Legal
Privacy policy
Last updated 1 October 2026. Published by the ProspectAPIs team.
This policy explains what we collect when you use ProspectAPIs, why, and what you can ask us to do with it.
What we collect
- Account details: your email address and sign-in method. Passwords are handled by our authentication provider and never stored by us in readable form.
- API keys: stored as a one-way hash plus a short prefix so you can tell them apart. We cannot show a key again after it is created.
- Usage records: for each call, the endpoint, status code, records billed, credits used, the key used and the time. These power your usage history and billing.
- Research inputs and results: the identifier, context and purpose you send to the research API, and the brief we return, kept so you can read the job again.
- Payments: our payment processor collects your card and billing details. We receive the payment result, the amount and a customer reference, never your full card number.
- Feedback: what you send through the feedback endpoint, delivered to the team.
Why we use it
- To run your account, authenticate calls and bill them correctly.
- To keep the service secure and to investigate abuse of it.
- To answer you when you contact us and to fix what you report.
We do not sell personal data and we do not use your research inputs to build products for anyone else.
Who processes it
- An authentication and database provider that hosts account and usage data.
- A payment processor for card payments and invoices.
- A language model provider that writes research briefs from the sources gathered for each job, including any context you send.
- Hosting providers for the website and the API.
- Google Analytics, for website traffic measurement, only with your consent where consent is required.
People in the data
Funding records and research briefs can name founders, executives and investors as they appear on public pages, such as a company's own team page or a press announcement. We do not buy people data and we do not scrape LinkedIn. If you are named and want a correction or removal, tell us and we will act on it.
In your browser
The site stores your sign-in session, your theme choice and your analytics choice in your browser's local storage. We do not use advertising cookies.
Analytics
We use Google Analytics 4 to see which pages bring developers to the API and where sign-up or checkout fails. It records pages viewed, the referring site, an approximate location, device and browser type, and events such as signing up or starting a checkout. It never receives your email address, API keys or card details.
In the EEA, the UK and Switzerland, nothing loads until you accept. Elsewhere, analytics runs by default and you can opt out at any time: accepting (or that default) sets the _ga and _ga_<id> cookies, which Google keeps for up to 2 years by default; declining stops every send and removes them. Analytics data is kept for 14 months. Google Signals and ad personalisation are off.
You can change your choice at any time: .
Retention and your rights
We keep account and billing records for as long as your account is open and as long as tax law requires after that. You can ask for a copy of your data, a correction, or deletion of your account.
Contact
For correction or removal requests and legal notices, email emma@prospectapis.com.
Building on ProspectAPIs? Create a free account, or read the API docs first.