Privacy Policy
Last updated: 5 October 2026
This Privacy Policy explains how API Test Generator ("we", "us"), operated by Arsen Hambardzumyan, handles your information. We aim to collect as little as possible.
1. Data we collect
- Specifications you submit: the OpenAPI, Swagger or Postman content you paste or fetch by URL. It is processed in memory to produce your tests and is not stored. Generation-log entries made before 4 October 2026 also contained the submitted spec; those entries are deleted automatically 30 days after they were created.
- Generation history (signed-in accounts): the title, runner, endpoint count and generated test code of your last 30 generations, so you can reopen them. Not the spec itself.
- Account data: when you sign in with GitHub we receive and store your email address, name, avatar URL and GitHub user ID. If you own a Team plan, we store the email addresses of the teammates you add.
- Billing data: if you subscribe, your payment details are collected and processed by Lemon Squeezy (see below). We store your subscription status, plan and email, never card numbers.
- Trial without sign-up: to limit visitors to 2 free tries a day we store a keyed hash of your IP address with a daily count, not the IP address itself.
- Usage counters: daily totals such as page views, generations, sign-ins and checkout clicks. They contain no personal data.
- Product analytics (PostHog, EU): pages viewed, the referring site and campaign tags, clicks, the events listed above, browser and device type, and the country derived from your IP address. Without your consent we set no cookies and store nothing in your browser, so visits are not linked to each other. If you press "Allow", a cookie/local-storage identifier links your visits and anonymous session recordings are made; form fields, specs, generated code, run results and keys are always hidden in recordings. If you are signed in, events carry your internal account number, never your email. You can change your choice by clearing this site's storage.
- Technical logs: our hosting providers log requests (IP address, time, browser type) for security, rate limiting and reliability.
- Running checks against your API (Pro): we store the host names you verified for your account. The auth value you enter for a run is used for that run only and is never stored or logged; the responses of your API are shown to you and not stored.
- Shared test pages: we sometimes generate tests from a company's publicly published API spec and share them at an unlisted link (apitestgen.dev/d/…). Only the public spec URL, its title and the generated code are stored. Email support@apitestgen.dev to have a page removed.
2. How we use it
- To provide the Service and return your generated tests.
- To operate billing, prevent abuse, and maintain security.
- To improve the Service. We do not sell your data.
3. Third parties
- Lemon Squeezy — our Merchant of Record, processes payments and related personal/billing data. See Lemon Squeezy's Privacy Policy.
- Render (application hosting, Frankfurt), Neon (database, United States) and Cloudflare (DNS and network delivery) process data solely to run the Service.
- GitHub handles sign-in; we receive only the profile data listed above.
- PostHog (EU Cloud) processes the product analytics described above, through our own domain.
4. Data retention
Generation history and account data are kept while your account exists and deleted on request. Generation-log entries are deleted after 30 days. Trial counters are kept per day. Hosting logs are kept by our providers for a limited period for security.
5. Your rights (GDPR & others)
If you are in the EU/UK or a jurisdiction with similar laws, you have the right to access, correct, delete, or export your personal data, and to object to or restrict processing. You can download all your data or delete your account yourself on the Account page; for anything else, email support@apitestgen.dev.
6. Cookies
We use one essential cookie to keep you signed in. Analytics cookies and session recordings are used only if you press "Allow" in the banner; your choice is remembered in your browser. We do not use advertising trackers.
7. Security
We apply reasonable technical measures (encryption in transit, access controls) to protect your data. No method is 100% secure, but we work to minimize risk.
8. Changes & contact
We may update this policy; changes are reflected by the date above. Questions or requests: support@apitestgen.dev.