Back to home

Legal

Privacy Policy

This policy explains what personal data AI API Harbor collects, why we collect it, how long we keep it, who processes it on our behalf, and the rights you have over it.

Last updated: 16 August 2026

Abstract matte gradient strip in the AI API Harbor palette

1. Who is responsible for your data

The data controller is AI API Harbor, operated by Mohd. Baquir Qureshi, a sole proprietorship located at Indore, Madhya Pradesh, India. For any privacy matter, contact hello@aiapiharbor.com. You can also reach us instantly through the live chat icon in the bottom right corner of any page.

2. What we collect

  • Email address: provided by you when you join the waitlist.
  • A salted one way hash of your IP address: used to limit the number of waitlist signups from a single network and to prevent abuse. We do not store the raw IP address of a waitlist signup.
  • Confirmation data: a random confirmation token, the timestamp of your signup and of your email confirmation, and the referral source of the page you signed up from.
  • Product analytics events: anonymous page views and interaction counts, with no advertising identifiers and no cross site tracking.
  • Support conversations: if you email us or use the chat widget, we keep the message content so we can reply.

We do not collect payment card data, we do not run advertising trackers, and we do not buy or enrich personal data from third parties.

3. Why we use it and the legal basis

  • To send you the confirmation email and launch updates you asked for. Legal basis: consent (GDPR Article 6(1)(a)), withdrawable at any time.
  • To prevent duplicate and abusive signups using hashed IP data and rate limiting. Legal basis: legitimate interests (Article 6(1)(f)) in keeping the service secure and the waitlist count honest.
  • To understand which parts of the site are useful, using aggregate analytics. Legal basis: legitimate interests in improving the product.
  • To answer your questions when you contact us. Legal basis: legitimate interests, or performance of a contract once you are a customer.

4. Double opt in and marketing

Joining the waitlist triggers one confirmation email. Your address only counts as a waitlist member once you click the confirmation link. If you never confirm, your pending record is deleted automatically. Every email we send contains a working one click unsubscribe link, and you can unsubscribe at any time from our unsubscribe page. We do not sell, rent or share your email address with third parties for their own marketing.

5. Processors we rely on

We use a small number of service providers who process data strictly on our instructions, under contract, and only for the purposes described here:

  • Application hosting and edge delivery, to serve this website.
  • Managed database and backend platform, to store waitlist records.
  • Transactional email delivery, to send confirmation and launch emails.
  • Customer chat widget, to handle support conversations you start.
  • Website translation service, to render the site in your chosen language.
  • Privacy conscious product analytics, to count anonymous page views.

Each provider is named, with what it processes and where, on our subprocessors page.

6. International transfers

We are based in India and our processors may store or process data in the European Union, the United Kingdom, the United States or other regions. Where personal data of individuals in the EEA or UK is transferred outside those regions, the transfer is covered by the European Commission Standard Contractual Clauses or an equivalent lawful transfer mechanism offered by the processor, together with appropriate technical safeguards such as encryption in transit and at rest.

7. How long we keep data

  • Confirmed waitlist records: until you unsubscribe or ask for deletion, or until 12 months after launch if you never engage.
  • Unconfirmed waitlist records: deleted automatically after 30 days.
  • Hashed IP records and rate limit counters: retained for up to 90 days for abuse prevention.
  • Analytics events: retained in aggregate form, with raw events deleted within 12 months.
  • Support emails: retained for as long as needed to handle the matter and any follow up.

8. Security

Data is encrypted in transit with TLS and encrypted at rest by our database provider. Access is restricted to the operator of the service. Waitlist reads and writes go through server side functions with row level security policies, so no client can query the underlying tables directly. IP addresses are hashed with a secret salt using a one way function and cannot be reversed by us.

9. Your rights

Depending on where you live, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to receive a portable copy, and to withdraw consent at any time without affecting processing already carried out. California residents additionally have the right to know what is collected and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined under the CCPA.

Send any request to hello@aiapiharbor.com. We respond within 30 days. If you are in the EEA or UK and are not satisfied, you have the right to lodge a complaint with your local data protection supervisory authority.

10. Children

The service is not directed at children and we do not knowingly collect their personal data. You must be 18 or older to join the waitlist or use the service. We do not knowingly collect data from anyone under 13 (United States, COPPA), under 16 (European Union and United Kingdom, where a lower national age may apply) or under 18 (India, where the DPDP Act requires verifiable parental consent for children). We do not carry out tracking, behavioural monitoring or targeted advertising directed at children under any circumstances. If you believe a child has given us data, contact us and we will delete it without delay.

