (including to the subprocessors listed on the Subprocessors page), on the User’s instructions, or as required by law.

4.3. ApiWay does not intentionally process special categories of Personal Data unless the User submits such data as part of Integration Content or AI Inputs. Users should avoid including sensitive data unless strictly necessary.

4.4. Purposes and lawful bases. Where ApiWay is the controller, it relies on the following bases (Article 6 GDPR and equivalent laws):

PurposeDataLawful basis
Creating and running your account, providing the products you use, supportAccount data, content you create, Integration Content, AI Inputs and Output, support messagesContract (Art. 6(1)(b))
Billing, invoices, tax and accountingName, billing address, plan, transactions (card data is held by Stripe, not by us)Contract; legal obligation (Art. 6(1)(c))
Security, preventing fraud and abuse, enforcing our TermsTechnical logs, IP address, device data, account activity, reportsLegitimate interests (Art. 6(1)(f)); legal obligation where it applies
Understanding how the Service is used and fixing problems (first-party product analytics on our own servers)Usage events tied to your account, technical logsLegitimate interests
Website analytics with Google Analytics 4Cookie identifiers, pages viewed, device and approximate locationConsent (Art. 6(1)(a)), via the cookie banner
Advertising measurement and audiences with Meta Pixel, Meta Conversions API and Google ad signalsCookie identifiers, events such as sign-up or purchase, hashed email addressConsent, via the cookie banner
Product updates and newsletters to account holders (§5.2.4)Name, email address, planLegitimate interests / soft opt-in where the law allows it; you can unsubscribe in every email
Apiway newsletter for people who are not account holders (e.g. the booking-page checkbox, §14.10)Name, email address, sourceConsent
Moderating public content and handling notices (§5J)Published content, reports, account data of the publisherLegitimate interests; legal obligation (e.g. Digital Services Act)
Answering rights requests, keeping suppression lists, legal claimsRequest records, suppressed addressesLegal obligation; legitimate interests
Proof that you accepted our Terms and this Policy, and that you were notified of updates (§5.1.8)Document and version, time, IP address, user agent, sign-up surface, notice recordsLegal obligation; legitimate interests
Processing Customer Personal Data for our customers (§2.5)Whatever the customer puts into the productDetermined by the customer as controller; we act on its instructions

5. Collection and Processing of Personal Data and other Data

5.1. Categories of data.

5.1.1. Account Data — email, name, profile picture, organization and workspace membership, password hashes or sign-in method, preferences, subscription, credit and billing details (if applicable).

5.1.2. Integration Content — data from the accounts and systems you connect (Gmail, Google Calendar, Google Drive, Google Sheets, Telegram, Instagram, Shopify, advertising lead forms, CRMs and the reporting connectors). What is stored for each product is described in §17 and the Google user data section, and how long in §7.

5.1.3. AI Inputs and AI Output — prompts, references, files, voice messages and generated results. Generated images, videos and files are kept in your gallery or files until you delete them (subject to the free-plan limits in §7); assistant conversations are kept in your account until you delete them.

5.1.4. Technical Logs & Diagnostics — IP address, timestamps, request/response metadata, error traces, device and browser information, and usage events used for first-party product analytics.

5.1.5. Support Data — content you provide to support channels for troubleshooting.

5.1.6. Customer Personal Data — data about other people that you process with the Service (§1.13, §2.5).

5.1.7. Cookie and similar data — see §16.

5.1.8. Records of acceptance — when an account is created, and whenever you accept our Terms of Use or this Policy, we record which document and version you accepted, when, the IP address and browser user agent, and where you signed up (for example the sign-up form, Google sign-in, phone, an invitation link, our Telegram or Instagram bot, or the consent screen of an AI client connecting through MCP). We also record which accounts were notified of an update to these documents, by email or by a notice in the Service, and when you accepted the update there. We keep these records as proof of acceptance and notice.

5.2. Purposes of processing.

5.2.1. Provide, operate, and improve the Service and integrations.

5.2.2. Authenticate Users and manage accounts and subscriptions.

5.2.3. Ensure security, prevent abuse, and investigate incidents.

5.2.4. Provide support and communicate about Service updates. When you create an account, your name and email address are added to the mailing lists we use for product updates and news — our own list in Apiway Email Marketing and our list at ActiveCampaign. Every such email carries an unsubscribe link, and unsubscribing does not affect transactional and account emails (sign-in codes, receipts, security and service notices).

5.2.5. Comply with legal obligations and enforce agreements.

5.3. ApiWay uses Personal Data in accordance with applicable law and this Policy; the lawful basis for each purpose is in §4.4.

5.4. Confidentiality is maintained for Personal Data and other User Data except where the data is publicly available, provided by the User for public display (for example a share link, a public booking page, a published Apiway Page or Hosted App, or a legacy public listing under §5A), or otherwise disclosed as described in this Policy.

Legacy Creator Marketplace (§§5A–5F)

The Creator Marketplace stopped accepting new listings on 6 September 2026, and the Instagram direct-message bot that used to receive creators’ photos was shut down on 25 September 2026. Sections 5A–5F now only describe what happens to listings and payouts that already exist. Sections 5G–5N apply to the whole Service.

5A. Publicly Published Creator Content — Definitions

5A.1. “Publicly Published Creator Content” means material that a Creator (§13.1.1) chose to make public through the Creator Marketplace while it accepted listings: Reference Photo Sets and their photos, captions, titles, descriptions and tags; the Creator’s public storefront or profile page; and AI Output the Creator chose to pin or feature on that profile.

5A.2. “Private Content” means all other content, including a User’s own product photographs and other generation inputs, account-internal assets and drafts, messages, Integration Content and support correspondence. Private Content is never published, never used for the purposes in §5C, and is processed only under the rest of this Policy.

5B. How ApiWay obtained Publicly Published Creator Content

5B.1. Until intake closed, Creators published content through web upload (including bulk upload), through direct messages to an ApiWay-operated Instagram account, and through an optional automated import from their connected Instagram account. Each route asked for a separate marketplace consent before anything was published.

