The controller of your personal data is:
Apistool is an application for project, task, and communication management for agencies and teams, available at app.apistool.com. As the controller, we decide on the purposes and means of processing data collected during use of the service.
When registering and using the account, we process:
If you register via Google, we receive your name, email address, and profile picture from Google.
While using the application, we process content created by you:
If you configure an email account in Apistool (any IMAP/SMTP provider — Gmail via app password, Outlook/Microsoft 365, custom servers), we process:
If you voluntarily connect a Google Calendar account, we fetch and synchronize:
A detailed description of Google data usage restrictions can be found in Section 4.
If you use AI agents or chat with Claude:
If you purchase a paid Apistool subscription, we process:
VAT invoices for buyers who are Polish VAT taxpayers are issued by Fakturownia Sp. z o.o. and automatically submitted to the Polish National e-Invoice System (KSeF) in accordance with applicable tax regulations.
| Data category | Purpose of processing | Legal basis |
|---|---|---|
| Account data (email, password, name) | Registration, authentication, provision of the service | Art. 6(1)(b) — contract |
| Tasks, projects, work time, chat | Core functionality of the application | Art. 6(1)(b) — contract |
| IMAP/SMTP email data | Provision of the email client service | Art. 6(1)(b) — contract |
| Google Calendar data | Synchronization with Google Calendar | |
| AI chat content (Anthropic) | Provision of AI agent and assistant features | Art. 6(1)(b) — contract |
| Server logs, IP addresses | Security, abuse detection, diagnostics | Art. 6(1)(f) — legitimate interest |
| Billing data and payment history | Performance of the subscription agreement, payment handling | Art. 6(1)(b) — contract |
| VAT invoices, NIP, invoice data | Issuing VAT invoices, submission to KSeF, archiving | Art. 6(1)(c) — legal obligation Polish VAT Act, KSeF Act |
| Data backups | Service continuity, protection against data loss | Art. 6(1)(f) — legitimate interest |
| Notification settings | Personalization of notification delivery | Art. 6(1)(b) — contract |
We fetch the following data and scopes from Google:
https://www.googleapis.com/auth/calendar) — calendar events; used solely to synchronize events with the calendar view and to plan tasks in Apistool. Apistool does not request other Google scopes (in particular, no Gmail API scopes).Google data commitments — Limited Use Requirements:
The use of data received from Google APIs is in accordance with the Google API Services User Data Policy, including the Limited Use requirements:
Additional commitments:
Your data may be transferred to the following categories of entities:
| Entity | Role | Data transferred | Location |
|---|---|---|---|
| VPS in the EU Controller's own infrastructure |
Database and file hosting — controller's own infrastructure | All application data | Germany (EEA) |
| Stripe Payments Europe Ltd. | Payment operator — subscription and payment card handling | Email address, billing data (name, NIP, address), customer ID. Card data is NOT visible to the controller. | Ireland (EEA) |
| Fakturownia Sp. z o.o. | Issuing VAT invoices and submitting them to KSeF | Invoice data (name / company name, NIP, address, email), invoice line items | Poland (EEA) |
| Anthropic, Inc. | AI processor — generating agent responses | Content of messages to AI agents (when you use this feature) | USA |
| Google LLC | OAuth authentication, Google Calendar API, Google Analytics 4 (marketing website statistics — consent only) | Google profile, OAuth tokens, calendar data; for GA4: an anonymized statistical identifier and IP address (after consent) | USA |
| Resend, Inc. | Delivery of system emails (account verification, password reset, booking notifications) | Email address, content of the system message | USA |
| Functional Software, Inc. (Sentry) | Application error monitoring (error tracking) | Error stack trace, URL, user identifier, browser and system information | Germany (EEA) — Frankfurt region |
| Notion Labs, Inc. | External task source — Notion synchronization (optional, opt-in OAuth) | OAuth token (stored in encrypted form), Notion database identifiers, task content (title, description, due date, status) | USA (San Francisco) — transfer based on Standard Contractual Clauses (SCC). Policy: notion.com/help/privacy |
| Doist Inc. | External task source — Todoist synchronization (optional, opt-in OAuth) | OAuth token (stored in encrypted form), Todoist project identifiers, task content | USA (Delaware) — operates from Portugal. Transfer based on Standard Contractual Clauses (SCC). Policy: todoist.com/privacy |
| Backblaze, Inc. | Offsite backups — storage of encrypted database dumps | Encrypted database dumps (AES-256, immutable write lock 14 days) | Germany (EEA) — Frankfurt |
We do not sell your personal data to third parties. The data is not shared with third parties for advertising or marketing purposes.
