Short, because there is not much to say.
For each call we store the endpoint, the plan, the HTTP status, the duration and the request and response sizes. That is what produces your usage figures. We do not store the file, its name, or its content, and uploads are deleted from disk as soon as the response is written.
For an account we store the email address you gave us and a SHA-256 hash of your key. We cannot show you the key again, because we do not have it.
The web server keeps standard access logs for 14 days for abuse handling.
No advertising, no analytics scripts, no third-party trackers on this site. Your content is never used to train anything and is never shared.
Do not use the API to attack, scan or overload someone else's systems; remote fetches are restricted to public addresses for that reason. Do not use it to process material you have no right to process. Do not resell raw access as your own API without telling us — building a product on top is exactly the point, reselling the endpoints verbatim is not.
Paid plans target 99.5% monthly availability. If we miss it, the month is credited. There is no separate SLA document to read: this paragraph is it.
If the API does not do what this site says it does, ask for your money back within 30 days and you get it, no argument.
Payments are handled by the processor shown at checkout. We never see or store card details.