5B.2. Instagram import has stopped. ApiWay no longer imports media from Creators’ Instagram accounts into the marketplace. A Creator’s Instagram connection is now used only for the features the Creator uses today, such as Comment → DM automations (§17.4).

5B.3. Mention index deleted. ApiWay used to keep an index of Instagram posts whose captions tagged an ApiWay account, to credit referrals. That index was deleted on 3 October 2026 and is no longer kept.

5B.4. Featured AI Output. AI Output that a Buyer produced from a Creator’s Reference Photo Set may be shown on that Creator’s public profile if the Creator chose to feature it, without identifying the Buyer.

5B.5. Bulk upload. Photos uploaded in bulk were published only after the Creator confirmed the marketplace consent for that upload.

5B.6. Direct-message uploads have ended. Until 25 September 2026, photos a Creator sent by direct message to the ApiWay-operated Instagram account after accepting the marketplace consent were published as listings. That channel is closed; photos sent by direct message are no longer published.

5C. How ApiWay uses Publicly Published Creator Content

5C.1. Analysis and moderation. Existing listings were analysed automatically (by Google Gemini) to write titles, descriptions and tags and to check for minors, explicit content and identifiable third parties. Moderation results can still hide or unpublish a listing or a single photo (§5J).

5C.2. Public pages. Existing listings stay visible on the Creator’s public profile, listing pages, Explore pages, sitemaps and machine-readable feeds until the Creator withdraws them (§5E).

5C.3. Third-party channels. Listings may have been mirrored as pins on ApiWay’s own Pinterest account. A Creator can ask us to remove those copies (§5E).

5C.4. No training of generalized AI models. ApiWay does not use Publicly Published Creator Content to train generalized AI or machine-learning models. Earlier versions of this Policy reserved that right; we will not begin such use without first changing this Policy with the notice required by §5G.

5C.5. Ranking and search. ApiWay may order, rank, show or hide existing listings on its own pages.

5C.6. Text preserved after deletion (“house” profiles). Where this feature is switched on, when a Creator deletes a listing or account, ApiWay may move the listing’s text (title, description, captions) to an ApiWay-owned “house” profile and redirect the old address there, and may illustrate it with newly generated images of fictional subjects. No photograph of the Creator is used for that, the moved text does not identify the Creator, and the deletion of the Creator’s own data proceeds as usual. A Creator may object to this under §9.

5D. Private Content is excluded

5D.1. Nothing in §5C applies to Private Content. Private Content is not published, not mirrored to third-party platforms, not used for public pages and not used to train any AI model.

5E. Withdrawing Publicly Published Creator Content

5E.1. How. A Creator can unpublish a listing, hide single photos or delete the account in the product, or write to info@apiway.ai, including to ask for copies on ApiWay’s own third-party channels (such as its Pinterest account) to be removed.

5E.2. What we do. We stop showing the content on the Service and remove the copies on channels ApiWay controls, as far as the platform allows, within a reasonable time.

5E.3. Limits. We cannot remove copies that other people, search engines or other platforms made, and we keep billing and legal records as described in §7. Withdrawing a listing does not cancel licences already granted to Buyers for their earlier Paid Generations (§13.4).

5E.4. Statutory rights preserved. Nothing in §§5A–5F limits your statutory rights, including erasure under Article 17 GDPR and deletion under the CCPA/CPRA (§9).

5F. Consent for legacy listings

5F.1. Listings were published on the basis of the marketplace consent the Creator gave at the time of publication. Registering an account, connecting Instagram or using any other feature of the Service never by itself amounts to that consent. Connecting an Instagram or any other account grants ApiWay only the operational licence needed to run the features you use (Terms of Use §2.4); the broader licence in §3A of the Terms of Use covers only content that was published to the Creator Marketplace.

5F.2. A Creator may withdraw that consent at any time under §5E; withdrawal works for the future and does not affect what was lawfully done before.

5G. Changes to this Policy

5G.1. ApiWay may update this Policy. Each version has a version identifier and a date at the top, and previous versions stay available. Material changes will be (a) posted on the Site at least thirty (30) calendar days before they take effect for existing accounts; (b) summarised in the changelog at https://apiway.ai/changelog; and (c) notified to you by email to the account email address or by a notice in the Service (for example a prompt when you next sign in). Where mandatory law requires a longer notice period, that period applies.

5G.2. Continuing use. Continued use of the Service after a change takes effect means the updated Policy applies to your use from then on. Where a change needs your consent under applicable law, we will ask for it rather than rely on continued use.

5G.3. Earlier content. Content you provided under an earlier version stays subject to the narrower terms of that version where it was narrower, unless you later agree otherwise or the processing is required for security, moderation or legal compliance.

5G.4. Withdrawal of consent. Where processing is based on consent, you may withdraw it at any time; withdrawal does not affect processing carried out before it.

5H. Your responsibility for other people's data and rights

5H.1. When you upload, publish, import or send content through the Service that shows or concerns other people, or that includes material protected by someone else’s rights, you must have the rights, consents and releases the law requires for what you do with it — including from every identifiable person depicted and, for a minor, from a parent or guardian.

5H.2. The same applies to Customer Personal Data you put into the Service: you are responsible for having a lawful basis, for giving the people concerned the information the law requires, and for answering their requests (§2.5, §10).

5H.3. Your obligation to indemnify ApiWay for claims arising from a breach of §5H is governed by the Terms of Use.

5H.4. If we receive a credible complaint that your content violates someone’s rights, we may restrict or remove it while we look into it and may ask you for evidence of the relevant permissions (§5J).

5I. Children's data; minors in content

5I.1. The Service is not intended for, and is not knowingly offered to, individuals under the age of sixteen (16) years (or, where the local age of digital consent under Article 8 GDPR is higher, that higher local age). By using the Service you confirm that you meet that age.

5I.2. Where ApiWay becomes aware that an account has been opened by, or that content has been submitted by, an individual below the applicable age, ApiWay will take reasonable steps to delete the account and the content and to notify the relevant authority where required by law.

