Privacy Policy

Last updated 2026-08-24

This policy describes what personal data GeoAPI collects, why, how long it is kept, and who else processes it. Every retention period stated below is enforced by an automated job that runs against this service's database — they are not intentions.

Who we are

GeoAPI is operated by an individual, not a company, resident in Spain. That operator is the controller of the personal data described here and decides why and how it is processed.

You can reach the operator at brscimen@gmail.com. That address is the route for every request described under your rights, and for any other question about your data.

What we collect and why

There is no optional profile data and no tracking of your activity across other sites. Every item below exists because the service cannot work, stay secure, or be billed without it.

IP addresses

The IP address your requests arrive from is recorded in this service's server logs and is attached to its operational telemetry. That telemetry is exported to a third-party observability provider, which means your request IP address leaves this service's own infrastructure and is processed on systems the operator does not run. We are stating this plainly rather than burying it: it is the one place where an address you did not choose to submit is handed to someone else. The provider processes it on the operator's instructions, for the purpose of keeping this service running and diagnosing faults, and retains it under its own schedule — see retention below.

Separately, an IP address you submit to the IP lookup endpoints is a query, not a record about you. It is matched against a geolocation dataset to produce the country, city, coordinates and time zone in the response, and it is not stored: it appears in the request log line like any other request path, and nowhere else. Looking up an address here creates no profile of it and no history of having looked it up.

Retention

Data Why we keep it How long
Account record and API keys You have an account until you delete your account
Request usage counters Quota enforcement and your usage history 13 months
Login attempts (email and IP) Brute-force defence 30 days
Expired password-reset tokens Answering questions about a reset that did not arrive 30 days
Onboarding stage records First-party product analytics until you delete your account
Payment-provider event records Not processing the same billing event twice 90 days
Sessions Keeping you signed in 30 days, and destroyed when you log out or delete your account
Server logs (including request IP) Operations, fault diagnosis, security a rolling window bounded by log rotation, typically days
Telemetry (including request IP) Operations, fault diagnosis, security the observability provider's own retention period

The periods in the third column are enforced by an automated job that deletes expired rows on a schedule, not by intention and not on request. Server logs are bounded by size rather than by a fixed number of days — each container keeps at most 10 MB across three rotated files, so the elapsed window that represents moves with traffic. Telemetry retention is set by the observability provider and governed by its policy, not by this one.

Who else processes your data

Your data is not sold, and it is not shared for anyone's advertising. It reaches the following categories of provider, each processing it only to deliver the function named:

These providers run in regions that may be outside Spain, so your data may be processed outside it. Where that is the case, the transfer relies on the safeguards in the contract between the operator and that provider. If you want to know the current region and safeguard for a specific provider, ask at brscimen@gmail.com — this list is written by category so that changing a provider's region does not make it untrue, but the answer for any given day is a question we will answer.

Your rights

Every right below is granted to every user, wherever you live. There is no separate section for one region: one policy, one set of rights. Each one names how to exercise it, because a right with no stated mechanism is not a right.

What deletion does

Deleting your account is immediate and is never blocked on billing state. It revokes every API key, destroys every active session, cancels any active subscription immediately with no refund of the remaining paid period, and erases your personal data: your email address, your password hash, your keys, your usage counters, your login attempts and your onboarding records.

One record survives, and it contains no personal data: a reference linking the deleted account to the customer record at our payment provider. It exists so that a billing message arriving after deletion resolves to a known, deleted customer instead of being retried against nothing. It holds no email address, no name and no usage.

Invoices, charges and tax records are held by the payment provider as an independent controller, under legal obligations of its own that this service cannot waive on your behalf. This service stores no invoices, no charges and no tax records — deleting your account here does not and cannot reach the provider's financial records. To ask about those, contact the payment provider directly.

Automated decision-making

There is none. Rate limiting and quota enforcement are deterministic threshold rules — a request count is compared against your plan's published limit — with no profiling, no scoring and no legal or similarly significant effect on you. Nothing here builds a model of you or predicts anything about you.

Complaints

If you think your data has been handled wrongly, please raise it at brscimen@gmail.com first — it is usually the fastest way to fix it. You also have the right to complain to a data protection supervisory authority without contacting us at all: the authority in Spain, where the operator is established, or the one in your own country of residence.

Changes to this policy

This policy may change. Material changes will be announced and the "Last updated" date at the top of this page will change with them. Because the retention periods above are checked against the code that enforces them, a change to one is a change to both.