Privacy Policy
This policy explains what data BG-API (operated by Sikasio) collects, why, and what happens to it. The short version: we collect the minimum needed to run an image-processing API, we don't sell your data, and the images you process are not kept.
1. What we collect
- Account data — your email address and a salted hash of your password. We never store the password itself.
- API usage logs — per-request metadata (API key, IP address, endpoint, response status, timing, request size) kept for up to 30 days for abuse prevention, quota accounting, and debugging.
- Uploaded images — processed transiently in memory to produce your result and not retained afterwards. If you request a hosted result URL, the result image is stored temporarily and automatically deleted after 24 hours.
- Billing data — payments for paid plans are handled entirely by Polar (polar.sh) as merchant of record. We never see or store your card details; we receive only your subscription status and plan.
2. What we use it for
To provide the service (authenticate keys, enforce quotas and rate limits), to send transactional email (verification codes, password resets, account notices), to prevent abuse, and to comply with legal obligations. We do not send marketing email without your consent, and we do not sell or rent your personal data to anyone.
3. Cookies
The customer portal sets a single session cookie so you stay signed in. There are no advertising, analytics, or third-party tracking cookies.
4. Sharing
We share data only with the processors needed to run the service: our hosting provider (servers in the EU), our transactional-email provider (to deliver account emails), and Polar for payments. Each receives only what it needs. We may disclose data if legally required.
5. Retention
- Account data — kept while your account exists.
- API usage logs — deleted after at most 30 days.
- Hosted result images — deleted after 24 hours.
- Uploaded source images — not retained after processing.
6. Your rights
You can ask us to export or delete the personal data we hold about you, or delete your account entirely, by emailing support@sikasio.com from your account address. We answer within 30 days. Depending on where you live you may have additional statutory rights (such as under the GDPR), which we honor.
7. Security
All traffic is encrypted in transit (TLS). Passwords are hashed with a memory-hard algorithm, API keys are stored only as hashes, and access to production systems is restricted. No system is perfectly secure — if a breach affects your data we will notify you.
8. Changes
We may update this policy as the service evolves. Material changes will be announced by email or on the site, with the "Last updated" date above revised.
9. Contact
Privacy questions and data requests: support@sikasio.com.