5I.3. No minors as subjects of public content. You must not publish content through the Service in which a minor is the principal subject. Automated checks try to detect such content, but they are not a substitute for this rule.

5I.4. Background minors. A minor who appears only incidentally in the background of otherwise compliant content does not by itself make it prohibited; you remain responsible under §5H.

5I.5. Minor-detection blocks. Content blocked because a minor was detected as its principal subject is not restored by an administrator on request; you may still use the complaint route in §5J.3 to show that the detection was wrong.

5I.6. Reporting content concerning minors. Anyone may report content believed to depict a minor unlawfully by writing to info@apiway.ai with the subject line “Child-safety report”. ApiWay cooperates with the National Center for Missing & Exploited Children (NCMEC) and equivalent authorities as required by law.

5J. Moderation, statement of reasons and complaints (EU DSA Article 17)

5J.1. What is moderated and how. Content you publish through public surfaces of the Service (for example legacy marketplace listings, share links, screen-recording pages, Apiway Pages and Hosted Apps) can be reported by anyone, and reports are reviewed by people. Legacy marketplace listings were also checked automatically (§5C.1). AI providers apply their own safety filters to AI Inputs and may refuse a request. We do not proactively read private content.

5J.2. Statement of reasons. If we restrict or remove content you uploaded, or restrict your account, we tell you what we did, the facts it was based on, the rule it was based on, whether automated means were used, and how to complain, as required by Regulation (EU) 2022/2065 (the Digital Services Act) where it applies.

5J.3. Complaints. You may complain within six (6) months by writing to info@apiway.ai with the subject line “Moderation complaint” and the address of the content. A person reviews each complaint, ordinarily within fourteen (14) days, and we tell you the outcome and our reasons. You may also use an out-of-court dispute settlement body under Article 21 DSA where it applies, or go to court.

5J.4. When an automated check fails. If an automated safety check cannot reach a result, we may keep the affected item hidden until it can be checked, rather than publish it unchecked. You keep the rights in §5J.2 and §5J.3, and nothing in this clause limits any claim you have under applicable law.

5K. Affiliate and referral programs — personal data

5K.1. The economic terms of the Affiliate Program and of legacy creator-pool payouts are in the Terms of Use §20 and at https://apiway.ai/docs/account/affiliate-program.

5K.2. To attribute referrals we process the referral link or code you followed, a first-party referral cookie (§16), the date of sign-up and the referred account’s purchases, and we show the referring partner aggregated earnings, not your activity.

5K.3. To pay partners we process payout details and the records needed for tax and accounting (§7).

5K.4. To prevent self-referral and fraud we may compare accounts, devices and payment details, and may withhold a payout we reasonably believe was obtained in breach of the program rules.

5K.5. Accrued balances on termination are handled under the Terms of Use and mandatory law.

5K.6. Attribution relies on cookies, links and codes, which can fail (for example when cookies are blocked); we implement them in good faith and, to the extent permitted by law, are not responsible for a referral that was not recorded for that reason.

5L. Subprocessors, international transfers, contact

5L.1. The current list of our subprocessors, what they do and where, is published at https://apiway.ai/legal/subprocessors. The main categories are hosting and storage, email delivery, payment processing, AI providers, analytics and advertising (only with consent, §16) and customer support. ApiWay may change subprocessors, subject to contractual obligations consistent with this Policy and the notice commitments in the Data Processing Addendum.

5L.2. International transfers. See §8.

5L.3. Data-protection contact; EU/UK representative. Inquiries regarding data protection, including requests under Articles 15–22 GDPR and equivalent CPRA/CCPA rights, may be addressed to info@apiway.ai with the subject line “Data-protection request.” Where ApiWay is required under Article 27 GDPR or Article 27 UK GDPR to designate a representative, or under Article 37 GDPR to designate a Data Protection Officer, the designated contact details are made available upon written request to the address above and will be published on this page as those designations are made.

5M. Security and breach notification

5M.1. ApiWay applies technical and organizational measures designed to protect Personal Data and Integration Content, including encryption in transit, access controls, separation of production systems, and routine security review, calibrated to the sensitivity of the data and the risks involved, consistent with Article 32 GDPR.

5M.2. No system is perfectly secure. No information system can be guaranteed to be completely secure or free of error, and our measures are commitments of practice and process. To the extent permitted by applicable law, a security incident does not by itself mean that we breached this Policy if we maintained the measures in §5M.1; this does not limit any right you have under data-protection law.

5M.3. Breach notification. In the event of a Personal Data breach as defined in Article 4(12) GDPR or an equivalent definition under applicable law, ApiWay will (a) notify the competent supervisory authority within seventy-two (72) hours of becoming aware of the breach where required by Article 33 GDPR or equivalent statute; (b) notify affected Users without undue delay where required by Article 34 GDPR or equivalent statute (including U.S. state breach-notification laws); (c) notify affected customers without undue delay where the breach concerns Customer Personal Data we process for them, as set out in the Data Processing Addendum; and (d) take reasonable steps to mitigate harm.

5M.4. Logs and operational data. Diagnostic logs, error traces and request metadata may contain references to Personal Data (for example identifiers, file paths or prompt strings). We limit access to them and keep them only as long as §7 allows.

5N. How this Policy relates to other materials

5N.1. This Policy, together with the Terms of Use and the Data Processing Addendum, is our statement of how we process personal data through the Service.

5N.2. Explanatory materials. Help pages, product copy, blog posts and similar materials explain the Service in simpler terms. If one of them is less protective of you than this Policy, this Policy controls; if one of them makes a more protective commitment, we will honour it.

5N.3. Providers and features change. Names of providers, models, schedules and similar operational details in this Policy describe the Service as it is today. We may change them; where a change materially affects how your personal data is processed, §5G applies, and the Subprocessors page is kept current.

5N.4. Your statutory rights. Nothing in this Policy or in any other material excludes or limits rights or remedies you have under mandatory law, including consumer-protection law.

