Privacy Policy

How we collect, use, and protect your data

1. What We Collect

When you create an account or use the API, we collect:

  • Account info: name, email address, and (if you sign up with a password) a securely hashed password. We never store your password in plain text.
  • If you sign in with GitHub or Google, we receive your name, email, and profile picture from that provider.
  • Your API key and usage data: which endpoints you call, response times, and status codes, used for your dashboard stats and rate limiting.
  • Your IP address is recorded for security and abuse-prevention purposes, in a partially masked form.
  • A session cookie (a signed token) that keeps you logged in between visits.

2. How We Use It

  • To operate your account: authentication, your API key, and your dashboard stats.
  • To enforce fair use: rate limits and daily request quotas per plan.
  • To detect abuse and protect the service from attacks.
  • To send account-related emails (e.g. email verification, security notices) and, if you opt into a donation, a receipt.

We do not sell your personal data to anyone.

3. Data Retention

Account data is kept for as long as your account exists. Raw API request logs are automatically deleted after 30 days. Aggregate, non-identifying usage totals (like total request counts) may be kept longer for service statistics. If you delete your account, your account record and API key are removed.

4. Third Parties

We rely on a small number of third-party services to run Malvin API:

  • MongoDB Atlas — hosts our database (accounts, API keys, usage stats).
  • Vercel — hosts and runs the API itself.
  • GitHub / Google — optional sign-in providers, only if you choose to use them.
  • PayPal — processes donations and Premium payments; we don't see or store your card details.
  • An email provider (SMTP) — sends verification and account emails.
  • Discord — receives non-personal notifications (e.g. new donation alerts) via a webhook.

5. Cookies

We use a single essential cookie (auth_token) to keep you signed in. It's required for login to work and isn't used for advertising or cross-site tracking.

6. Your Rights

You can, at any time:

  • View your account data from your Settings page.
  • Regenerate or set a custom API key.
  • Delete your account entirely, which removes your account record and API key.
  • Contact us to ask what data we hold about you.

7. Children's Privacy

Malvin API is not directed at children under 13, and we don't knowingly collect data from them.

8. Changes to This Policy

We may update this policy from time to time. The latest version will always be available at this page. Continued use of the API after a change implies acceptance of the update.

9. Contact Us

Questions about your data? Reach us through our Support page.

Contact Support