datafloe Get a key

Legal

Privacy

Plain-language summary of the little data we collect and why. datafloe is a solo, bootstrapped project — we collect as little as we can.

What we collect

  • Your email, when you request an API key or register interest in a dataset that's being compiled. That's the only personal data we ask for.
  • Basic request metadata (e.g. IP address, timestamp) that any web service sees, used for rate-limiting and abuse prevention. Where we log usage events, the visitor is identified by a salted hash, not by storing your raw IP.

Why, and how we use it

  • To send you your API key, and occasional low-volume notes about the service (launches, breaking changes). We don't run marketing campaigns.
  • To operate and protect the API — issuing keys, enforcing the 100 calls/day limit, and blocking abuse.

We do not sell your data, and we don't use it to train machine-learning models.

How your key is stored

The API key itself is shown to you once and never stored — we keep only a one-way SHA-256 hash to recognise the key on future calls. Your email is stored once so that re-requesting a key returns the same key rather than minting a new one.

Who processes it

We use a small number of processors to run the service: Cloudflare (hosting, the API, the database, and bot protection via Turnstile) and Resend (delivering the key email). Your email is shared with these only to the extent needed to deliver the service.

Retention & your choices

We keep your email while your key is active. You can ask us to delete your email and revoke your key at any time — email legal@datafloe.dev and we'll action it.

Contact

Privacy questions, access, or deletion requests: legal@datafloe.dev. General help: support@datafloe.dev.