5N.5. Image fingerprints. For legacy marketplace uploads, the SHA-256 fingerprint of an uploaded image may be kept after the image is deleted, only to stop the same image being re-published by the same account; it is treated as personal data and deleted with the account.

5N.6. Severability. If any part of this Policy is held unenforceable in a particular case, the rest continues to apply.

6. Security and Availability

6.1. ApiWay applies appropriate technical and organizational measures (including encryption in transit, access controls, and segregation of duties) to protect Personal Data and Integration Content.

6.2. No system can be guaranteed to be 100% secure or error-free, and outages or incidents may occur. In the event of a Personal Data breach, ApiWay will notify affected Users as required by applicable law and will take reasonable steps to mitigate harm (see §5M.3 for the specific notification framework).

7. Retention

7.1. Retention periods. We keep personal data for the periods below. When a period ends, the data is deleted or irreversibly anonymised by automated jobs; deleted data can survive in encrypted database backups for up to fourteen (14) days, after which the backups are overwritten.

DataHow long we keep it
Account data, workspace membership and settingsUntil you delete your account (or the workspace owner removes you), then deleted, except the records below that the law requires us to keep
Billing records (invoices, payments, tax data)Up to 7 years after the transaction
Records of acceptance of the Terms and this Policy, and of update notices (§5.1.8)For the life of the account; deleted with the account
Database backups14 days, rolling
Content you create and keep (generations, files, tasks, notes, assistant conversations, Rooms, Apiway Pages, email-marketing data)Until you delete it or your account, subject to the free-plan limits below
Files on the free plan180 days
Screen recordings on the free planVideos: 30 days. Screenshots and voice recordings are kept until you delete them. A public link to an expired video keeps showing its preview image and a notice.
Lead transfer: lead data received from ad forms, and the delivery logWhile the customer’s account exists; deleted with the account, or earlier when the customer asks us to delete it
Email Marketing: IP address and user agent recorded with email opens and clicks12 months, then removed from the event
Telegram team rooms and the Telegram personal assistant: message text90 days
Instagram direct-message log of automations and the DM assistant30 days
Apiway Bot rooms: messages and filesAs long as the room exists; deleted with the room
Instagram mention index (legacy referral attribution)Deleted on 3 October 2026; no longer collected
Gmail thread index and tokensWhile the mailbox stays connected; deleted when you disconnect it
Hosted App data (App Factory)While the app exists; daily copies kept 14 days; 6 months after you delete the app (§15.4)
Email suppression and unsubscribe recordsAs long as needed to honour the unsubscribe, so an address is not re-added
Booking records (§14)Until the host deletes them or their account

7.2. Where a product lets you delete an item (a message, a file, a contact, a room, a recording), deleting it removes it from the Service at once and from backups within fourteen (14) days.

7.3. We may keep data longer where the law requires it, or for as long as needed to establish, exercise or defend a legal claim, and only for that purpose.

8. International Data Transfers

8.1. ApiWay, Inc. is a United States company. Our primary hosting is in the European Union: our application servers and databases are in the Netherlands (Fornex), and our file storage is with Amazon Web Services in the EU (Stockholm, eu-north-1). Some subprocessors — including AI providers, email delivery, payments, support tools and, with your consent, analytics and advertising providers — process data in the United States and other countries, and AI models reached through PiAPI may process data in China or Singapore (“Use of AI Services”).

8.2. For transfers of personal data from the European Economic Area, the United Kingdom or Switzerland to countries without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum and Swiss amendments where needed, or, where the recipient is certified, on the EU–U.S. Data Privacy Framework and its UK and Swiss extensions, together with supplementary measures where appropriate. You can ask us for a copy of the relevant safeguards at info@apiway.ai.

8.3. A current list of subprocessors and their locations is available at /legal/subprocessors.

9. Your Rights

9.1. Subject to applicable law, you may ask to access, correct, delete, restrict or export (portability) your Personal Data, and you may object to processing based on legitimate interests (including any profiling) and, at any time, to direct marketing. Where processing is based on consent, you may withdraw it at any time. You can delete your account yourself in Account settings (“Delete account”), and you can make any request by writing to info@apiway.ai.

9.2. EEA/UK residents may lodge a complaint with a supervisory authority, in particular in the country where they live or work.

9.3. Meta (Facebook/Instagram) Data Deletion. If you connected a Meta account (Facebook/Instagram) to Apiway, you may request deletion of data associated with that connection by emailing info@apiway.ai. We also honor deletion requests received from Meta via our data deletion callback and will delete or anonymize data associated with the app-scoped user ID.

9.4. California and other U.S. states. If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon or another U.S. state with a comprehensive privacy law, you have, as that law provides, the right to know and access the personal information we collect about you, to correct it, to delete it, to receive a portable copy, and to opt out of the “sale” or “sharing” of personal information and of targeted advertising. We do not sell personal information for money and do not use sensitive personal information to infer characteristics about you. However, if you allow marketing cookies (§16), the Meta Pixel, Meta Conversions API and Google advertising signals disclose identifiers and activity to those companies for cross-context behavioural advertising, which California law treats as “sharing” and other states treat as targeted advertising. You can opt out at any time through Your Privacy Choices, and we treat a Global Privacy Control signal from your browser as a valid opt-out. We will not discriminate against you for using these rights. In the preceding twelve months we collected the categories of personal information described in §5.1 and §17 (identifiers, commercial information, internet activity, approximate geolocation from IP address, audio and visual content you upload, and professional information you provide), from you, from the accounts you connect and from your devices, for the purposes in §4.4, and disclosed them to the categories of recipients on the Subprocessors page. We do not knowingly sell or share personal information of consumers under 16.

9.5. Verification and appeals. We may need to verify your identity before acting on a request, usually by asking you to confirm from the email address on your account. You may use an authorised agent where the law allows. We answer within one month (GDPR) or forty-five (45) days (U.S. state laws), which we may extend where the law permits. If we decline your request you may appeal by replying to our answer with the subject line “Appeal”; a different person reviews the appeal and tells you the result and, where applicable, how to contact your state Attorney General.

