Privacy Policy

Last updated: October 7, 2026  ·  Effective immediately

Short version: Your workspace data (collections, environments, mock scenarios, request history) never leaves your browser. Only Live Request calls pass through our proxy server so we can bypass browser CORS restrictions. We collect no tracking cookies, and no personally identifiable information is stored beyond the anonymised, in-memory page-view counts described below.

1. Who We Are

APIFlow Studio is an open-source, browser-based API testing client, synthetic mock server, and webhook testing tool created by Yash Padaliya. The live version is hosted at apiflowstudio.onrender.com. Source code is available on GitHub under the MIT License.

2. Your Workspace Data

All collections, environments, mock scenarios, request history, and UI preferences you create are stored exclusively on your own device using:

This data never touches our servers. Clearing your browser data will permanently delete it. We have no way to recover it for you.

3. The Live Request Proxy

When you click Send with a real endpoint (Live mode), your HTTP request is routed through our proxy at apiflowstudio.onrender.com/proxy?url=... to bypass browser CORS restrictions. You should know:

We strongly recommend not sending production secrets, credentials, or sensitive data through any public proxy. Use the self-hosted Docker version for sensitive workloads.

4. Analytics & Telemetry

We run a lightweight, privacy-first, server-side analytics system with no third-party scripts. Here is exactly what it does and does not collect:

All analytics data lives in server memory only and is permanently cleared each time Render's free-tier server restarts (typically every few hours or after periods of inactivity).

5. Cookies

We do not set any tracking cookies. The only cookie that may be set is a short-lived session cookie used for the /stats admin dashboard, which is accessible only with an admin key. Cloudflare may set its own cookies (__cf_bm, cf_clearance) for bot-mitigation purposes; these are governed by Cloudflare's Privacy Policy.

6. Third-Party Services

Service Purpose Their Policy
Google Fonts Loads Inter (legal & marketing pages) and JetBrains Mono (code editor workspace) Google Privacy
Cloudflare CDN, DDoS protection, DNSSEC Cloudflare Privacy
Render Hosts the Express proxy server Render Privacy

7. Self-Hosting

If you run APIFlow Studio via Docker on your own infrastructure, zero data is sent to our servers. You control all data completely. See the GitHub repository for Docker setup instructions.

8. GDPR & Your Rights

Because all telemetry is anonymised, masked, or cryptographically hashed in memory, we hold no personal data beyond what is described above. If you have any questions or privacy concerns, please contact us via the methods in section 11 and we will respond promptly.

9. Children's Privacy

APIFlow Studio is a developer tool not directed at children. We do not knowingly collect any data from individuals under 16 (the EU GDPR threshold) or under 13 (the US COPPA threshold).

10. Changes to This Policy

If we materially change this policy — particularly around proxy logging or analytics — we will update this page and the "Last updated" date above. We recommend checking this page periodically if you use the Live Request proxy with sensitive endpoints.

11. Contact

Privacy questions? Reach us at: