What we process
- Account. When you sign in via the Astraea login hub, we keep your account identity (email, name, avatar), your plan, and your Paddle customer link so the product can serve you.
- Usage records. For each API request we store a hash of your API key (raw keys are never stored), the endpoint, the outcome, the duration, and a timestamp. This is what powers quotas and the usage report.
- Cache. Rendered bytes are cached with their render parameters and expire automatically (default 24 hours, at most 7 days, or disabled per request).
- Payments. Billing is handled by Paddle as merchant of record. We never see or store your card details.
- This website. Public pages set no cookies and run no analytics. Signed-in pages (profile, checkout) recognize you through the login hub's session cookie.
Why we process it
To operate the service, enforce quotas, report your usage back to you, prevent abuse, and comply with legal obligations.
Sharing
We share data only with our infrastructure providers — Cloudflare (hosting) and Paddle (billing) — and when required by law. We do not sell personal data.
Retention
Usage records are kept while needed for quotas, reporting, and operations. Cached renders expire on their own schedule as described above.
Your rights
You may request a copy or deletion of your usage data at any time by emailing admin@astraeatech.dev.
Security
Traffic is encrypted in transit (TLS). API keys are stored only as hashes, and production data access follows least privilege.
Changes
We will post any changes to this policy on this page.