9.6. If a customer of Apiway holds your data. If your data reached us because an Apiway customer uses the Service (for example you booked a meeting on someone’s booking page, subscribed to someone’s newsletter, commented on someone’s Instagram post, sent a lead form, or use an app someone hosts with us), that customer controls the data and you should contact them. If you contact us, we will forward your request to the customer and help it respond (§2.5).

9.7. Other countries. If you are in Brazil (LGPD), Canada (PIPEDA and provincial laws), Australia (Privacy Act 1988), India (Digital Personal Data Protection Act 2023) or another country with a data-protection law, we honour the same rights described in this section on request, and you may also complain to your local data-protection authority.

10. Third-Party Personal Information Used by Users

10.1. When using the Service, Users may transmit third-party data as Integration Content, Customer Personal Data or AI Inputs.

10.2. The User is responsible for ensuring a lawful basis and, where required, prior consent for processing third-party data in the Service (see also §5H).

10.3. The User (including legal-entity representatives) is responsible for answering requests and claims from data subjects regarding data the User submitted to the Service; ApiWay assists as described in the Data Processing Addendum.

10.4. ApiWay implements appropriate measures to safeguard third-party data processed through the Service as described in this Policy.

11. Other Provisions

11.1. Governing law for this Policy is the law of the State of Delaware, USA, without prejudice to mandatory protections afforded to individuals under the laws of their habitual residence (e.g., GDPR).

11.2. Disputes shall be resolved in accordance with applicable law and the Terms of Use. Before going to court, we encourage you to write to us so we can try to resolve the matter; we answer within 30 (thirty) days. This does not affect your right to complain to a supervisory authority at any time.

11.3. If any provision of the Policy is held invalid, the remaining provisions remain in effect.

11.4. ApiWay may modify this Policy under the procedure in §5G.

11.5. Contact. ApiWay, Inc., a corporation incorporated in Delaware, USA. Postal address: Suite S2, 1050 North Third Street, Laramie, Wyoming 82072, USA. Privacy requests: info@apiway.ai. Abuse and content reports: info@apiway.ai.

12. AI Transparency and User Responsibilities

12.1. AI Output is generated automatically and may contain errors, inaccuracies, omissions, distortions, misleading elements, or content that does not meet your expectations. AI Output must not be relied upon as fact, legal advice, medical advice, professional advice, or as the sole basis for business, commercial, design, advertising, or compliance decisions.

12.2. ApiWay provides the technology that sends AI Inputs to AI providers and returns AI Output. Apart from the safety filters and moderation described in “Use of AI Services” and §5J, ApiWay does not review AI Inputs or AI Output for legality, accuracy, originality, non-infringement, or suitability for any specific use.

12.3. You are responsible for the AI Inputs you submit and for your use of any AI Output, and you must have the rights, permissions and lawful bases that use requires.

12.4. You must not submit content that infringes third-party rights (copyright, trademark, publicity, privacy, confidentiality or others) unless you have the necessary permissions. Use of the Service does not grant you rights in third-party content.

12.5. AI Output may resemble existing works, names, brands, images, voices or likenesses. ApiWay makes no representation that any AI Output is non-infringing, unique or available for commercial use; clearing it is your responsibility.

12.6. Claims, notices and disputes arising from your AI Inputs, AI Output or your use of the Service are allocated between you and ApiWay by the Terms of Use.

12.7. As between you and ApiWay, and subject to applicable law, third-party rights, and the terms of any relevant third-party providers, you retain whatever rights you may have in your AI Inputs and bear full responsibility for your use of any AI Output. ApiWay does not claim ownership of your AI Inputs or AI Output except for the limited rights necessary to host, process, transmit, secure, troubleshoot, prevent abuse, comply with law, and provide the Service in accordance with this Policy and the Terms of Use.

12.8. ApiWay may use, replace, or combine AI, cloud, moderation, hosting, storage, analytics, and infrastructure providers in order to provide the Service; the current ones are named in “Use of AI Services” and on the Subprocessors page.

12.9. You must independently review and verify AI Output before relying on it or publishing, distributing, displaying, performing, commercializing, or otherwise using it.

12.10. Credits, charges and refunds for AI processing are governed by §18 of the Terms of Use.

13. Legacy Creator Marketplace — Creators and Buyers

13.1. Definitions.

13.1.1. Creator — a User who published a Reference Photo Set to the Creator Marketplace while it accepted listings.

13.1.2. Co-Creator — a person entitled with the Creator to a share of the credits earned by a Reference Photo Set, including a referring creator under a referral program. References to the Creator include Co-Creators.

13.1.3. Buyer — a User who generates AI Output from a Reference Photo Set.

13.1.4. Reference Photo Set — one or more photographs published by a Creator for use as references in AI generation.

13.1.5. Marketplace Listing — the published representation of a Reference Photo Set, including its price, metadata and previews.

13.1.6. Generated Output — the AI Output produced for a Buyer on the basis of a Reference Photo Set.

13.1.7. Paid Generation — a generation for which the Buyer’s credits were charged and the Creator’s share was recorded.

13.2. Creator representations. A Creator who keeps a listing published confirms that they hold the rights and consents described in §5H.1 for it, that it does not infringe anyone’s rights, and that, as between the Creator and ApiWay, the Creator owns the photographs subject to the licences in this Section and the Terms of Use.

13.3. Buyer’s licence to Generated Output. On completion of a Paid Generation the Creator grants the Buyer a perpetual, worldwide, irrevocable, non-exclusive, royalty-free licence to use, reproduce, modify, distribute and commercially exploit the resulting Generated Output (but not the Reference Photo Set itself). Other Buyers may receive parallel licences to their own outputs from the same set. ApiWay facilitates this licence as a technology platform and is not a party to it.

13.3.1. Reversals. If a Paid Generation is refunded, charged back or obtained fraudulently, the licence for its Generated Output may be terminated, and the Buyer must then stop using it.

