Privacy Policy
The short version: birth data is never persisted. We store the minimum needed to run keys and billing, and nothing else.
Birth data — the product guarantee
Birth dates and times you send to any endpoint (including the demo and MCP tools) are processed in memory only to compute the response, then discarded. They are:
- never written to our database — usage records store only which engine was called, when, and how many times;
- never written to logs — request-URL logging is disabled on our infrastructure precisely because query strings can carry birth parameters, and our application logs are audited (with an automated test) to never contain birth inputs;
- never sent to analytics — we run no third-party analytics scripts and no tracking pixels on this site. All measurement is server-side counting (below), and it never contains birth data.
What we do store
- Account email — to deliver your key and account notices.
- A SHA-256 hash of your API key — never the key itself.
- Usage counters — engine name, hour bucket, call counts — for quota enforcement and billing. No request contents.
- First-party traffic counters — for a few actions (page view, key signup, checkout redirect, newsletter signup, design-partner application) we record the event name, page path, referrer host, campaign tags, and non-identifying qualification bands. No email, name, company, message, IP address, user agent, or birth data is written to analytics. Views of these HTML pages are additionally counted server-side in our analytics tool with the query string stripped and a one-way hash in place of any identifier — no cookie is set and no script runs in your browser for this.
- Design-partner applications — when you apply, we use the contact details, product URL, and project description you submit to evaluate and operate the cohort. Application details are delivered to our operating inbox and are not added to the MysticAPI account database.
Third parties we rely on
- Stripe processes payments; we never see your card details. Stripe shares with us your checkout email and subscription status.
- Resend delivers key emails and design-partner applications to our operating inbox.
- beehiiv hosts the optional Sky letter newsletter. Subscribing sends your email to beehiiv (not to our database); every issue carries an unsubscribe link.
- PostHog stores the server-side page-view counts described above: page URL without its query string, referrer, and a one-way hash — never birth data, form contents, IP addresses, or account details.
- Cloudflare runs the service infrastructure; Oracle Cloud Infrastructure hosts the Postgres database (accounts, hashed keys, usage counters, and privacy-preserving first-party funnel events only).
- x402 payments settle on a public blockchain (Base). On-chain transactions are public by the nature of the chain; they carry no birth data.
Retention and deletion
Account email, hashed keys, and usage counters are kept while your account is active. Design-partner applications are reviewed for up to 90 days; accepted-partner records are retained for the duration of the working relationship. Email support@mysticapi.com to delete your account or application; we remove the account row and its keys (usage counters are anonymized by the deletion cascade).
Contact
support@mysticapi.com, or reply to your key email. Effective: 2026-07-07.