1 Data Controller

The controller of your personal data is:

Fajny Marketing Sp. z o.o.
NIP: 8982314140 · REGON: 540165591 · KRS: 0001137411
ul. Szczytnicka 52/2, 50-382 Wrocław, Poland
Email for personal data matters: kontakt@apistool.com

Apistool is an application for project, task, and communication management for agencies and teams, available at app.apistool.com. As the controller, we decide on the purposes and means of processing data collected during use of the service.

2 What Data We Collect and Why

2.1 Account data

When registering and using the account, we process:

  • Email address and password (stored only as a secure hash) — necessary for authentication.
  • First and last name / display name — visible to collaborators in the workspace.
  • Role in the application (workspace owner, member, platform admin).
  • Registration date, last login date — for account management.

If you register via Google, we receive your name, email address, and profile picture from Google.

2.2 Task and project data

While using the application, we process content created by you:

  • Tasks: titles, descriptions, dates, priorities, assignments, time tracking.
  • Projects: names, settings, columns, templates, comments, attachments.
  • Messages in team chat and chat with AI agents.
  • Notifications and notification settings.

2.3 Email data (IMAP/SMTP)

If you configure an email account in Apistool (any IMAP/SMTP provider — Gmail via app password, Outlook/Microsoft 365, custom servers), we process:

  • Authentication credentials for the IMAP/SMTP server — the app password is stored only in encrypted form (AES-GCM). It is never transmitted to third parties.
  • Email message content, headers, attachments — fetched from your mail server only at your request and stored for the purpose of providing the service.
  • Email contacts — imported or added manually for address autocomplete.
Important: Apistool connects to your mail server directly via standard IMAP/SMTP protocols (ports 993/465 with TLS). In the case of Gmail, an app password generated in the Google panel (myaccount.google.com/apppasswords) is used, without using the Gmail API. The content of your email messages is not transferred to any external entities, nor is it used for purposes other than providing the email service in the application.

2.4 Google Calendar data

If you voluntarily connect a Google Calendar account, we fetch and synchronize:

  • Calendar events (title, time, description, status) within the scope chosen by you.
  • Google OAuth token — stored in encrypted form; used solely for operations on your calendar.

A detailed description of Google data usage restrictions can be found in Section 4.

2.5 AI data (Anthropic)

If you use AI agents or chat with Claude:

  • The content of messages sent to the agent is transmitted to the Anthropic API to generate a response.
  • You can use your own Anthropic API key (BYOK) — the key is stored in encrypted form.
  • Data sent to Anthropic is subject to Anthropic's privacy policy. Under the Anthropic API terms, requests sent via the API are not used to train models.

2.6 Billing data (subscription)

If you purchase a paid Apistool subscription, we process:

  • Billing data — first and last name or company name, NIP (optional), registered office address, country, postal code.
  • Email address — used to deliver VAT invoices, payment confirmations, and subscription notifications.
  • Stripe customer ID — an internal identifier used to link the Apistool account with the subscription at the payment operator.
  • Payment and invoice history — dates, amounts, status (paid / refunded), VAT invoice numbers.
Payment card data (number, CVV, expiry date): Apistool does NOT see or store full card data. The card is entered directly in the secure form of the payment operator Stripe (Dublin, Ireland). Apistool receives only masked information (last 4 digits, card type, expiry date) necessary to identify the payment method in the client panel.

VAT invoices for buyers who are Polish VAT taxpayers are issued by Fakturownia Sp. z o.o. and automatically submitted to the Polish National e-Invoice System (KSeF) in accordance with applicable tax regulations.

2.7 Technical data

  • IP address — used for security (detection of unauthorized access).
  • Browser agent (User-Agent) — for compatibility handling.
  • Session and authentication tokens — necessary for the application to function.
  • Server access logs — stored for a limited time for diagnostic and security purposes.

3 Legal Bases for Processing (Article 6 GDPR)

Data category Purpose of processing Legal basis
Account data (email, password, name) Registration, authentication, provision of the service Art. 6(1)(b) — contract
Tasks, projects, work time, chat Core functionality of the application Art. 6(1)(b) — contract
IMAP/SMTP email data Provision of the email client service Art. 6(1)(b) — contract
Google Calendar data Synchronization with Google Calendar Art. 6(1)(a) — consent
AI chat content (Anthropic) Provision of AI agent and assistant features Art. 6(1)(b) — contract
Server logs, IP addresses Security, abuse detection, diagnostics Art. 6(1)(f) — legitimate interest
Billing data and payment history Performance of the subscription agreement, payment handling Art. 6(1)(b) — contract
VAT invoices, NIP, invoice data Issuing VAT invoices, submission to KSeF, archiving Art. 6(1)(c) — legal obligation
Polish VAT Act, KSeF Act
Data backups Service continuity, protection against data loss Art. 6(1)(f) — legitimate interest
Notification settings Personalization of notification delivery Art. 6(1)(b) — contract
Legitimate interest: Processing data for security and backup purposes is necessary to ensure the reliability and integrity of the service. This interest does not infringe your rights and freedoms, as the data is processed solely to protect your own data and the system.