13.4. Withdrawal does not revoke existing licences. A Creator may withdraw a listing at any time; withdrawal stops new Paid Generations but does not affect licences already granted under §13.3. ApiWay may keep the Reference Photo Set for as long as necessary to support those licences, resolve disputes and meet legal obligations, within the limits of §7.

13.4.1. Mandatory law. Where the law requires ApiWay, a Creator or a provider to delete or restrict a Reference Photo Set or Generated Output (for example an erasure request under Article 17 GDPR, a publicity-rights claim or a court order), ApiWay may do so even if it affects a Buyer’s licence, and will try to tell the affected Buyer where lawful and practicable.

13.5. ApiWay’s role. ApiWay is a technology platform and not a seller, agent or licensor of Reference Photo Sets. It cannot prevent copying or misuse of public content by third parties; enforcing rights against them is for the Creator or the Buyer.

13.6. AI terms continue to apply. Sections 5.1.3 and 12 apply to Reference Photo Sets and Generated Output.

13.7. Indemnities, warranties and disclaimers, limitations of liability, time limits for claims, class-action waivers and dispute resolution for the Legacy Creator Marketplace are governed exclusively by the Terms of Use (in particular §9, §10, §13 and §16). Sections 13.8–13.9 and 13.12–13.17 of earlier versions of this Policy no longer apply under this version.

13.10. Infringement notices. Notices of alleged infringement involving any content available through the Service may be sent to info@apiway.ai and are handled under the notice-and-action procedure in §19 of the Terms of Use.

13.11. Survival. Sections 13.3, 13.3.1, 13.4 and 13.4.1 survive the closing of the Creator Marketplace and the deletion of a listing or account, to the extent necessary to give effect to licences already granted.

14. Booking Pages (apiway.ai/book/…)

14.1. What a Booking Page is. The Service lets a User (the “Host”) publish a scheduling page at a public URL of the form apiway.ai/book/<slug>. Any person who opens that page and submits the form (the “Invitee”) requests a meeting with the Host. An Invitee is normally not a registered User of the Service and has no account with ApiWay; this Section describes how ApiWay processes the Invitee’s Personal Data, and applies in addition to the general provisions of this Policy.

14.2. What is collected. When an Invitee books, the Service processes: (a) the name and email address the Invitee enters; (b) the optional free-text note and the answers to any additional questions the Host configured on that page; (c) the selected date, time, and the Invitee’s browser time zone; (d) whether the Invitee ticked any of the optional marketing checkboxes (§14.6, §14.10) and, if so, a record of that consent (the wording of the checkbox, its version and the time it was given); and (e) campaign attribution parameters carried in the link the Invitee followed (for example utm_source, utm_medium, utm_campaign, utm_term, utm_content, ref, gclid, fbclid), together with the referring URL and the landing URL. ApiWay does not ask an Invitee for payment details, government identifiers, or special-category data on a Booking Page, and Invitees should not enter such data in free-text fields.

14.3. Why, and on what basis. The data in §14.2(a)–(c) is processed to create and administer the meeting the Invitee requested (performance of a contract or of pre-contractual steps taken at the Invitee’s request, and the Host’s legitimate interest in scheduling). The attribution data in §14.2(e) is processed on the basis of legitimate interests, solely to measure which channel a booking came from and to detect abuse; it is not used to build advertising profiles of Invitees, is not sold or shared as those terms are defined by the CPRA, and is not combined with data obtained from third-party advertising networks. The marketing-consent flags in §14.2(d) are processed on the basis of the Invitee’s consent (§14.6, §14.10). Apiway’s own analytics and advertising tags are not loaded on Booking Pages (§16.4), no cookie is set for attribution, and no cross-site or cross-Host profile of the Invitee is built; only the fixed list of parameters named in §14.2(e) is recorded, every other query parameter present in the URL is discarded, and each recorded value is truncated.

14.4. Roles. For Booking Pages published by a Host other than ApiWay, the Host is the controller of the Invitee’s Personal Data and ApiWay acts as a processor on the Host’s behalf, in accordance with §2.5, the Data Processing Addendum and §10. Where ApiWay itself is the Host of a Booking Page, and for the Apiway newsletter checkbox in §14.10, ApiWay acts as the controller. The Host is solely responsible for the lawfulness of the additional questions it configures, for any special-category data it invites, and for its own communications with the Invitee (see §§5H and 10).

14.5. Google Calendar. Confirming a booking creates a calendar event in the Host’s connected Google Calendar and, where the Host has enabled it, a video-conference link for that event. The event carries the Invitee’s name, email address, the selected time, and the note and answers submitted with the request, and the Invitee is added as an attendee, which means Google sends the Invitee an invitation. Google therefore receives that data as a recipient and acts as a subprocessor in respect of it; see §§5L and 8, and the Subprocessors page. ApiWay reads only the free/busy windows of the calendars the Host designated in order to compute available slots, and does not read the content of the Host’s other calendar entries for that purpose. Deleting the event in Google Calendar does not by itself delete the corresponding booking record held by the Service, and deleting the booking record in the Service does not by itself delete any copy Google or the Invitee already holds.

14.6. Marketing emails are opt-in and separable. A Booking Page may show a clearly labelled, optional checkbox offering product updates from the Host. It is not ticked in advance, and the booking itself never depends on it. Only if the Invitee ticks that checkbox is the Invitee’s name and email address added to the Host’s marketing contact list and, where the Host has configured one, enrolled in an automated email sequence; the attribution data in §14.2(e) is stored alongside that contact record so the Host can see which campaign produced it. Every such message carries a working unsubscribe link and one-click unsubscribe support, and the Invitee may withdraw consent at any time, either through that link or by writing to the Host or to info@apiway.ai. Withdrawal does not affect the lawfulness of processing carried out before withdrawal and does not cancel the meeting. Transactional messages about the booking itself (confirmation, change, cancellation, reminder) are not marketing and are sent regardless of the checkbox.

