Legal
Privacy Policy
BuyAPI is run by Fang Labs LLC. This policy explains what we collect, why we collect it, and how to ask us to delete it.
Last updated: April 28, 2026
What we collect
Account information, such as the name, email address, avatar, and account identifiers provided by your sign-in provider.
Stack and product data you choose to save or import, including project names, summaries, detected tools, notes, reviews, watchlists, follows, and discussion posts.
API key records. We store key names, prefixes, timestamps, and cryptographic hashes. We do not store the full plaintext API key after it is shown to you.
Basic technical and usage data, such as request metadata, device or browser details, approximate location from IP address, logs, security events, and product interactions.
Messages you send us, including email, bug reports, support requests, and feedback.
Local scans
The local BuyAPI scanner is designed to inspect project files on your machine and print a stack report. It is not meant to upload source code, secrets, or environment files.
If you choose to sync or import a stack, BuyAPI may store the project name, summary, detected vendors, categories, confidence levels, and notes included in that import.
How we use information
We use information to provide BuyAPI, keep accounts and API keys working, personalize recommendations, secure the service, debug issues, improve the product, respond to requests, and comply with legal obligations.
We do not sell personal data for advertising. We also do not plan to use personal data for cross-site ad targeting.
Analytics
We do not use Google Analytics today. We may use limited product or web analytics, including tools such as Vercel Web Analytics, to understand traffic, feature usage, reliability, and performance.
Analytics may include page views, referrers, browser or device type, approximate region, and product events. We use this to run and improve BuyAPI, not to sell advertising profiles.
Sharing
We share information with service providers that help us host, authenticate, store data, deliver analytics, send messages, prevent abuse, or operate BuyAPI. They may only use the information to provide services to us.
We may also disclose information if required by law, to protect users or BuyAPI, or as part of a merger, financing, acquisition, or sale of assets.
Retention and deletion
We keep information while it is needed to provide BuyAPI, maintain security, meet legal obligations, resolve disputes, or enforce our terms.
You can request deletion by emailing me@kevinfang.tech. We may need to verify your account before deleting data.
Security
We use reasonable technical and organizational measures to protect information. No internet service is perfectly secure, so you should protect your account credentials and API keys.
Children
BuyAPI is not intended for children under 13. If you believe a child has provided personal information, contact us and we will take appropriate steps.
Changes
We may update this policy as BuyAPI changes. If the changes are material, we will take reasonable steps to make them visible.
Contact
Questions or deletion requests can go to me@kevinfang.tech.
Need the shorter version? See the contact page.