11. Cookies and local storage

When you first visit the site we ask for your choice before anything optional is stored. We group storage into three categories:

Strictly necessary. Always on and exempt from consent. This covers your language preference cookie and local storage entry, security and rate limiting checks, waitlist confirmation, and storage used by the support chat widget so a conversation survives a page reload.

Analytics. Off unless you allow it. This is our own first party counter of page views and signups, stored on our servers. We do not use third party analytics products and we do not build advertising profiles.

Marketing. Off unless you allow it. Nothing in this category runs on the site today. It is reserved for future advertising or attribution tools and will only load if you opt in.

Your choice is stored in your browser for twelve months, or until you change it. You can withdraw or change consent at any time using the Cookie settings link in the footer, and withdrawing is as easy as giving consent. We do not set advertising or cross site tracking cookies.

12. India: DPDP Act 2023

We are established in India and process personal data as a Data Fiduciary under the Digital Personal Data Protection Act, 2023. We collect personal data only for the lawful purposes described in this notice, with your consent, and only the data needed for those purposes. You may withdraw consent at any time, with the same ease with which it was given, using the unsubscribe link in any email or by writing to us.

As a Data Principal you have the right to access a summary of your personal data and our processing, to correction, completion and updating, to erasure, to nominate another person to exercise your rights in the event of death or incapacity, and to a readily available grievance redressal mechanism.

Grievance Officer. Mohd. Baquir Qureshi, Grievance Officer and Data Protection Contact, Indore, Madhya Pradesh, India. Email privacy@aiapiharbor.com, phone +91 90093 50895. We acknowledge grievances within 7 days and resolve them within 30 days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.

13. United States: state privacy rights

We do not sell or share personal information, and we never have. We do not disclose personal information to third parties for monetary or other valuable consideration, and we do not share it for cross context behavioural advertising. We do not process sensitive personal information beyond what is described in this notice, and we do not use personal data for automated decision making or profiling.

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana or another state with a comprehensive privacy law, you may request to know or access the personal information we hold, request deletion, request correction, request a portable copy, and opt out of sale, sharing or targeted advertising. You will never be discriminated against for exercising these rights, and we do not offer financial incentives in exchange for personal data.

We honour the Global Privacy Control signal. If your browser or extension sends a GPC or Do Not Track header, we treat it as an opt out and keep analytics and marketing storage switched off without asking you again. To exercise any other right, email privacy@aiapiharbor.com. We verify requests by replying to the email address on record, and an authorised agent may act on your behalf with written permission.

14. Australia: Privacy Act and the APPs

For individuals in Australia we handle personal information in line with the Australian Privacy Principles. We collect only information reasonably necessary for our functions, we collect it directly from you, and we tell you why at the point of collection. You may deal with us anonymously or under a pseudonym for general enquiries, though we need an email address to place you on the waitlist.

Because our infrastructure and service providers are located outside Australia, your personal information may be disclosed to overseas recipients in India, the European Union and the United States, as listed on our subprocessors page. Before disclosing, we take reasonable steps to ensure recipients handle the information consistently with the APPs through contractual commitments. We do not use personal information for direct marketing without consent, and every marketing email carries an unsubscribe facility as required by the Spam Act 2003. You may request access or correction, or complain, by emailing privacy@aiapiharbor.com. If you are unhappy with our response you may complain to the Office of the Australian Information Commissioner.

15. EEA and UK representation

We are established in India and offer this website to visitors worldwide. Our processing of EEA and UK personal data is limited to a waitlist email address, a hashed IP value and anonymous analytics, and is occasional and low risk. We have therefore not appointed an Article 27 representative at this stage, and we will appoint one before we begin regular or large scale processing of EEA or UK personal data. Until then, all requests and supervisory authority correspondence should be sent to privacy@aiapiharbor.com and will be handled directly by us within 30 days.

16. Data breach notification

We maintain an incident response process. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by the GDPR and UK GDPR. We will notify affected individuals directly and without undue delay where the risk is high. We will also report to the Indian Computer Emergency Response Team and the Data Protection Board of India as required under the DPDP Act, and follow the Notifiable Data Breaches scheme for affected Australian individuals. US state notification requirements are followed where they apply.

17. Automated decisions and AI training

We do not make decisions about you by automated means that produce legal or similarly significant effects. We do not use your personal data, your prompts or your generated outputs to train any AI model, and we do not sell them to anyone who does. Model providers reached through our API apply their own terms to the content you submit, and those terms are linked from our Terms of Service.

18. Changes to this policy

If we make a material change, we will update the date at the top of this page and, where the change affects how we use your email, notify confirmed waitlist members by email before it takes effect.