14.7. Retention. Booking records, including the data in §14.2, are retained until the Host deletes them or the Host’s account is deleted (§7). Contact records created under §14.6 are retained until the Invitee unsubscribes or the Host deletes them, subject to the suppression records ApiWay must keep to honour that unsubscribe.

14.8. Invitee rights. Section 9 applies in full to Invitees. An Invitee may request access to, rectification of, erasure of, restriction of, or portability of the data described in this Section, and may object to processing based on legitimate interests, by contacting the Host or by writing to info@apiway.ai; where ApiWay acts as a processor for a Host, ApiWay will forward the request to that Host and assist the Host in responding.

14.9. Legal links on the page. Every Booking Page carries links to this Policy and to the Terms of Use. Submitting a booking form indicates that the Invitee has been given the opportunity to read them; it does not create an account, a subscription, or any payment obligation for the Invitee.

14.10. The Apiway newsletter checkbox. Separately from any checkbox the Host configures under §14.6, a Booking Page may show its own optional checkbox labelled “Subscribe me to the Apiway newsletter.” It is not ticked in advance. Only if the Invitee ticks it when confirming the meeting does ApiWay, acting as controller, add the Invitee’s name and email address to ApiWay’s own newsletter mailing list, together with the name of the Booking Page the subscription came from, and send the Invitee product news and updates about the Service. If the Invitee leaves it unticked, nothing is added to ApiWay’s list. This consent is independent of the booking and of the Host’s own list: leaving it unticked never cancels or changes the meeting, and ticking it does not subscribe the Invitee to the Host’s mail. Every newsletter carries a working unsubscribe link with one-click unsubscribe support, and the Invitee may withdraw at any time through that link or by writing to info@apiway.ai; ApiWay keeps a suppression record so an unsubscribed address is not re-added by a later booking.

15. App Data (App Factory Hosted Apps)

15.1. What App Data is. “App Data” is everything a Hosted App built in App Factory stores or processes: the records in its own database, files, secrets and logs, the code versions ApiWay builds and runs, and the materials of its brief (the name, description, reference screenshots and links the App Owner provided).

15.2. Roles. The User who owns a Hosted App (the “App Owner”) decides what data it collects and why, and is the controller of the personal data in it. ApiWay hosts the Hosted App and processes App Data only on the App Owner’s behalf, as a processor under the Data Processing Addendum, to run, secure, back up and restore it. ApiWay does not use App Data for advertising, does not sell it and does not use it to train AI models.

15.3. The brief and the build. The App Owner’s description, screenshots and links for an app are processed by an AI model (see “Use of AI Services”) to write the app’s specification. An app is then built either by the App Owner’s own coding agent, operated by its own provider under the App Owner’s agreement with that provider, or, when the App Owner chooses to build it in ApiWay, by an AI coding agent that ApiWay runs on its side using Anthropic’s Claude models. In that case the brief, the app’s code and the conversation with the agent are sent to Anthropic to produce the code; secrets the App Owner enters for the app are stored in the app’s settings and are not sent to the model.

15.4. Retention. App Data is kept while the Hosted App exists. A copy of its database is made daily and the last fourteen (14) copies are kept. When the App Owner deletes a Hosted App, its database, code versions, backups and brief materials are kept for six (6) months so it can be restored, and are then permanently deleted. When the App Owner’s paid plan ends, a published Hosted App is paused, not deleted.

15.5. Requests from an app’s users. People whose data is in a Hosted App should direct requests under §9 to the App Owner. ApiWay will assist the App Owner in answering them and will forward any such request it receives.

16. Cookies, tracking and Your Privacy Choices

16.1. Strictly necessary. We use first-party cookies and similar storage that the Service cannot work without: to keep you signed in and secure your session, to protect sign-in and connection flows against forgery, to remember which workspace or account you are using, to let a share link or invitation open what it was issued for, to remember your interface preferences, and to remember your cookie choice itself (cookie apiway_consent, kept 12 months). These do not need consent.

16.2. Referral and attribution. If you arrive through a partner’s referral link, or through a link in an email, a shared page or an Apiway Bot invitation, we set a first-party cookie that remembers that source for up to 30 days, so the referral can be credited when you sign up (§5K). These cookies are read only by Apiway.

16.3. Analytics and marketing — only with your consent. Our websites ask for your choice in a cookie banner. Nothing below is loaded or sent until you allow it, and you can change your choice at any time through Your Privacy Choices (also in the footer of every page):

  • Analytics: Google Analytics 4, to understand how our websites are used. Its script is not requested at all until you allow analytics (Google Consent Mode v2, basic mode), and if you later withdraw consent we switch it off and delete its cookies.
  • Marketing: the Meta Pixel in your browser and the Meta Conversions API from our servers (which sends events such as sign-up or purchase with a hashed email address), and Google’s advertising consent signals, to measure our advertising and build advertising audiences.

16.4. Never on our customers’ pages. Apiway’s own analytics and advertising tags, and the cookie banner, are not loaded on pages our customers hand to their own visitors — for example booking pages (/book), hosted forms (/f), shared rooms and links (/r), screen recordings (/v, /s), shared apps (/a) and Apiway Pages (/pages). A customer may add its own tracking pixels to its hosted forms or pages; the customer is responsible for that tracking and for asking its visitors’ consent.

16.5. Global Privacy Control. If your browser sends a Global Privacy Control signal, we treat it as a refusal of marketing cookies and as an opt-out of sale, sharing and targeted advertising, whatever the banner says.

16.6. Emails. Product-update emails from Apiway contain links that let us see whether an email was opened or a link clicked, so we can measure them; you can avoid this by blocking images or unsubscribing. Tracking in emails our customers send with Email Marketing is described in §17.2.

17. What each product does with personal data

This section summarises, product by product, what is processed and kept. For Customer Personal Data handled in these products, the customer is the controller and we are its processor (§2.5). What our assistants, bots and connected accounts may do on your behalf is set out in§6A of the Terms of Use.

