Privacy Policy
Last updated: October 8, 2026 · Version 1.8
Revision 1.8 (October 8, 2026): section 1 now names, among the uses of the e-mail address, at most one note from the founder asking whether the key is useful, and says that a reply STOP ends everything but legal and security notices; the payment data row says that we keep the payer's e-mail address, the amount and the currency of each purchase, and that an invoice you ask for carries the name and address you give us and is kept ten years, as Swiss accounting law requires. Nothing new is collected.
Revision 1.7 (October 6, 2026): section 1 now says that the network edge log of our API host records the request path, without saying whether the query string is kept: we observed it absent once, and Railway's documentation does not say. The advice is therefore wider: send IBANs in the body of a POST request, never in a URL. Section 2 now says where the API and the website's functions run, and that the operator is established in Switzerland, instead of saying that processing stays within the EU. Sections 2 and 4 now describe the backups of the account state, which already exist, and how long a deleted e-mail address can remain in them. Section 3 adds these backups to Infomaniak's role, and says more precisely what Anthropic can receive: the API never sends it an IBAN. It also points to the transfer mechanism of each processor, listed in Annex II of the DPA and on the Security and trust page. A German courtesy translation is published; the English version prevails. Nothing new is collected.
Revision 1.6 (October 5, 2026): sections 1 to 4 now describe the processing as it already works, more precisely. For an invalid IBAN, at most the first 4 characters (country code and check digits) are kept, not 12. The network edge of our API host keeps the raw IP address and the path of each request for 7 days, outside our own logs. The website's functions run in the Frankfurt region (EU). The processor list now says which processors can receive the IBANs you submit. Nothing new is collected.
Revision 1.5 (September 27, 2026): section 1 and the retention summary now describe the file audit: the annotated report it produces, which reproduces the columns of the uploaded file, is kept 2 hours if unpaid and 24 hours after payment, then deleted. It describes the file audit as it already works; nothing new is collected.
Revision 1.4 (September 26, 2026): section 1 now says that, for a USDC purchase, we store the paying wallet address and the on-chain transaction hash, to reconcile a payment whose settlement could not be confirmed.
Revision 1.3 (September 24, 2026): section 6 now describes the sign-in cookie and the sign-in codes of the account page.
Revision 1.2 (August 6, 2026): the daily account-lifecycle job moved from CI into the API runtime itself — GitHub's runners no longer process account data at all; the GitHub row below is updated accordingly.
Revision 1.1 (August 5, 2026): corrected the hosting region — the API runs in Railway's Amsterdam (EU) region, not Zurich; only Railway's network edge sits in Zurich. Completed the processor list (AI drafting assistance, CI infrastructure, dashboard traffic), added the feedback-reports row and the business-contacts section.
This policy explains what personal data IBANforge (see Legal Notice) processes when you use ibanforge.com and api.ibanforge.com, under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR. The short version: IBANs you submit for validation are processed in memory and are not stored. A file you upload to the file audit is kept only as its annotated report, 2 hours if unpaid and 24 hours after payment.
1. What we process, and why
| Data | Purpose | Stored? |
|---|---|---|
| IBANs submitted for validation | Validation and enrichment (performance of the service) | No. Processed in memory, never written to storage. One exception: for invalid IBANs, at most the first 4 characters (country code and check digits, never the bank or account part) may be retained for data-quality diagnostics. |
| Files uploaded to the file audit (for example payee names, IBANs and addresses) | Producing the annotated report you order (performance of the service) | Yes, briefly. The report reproduces the columns of the uploaded file. It is kept 2 hours if unpaid and 24 hours after payment, then automatically deleted. |
| Email address (free key signup) | Issuing your key, quota notifications, service messages, and at most one note from the founder asking whether the key is useful. A reply STOP ends everything but legal and security notices. | Yes, while your key exists; after deletion, backups that still hold it age out within 90 days. |
| Request metadata (path, status, latency, timestamp, pseudonymised IP, user-agent, key prefix) | Abuse prevention, capacity planning, the public status page | Yes, 12 months maximum, then automatically deleted. |
| Network edge log of our API host (raw IP address, request path, status, user-agent, timestamp) | Kept by Railway, our API host, to route and secure traffic, outside our own logs | Yes, 7 days, then deleted by Railway. Send IBANs in the body of a POST request, never in a URL. |
| Aggregated statistics (daily counts by endpoint/country — no personal data) | Product analytics, public metrics | Yes, indefinitely (anonymous). |
| Payment data | Processing card or USDC payments | Handled by Stripe / the x402 facilitator. We never see card numbers; we store the transaction reference and, for a USDC purchase, the paying wallet address and the on-chain transaction hash, to reconcile a payment whose settlement could not be confirmed. We also keep the payer's e-mail address, the amount and the currency of each purchase. If you ask for an invoice, it carries the name and address you give us, and we keep it for ten years, as Swiss accounting law requires. |
| Feedback reports (free-form report, optional contact address) | Investigating data-quality issues, x402 refund decisions | Yes, 12 months, then automatically deleted. |
IP addresses are pseudonymised before they enter our own logs: we keep only a salted hash, never the raw address. The edge log of our API host, described above, keeps the raw address for 7 days.
