All policies

Privacy Policy

What we collect, why we collect it, how long we keep it, and how to make us delete it.

Last updated: 21 July 2026

Draft — not yet in force. The operating entity, registered address and governing law have not been configured for this deployment, so this document does not yet name a party who can be held to it. It must be completed and reviewed by a qualified lawyer in the relevant jurisdiction before being relied on.

1. Who is responsible

the operator of ToolsXpo is the data controller for personal data processed through ToolsXpo. Data protection enquiries: privacy@toolsxpo.com.

For payments, Paddle.com Market Ltd is a separate controller. We never see or store your card number.

2. What we collect

Account data

Your email address and a hash of your password (bcrypt — we cannot read your password). If you provide a name, that too. We record the IP address used at signup, to detect people creating multiple accounts to farm free credits.

API keys

Stored only as SHA-256 hashes alongside a short non-secret prefix so you can tell your keys apart. The key itself is shown once at creation and is never recoverable — not by you, and not by us.

Usage records

For each API call we record the tool called, the credit cost, the HTTP status, the calling IP address and the timestamp. This is what your dashboard totals are built from, and it is how billing is auditable.

We do not store the contents of your API requests or the results returned. Inputs are processed in memory to produce a response and are not written to our database.

Billing data

A record of credits bought, granted, spent and expired, and an identifier linking your account to your Paddle customer record. Card details never reach us.

Cookies

A session cookie when you sign in, and an admin session cookie for staff. Both are HttpOnly and strictly necessary. See the Cookie Policy.

3. Why we process it, and on what legal basis

PurposeDataLawful basis (UK/EU GDPR)
Providing the ServiceAccount, API keys, usagePerformance of a contract
Billing and meteringUsage, credit ledgerPerformance of a contract
Service emails (receipts, low balance, renewal notices)Email addressPerformance of a contract
Preventing fraud and abuseIP addresses, signup patterns, payment outcomesLegitimate interests
Security and debuggingRequest metadata, error logsLegitimate interests
Meeting tax and accounting obligationsTransaction recordsLegal obligation

We do not use your data for advertising, we do not sell it, and we do not use the contents of your requests to train machine-learning models.

4. Who we share it with

Only the processors needed to run the Service. Each is listed, with what it can see and where, on the Subprocessors page. In summary: Cloudflare (hosting, database, storage), Paddle (payments), and an email delivery provider.

We may also disclose data where legally required, or to establish or defend legal claims. If we are ever compelled to hand over customer data, we will tell you unless legally prohibited from doing so.

5. International transfers

Our infrastructure runs on Cloudflare's global network, so data may be processed in countries outside your own, including the United States. These transfers rely on the UK/EU Standard Contractual Clauses and the providers' own transfer frameworks.

6. How long we keep it

  • Account data — until you delete your account, then removed within 30 days.
  • API usage records — 24 months, so you and we can audit historical billing.
  • Billing and credit ledger — as long as tax law requires, typically 6–7 years. These records survive account deletion because we are legally required to keep them.
  • Fraud and abuse records — up to 24 months after the account closes, so a blocked account cannot simply be recreated.

7. Your rights

Depending on where you live, you have some or all of the following rights:

  • access a copy of your personal data;
  • correct data that is wrong;
  • delete your data (subject to the retention obligations above);
  • restrict or object to processing, including processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw consent, where we relied on it; and
  • complain to your data protection authority.

California residents:you additionally have the right to know what is collected and to opt out of "sale" or "sharing" of personal information. We do neither, so there is nothing to opt out of. We will not discriminate against you for exercising any right.

To exercise a right, email privacy@toolsxpo.com from your account address. We respond within 30 days.

8. Security

Passwords are hashed with bcrypt and API keys with SHA-256; neither is recoverable from our database. Traffic is encrypted in transit. Admin access is restricted and separately authenticated. No system is perfectly secure, but a database breach alone would not expose usable API keys or passwords.

If a breach affects your data and creates a real risk to you, we will notify you and the relevant regulator as the law requires.

9. Children

The Service is not for anyone under 16. We do not knowingly collect their data; if we learn we have, we delete it.

10. Changes

We will post any update here and change the date at the top. For material changes we will notify you by email or in the dashboard.