Privacy policy
Effective September 2026. Controller: Vembar LLC, support@vembar.io.
What we collect
Account data: your email address, name and password hash. Usage data: for each API request, the time, endpoint, ticker, status, latency and the key used, plus a hashed form of the client address, kept for up to 400 days to operate quotas, the usage dashboard and abuse prevention. Billing: handled by Stripe; we store your Stripe customer identifier and plan, never card numbers. Website: server logs with client addresses for security, kept for 30 days. We use no third party analytics or advertising trackers.
Why
To provide and bill the Service, to enforce plan limits, to detect abuse, and to send transactional email such as key confirmations, quota notices and receipts. We do not sell personal data and we do not send marketing email without consent.
Processors
Amazon Web Services (hosting, United States), Stripe (payments) and SendGrid (transactional email). Each processes data only on our instructions.
Your rights
You may access, correct or delete your account data at any time from the account page or by writing to us. Deleting an account revokes its keys and removes personal data within 30 days, except records we must keep for accounting.
Security
Transport is encrypted, keys are stored hashed, databases are authenticated and not reachable from the internet, and access to production is restricted to named administrators.
Changes
Material changes are announced on this page and by email to account holders before they take effect.