2. Where the data lives
The API and its databases run on Railway infrastructure in the Amsterdam, Netherlands region (EU), fronted by Railway's European network edge (Zurich for most Swiss traffic). The website's functions run in Vercel's Frankfurt, Germany region (EU); its static pages are served from Vercel's global network. The operator is established in Switzerland, which the European Commission recognises as providing an adequate level of protection; Swiss law recognises the EU likewise. The account state is backed up every night to a server of Infomaniak in Switzerland, which keeps 30 days of copies; monthly copies, the last three kept, are held on a computer operated by the operator in Switzerland. The account state covers the API keys (as hashes) and the e-mail addresses attached to them, quotas, credit balances, monthly usage counts, purchase records (payment references, payer e-mail, and for USDC the paying wallet address and transaction hash), and the records of key creation, claim and revocation, with the salted IP hash and user-agent recorded for them. It contains no IBAN submitted for validation and not the request log. Section 3 lists the processors and where they operate, and this policy and the DPA apply regardless of where you are.
3. Processors we use
| Processor | Role | Location/region | Receives the IBANs you submit? |
|---|---|---|---|
| Railway Corp. | API hosting & storage | Region: Amsterdam (EU) | Yes, in memory, to answer the request |
| Vercel Inc. | Website & dashboard hosting — customer data transits its functions when the operator uses the dashboard, and playground submissions are relayed to the API | Functions: Frankfurt (EU); static pages: global CDN | Only an IBAN typed into the website's playground, relayed to the API |
| Stripe Payments Europe | Card payments | EU | No |
| Coinbase (CDP facilitator) | x402/USDC settlement (x402.org facilitator as fallback) | US | No |
| Infomaniak Network SA | Transactional & support email (operator-managed relay); nightly backup of the account state | Switzerland | Only an IBAN you write in an e-mail to us |
| GitHub Inc. | Public source code & CI (no customer data — scheduled data-refresh jobs handle public reference files only) | US | No |
| Anthropic PBC | AI-assisted drafting of customer correspondence, operator-triggered, under redaction rules | US | The API never sends it one; only an IBAN you write in an e-mail to us |
Where processors are outside Switzerland/EEA, transfers rely on adequacy decisions (for US processors certified under them, the EU-US and Swiss-US Data Privacy Framework) or standard contractual clauses maintained by the processor. The mechanism for each processor is listed in Annex II of the DPA and on the Security and trust page.
4. Retention summary
- IBANs submitted for validation: not stored (invalid-IBAN prefixes of at most 4 characters: up to 12 months as request metadata).
- Edge log of our API host (raw IP address and path): 7 days, kept and deleted by Railway.
- File audit: the annotated report is deleted 2 hours after the upload if unpaid, and 24 hours after payment otherwise.
- Request metadata: 12 months, purged automatically. For API customers who terminate, metadata attributable to their keys is deleted by default 30 days after termination (DPA clause 4.7).
- Key account (email): lifetime of the key; deleted from the live record on request; backups that still hold it age out within 90 days.
- Backups of the account state: 30 days of nightly copies on a server of Infomaniak in Switzerland; monthly copies, the last three kept, on a computer operated by the operator in Switzerland.
- Anonymous aggregates: kept indefinitely.
5. Your rights
Under the FADP/GDPR you can request access, rectification, deletion, restriction, or a copy of your data, and object to processing. Write to support@ibanforge.com — we answer within 30 days. Deleting your email deactivates your API key. If you are in the EU/EEA you may lodge a complaint with your supervisory authority; in Switzerland, with the FDPIC.
6. Cookies and website
The website uses no advertising trackers. The dashboard uses a session cookie strictly for authentication. The account page uses a sign-in cookie for 7 days, strictly for authentication. Sign-in codes are valid 15 minutes and stored only as a hash. Locale preference is stored client-side.
7. Business contacts and prospecting
For sales and support, IBANforge keeps a lightweight record of business contacts: name, role, professional email address, company, the correspondence exchanged with us, and notes about product needs. Legal basis: legitimate interest in B2B communication (art. 6(1)(f) GDPR; FADP balancing test). We may also record publicly available professional contact details of companies that could plausibly use the Service, in order to write to them once, relevantly.
- These records are never sold, never shared beyond the processors above, and not used for automated profiling.
- Correspondence is kept for the duration of the business relationship; billing-related records follow statutory bookkeeping duties.
- If you want out, reply "remove me" to any message or write to support@ibanforge.com — we delete the contact record and stop writing.
8. Changes
Material changes to this policy are announced on this page and in the changelog 30 days before they take effect.
Contact: support@ibanforge.com