Privacy
Last updated 3 September 2026.
Who is responsible
Mirko Zagami is the data controller for this site. Write to privacy@apifae.com with any question about your data, or to exercise any of the rights below.
What is collected when you join the waitlist
If you join the waitlist, five things are stored:
- the email address you type;
- a one-way hash of your IP address, salted per deployment — enough to show the signup was a real request, not enough to locate you;
- the date and time you signed up;
- whether you confirmed, when you did, and how many times the confirmation link was sent to you;
- the exact wording you agreed to, stored word for word:
I agree to APIFae storing my email address so it can send me a message when the platform launches, and occasional news about it. I can unsubscribe at any time.
Alongside those, the row carries an internal identifier — which is what the unsubscribe link in an email points at — and the version number of the wording above. There is no account and no profile, and nothing in that row is connected to the pages you read here. The page-view counting described under Cookies and measurement is anonymous and cannot be linked back to your address.
Why the waitlist, and on what basis
To tell you when the APIFae platform launches, and to send occasional news about it before then. The lawful basis is your consent, GDPR Article 6(1)(a), and you may withdraw it at any time.
How you withdraw it depends on where you are. Before you confirm, ignore the confirmation email and nothing further happens — the address is deleted automatically within 30 days. To have it removed sooner, write to privacy@apifae.com. That email carries no unsubscribe link, deliberately: until you confirm there is nothing yet to unsubscribe from. After you confirm, every email we send you carries an unsubscribe link, and using it deletes your address immediately.
How long the waitlist keeps it
Until you unsubscribe. If you never click the confirmation link, the address is deleted automatically within 30 days by a scheduled job.
What is collected when you write to us
The form on the contact page stores what you send it:
- the address you write from;
- which of the two topics you chose — a question, or feedback;
- the message you type, as you typed it;
- a one-way hash of your IP address, salted per deployment, exactly as above;
- the date and time you wrote.
The row also carries an internal identifier. A copy of the message is emailed to the maintainer so it can be read and answered, which means Resend carries the message text as well as your address.
Choosing “a bug” on that page stores nothing at all: it sends you to the public issue tracker instead, because a bug report is more useful where other people can read and follow it. Nothing you type into a tracker run by GitHub is covered by this policy.
The basis is your consent, GDPR Article 6(1)(a), given by sending the form. Messages are deleted automatically after 12 months by a scheduled job; to have yours removed sooner, write to privacy@apifae.com. Writing to us does not put you on the waitlist, and the two are stored separately.
Who else sees it
Only the services needed to run the site, measure it and send the message. Each acts on instructions and none may use your address for anything else:
- Vercel — hosting and the cookieless page-view measurement described below, United States, under standard contractual clauses;
- Supabase — the database and the aggregate download counts, hosted in the EU (Ireland);
- Resend — email delivery, EU region;
- Cloudflare — the Turnstile check that keeps bots off both forms. It sees your IP address and browser, but never your email address. See their privacy policy.
Your address is never sold, never shared for advertising, and given to no one beyond the four above.
Your rights
You may request access to your data, correction of it, its erasure, restriction of its use, a portable copy, or object to its use. You may withdraw consent at any time, by the route above that matches your state. For anything else, or if you would rather not wait, write to the contact address above.
If you believe your data has been mishandled you may complain to the Office of the Information and Data Protection Commissioner, the Maltese supervisory authority.
Cookies and measurement
This site sets no cookies of its own. It does count page views, using Vercel’s cookieless analytics: each view records the page, the referring site, and a coarse country, device type and browser. There is no identifier that follows you between pages or between visits, nothing is shared with an advertising network, and no profile is built. That is why you are not being asked to agree to anything here.
Downloads are counted too. When the command-line tool is installed from apifae.com, we record which file was downloaded, which version, on what day, and through which channel — aggregate totals only. There is no address kept, no cookie, and nothing that identifies a machine or links a download to a visit or to your email address.
Turnstile may store data of its own in your browser in order to tell a person from a script; that is described in the privacy policy linked above.