Privacy Policy

Version 2026-08-03 · Effective 3 August 2026

How we collect, use, share, and protect your personal data when you use Shingou.

1. Data controller

The controller of your personal data is Adolfo Gastalver Rubio, Sole trader (autónomo), NIF 05294386Q, Carrer de la Igualtat 67, 6-2, 08902 Barcelona, Spain. For any privacy matter, contact contact@shingou.io. This policy is provided under the EU General Data Protection Regulation (GDPR) and Spain’s Organic Law 3/2018 (LOPDGDD).

2. What we collect

  • Account data: your email address (used for passwordless sign-in) and your plan.
  • API-key metadata: a key name, prefix, creation and last-used timestamps, and a hash of the key (never the key itself).
  • Usage data: API request counts and technical logs, including IP address and request metadata, kept for security, abuse prevention, and quota metering.
  • Billing data: if you subscribe to a paid plan, a customer identifier and invoice records. Card details are collected and processed directly by Stripe; we do not store your full card number.
  • Signup attribution: if you arrive through a link we published, the standard campaign tags in that link (utm_source, utm_medium, utm_campaign) and the referring site's domain name are recorded once, when your account is created, so we can tell which channels bring people here. Domain only, never the page you came from. Nothing is transmitted unless you actually sign up.
  • Site analytics: aggregate page views and referring domains via Cloudflare Web Analytics, which sets no cookie and assigns no identifier to you. It cannot follow you across sites and cannot be tied back to your account.
  • Documentation readership: for a short list of public pages (our API docs, research page, integrations page, llms.txt and the MCP endpoint) we keep a daily counter of how many times each was fetched, grouped by a coarse label for the software that fetched it, such as "browser" or the name of a published AI crawler. We keep the counter and the label only. No IP address, no account, no session, no identifier, and never the full browser string. The purpose is narrow: to find out whether AI crawlers and agents actually read the files we publish for them.
  • Communications: messages you send us (e.g. support email).

3. Why we use it, and our lawful bases

  • To provide the Service (accounts, authentication, API access, billing): performance of a contract.
  • Security, abuse prevention, rate limiting, and service improvement: our legitimate interests in running a safe, reliable service.
  • Accounting and tax records: compliance with a legal obligation.
  • Any non-essential cookies or optional communications: your consent, which you may withdraw at any time.

4. Who we share it with (processors)

We do not sell your personal data. We share it with service providers who process it on our behalf under data-processing agreements:

  • Supabase: authentication and database hosting.
  • Resend: delivery of the sign-in link emails we send you.
  • Google Workspace: the mailbox that receives email you send us, including data-protection requests.
  • Stripe: payment processing and invoicing.
  • Vercel: web application hosting and delivery.
  • Cloudflare: DNS, network security, and content delivery.
  • GitHub: hosting of our public, append-only hash-commitment log (which contains no personal data).

We may also disclose data where required by law or to protect our rights.

5. International transfers

Some processors are located outside the European Economic Area (for example, in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.

6. How long we keep it

We keep account and usage data for as long as your account is active and for a reasonable period afterwards. We retain billing and invoicing records for the period required by Spanish tax and commercial law. Usage records that include an IP address are deleted after 90 days. Aggregate counters that identify nobody, such as daily request totals, are kept indefinitely. When data is no longer needed, we delete or anonymise it.

7. Your rights

You have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability, as provided by the GDPR. Where processing is based on consent, you may withdraw it at any time without affecting prior processing. To exercise any right, email contact@shingou.io. You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or your local supervisory authority.

8. Cookies

We use only cookies that are strictly necessary for the Service to work, chiefly a session cookie to keep you signed in, and functional cookies set by Stripe and Cloudflare for payment security and network protection. Because these are essential, they do not require consent. One further short-lived cookie is set only when you ask for a sign-in link: it carries the campaign tag described in section 2 across the magic-link round trip and expires after 30 minutes. Our site analytics are cookieless and set no identifier. We do not use advertising cookies. If we introduce tracking or other non-essential cookies in future, we will ask for your consent first and update this policy.

9. Security

We apply reasonable technical and organisational measures to protect your data, including encryption in transit, hashing of API keys, and access controls. No system is perfectly secure, so we cannot guarantee absolute security.

10. Changes

We may update this policy; the version and effective date appear at the top of this page. For material changes we will provide reasonable notice.

11. Contact

Privacy questions or requests: contact@shingou.io.