Your data, handled carefully
AI API Harbor is pre-launch. Today the only personal data we hold is the email address you gave us, plus a hashed signal that stops the waitlist being abused. This page states exactly what we do with it. It describes our own commitments and is not a certification or an audit result.
What we collect
- Your email address, submitted by you when you join the waitlist.
- A short source label telling us which part of the page you signed up from.
- A salted one way hash of your IP address, used only to cap signups per device and to rate limit abuse.
- Anonymous page events (page view, signup) with no name, no account and no advertising identifiers.
What we never collect
- No passwords, because there are no accounts yet.
- No payment details. Nothing on this site takes money.
- No raw IP addresses, no precise location, no device fingerprinting.
- No third party advertising or tracking pixels anywhere on this site.
Encryption
- All traffic is served over HTTPS with TLS. Plain HTTP requests are redirected.
- Data is stored on managed Postgres infrastructure with encryption at rest enabled by the provider.
- Backups inherit the same encryption as the primary database.
IP handling
- We never write your IP address to the database. It is combined with a private server side salt and hashed with SHA-256.
- The hash is one way. It cannot be reversed back to your address, and the same address produces a different hash if the salt is rotated.
- The hash exists for one reason: stopping a single device from flooding the waitlist.
Access control
- Every database table has row level security enabled and no public read access. The waitlist cannot be listed, exported or enumerated from the browser.
- Reads and writes go through server side functions with validated input and per identity rate limits.
- Privileged database credentials exist only in the server environment and are never sent to the browser.
Email and consent
- Signup is double opt in. Your address only counts once you click the confirmation link we email you.
- Every email carries a one click unsubscribe link that works immediately, with no login and no confirmation step.
- We send a confirmation email now and a launch email later. That is the entire plan.
- We never sell, rent, share or trade your address.
Retention and deletion
- Unconfirmed signups are cleared from the list before launch, since an unconfirmed address is never emailed again beyond its confirmation link.
- Confirmed addresses are kept until you unsubscribe or ask for deletion.
- Rate limiting records are short lived and deleted automatically once their window expires.
- Email hello@aiapiharbor.com and we will delete everything associated with your address within seven days, then confirm it.
Service providers
- Hosting and edge delivery for this website.
- A managed Postgres database for the waitlist and rate limiting records.
- An email delivery provider for the confirmation and launch emails.
- Each provider receives only what it needs to do its job, and none of them are permitted to use your data for their own purposes.
Reporting a vulnerability
Found something that looks wrong? Email hello@aiapiharbor.com with the details and steps to reproduce. We read every report, respond within three working days, and will never take action against anyone reporting an issue in good faith. You can also reach us instantly through the live chat icon in the bottom right corner of any page.