17.1. Mail (Gmail). See the Google user data section for what we access and store. Additional features: you can schedule emails (they wait as drafts in your Gmail), turn on read receipts for emails you send (we record that and when a receipt image was loaded, but not the reader’s IP address or location), share a thread, file or draft through a link (anyone with the link sees what you chose to share), invite colleagues to a mailbox you share with them, forward a message to a Telegram or Discord chat you choose, and record voice, video or screen messages, which are stored in our storage and sent as a link. The mail assistant sends the content needed for your request to our AI providers.

17.2. Email Marketing. Customers import or collect contacts (email, name, phone and custom fields they define), lists, signup forms and campaigns; we store them to send the customer’s emails through Amazon SES. Each sent email contains a tracking image and rewritten links; when a recipient opens it or clicks a link we record the event with the IP address, user agent and the country derived from them (IP address and user agent are removed after 12 months, §7). Signup forms record the consent given, with time, IP address and user agent, and support double opt-in. Unsubscribes, bounces and complaints are kept on a suppression list so the address is never emailed again by that customer. To protect deliverability, addresses may be checked with an email-verification provider (such as Bouncer, Clearout, ZeroBounce, MillionVerifier or Emailable), which receives the address only. Apiway is the processor for the customer’s contacts; the customer’s duties as a sender are in §17 of the Terms of Use.

17.3. Telegram. In team rooms, once a chat’s owner activates it in Apiway, the Apiway bot stores the chat’s messages (text for 90 days), the participants’ Telegram names and identifiers, and files sent in the chat, and uses AI to extract tasks and agreements, transcribe voice messages and answer when it is called. Nothing is stored for a chat that was only added to the bot and not activated. The personal assistant links your Telegram account to your Apiway account and processes your messages, voice notes and files (message text for 90 days) to create tasks and reminders and to answer questions about your account. The bot can forward a file to the person a task is assigned to without downloading it.

17.4. Instagram automations and the DM assistant. When a User connects an Instagram professional account, we process, through Meta’s official API and the User’s own authorisation, the comments and direct messages that trigger the User’s automations (the commenter’s Instagram-scoped identifier, username, comment and message text), send the replies the User configured, and keep a message log for 30 days. If the User’s automation asks for an email address or phone number, the answer is stored for the User. Voice instructions you give the assistant to set up an automation are transcribed with AI. We do not look up Instagram accounts or posts that have not interacted with the User’s account. The User is the controller of its audience’s data.

17.5. Lead transfer. Lead transfer receives leads from advertising lead forms the customer connects (for example Meta and TikTok) and delivers them to the destinations the customer chooses (CRMs, email marketing tools, Google Sheets, email, messengers). Lead data received from ad forms, and a delivery log so the customer can see what was sent where, are kept while the customer’s account exists (also after an automation is switched off or removed, so its history stays visible), and are deleted with the account or earlier at the customer’s request. Apiway is the processor for the leads.

17.6. Screen recorder and public links. Recordings and screenshots are uploaded to our storage and can be shared through a short public link. We count views of a public link without recording the viewer’s IP address; requests to unknown links are rate-limited, which processes the IP address briefly. Anyone with the link can view the recording until the owner revokes or deletes it. Free-plan videos are kept for 30 days (§7).

17.7. Apiway Bot rooms. When someone adds Apiway’s workspace bot to an email thread (as To or Cc), the bot receives the messages sent to it from then on — it never reads anyone’s mailbox — and stores their text, the participants’ names and email addresses and the attached files in a room, for as long as the room exists. People in the thread who are not Apiway users may receive a single invitation to the room, which names the inviter only by the name on their Apiway account, never by a name typed into an email; they can open the room through the link in it, and can reply “STOP” or use the unsubscribe link to never be emailed by the bot again. Removing the bot from Cc stops it receiving anything. Messages from senders who cannot be authenticated are quarantined and not shown.

17.8. Connectors. When you connect a reporting source for the assistant (for example Stripe, Google Analytics 4, Google Search Console, HubSpot, Pipedrive, Trello or Notion), we read data from it only when you or a teammate you gave access ask a question, and only read-only (Stripe through a restricted key that can only read; Google Analytics and Search Console through our service account, which you grant view access to). The answer becomes part of that assistant conversation. Each read is recorded in an access log (who, which connector, when), without the data itself.

17.9. The assistant in ChatGPT and through MCP. If you connect Apiway to ChatGPT or to another AI client through our MCP server, that client sends us the requests you make there and receives our answers. OpenAI (for ChatGPT) and the provider of any other client are independent controllers of what you type into their products and of how they handle our answers, under their own privacy policies.

17.10. Apiway Pages and hosted forms. Pages and forms you publish are public. Data their visitors submit is stored for you, and you are its controller.

17.11. Workspaces. If you join a workspace, its owner (and administrators the owner appoints) can see your name and email address, your role, the credits you use and the limits set for you, the items you create in shared spaces, and the mailboxes or rooms shared with you. If the workspace uses Fitness Guard, the owner and other members can see per-person break statistics (breaks done, skipped and the reasons chosen); the camera image used to count exercises never leaves your browser. The workspace owner pays for and is responsible for the workspace.

17.12. Generation (images and video). Inputs and outputs are processed by the AI providers named in “Use of AI Services”, including the automatic Seedream fallback when Gemini refuses an image. Results are saved to your gallery.

17.13. Calendar, tasks and booking pages. Tasks, reminders and meeting polls you create are stored in Apiway. Booking pages are described in §14.

17.14. Shopify. When you connect a Shopify store, we read its product catalogue and stock levels (titles, descriptions, images, prices, inventory) and, when you approve a product in Apiway, create it in your store as a draft. The Shopify connection does not give us access to your store’s customers or orders.

18. Contact and complaints

18.1. Privacy questions and requests: info@apiway.ai (subject line “Data-protection request”). Abuse, infringement and child-safety reports: info@apiway.ai.

18.2. ApiWay, Inc., Delaware, USA. Suite S2, 1050 North Third Street, Laramie, Wyoming 82072, USA.

18.3. You may complain to your data-protection authority at any time (§9.2, §9.7).