Privacy Policy
1. Who We Are
APIFlow Studio is an open-source, browser-based API testing client, synthetic mock server, and webhook testing tool created by Yash Padaliya. The live version is hosted at apiflowstudio.onrender.com. Source code is available on GitHub under the MIT License.
2. Your Workspace Data
All collections, environments, mock scenarios, request history, and UI preferences you create are stored exclusively on your own device using:
- IndexedDB — your main workspace database (
APIFlowDB) - localStorage — small UI state values (active collection, active endpoint, onboarding seed flag)
This data never touches our servers. Clearing your browser data will permanently delete it. We have no way to recover it for you.
3. The Live Request Proxy
When you click Send with a real endpoint (Live mode), your HTTP request is routed through our proxy at apiflowstudio.onrender.com/proxy?url=... to bypass browser CORS restrictions. You should know:
- The target URL is transmitted in the query string (
/proxy?url=...) and forwarded to the destination along with your headers (including anyAuthorizationheader or API key you add) and request body. - Platform Access Logs: Because the target URL is passed as a query parameter, the full destination URL and any query parameters embedded in it (such as query-based API keys or tokens) will appear in standard HTTP access logs maintained by Render (hosting provider) and Cloudflare (CDN/proxy). We strongly advise passing sensitive API credentials in HTTP headers (e.g.
Authorization) rather than query parameters when using the public proxy. - We do not intentionally log, store, or inspect request bodies, headers, or response payloads on our application server. Requests are processed in-memory and discarded immediately after the response is returned.
- Render and Cloudflare retain standard platform-level HTTP access logs (client IP address, full request URL, timestamp) per Render's Privacy Policy and Cloudflare's Privacy Policy.
We strongly recommend not sending production secrets, credentials, or sensitive data through any public proxy. Use the self-hosted Docker version for sensitive workloads.
4. Analytics & Telemetry
We run a lightweight, privacy-first, server-side analytics system with no third-party scripts. Here is exactly what it does and does not collect:
- What we count: aggregate page views, approximate traffic source (Google / GitHub / Direct / etc.), device type category (Desktop / Mobile / Bot), country code (from Cloudflare's
CF-IPCountryheader — a two-letter country code, not a precise location), and aggregate feature usage events (proxy requests sent, exports, code copies). - No raw IP storage: Raw IP addresses are never stored in memory or written to disk. To de-duplicate visitor counts and measure active sessions without storing personal identifiers, our server computes a one-way cryptographic hash (
SHA-256(IP + Salt)) using an ephemeral, randomly generated salt that resets every time the server restarts. Active sessions expire from memory after 5 minutes. - IP Masking: In the ephemeral recent-visits log (capped at 100 entries, memory-only), IP addresses are stripped of identifiable segments: for IPv4, the last two octets are masked (e.g.
192.168.***.***); for IPv6, only the first 3 hextets (48-bit network prefix) are retained while the remaining host identifier bits are masked (e.g.2001:db8:85a3:*:*:*:*). - User-Agent: Used solely to classify your device as Desktop, Mobile, Tablet, or Bot. The raw User-Agent string is never stored; only the derived category is kept.
- What we never do: track individual users across sessions, build profiles, use browser fingerprinting, set tracking cookies, or share any telemetry data with third parties.
All analytics data lives in server memory only and is permanently cleared each time Render's free-tier server restarts (typically every few hours or after periods of inactivity).
5. Cookies
We do not set any tracking cookies. The only cookie that may be set is a short-lived session cookie used for the /stats admin dashboard, which is accessible only with an admin key. Cloudflare may set its own cookies (__cf_bm, cf_clearance) for bot-mitigation purposes; these are governed by Cloudflare's Privacy Policy.
6. Third-Party Services
| Service | Purpose | Their Policy |
|---|---|---|
| Google Fonts | Loads Inter (legal & marketing pages) and JetBrains Mono (code editor workspace) | Google Privacy |
| Cloudflare | CDN, DDoS protection, DNSSEC | Cloudflare Privacy |
| Render | Hosts the Express proxy server | Render Privacy |
7. Self-Hosting
If you run APIFlow Studio via Docker on your own infrastructure, zero data is sent to our servers. You control all data completely. See the GitHub repository for Docker setup instructions.
8. GDPR & Your Rights
Because all telemetry is anonymised, masked, or cryptographically hashed in memory, we hold no personal data beyond what is described above. If you have any questions or privacy concerns, please contact us via the methods in section 11 and we will respond promptly.
9. Children's Privacy
APIFlow Studio is a developer tool not directed at children. We do not knowingly collect any data from individuals under 16 (the EU GDPR threshold) or under 13 (the US COPPA threshold).
10. Changes to This Policy
If we materially change this policy — particularly around proxy logging or analytics — we will update this page and the "Last updated" date above. We recommend checking this page periodically if you use the Live Request proxy with sensitive endpoints.
11. Contact
Privacy questions? Reach us at:
- Email: yashpadaliya2@gmail.com
- GitHub Issues: github.com/yashpadaliya08/apiflow/issues
- LinkedIn: linkedin.com/in/padaliya-yash