4 Google Data — Limited Use Scope

Statement on Limited Use of Google Data
Apistool uses the Google Calendar API and Google login (OAuth) solely in accordance with the Google API Services User Data Policy, including the Limited Use requirement. The Gmail mailbox is not handled via the Gmail API — we connect to it solely via the standard IMAP/SMTP protocol with an app password (see Section 2.3).

We fetch the following data and scopes from Google:

  • openid, email, profile — name, email address, profile picture; used solely for authentication (Google login) and displaying account data in the application.
  • Google Calendar (https://www.googleapis.com/auth/calendar) — calendar events; used solely to synchronize events with the calendar view and to plan tasks in Apistool. Apistool does not request other Google scopes (in particular, no Gmail API scopes).

Google data commitments — Limited Use Requirements:

The use of data received from Google APIs is in accordance with the Google API Services User Data Policy, including the Limited Use requirements:

  1. Limited use purpose. Data received from Google APIs is used SOLELY to provide or improve user-facing features within the Apistool application interface (e.g. displaying calendar events, synchronizing dates with tasks).
  2. No transfer to other applications. Apistool does NOT transfer data received from Google APIs to other applications, except as necessary to provide or improve user-facing features, comply with legal requirements, or as part of a merger/acquisition/asset sale with appropriate notice.
  3. No advertising. Apistool does NOT use Google API data to serve advertisements, including retargeting, personalized, or interest-based ads.
  4. No human access. Apistool does NOT allow humans to read user data from Google APIs, unless:
    • explicit, unambiguous user consent has been obtained,
    • it is necessary for security purposes (e.g. abuse tracking),
    • it is required by applicable law, or
    • the data (including its derivatives) is aggregated and used for internal operations.

Additional commitments:

  • Google data is not used to train artificial intelligence models (whether internal or from external providers).
  • Google OAuth tokens are stored in encrypted form (AES-GCM) and refreshed solely to maintain an active session.
  • You may revoke Apistool's access to your Google account at any time from your Google settings (myaccount.google.com/permissions) or by removing the email account in the Apistool settings.

5 Recipients and Processors

Your data may be transferred to the following categories of entities:

Entity Role Data transferred Location
VPS in the EU
Controller's own infrastructure
Database and file hosting — controller's own infrastructure All application data Germany (EEA)
Stripe Payments Europe Ltd. Payment operator — subscription and payment card handling Email address, billing data (name, NIP, address), customer ID. Card data is NOT visible to the controller. Ireland (EEA)
Fakturownia Sp. z o.o. Issuing VAT invoices and submitting them to KSeF Invoice data (name / company name, NIP, address, email), invoice line items Poland (EEA)
Anthropic, Inc. AI processor — generating agent responses Content of messages to AI agents (when you use this feature) USA
Google LLC OAuth authentication, Google Calendar API, Google Analytics 4 (marketing website statistics — consent only) Google profile, OAuth tokens, calendar data; for GA4: an anonymized statistical identifier and IP address (after consent) USA
Resend, Inc. Delivery of system emails (account verification, password reset, booking notifications) Email address, content of the system message USA
Functional Software, Inc. (Sentry) Application error monitoring (error tracking) Error stack trace, URL, user identifier, browser and system information Germany (EEA) — Frankfurt region
Notion Labs, Inc. External task source — Notion synchronization (optional, opt-in OAuth) OAuth token (stored in encrypted form), Notion database identifiers, task content (title, description, due date, status) USA (San Francisco) — transfer based on Standard Contractual Clauses (SCC). Policy: notion.com/help/privacy
Doist Inc. External task source — Todoist synchronization (optional, opt-in OAuth) OAuth token (stored in encrypted form), Todoist project identifiers, task content USA (Delaware) — operates from Portugal. Transfer based on Standard Contractual Clauses (SCC). Policy: todoist.com/privacy
Backblaze, Inc. Offsite backups — storage of encrypted database dumps Encrypted database dumps (AES-256, immutable write lock 14 days) Germany (EEA) — Frankfurt
The content of your email messages (IMAP) is not transferred to any external entities. We fetch it directly from your own mail server and store it only on our server in the EU.

We do not sell your personal data to third parties. The data is not shared with third parties for advertising or marketing purposes.

6 Transfer of Data Outside the EEA

Most data processors (VPS, Stripe, Fakturownia, Sentry, Backblaze) are located in EEA states (Poland, Ireland, Germany). Some processors (Anthropic, Google, Resend, Notion Labs, Doist) have their registered office in the United States, which means a transfer of data outside the European Economic Area (EEA). Transfer to Notion and Doist takes place only when the User voluntarily connects a Notion or Todoist account as an external task source.

