Privacy Policy
Last updated 2026-08-24
This policy describes what personal data GeoAPI collects, why, how long it is kept, and who else processes it. Every retention period stated below is enforced by an automated job that runs against this service's database — they are not intentions.
Who we are
GeoAPI is operated by an individual, not a company, resident in Spain. That operator is the controller of the personal data described here and decides why and how it is processed.
You can reach the operator at brscimen@gmail.com. That address is the route for every request described under your rights, and for any other question about your data.
What we collect and why
There is no optional profile data and no tracking of your activity across other sites. Every item below exists because the service cannot work, stay secure, or be billed without it.
- Your email address and a hash of your password. These are what an account is. The email is also how verification, password resets and usage alerts reach you. We store a one-way hash of your password, never the password itself. Basis: performing the contract you enter into by creating an account.
- Your API keys and their usage counters. We store a hash of each key, not the key, along with per-day request counts by endpoint and a per-account monthly total. These are what enforce your plan's quota and what the dashboard shows you. Basis: performing the contract.
- Login attempts, including the email tried and the IP address it came from. Recorded for every attempt, successful or not, including attempts using an email that has no account here. This is how repeated failed logins are throttled. Basis: our legitimate interest in defending accounts against password-guessing attacks.
- Which onboarding stages your account reached. Signed up, verified, created a key, made a first call, upgraded — five possible records, with a timestamp each. This is first-party product analytics: it tells the operator where new users get stuck. It is not shared with anyone and it drives no advertising. Basis: our legitimate interest in understanding and improving the product.
- Billing identifiers. If you subscribe to a paid plan, we store the identifiers our payment provider assigns to you and your subscription, so its records and ours describe the same customer. We never receive or store your card details. Basis: performing the contract.
- Server logs and operational telemetry. Described in full in the next section, because they behave differently from everything above. Basis: our legitimate interest in operating and securing the service.
IP addresses
The IP address your requests arrive from is recorded in this service's server logs and is attached to its operational telemetry. That telemetry is exported to a third-party observability provider, which means your request IP address leaves this service's own infrastructure and is processed on systems the operator does not run. We are stating this plainly rather than burying it: it is the one place where an address you did not choose to submit is handed to someone else. The provider processes it on the operator's instructions, for the purpose of keeping this service running and diagnosing faults, and retains it under its own schedule — see retention below.
Separately, an IP address you submit to the IP lookup endpoints is a query, not a record about you. It is matched against a geolocation dataset to produce the country, city, coordinates and time zone in the response, and it is not stored: it appears in the request log line like any other request path, and nowhere else. Looking up an address here creates no profile of it and no history of having looked it up.
Retention
| Data | Why we keep it | How long |
|---|---|---|
| Account record and API keys | You have an account | until you delete your account |
| Request usage counters | Quota enforcement and your usage history | 13 months |
| Login attempts (email and IP) | Brute-force defence | 30 days |
| Expired password-reset tokens | Answering questions about a reset that did not arrive | 30 days |
| Onboarding stage records | First-party product analytics | until you delete your account |
| Payment-provider event records | Not processing the same billing event twice | 90 days |
| Sessions | Keeping you signed in | 30 days, and destroyed when you log out or delete your account |
| Server logs (including request IP) | Operations, fault diagnosis, security | a rolling window bounded by log rotation, typically days |
| Telemetry (including request IP) | Operations, fault diagnosis, security | the observability provider's own retention period |
The periods in the third column are enforced by an automated job that deletes expired rows on a schedule, not by intention and not on request. Server logs are bounded by size rather than by a fixed number of days — each container keeps at most 10 MB across three rotated files, so the elapsed window that represents moves with traffic. Telemetry retention is set by the observability provider and governed by its policy, not by this one.
Who else processes your data
Your data is not sold, and it is not shared for anyone's advertising. It reaches the following categories of provider, each processing it only to deliver the function named:
- The payment provider (Stripe). Subscriptions, checkout and invoicing. Card details go directly to Stripe and are never received here.
- The transactional email provider. Delivering verification, password-reset and usage-alert emails to your address.
- The observability provider. Operational telemetry, which includes your request IP address, as described above.
- The managed database provider. Hosting the database in which everything above is stored, and its backups.
- The server provider. Running the application itself, and holding its server logs on disk.
- The DNS provider. Resolving this service's domain names.
These providers run in regions that may be outside Spain, so your data may be processed outside it. Where that is the case, the transfer relies on the safeguards in the contract between the operator and that provider. If you want to know the current region and safeguard for a specific provider, ask at brscimen@gmail.com — this list is written by category so that changing a provider's region does not make it untrue, but the answer for any given day is a question we will answer.
Your rights
Every right below is granted to every user, wherever you live. There is no separate section for one region: one policy, one set of rights. Each one names how to exercise it, because a right with no stated mechanism is not a right.
- Access. Email brscimen@gmail.com from your account address and we will send you a copy of the personal data held about you within 30 days.
- Portability. The same request, answered in the same 30 days, in a machine-readable format. The exportable set is your account record, your API-key metadata (names and creation dates — never the key values, which we cannot recover), your usage counters, and your onboarding stages. This is a manual process today, not a self-serve export.
- Rectification. Your email address is the only free-text personal data we hold, and correcting it is a reply to the same address. Nothing else about you is entered by hand.
- Erasure. Delete your account yourself, at any time, from your account settings. It takes effect immediately and needs no request and no reason — see what deletion does.
- Restriction. Email brscimen@gmail.com and we will suspend processing while a dispute about accuracy or legitimate interests is resolved, answering within 30 days.
- Objection. You may object to the processing we do on the basis of legitimate interests — the onboarding-stage records, and the operational logging and telemetry. Email the same address. Note that brute-force defence and request logging cannot be switched off for one account without switching off the security of every account, so an objection there may be answered by explaining that balance rather than by stopping.
What deletion does
Deleting your account is immediate and is never blocked on billing state. It revokes every API key, destroys every active session, cancels any active subscription immediately with no refund of the remaining paid period, and erases your personal data: your email address, your password hash, your keys, your usage counters, your login attempts and your onboarding records.
One record survives, and it contains no personal data: a reference linking the deleted account to the customer record at our payment provider. It exists so that a billing message arriving after deletion resolves to a known, deleted customer instead of being retried against nothing. It holds no email address, no name and no usage.
Invoices, charges and tax records are held by the payment provider as an independent controller, under legal obligations of its own that this service cannot waive on your behalf. This service stores no invoices, no charges and no tax records — deleting your account here does not and cannot reach the provider's financial records. To ask about those, contact the payment provider directly.
Automated decision-making
There is none. Rate limiting and quota enforcement are deterministic threshold rules — a request count is compared against your plan's published limit — with no profiling, no scoring and no legal or similarly significant effect on you. Nothing here builds a model of you or predicts anything about you.
Complaints
If you think your data has been handled wrongly, please raise it at brscimen@gmail.com first — it is usually the fastest way to fix it. You also have the right to complain to a data protection supervisory authority without contacting us at all: the authority in Spain, where the operator is established, or the one in your own country of residence.
Changes to this policy
This policy may change. Material changes will be announced and the "Last updated" date at the top of this page will change with them. Because the retention periods above are checked against the code that enforces them, a change to one is a change to both.