Most data processors (VPS, Stripe, Fakturownia, Sentry, Backblaze) are located in EEA states (Poland, Ireland, Germany). Some processors (Anthropic, Google, Resend, Notion Labs, Doist) have their registered office in the United States, which means a transfer of data outside the European Economic Area (EEA). Transfer to Notion and Doist takes place only when the User voluntarily connects a Notion or Todoist account as an external task source.
The transfer takes place on the basis of appropriate safeguards:
You may obtain information about the safeguards applied by contacting us at kontakt@apistool.com.
| Data category | Retention period |
|---|---|
| Account and profile data | Until account deletion, then permanently deleted within 30 days. |
| Tasks, projects, comments | Throughout the account's active period; after account deletion — 30 days (with the option to restore), then permanently. |
| IMAP email data (messages, folders) | Until the email account is removed from the application or the Apistool account is deleted. |
| Google OAuth token | Until Google Calendar is disconnected in settings or the account is deleted. |
| VAT invoices and invoice data | 5 years from the end of the year in which the tax obligation arose (required by the Polish VAT Act and Tax Ordinance). |
| Payment history (Stripe) | Throughout the duration of the subscription + an additional period required by tax regulations (up to 5 years). |
| Error reports (Sentry) | 90 days (automatic rotation). |
| Server logs and IP addresses | Up to 90 days. |
| Database backups | 30 days locally + 30 days offsite (immutable copies, write lock 14 days). Automatic rotation. |
| AI chat data | Throughout the account's active period; deleted together with the account. |
You may delete your account in the application settings or by sending a request to kontakt@apistool.com. Upon receipt of the request, the data will be permanently deleted within 30 days, except for data whose retention is required by law.
Providing account data (email address, password, or Google account) is voluntary but necessary to conclude the agreement and use Apistool — without this data, registration and login are not possible.
The remaining data is fully optional:
Under the GDPR (Regulation 2016/679), you have the following rights:
Send a message to kontakt@apistool.com. We will respond within 30 days of receiving the request (this period may be extended by a further 60 days for particularly complex requests — we will notify you of this).
Apistool does not apply automated decision-making or profiling within the meaning of Article 22 GDPR that would produce legal effects concerning you or similarly significantly affect you.
You have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO):
We apply the following technical and organizational measures to protect your data:
In the event that a security breach affecting your data is detected, we will inform you in accordance with GDPR requirements (Articles 33–34).
Apistool uses a minimal set of browser-side storage mechanisms:
apistool.com only — anonymous visit statistics used to improve the website. Enabled only after you give consent in the cookie banner. Until consent is given, in line with Google Consent Mode v2, no analytics cookies are set. Legal basis: consent (Art. 6(1)(a) GDPR); you may withdraw consent at any time by clearing your browser's local storage / cookies.The application (app.apistool.com) does not use tracking, advertising, or analytical cookies. The marketing website (apistool.com) uses Google Analytics 4 solely with your consent (see above). We do not use advertising cookies or behavioural profiling anywhere.
Apistool is a service aimed at professionals and businesses. It is not intended for persons under 16 years of age and we do not knowingly collect data from such persons. If you have information that a minor has provided us with data, please contact us at kontakt@apistool.com — the data will be deleted immediately.
We will inform you of significant changes:
Continued use of Apistool after the changes take effect constitutes acceptance of them. If the changes concern data processed on the basis of consent, we will ask you to give it again.
Effective date of the current version: July 12, 2026.
For all matters concerning the protection of personal data, you can contact us:
We will endeavor to respond to all inquiries within 5 business days. Formal requests concerning rights (Articles 15–22 GDPR) will be answered within the statutory 30-day period.