The transfer takes place on the basis of appropriate safeguards:

  • Standard Contractual Clauses (SCC) approved by the European Commission — applied by Anthropic, Resend, Notion Labs, Doist, and the backup provider.
  • EU–US Data Privacy Framework (DPF) — Google LLC participates in this program, which provides an adequate level of protection.

You may obtain information about the safeguards applied by contacting us at kontakt@apistool.com.

7 How Long We Keep the Data

Data category Retention period
Account and profile data Until account deletion, then permanently deleted within 30 days.
Tasks, projects, comments Throughout the account's active period; after account deletion — 30 days (with the option to restore), then permanently.
IMAP email data (messages, folders) Until the email account is removed from the application or the Apistool account is deleted.
Google OAuth token Until Google Calendar is disconnected in settings or the account is deleted.
VAT invoices and invoice data 5 years from the end of the year in which the tax obligation arose (required by the Polish VAT Act and Tax Ordinance).
Payment history (Stripe) Throughout the duration of the subscription + an additional period required by tax regulations (up to 5 years).
Error reports (Sentry) 90 days (automatic rotation).
Server logs and IP addresses Up to 90 days.
Database backups 30 days locally + 30 days offsite (immutable copies, write lock 14 days). Automatic rotation.
AI chat data Throughout the account's active period; deleted together with the account.

Account deletion

You may delete your account in the application settings or by sending a request to kontakt@apistool.com. Upon receipt of the request, the data will be permanently deleted within 30 days, except for data whose retention is required by law.

Voluntary provision of data (Article 13(2)(e) GDPR)

Providing account data (email address, password, or Google account) is voluntary but necessary to conclude the agreement and use Apistool — without this data, registration and login are not possible.

The remaining data is fully optional:

  • Google Calendar — no connection means no Google calendar synchronization; the other application features work normally.
  • IMAP/SMTP email account — no configuration means no access to the email client; the other features work normally.
  • AI features (agents, Claude chat) — no Anthropic key (BYOK) means no access to AI features; the other features work normally.
  • Paid subscription — without providing billing data (NIP, address) and purchasing a subscription with the payment operator, only the 14-day trial period of the Studio plan is available.

8 Your Rights

Under the GDPR (Regulation 2016/679), you have the following rights:

Right of access (Art. 15)
You can obtain confirmation of whether we process your data, as well as a copy of that data.
Right to rectification (Art. 16)
You can request the correction of inaccurate data or the completion of incomplete data.
Right to erasure (Art. 17)
"Right to be forgotten" — you may request deletion of data when it is no longer necessary.
Right to restriction (Art. 18)
You may request restriction of processing in specific situations.
Right to portability (Art. 20)
You may receive your data in a structured, machine-readable format.
Right to object (Art. 21)
You may object to processing based on legitimate interest.
Withdrawal of consent
If processing is based on consent, you may withdraw it at any time (e.g. disconnect Google Calendar in settings).
Right to lodge a complaint
You have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (PUODO).

How to exercise your rights

Send a message to kontakt@apistool.com. We will respond within 30 days of receiving the request (this period may be extended by a further 60 days for particularly complex requests — we will notify you of this).

Automated decision-making and profiling (Article 13(2)(f) GDPR)

Apistool does not apply automated decision-making or profiling within the meaning of Article 22 GDPR that would produce legal effects concerning you or similarly significantly affect you.

Supervisory authority — PUODO

You have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO):

Personal Data Protection Office
ul. Stawki 2, 00-193 Warszawa, Poland
Phone: +48 22 531 03 00
Website: uodo.gov.pl
Email: kancelaria@uodo.gov.pl

9 Security

We apply the following technical and organizational measures to protect your data:

  • Transmission encryption — all communication takes place via HTTPS/TLS.
  • Encryption of sensitive data — passwords for email accounts and API keys are stored in encrypted form (AES-GCM).
  • User passwords — stored only as a cryptographic hash (bcrypt).
  • Data isolation (Row Level Security) — each user has access only to their own data; enforced at the database level.
  • Backups — automatic daily database backups retained for 30 days.
  • Data in the European Union — the main database and files are stored on a server in the EU.

In the event that a security breach affecting your data is detected, we will inform you in accordance with GDPR requirements (Articles 33–34).

11 Privacy Policy Changes

We will inform you of significant changes:

  • by email to the address provided during registration, or
  • by an explicit notification in the application at your next login.

Continued use of Apistool after the changes take effect constitutes acceptance of them. If the changes concern data processed on the basis of consent, we will ask you to give it again.

Effective date of the current version: July 12, 2026.

12 Contact

For all matters concerning the protection of personal data, you can contact us:

Fajny Marketing Sp. z o.o.
NIP: 8982314140 · REGON: 540165591 · KRS: 0001137411
ul. Szczytnicka 52/2, 50-382 Wrocław, Poland

We will endeavor to respond to all inquiries within 5 business days. Formal requests concerning rights (Articles 15–22 GDPR) will be answered within the statutory 30-day period.