Privacy Policy

Last updated: September 2026

What we collect

To operate FundFacts API we store your e-mail address, a hashed password or magic-link session, hashed API keys, and a log of your API requests (ISIN, status, latency, timestamp). Payments are processed by Stripe; we store only Stripe customer and subscription identifiers, never card details.

How we use it

Request logs are used for rate limiting, usage dashboards, invoicing and abuse prevention. We do not sell personal data and do not use it for advertising.

Where it lives

Data is hosted on Supabase (AWS, eu-west-1) and Vercel. Fund data itself is not personal data.

Your rights

You can revoke API keys at any time from the dashboard and request export or deletion of your account by e-mailing hello@fundfactsapi.com.